Historical retrospective · Bitcoin

BIP 340 specified Schnorr signatures for secp256k1

BIP 340 defines Schnorr signatures over the secp256k1 curve, including encoding and verification rules for Bitcoin’s Taproot upgrade.

Proposal / specification year: 2020First published

Schnorr signatures support key aggregation and more efficient signature verification in some constructions, while giving the protocol a carefully specified alternative to ECDSA.

The specification was a prerequisite for Taproot’s broader script and privacy improvements.

Cryptographic primitives are only as strong as their implementation and review; formal standards reduce ambiguity but do not eliminate implementation risk.

Primary source

This retrospective summarizes the source below in original language. The displayed year refers to the dated event, proposal or specification; it is not the article’s publication date. This is not investment, legal or security advice.

BIP 340 ↗