Featured Developer Sponsor • Zero-Token Protection
Bitcoin BIP 352 Standard
Reusable sp1... Static Address
Zero Address-Reuse Taproot
BIP 352 Silent Payments Studio
Simulate Bitcoin BIP 352 Silent Payments. Inspect dual-key generation (B_scan & B_spend), Alice's input-aggregated ECDH tweak derivation, on-chain Taproot output synthesis, and Bob's light-client scanning engine.
1. Recipient Key Material (Bob — Merchant)
sp1qq9w7c5g998e3y327s5m... (67-byte bech32m)
2. Sender Transaction Setup (Alice)
ECDH Tweak Scalar (t)
0x4c2b9f...
H(a_sum · B_scan)
On-Chain Output Key (P)
028a3f1b...
B_spend + t · G
Address Unlinkability
100.0%
Zero chain graph trace
Bob Detection Status
DETECTED
Private key derived!
Spendable Private Key (p)
b_spend + t mod n
Ready for Taproot spend
3. Dual-Key Diffie-Hellman Cryptographic Flow
Step 1: Alice's Tweak Derivation
Inputs: [UTXO 1, UTXO 2] → Sum: a_sum.
ECDH: S = a_sum · B_scan.
Tweak scalar: t = H("BIP0352/SharedSecret", S, k).
One-time Output: P = B_spend + t · G.
ECDH: S = a_sum · B_scan.
Tweak scalar: t = H("BIP0352/SharedSecret", S, k).
One-time Output: P = B_spend + t · G.
Step 2: On-Chain Public Footprint
Broadcasted Script:
Chain Observers See: Normal Taproot spend.
Address reuse: NONE (P is mathematically unique).
Link to Bob's sp1... address: IMPOSSIBLE.
OP_1 <P> (34 bytes).Chain Observers See: Normal Taproot spend.
Address reuse: NONE (P is mathematically unique).
Link to Bob's sp1... address: IMPOSSIBLE.
Step 3: Bob's Scanning & Spend Key
Bob checks TX inputs: computes A_sum.
ECDH: S' = b_scan · A_sum == S!
Recovers tweak: t = H(S', k).
Computes: p = (b_spend + t) mod n → Spends UTXO!
ECDH: S' = b_scan · A_sum == S!
Recovers tweak: t = H(S', k).
Computes: p = (b_spend + t) mod n → Spends UTXO!
4. BIP 352 Python Reference Implementation (secp256k1)
Sponsored Utility
While You're Here
Sponsored Recommendations
Advertisement