Public key recovery for EC leaves in P2MR (BIP-360)

Posted by sipa

Jul 8, 2026/02:30 UTC

The discussion revolves around the complexities and strategic decisions involved in adopting specific types of cryptographic outputs, notably P2MR (Pay-to-Multisig-Reuse) and P2TRv2 (Pay-to-Taproot Version 2), as well as considering an additional combination of P2QR and P2TRv2. The primary concern with blending P2MR and P2TRv2 into a single output type, such as P2TRH, is that it introduces greater complexity without sufficient benefits to justify such a design. This approach would entail a new BIP340 variant that includes keyhash-commitment and recovery, compromises on batch validation, and eliminates the simplicity benefits derived from direct public keys used in ring signatures and other similar constructions. These issues underscore the potential drawbacks of merging these two types into one, suggesting that maintaining them as distinct outputs could be more advantageous.

Moreover, there is a proposition to consider integrating P2QR with P2TRv2. P2QR is seen as potentially more robust in providing security that does not rely on the actions within the ecosystem, particularly for users who may reuse addresses or share public keys—practices deeply embedded in current workflows. However, this comes at a significant cost and may not suit everyone, making P2TRv2 a necessary alternative. The critique of P2QR lies in its promise of post-quantum security, which might be misleading if address reuse or unconventional practices are involved, thus reducing the effectiveness of the security measures promised under such conditions.

Additionally, concerns are raised about the practical equivalence of P2MR and P2QR if elliptic curve cryptography (ECC) disabling occurs as expected by proponents of P2TRv2. This scenario suggests a reliance on ECC disabling to compensate for security lapses due to non-ideal user practices—a strategy that might not hold up if the disabling does not perform as anticipated. This highlights the underlying issue of depending on theoretical advantages that may not materialize, thereby posing risks to the security framework supposed to protect users under various circumstances.

Link to Raw Post
Bitcoin Logo

TLDR

Join Our Newsletter

We’ll email you summaries of the latest discussions from high signal bitcoin sources, like bitcoin-dev, lightning-dev, and Delving Bitcoin.

Explore all Products

ChatBTC imageBitcoin searchBitcoin TranscriptsSaving SatoshiDecoding BitcoinWarnet
Built with 🧡 by the Bitcoin Dev Project
View our public visitor count

We'd love to hear your feedback on this project.

Give Feedback