Public key recovery for EC leaves in P2MR (BIP-360)

Jun 6 - Jul 13, 2026

  • The email discussion presents a detailed exploration of the proposed optimization for BIP-360, focusing on various cryptographic implications, security risks, and potential efficiency improvements within blockchain technology.

The proposal introduces a recoverable elliptic curve (EC) leaf within a Pay-to-Merkle-root (P2MR) structure, aiming to reduce the witness size in transactions involving EC public keys without increasing quantum vulnerability. This method eliminates the need for a script containing the EC public key from the witness, allowing the public key to be derived directly from the signature using a modified Schnorr verification equation. This optimization is designed to reduce blockchain space usage and lower transaction costs while maintaining resistance to quantum attacks.

The proposal also details technical changes necessary for implementing this optimization, including modifications to how witnesses are parsed and validated due to the absence of a traditional script component in the recoverable EC leaf. This streamlined witness structure would include only essential elements like the signature and a control block defining the leaf version and path within the Merkle tree.

Additionally, the email discusses the broader implications of using hardened elliptic curve keys in the P2MR constructions to prevent derivation from an extended public key (xpub), enhancing security against quantum-capable attackers. It emphasizes that even though using xpubs for key derivation is considered safe under current conditions, this assumes that xpubs remain confidential. In scenarios where quantum attackers might access these, additional protections for the associated chaincode are necessary.

Moreover, the possibility of integrating the hash of the public key in the Schnorr challenge to enhance pubkey recovery processes in future upgrades is explored. This could potentially improve privacy and security but may require adjustments in weight units due to increased computational overhead. The trade-offs between CPU usage and bandwidth consumption offer flexibility depending on the verification practices at the node level.

In conclusion, while the introduction of new cryptographic methods in the P2MR setups presents operational challenges, particularly in terms of performance and usability, the strategic benefits, especially concerning security against emerging quantum threats, justify exploring and potentially adopting these complexities. The ongoing developments and optimizations in related cryptographic libraries could further mitigate some of the initial concerns regarding efficiency and cost, paving the way for more secure and efficient cryptographic practices in blockchain technologies.

Link to Raw Post
Bitcoin Logo

TLDR

Join Our Newsletter

We’ll email you summaries of the latest discussions from high signal bitcoin sources, like bitcoin-dev, lightning-dev, and Delving Bitcoin.

Explore all Products

ChatBTC imageBitcoin searchBitcoin TranscriptsSaving SatoshiDecoding BitcoinWarnet
Built with 🧡 by the Bitcoin Dev Project
View our public visitor count

We'd love to hear your feedback on this project.

Give Feedback