From mboxrd@z Thu Jan 1 00:00:00 1970 Delivery-date: Tue, 28 Jul 2026 08:04:40 -0700 Received: from mail-oo1-f62.google.com ([209.85.161.62]) by mail.fairlystable.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (Exim 4.94.2) (envelope-from ) id 1wojMF-00007l-QD for bitcoindev@gnusha.org; Tue, 28 Jul 2026 08:04:40 -0700 Received: by mail-oo1-f62.google.com with SMTP id 006d021491bc7-6ab1946bb8esf2205720eaf.2 for ; Tue, 28 Jul 2026 08:04:39 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=googlegroups.com; s=20251104; t=1785251073; x=1785855873; darn=gnusha.org; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :list-id:mailing-list:precedence:x-original-sender:content-type :mime-version:subject:references:in-reply-to:message-id:to:from:date :sender:from:to:cc:subject:date:message-id:reply-to:content-type; bh=Pls6Ifub+T2lntgQDvaTN6DGP9sr5RzADTEdyjYhXMw=; b=lEASi6dEf4cg0Ersrm26muvQMwdMyoyl9UREhxrALlVky24Zn1+X8i2sHYNJ94GdhG xImTIKrHpRIjor3aDfe8WNweLZOGdNgIBsVunkbJrrHVZq8WGO20sa76HP3zStlnNw/z NZFYB46BUnH80zuA5IQO/qAnKF7T2U96YTIizKVr3RK5r6SCR7vRDiEzFMsf2PipyHkc kMuxmTnP48idXzBVw6htrU+14SoGnQhLYzqlM1EEGfC+EmOeii0EvjbNNtY+YtY61qTN U+0FSUlUR3YgO2sf7Vi7Oexau9ao0mF5Yh1lkNgmxy98QjqbanuBJy9l9ZJu/T9wK1bJ Y5Pg== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785251073; x=1785855873; darn=gnusha.org; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :list-id:mailing-list:precedence:x-original-sender:content-type :mime-version:subject:references:in-reply-to:message-id:to:from:date :from:to:cc:subject:date:message-id:reply-to:content-type; bh=Pls6Ifub+T2lntgQDvaTN6DGP9sr5RzADTEdyjYhXMw=; b=eZaU7gVn6VdoR36+jS/JkiHG9VDbjfI0nUyxg6w0ZfYu1wrL0rEnc50Qhi6jULyQ57 FVyxiTaut9u+HMGgcLE2OwkT3UuhfHZQ8J1pJjDeshc5KX0uNkn2PfUBMAnn75WwceCN Ojp7hpebbkNJZPeSg68kyS7cgoC4dlx6PKMr754Q05VYTwTSUmBbGFqNlYjzlBmX+GrI b5HFcZtHLU2uQsc3nACny68H2kG7kVopQwmjz1cAXNhFhTFeoPnUBM9nZPUuKNkEX9n+ e4Y4+66I/LhhyVdf0LqUg69h6hGA8Up9w7xtaNn1a+NRUyE9OwfhV4KKgO/vTZYaIfQq Tx7g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785251073; x=1785855873; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :list-id:mailing-list:precedence:x-original-sender:content-type :mime-version:subject:references:in-reply-to:message-id:to:from:date :x-beenthere:x-gm-message-state:sender:from:to:cc:subject:date :message-id:reply-to:content-type; bh=Pls6Ifub+T2lntgQDvaTN6DGP9sr5RzADTEdyjYhXMw=; b=Vexh5v2COU2YwFs/fR1VUWSVJnBRwEH8wy+9pbKD23gtSZzUyxjCqv7Zu9nhyOVVqx T4LOqYSPnS+RxYxPwNQmyEcqQ4x2A+rF28WHRwbx6qWMCS7zxNjWxm6DXs8ENd3mqeD5 TwetHjwPj6uotPEW51ZWf+jPIaAobJuhRc+WoyOCc5+k67u2FbEom08i4hLtPimwgHTq tBpOsZaJ3iZxvhWbYcY9Z1V3NztoUKJ/GGxxEI92kLX4hC2X+g/M3ewbo4grPErwwspY yCXkSjKV8g8hz06uUnmC991c3wp4eZOqqsWJKGt7qxfRfjIdryjyhqtqi2RmMvl9Lj0u p22w== Sender: bitcoindev@googlegroups.com X-Forwarded-Encrypted: i=1; AHgh+Rox0Ax+VNXMeGAco+CdsJB6aZQr36ri6UGERG+lnzspailz1XClyt+leZsJveVR5J+0ZaAUUwAVbnra@gnusha.org X-Gm-Message-State: AOJu0Yz/51N5uJfEyGLgLWghwYbA/gxSFkccDAyXFZqqtfe6C3LVzZXT 0PxGzynV6TCvZjmhzmWrK/ha6gBC1SDTYJPKdYeB9Iw5zGylGY5z1gip X-Received: by 2002:a05:6820:4c8a:b0:6a1:871b:fffa with SMTP id 006d021491bc7-6ac96d75636mr1357599eaf.51.1785251073515; Tue, 28 Jul 2026 08:04:33 -0700 (PDT) X-BeenThere: bitcoindev@googlegroups.com; h="Aa7YSPRNtYeDnNzFtCToG7oXCrS2J2FB0Nhg0vIzq7Vy5a8NeA==" Received: by 2002:a05:6870:b50d:b0:456:be08:f0b2 with SMTP id 586e51a60fabf-4579d56fbccls3980577fac.0.