Skip to content

LibraryScaling2015Design paperCorpus record

Segregated Witness

BIP 141. Eric Lombrozo, Johnson Lau and Pieter Wuille.

Move witness data outside the input script. The transaction id that contracts depend on no longer covers the witness. A new weight limit counts witness bytes less than base bytes.

A reading of the public document. Not a copy of it, and not a claim about a later network that reused the name.

A contract that keys off a transaction id should say whether it means txid or wtxid.

The five-minute read

The defect

A transaction's signature data sat in the part of the transaction that is hashed into the id and counted fully toward the block limit, which made upgrades and capacity both awkward.

The rule

Move witness data outside the input script. The transaction id that contracts depend on no longer covers the witness. A new weight limit counts witness bytes less than base bytes.

How it is put together

The witness is a separate structure. The txid excludes it. The wtxid includes it. Weight, not raw bytes, is the block constraint.

Where the claim stops

Segwit is not the Lightning protocol. It is the transaction format Lightning wanted.

One action, walked through

  1. Spend a segwit output by providing a witness.
  2. Hash the base transaction for the txid.
  3. Count witness bytes with the discount the BIP specifies.
  4. Does the identifier include the witness?

The argument, unpacked

Why it is still on the desk

A contract that keys off a transaction id should say whether it means txid or wtxid.

After the text

Taproot later nested a new witness version. Segwit is the split that made that possible.

What has to be true

  • Segwit is not the Lightning protocol. It is the transaction format Lightning wanted.
  • The discount is a policy. It is not a moral claim about signatures.
  • Old nodes treat these outputs as anyone-can-spend unless they upgrade. That was the activation argument.

What happened after the paper

Taproot later nested a new witness version. Segwit is the split that made that possible.

What to check before you use the idea

  • Does the identifier include the witness?
  • How is weight computed?
  • What does a non-upgraded node think a segwit output is?

Terms

Witness
The signatures and related data, stored apart from the base transaction.
Weight
The block accounting that discounts witness bytes.

The problem the paper names

A transaction's signature data sat in the part of the transaction that is hashed into the id and counted fully toward the block limit, which made upgrades and capacity both awkward.

What the design proposes

  • The witness is a separate structure.
  • The txid excludes it. The wtxid includes it.
  • Weight, not raw bytes, is the block constraint.

How the mechanism is specified

  • Spend a segwit output by providing a witness.
  • Hash the base transaction for the txid.
  • Count witness bytes with the discount the BIP specifies.

What this page does not treat as proven

  • Segwit is not the Lightning protocol. It is the transaction format Lightning wanted.
  • The discount is a policy. It is not a moral claim about signatures.
  • Old nodes treat these outputs as anyone-can-spend unless they upgrade. That was the activation argument.

Why a venture studio still reads it

A contract that keys off a transaction id should say whether it means txid or wtxid.

This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.

Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.