PQC output type discussion

Posted by fjahr

Sep 15, 2026/13:40 UTC

The discussion around Bitcoin Improvement Proposals (BIPs) often revolves around the technical specifications and the practical application of those specifications. The BIPs generally outline how signers should produce and combine their signatures, but they do not dictate the specific processes for how the combining of signatures should be executed within the network by relay nodes or wallets. This lack of directive implies that the responsibility of signature aggregation might fall on the signers themselves rather than being an automated network function.

It's important to recognize that signature aggregation is designed as an opt-in feature where each signer explicitly commits to an aggregation mode through their signature message. This setup suggests that since the signers are already handling the integration work for creating these signatures, they could feasibly manage the combination of these signatures before any broadcast occurs. This method would preempt the need for additional network or peer-to-peer protocol support since the operation is simple and can be performed without incurring high costs.

Furthermore, the email points out that nodes performing such aggregation tasks would essentially be replicating the work already done by the signers but at a later stage and without access to necessary data unless facilitated by a new P2P extension. Such changes would require nodes to handle transactions that aren't fully valid yet, introducing unnecessary complexity into the network with minimal to no clear benefit. This contrasts with other protocols like Mimblewimble, where transaction aggregation, termed "cut-through," is an intrinsic part of the protocol during the relay phase.

In sum, the optimal approach seems to be that signers handle both half and full aggregations directly, whether through interactive or non-interactive methods. This strategy avoids the complications associated with third-party aggregation and aligns well with the current discussions and implementations of signature protocols such as BIP341, which incorporate explicit opt-out mechanisms to prevent unintended aggregation. These mechanisms ensure that signers retain control over their signatures, supporting the integrity and intended functionality of the cryptographic processes outlined in the BIPs.

Link to Raw Post
Bitcoin Logo

TLDR

Join Our Newsletter

We’ll email you summaries of the latest discussions from high signal bitcoin sources, like bitcoin-dev, lightning-dev, and Delving Bitcoin.

Explore all Products

ChatBTC imageBitcoin searchBitcoin TranscriptsSaving SatoshiDecoding BitcoinWarnet
Built with 🧡 by the Bitcoin Dev Project
View our public visitor count

We'd love to hear your feedback on this project.

Give Feedback