Skip to content

LibraryPrivacy2024Design paperCorpus record

MuSig2 PSBT Fields

BIP 373. Ava Chow.

BIP 373, MuSig2 PSBT Fields. The new per-input types are defined as follows: {| ! Name ! ! ! ! Versions Requiring Inclusion ! Versions Requiring Exclusion ! Versions Allowing Inclusion |- | rowspan="2"|MuSig2 Participant Public Keys | rowspan="2"| PSBT_IN_MUSIG2_PARTICIPANT_PUBKEYS = 0x1a | | | rowspan="2"| | rowspan="2"| | rowspan="2"| 0, 2 |- | The MuSig2 aggregate public key (compressed) '''Why the compressed aggregate public key instead of x-only?''' [[bip-0032.mediawiki|BIP 32]] public keys can be derived from a [[bip-0327.mediawiki|BIP 327]] MuSig2 aggregate public key (see: [[bip-0328.mediawiki|BIP 328]]).

Status in the source: Complete. A reading of the public specification, not a copy of it and not a certification.

MuSig2 PSBT Fields is worth reading for the rule it actually adds: The new per-input types are defined as follows: {| ! Name ! ! ! ! Versions Requiring Inclusion ! Versions Requiring Exclusion ! Versions Allowing Inclusion |- | rowspan="2"|MuSig2 Participant Public Keys | rowspan="2"| PSBT_IN_MUSIG2_PARTICIPANT_PUBKEYS = 0x1a | | | rowspan="2"| | rowspan="2"| | rowspan="2"| 0, 2 |- | The MuSig2 aggregate public ke...

The five-minute read

The rule

The new per-input types are defined as follows: {| ! Name ! ! ! ! Versions Requiring Inclusion ! Versions Requiring Exclusion ! Versions Allowing Inclusion |- | rowspan="2"|MuSig2 Participant Public Keys | rowspan="2"| PSBT_IN_MUSIG2_PARTICIPANT_PUBKEYS = 0x1a | | | rowspan="2"| | rowspan="2"| | rowspan="2"| 0, 2 |- | The MuSig2 aggregate public key (compressed) '''Why the compressed aggregate public key instead of x-only?''' [[bip-0032.mediawiki|BIP 32]] public keys can be derived from a [[bip-0327.mediawiki|BIP 327]] MuSig2 aggregate public key (see: [[bip-0328.mediawiki|BIP 328]]).

What was already failing

A signature that does not commit to what the user saw can be replayed into a different spend, a different chain, or a different message.

What the number does not mean

The source marks this complete. That is a statement about the text, not a promise that every wallet or node has shipped it.

What a builder should be able to point at

An implementation either constrains PSBT_IN_MUSIG2_PARTICIPANT_PUBKEYS, PSBT_IN_TAP_BIP32_DERIVATION, PSBT or it is a different design.

One action, walked through

  1. Open BIP 373 and read the status line before the examples.
  2. Write down the rule in one sentence. A fair version of that sentence is: The new per-input types are defined as follows: {| ! Name ! ! ! ! Versions Requiring Inclusion ! Versions Requiring Exclusion ! Versions Allowing Inclusion |- | rowspan="2"|MuSig2 Participant Public Keys | rowspan="2"| PSBT_IN_MUSIG2_PARTICIPANT_PUBKEYS = 0x1a | | | rowspan="2"| | rowspan="2"| | rowspan="2"| 0, 2 |- | The MuSig2 aggregate public key (compressed) '''Why the compressed aggregate public key instead of x-only?''' [[bip-0032.mediawiki|BIP 32]] public keys can be derived from a [[bip-0327.mediawiki|BIP 327]] MuSig2 aggregate public key (see: [[bip-0328.mediawiki|BIP 328]]).
  3. Name the object that changes: PSBT_IN_MUSIG2_PARTICIPANT_PUBKEYS, PSBT_IN_TAP_BIP32_DERIVATION, PSBT.
  4. Ask what an old client, an old contract, or an offline counterparty does. If the document is silent, the silence is part of the design.

The argument, unpacked

What the text is allowed to settle

Bitcoin Improvement Proposal 373 can settle the shape of MuSig2 PSBT Fields. It cannot settle whether a later client, a later fork, or a later wallet still does this.

What this page will not pretend

There is no benchmark, no adoption number, and no claim that the mechanism is safe outside the assumptions written in the source.

What has to be true

  • You are implementing BIP 373 at the status the text itself states: Complete.
  • The object that has to change is PSBT_IN_MUSIG2_PARTICIPANT_PUBKEYS, PSBT_IN_TAP_BIP32_DERIVATION, PSBT. A neighbouring document with a similar name is not this one.
  • Wallet support is not the same as consensus validity.

What happened after the paper

The source marks this complete. That is a statement about the text, not a promise that every wallet or node has shipped it. Later documents can narrow, replace, or ignore this one. Cite the number you mean.

What to check before you use the idea

  • What is covered by the signed bytes in MuSig2 PSBT Fields?
  • Can the same signature be replayed on another chain, account, or message?
  • Which primitive does the text require: PSBT_IN_MUSIG2_PARTICIPANT_PUBKEYS, PSBT_IN_TAP_BIP32_DERIVATION, PSBT?

Terms

BIP 373
The public text titled MuSig2 PSBT Fields.
Complete
The document's own label for how finished the text is. It is not a market fact.

The problem the paper names

A signature that does not commit to what the user saw can be replayed into a different spend, a different chain, or a different message.

What the design proposes

  • The new per-input types are defined as follows: {| ! Name ! ! ! ! Versions Requiring Inclusion ! Versions Requiring Exclusion ! Versions Allowing Inclusion |- | rowspan="2"|MuSig2 Participant Public Keys | rowspan="2"| PSBT_IN_MUSIG2_PARTICIPANT_PUBKEYS = 0x1a | | | rowspan="2"| | rowspan="2"| | rowspan="2"| 0, 2 |- | The MuSig2 aggregate public key (compressed) '''Why the compressed aggregate public key instead of x-only?''' [[bip-0032.mediawiki|BIP 32]] public keys can be derived from a [[bip-0327.mediawiki|BIP 327]] MuSig2 aggregate public key (see: [[bip-0328.mediawiki|BIP 328]]).
  • But since BIP 32 requires public keys to include their evenness byte, BIP 327 MuSig2 aggregate public keys must include their evenness byte as well.
  • Furthermore, PSBT_IN_TAP_BIP32_DERIVATION fields include fingerprints to identify master keys, and these fingerprints require the y-coordinate of the public key, so x-only serialization can't be used.

How the mechanism is specified

  • Taken from the specification, the next constraint is: But since BIP 32 requires public keys to include their evenness byte, BIP 327 MuSig2 aggregate public keys must include their evenness byte as well.
  • Locate PSBT_IN_MUSIG2_PARTICIPANT_PUBKEYS, PSBT_IN_TAP_BIP32_DERIVATION, PSBT in BIP 373 and apply it to one transaction or call.
  • Then check the failure the class of rule always has: a node that did not upgrade, a reverted call, a replayed signature, or a peer that does not speak the message.

What this page does not treat as proven

  • A signature scheme is not a privacy system. It hides the signer only if the protocol says so.
  • Wallet support is not the same as consensus validity.
  • The source marks this complete. That is a statement about the text, not a promise that every wallet or node has shipped it.

Why a venture studio still reads it

Use BIP 373 when a pitch says 'MuSig2 PSBT Fields' without saying whether the rule is consensus, policy, or an interface. The number is the citation. The pitch is not.

This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.

Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.