/
sipaPosted by sipa
Jul 15, 2025/15:35 UTC
The discussion centers on two primary privacy concerns associated with the use of MAST (Merkelized Abstract Syntax Trees) in cryptographic systems. The first issue arises from the potential distinguishability of outputs. Specifically, unless it is mandated that outputs in the MAST root case must resemble valid points on a cryptographic curve, the outputs may be identifiable as only approximately half of all 32-byte values serve as valid X coordinates on such curves. This characteristic can make certain outputs stand out, undermining privacy.
The second concern relates to the implications of spending a MAST root output. When such an output is spent, it inadvertently signals that no key path was ever present within the output. This revelation can provide additional information that might be leveraged in certain analytical or adversarial contexts, further compromising privacy. Together, these issues highlight the complex balance between functionality and privacy in the design and implementation of cryptographic protocols.
TLDR
We’ll email you summaries of the latest discussions from authoritative bitcoin sources, like bitcoin-dev, lightning-dev, and Delving Bitcoin.
We'd love to hear your feedback on this project?
Give Feedback