BIP Draft: Low-R Grinding for ECDSA Signatures #2224

pull liamgilligan wants to merge 1 commits into bitcoin:master from liamgilligan:bip-low-r-grinding changing 1 files +98 −0
  1. liamgilligan commented at 2:59 PM on July 28, 2026: none

    Informational BIP describing low-R grinding: re-deriving the ECDSA nonce under a counter until r has its high bit unset, so the DER encoding needs no leading null byte.

    This was discussed on the mailing list: https://groups.google.com/g/bitcoindev/c/boEZRlqczvw

    Reference implementation and test vectors are TODO.

    Feedback is very welcome.

  2. Add BIP: Low-R Grinding for ECDSA Signatures
    Informational BIP describing low-R grinding: re-deriving the ECDSA
    nonce under a counter until r has its high bit unset, so the DER
    encoding needs no leading null byte.
    0ad92c766a
  3. jonatack added the label New BIP on Jul 28, 2026
  4. murchandamus renamed this:
    Add BIP bip-low-r-grinding: Low-R Grinding for ECDSA Signatures
    BIP Draft: Low-R Grinding for ECDSA Signatures
    on Jul 28, 2026
  5. murchandamus commented at 11:27 PM on July 28, 2026: member

    Thanks, adding this to my to-read list.

  6. craigraw commented at 8:16 AM on July 29, 2026: contributor

    Another important motivation is that signatures produced according to a standardised approach will be byte-identical. This means signers can be compared to ensure they are not leaking secrets by embedding them in signatures (e.g. Dark Skippy).


github-metadata-mirror

This is a metadata mirror of the GitHub repository bitcoin/bips. This site is not affiliated with GitHub. Content is generated from a GitHub metadata backup.
generated: 2026-08-03 08:10 UTC

This site is hosted by @0xB10C
More mirrored repositories can be found on mirror.b10c.me