BIP352: align reference address decoding with silent payment rules #2288

pull ginavalent wants to merge 1 commits into bitcoin:master from ginavalent:master changing 2 files +62 −5
  1. ginavalent commented at 9:35 AM on September 13, 2026: none

    BIP 352 specifies that silent payment addresses use Bech32m encoding and defines forward-compatible address decoding rules for versions 0 through 30.

    The BIP352 reference implementation currently uses the generic SegWit decoder without checking the encoding type, which allows a Bech32 checksum for a silent payment address. It also rejects versions above 16 and passes the complete payload to the spend key parser instead of discarding extension data for future versions.

    Update the BIP352-specific decoder to:

    • require Bech32m encoding;
    • accept versions 0 through 30 and reject version 31;
    • require exactly 66 decoded bytes for version 0;
    • accept at least 66 decoded bytes for versions 1 through 30 and consume only the first 66 bytes.
  2. BIP352: align reference address decoding with silent payment rules
    Signed-off-by: ginavalent <ginavalent@outlook.com>
    c39bae2a3b
  3. murchandamus commented at 3:30 PM on September 15, 2026: member

    Thanks. @theStack, this seems to fix a discrepancy between the specification and the reference implementation. Do you want it?

  4. murchandamus added the label Proposed BIP modification on Sep 15, 2026
  5. murchandamus added the label Pending acceptance on Sep 15, 2026
  6. murchandamus added the label Bug fix on Sep 15, 2026
  7. theStack commented at 3:20 PM on September 16, 2026: contributor

    Concept ACK

  8. fametrano commented at 7:25 PM on October 3, 2026: contributor

    ACK c39bae2a3b65d34b0fb064fb32dacbf5a514a62f

    The decoder now does what the BIP says: bech32m only, exactly 66 bytes for v0, the first 66 bytes for v1 through v30, fail on v31. At c39bae2a the five new tests pass and reference.py send_and_receive_test_vectors.json passes all 28 cases; against master's decoder four of the five new tests fail. I also ran 33 addresses, the ten from the test vectors and 23 constructed edge cases, through the BIP's rules over btclib's bech32m decoder: accept/reject and the decoded keys agree with this PR on all 33, while master differs on nine, among them accepting a v0 address with a bech32 checksum.


github-metadata-mirror

This is a metadata mirror of the GitHub repository bitcoin/bips. This site is not affiliated with GitHub. Content is generated from a GitHub metadata backup.
generated: 2026-10-11 23:10 UTC

This site is hosted by @0xB10C
More mirrored repositories can be found on mirror.b10c.me