Skip to content

LibraryConsensus2017Design paperCorpus record

SIGHASH_ANYPREVOUT for Taproot Scripts

BIP 118. Christian Decker.

BIP 118, SIGHASH_ANYPREVOUT for Taproot Scripts. This BIP modifies the behaviour of the [[bip-0342.mediawiki|BIP 342]] signature opcodes '''What about key path spends?''' This proposal only supports ANYPREVOUT signatures via script path spends, and does not support ANYPREVOUT signatures for key path spends.

Status in the source: Draft. A reading of the public specification, not a copy of it and not a certification.

SIGHASH_ANYPREVOUT for Taproot Scripts is worth reading for the rule it actually adds: This BIP modifies the behaviour of the [[bip-0342.mediawiki|BIP 342]] signature opcodes '''What about key path spends?''' This proposal only supports ANYPREVOUT signatures via script path spends, and does not support ANYPREVOUT signatures for key path spends.

The five-minute read

The rule

This BIP modifies the behaviour of the [[bip-0342.mediawiki|BIP 342]] signature opcodes '''What about key path spends?''' This proposal only supports ANYPREVOUT signatures via script path spends, and does not support ANYPREVOUT signatures for key path spends.

What was already failing

Bitcoin script and block validity only change when a soft fork says an old pattern is now invalid. Without that rule, every node is free to accept what this document wants to reject.

What the number does not mean

The source marks this draft. It is not a live consensus rule just because it has a number.

What a builder should be able to point at

An implementation either constrains ANYPREVOUT, CHECKSIG, CHECKSIGVERIFY or it is a different design.

One action, walked through

  1. Open BIP 118 and read the status line before the examples.
  2. Write down the rule in one sentence. A fair version of that sentence is: This BIP modifies the behaviour of the [[bip-0342.mediawiki|BIP 342]] signature opcodes '''What about key path spends?''' This proposal only supports ANYPREVOUT signatures via script path spends, and does not support ANYPREVOUT signatures for key path spends.
  3. Name the object that changes: ANYPREVOUT, CHECKSIG, CHECKSIGVERIFY.
  4. Ask what an old client, an old contract, or an offline counterparty does. If the document is silent, the silence is part of the design.

The argument, unpacked

What the text is allowed to settle

Bitcoin Improvement Proposal 118 can settle the shape of SIGHASH_ANYPREVOUT for Taproot Scripts. It cannot settle whether a later client, a later fork, or a later wallet still does this.

What this page will not pretend

There is no benchmark, no adoption number, and no claim that the mechanism is safe outside the assumptions written in the source.

What has to be true

  • You are implementing BIP 118 at the status the text itself states: Draft.
  • The object that has to change is ANYPREVOUT, CHECKSIG, CHECKSIGVERIFY. A neighbouring document with a similar name is not this one.
  • Activation is a separate mechanism from the opcode or the sighash. This page does not pick a height.

What happened after the paper

The source marks this draft. It is not a live consensus rule just because it has a number. Later documents can narrow, replace, or ignore this one. Cite the number you mean.

What to check before you use the idea

  • Which bytes become invalid under SIGHASH_ANYPREVOUT for Taproot Scripts, and which old transactions stay valid?
  • Is enforcement in consensus, or only in the mempool policy of one client?
  • Which of these objects does the text actually define: ANYPREVOUT, CHECKSIG, CHECKSIGVERIFY?

Terms

BIP 118
The public text titled SIGHASH_ANYPREVOUT for Taproot Scripts.
Draft
The document's own label for how finished the text is. It is not a market fact.

The problem the paper names

Bitcoin script and block validity only change when a soft fork says an old pattern is now invalid. Without that rule, every node is free to accept what this document wants to reject.

What the design proposes

  • This BIP modifies the behaviour of the [[bip-0342.mediawiki|BIP 342]] signature opcodes '''What about key path spends?''' This proposal only supports ANYPREVOUT signatures via script path spends, and does not support ANYPREVOUT signatures for key path spends.
  • This is for two reasons: first, not supporting key path spends allows this proposal to be independent of the core changes included in [[bip-0341.mediawiki|BIP 341]] and [[bip-0342.mediawiki|BIP 342]]; second, it allows addresses to opt-in or opt-out of ANYPREVOUT support while remaining indistinguishable prior to being spent.
  • ( CHECKSIG , CHECKSIGVERIFY , and CHECKSIGADD ) for public keys that have a length of 33 bytes and a first byte of 0x01 or the public key which is precisely the single byte vector 0x01 '''Use of 0x01 public key type''' Because OP_0 leaves an empty vector on the stack it would not satisfy [[bip-0342.mediawiki|BIP 342]]'s rules for unknown public key types.

How the mechanism is specified

  • Taken from the specification, the next constraint is: This is for two reasons: first, not supporting key path spends allows this proposal to be independent of the core changes included in [[bip-0341.mediawiki|BIP 341]] and [[bip-0342.mediawiki|BIP 342]]; second, it allows addresses to opt-in or opt-out of ANYPREVOUT support while remaining indistinguishable prior to being spent.
  • Locate ANYPREVOUT, CHECKSIG, CHECKSIGVERIFY in BIP 118 and apply it to one transaction or call.
  • Then check the failure the class of rule always has: a node that did not upgrade, a reverted call, a replayed signature, or a peer that does not speak the message.

What this page does not treat as proven

  • A soft fork does not bind a node that never upgrades. It binds the nodes that enforce the new rejection.
  • Activation is a separate mechanism from the opcode or the sighash. This page does not pick a height.
  • The source marks this draft. It is not a live consensus rule just because it has a number.

Why a venture studio still reads it

Use BIP 118 when a pitch says 'SIGHASH_ANYPREVOUT for Taproot Scripts' without saying whether the rule is consensus, policy, or an interface. The number is the citation. The pitch is not.

This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.

Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.