Skip to content

LibraryMarkets2017Design paperCorpus record

Discreet Log Contracts

Discreet log contracts. Thaddeus Dryja.

The oracle publishes a signature on an outcome. Parties use adaptor signatures so the signature that settles the contract also reveals the oracle's secret, without the oracle knowing which contract it served.

A reading of the public document. Not a copy of it, and not a claim about a later network that reused the name.

An oracle pitch that puts the contract address in the oracle's log has refused the privacy property this paper is about.

The five-minute read

The defect

A bet that settles on a chain wants an oracle. Publishing the oracle's answer in clear couples the oracle to every contract that used it.

The rule

The oracle publishes a signature on an outcome. Parties use adaptor signatures so the signature that settles the contract also reveals the oracle's secret, without the oracle knowing which contract it served.

How it is put together

The oracle does not see the contract. The contract pays out only if the oracle's signature is published. Adaptor signatures are the join.

Where the claim stops

The oracle can still lie, go silent, or sign two outcomes if the scheme allows it.

One action, walked through

  1. Parties lock coins under a contract that embeds the oracle's public nonce.
  2. The oracle later signs an outcome.
  3. That signature completes one party's transaction and pays them.
  4. Does the oracle see the contract?

The argument, unpacked

Why it is still on the desk

An oracle pitch that puts the contract address in the oracle's log has refused the privacy property this paper is about.

After the text

DLC work on Bitcoin continued from this note. Attestation schemes differ. The adaptor-signature join is the idea.

What has to be true

  • The oracle can still lie, go silent, or sign two outcomes if the scheme allows it.
  • This is not a price feed for a lending protocol.
  • It does not remove the need to list the outcomes in advance.

What happened after the paper

DLC work on Bitcoin continued from this note. Attestation schemes differ. The adaptor-signature join is the idea.

What to check before you use the idea

  • Does the oracle see the contract?
  • What if the oracle never signs?
  • Are the outcomes enumerated in advance?

Terms

Adaptor signature
A signature that becomes valid when a secret, here the oracle's, is known.
Outcome
One of the results the contract listed before locking funds.

The problem the paper names

A bet that settles on a chain wants an oracle. Publishing the oracle's answer in clear couples the oracle to every contract that used it.

What the design proposes

  • The oracle does not see the contract.
  • The contract pays out only if the oracle's signature is published.
  • Adaptor signatures are the join.

How the mechanism is specified

  • Parties lock coins under a contract that embeds the oracle's public nonce.
  • The oracle later signs an outcome.
  • That signature completes one party's transaction and pays them.

What this page does not treat as proven

  • The oracle can still lie, go silent, or sign two outcomes if the scheme allows it.
  • This is not a price feed for a lending protocol.
  • It does not remove the need to list the outcomes in advance.

Why a venture studio still reads it

An oracle pitch that puts the contract address in the oracle's log has refused the privacy property this paper is about.

This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.

Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.