Skip to content

LibraryPrivacy2020Design paperCorpus record

BIP 341: Taproot: SegWit version 1 spending rules

Taproot. Pieter Wuille, Jonas Nick and Anthony Towns.

A Bitcoin spend that can look like a single key, while still hiding a tree of alternative scripts until one of them is used. Schnorr signatures and the key-path spend are the mechanism. Amounts stay public. This is not a privacy coin.

Taproot is a Bitcoin spending rule. A key-path spend is a single Schnorr signature and reveals no script. A script-path spend reveals only the leaf that was used. Complex contracts can therefore look like ordinary payments until they do not. Amounts and the transaction graph stay public.

The five-minute read

The tweak commits to the tree

The on-chain key is the internal key tweaked by the Merkle root of the scripts. A key-path signature is valid only for the party who knows that key. The scripts stay off-chain unless needed.

One leaf, not the whole contract

The script path publishes one leaf and a Merkle proof. Unused branches are not revealed. That is the privacy gain, and its limit.

Three BIPs

BIP 340 is Schnorr. BIP 341 is this spending rule. BIP 342 is the small script upgrade used inside leaves. A wallet can implement one badly and still say Taproot.

The anonymity set is social

Key-path spends resemble each other only if people actually use them. A network where every interesting contract takes the script path immediately does not get the set the BIP describes.

One action, walked through

  1. A wallet constructs an internal key and an optional script tree.
  2. It publishes the tweaked key as the output.
  3. To take the key path, it produces a Schnorr signature.
  4. To take a script path, it reveals the leaf, the proof, and whatever that leaf's script requires.
  5. Nodes apply BIP 341's weight and validation rules. They do not learn the unused leaves.

The argument, unpacked

Not a privacy coin

Nothing in the BIP hides amounts or breaks the transaction graph. A reader who needs those properties is in the wrong paper. CryptoNote and Zerocash are about different designs.

Not a new execution engine

Taproot does not make Bitcoin script Turing-complete. BitVM is a later attempt to dispute general computation using Taproot trees, and it is a different document.

What has to be true

  • Outputs use this witness version. A wrapped older script is not in the anonymity set.
  • Key-path keys are aggregated properly when more than one party must sign. That is MuSig2 or FROST, not BIP 341 alone.
  • Unused script leaves remain private only if they are not published elsewhere.
  • Consensus rules are the BIPs as deployed. Draft text and activated text should not be mixed silently.

What happened after the paper

Taproot activated on Bitcoin and became the assumed output type for new Lightning and for MuSig2 wallets. The BIP is still the right document for what a spend reveals. It is the wrong document for a claim that Bitcoin transactions became private.

What to check before you use the idea

  • Was the spend key path or script path?
  • What did the revealed leaf contain?
  • Are amounts still public? Yes.
  • If several parties hold the key, which multi-signature scheme produced it?

Terms

Key path
A spend that is just a signature under the tweaked key, with no script revealed.
Script path
A spend that reveals one committed script leaf and a Merkle proof of its place in the tree.

The problem the paper names

Complex Bitcoin scripts announce themselves. A multisig, a lightning channel and a simple payment should not have to look different when they take the ordinary path. Taproot makes the ordinary path a key spend.

What the design proposes

  • A public key tweaked by the Merkle root of a script tree.
  • The key path spends with a Schnorr signature and reveals no script.
  • The script path reveals only the leaf that was used, plus a proof it sat in the tree.

How the mechanism is specified

  • Unspent outputs that share this pattern are indistinguishable from each other on the key path.
  • Taking the script path publishes that leaf. The privacy claim is about the path not taken.
  • BIP 341 is the spending rule. BIP 340 is the signature. BIP 342 is the script opcode change. They travel together in deployment and they are not the same document.

What this page does not treat as proven

  • Amounts, the graph of transactions, and a revealed script are still visible.
  • If most users do not use the key path, the anonymity set the BIP hopes for does not arise.
  • The BIP does not create covenants, a virtual machine, or a bridge.

Why a venture studio still reads it

A wallet that says Taproot should be able to say whether a given spend was key path or script path. If every spend reveals a custom script, the BIP's privacy argument is not in use.

This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.

Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.