-pod-prod-07-us; Tue, 28 Jul 2026 08:04:23 -0700 (PDT) X-Received: by 2002:a05:6808:159a:b0:497:deab:2bfe with SMTP id 5614622812f47-4ad5b7e79aamr1713147b6e.1.1785251063732; Tue, 28 Jul 2026 08:04:23 -0700 (PDT) Received: by 2002:a05:690c:c747:b0:81e:e2ea:ecde with SMTP id 00721157ae682-81f5a570109ms7b3; Tue, 28 Jul 2026 08:01:35 -0700 (PDT) X-Received: by 2002:a05:690c:c504:b0:80c:85c6:8989 with SMTP id 00721157ae682-81f993f2b4cmr10484007b3.72.1785250894445; Tue, 28 Jul 2026 08:01:34 -0700 (PDT) Date: Tue, 28 Jul 2026 08:01:34 -0700 (PDT) From: Liam Gilligan To: Bitcoin Development Mailing List Message-Id: <88bb6722-401a-4a6c-81cb-40c804924684n@googlegroups.com> In-Reply-To: References: <44b6bccc-c34f-491c-9f8f-fac5045290de@msgilligan.com> <40918d93-092c-451a-96e1-03f363ac3720@murch.one> Subject: Re: [bitcoindev] [BIP Proposal] Informational BIP on Low-R Signature Grinding MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="----=_Part_806044_1888640547.1785250894029" X-Original-Sender: liamdgilligan@gmail.com Precedence: list Mailing-list: list bitcoindev@googlegroups.com; contact bitcoindev+owners@googlegroups.com List-ID: X-Google-Group-Id: 786775582512 List-Post: , List-Help: , List-Archive: , List-Unsubscribe: , X-Spam-Score: 2.6 (++) ------=_Part_806044_1888640547.1785250894029 Content-Type: multipart/alternative; boundary="----=_Part_806045_427323194.1785250894029" ------=_Part_806045_427323194.1785250894029 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Hey everyone! I went ahead and wrote up a draft and submitted a PR=20 . If you have a chance, I would= =20 love feedback. Thanks, Liam On Tuesday, June 9, 2026 at 11:14:50=E2=80=AFPM UTC Sean Gilligan wrote: Thanks Murch!=20 We will start work on a Draft. Worrying about the test vectors later=20 sounds like a great idea. They are important and probably the hardest=20 part of the effort, but aren't necessary for a draft.=20 As recommended in BIP 3, we'll create a PR against our fork of the BIPs=20 repo and report back when we have made some progress.=20 Regards,=20 Sean=20 On 6/9/26 1:48 PM, Murch wrote:=20 > Hi Sean,=20 >=20 > Thanks for proposing this idea. It would be splendid if someone were=20 > to write up the best practices for low-r signature grinding. You don=E2= =80=99t=20 > need to worry about test vectors too much in advance, they are only=20 > required for advancing a BIP to the Complete status, so if people have=20 > more suggestions, those could also added to the document after the PR=20 > is open or even after it has been published in Draft.=20 >=20 > Cheers,=20 > Murch=20 >=20 > On 2026-06-09 00:02, Sean Gilligan wrote:=20 >> Hi Everyone,=20 >>=20 >> I would like to propose a new informational BIP to formally document=20 >> the Low-R signature algorithm used by Bitcoin Core and many other=20 >> wallets.=20 >>=20 >> It was implemented in 2018 in Bitcoin Core by PR 1366 [0]. The Low-r=20 >> grinding page on Bitcoin Optech [1] references several other=20 >> implementations.=20 >>=20 >> While working on secp256k1-jdk [2] (a new wrapper for secp256k1 for=20 >> Java/JDK/JVM-languages) we ended up looking at the C++ implementation=20 >> for reference and at rust-secp256k1 for a test vector. Since all=20 >> wallets should implement the algorithm identically (for privacy=20 >> reasons) it would be helpful to have the behavior clearly documented=20 >> in an informational BIP.=20 >>=20 >> I have spoken with a handful of developers who think having a BIP=20 >> would be a good idea and it was suggested on PR 13666.=20 >>=20 >> It should be short and relatively simple and also have a nice=20 >> collection of test vectors.=20 >>=20 >> What do people think? Any suggestions on what should be included or=20 >> pointers to test vectors?=20 >>=20 >> Thanks,=20 >>=20 >> Sean=20 >>=20 >> [0] https://github.com/bitcoin/bitcoin/pull/13666=20 >> [1] https://bitcoinops.org/en/topics/low-r-grinding/=20 >> [2] https://github.com/bitcoinj/secp256k1-jdk=20 >>=20 >=20 --=20 You received this message because you are subscribed to the Google Groups "= Bitcoin Development Mailing List" group. To unsubscribe from this group and stop receiving emails from it, send an e= mail to bitcoindev+unsubscribe@googlegroups.com. To view this discussion visit https://groups.google.com/d/msgid/bitcoindev/= 88bb6722-401a-4a6c-81cb-40c804924684n%40googlegroups.com. ------=_Part_806045_427323194.1785250894029 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable
Hey everyone!

I went ahead and wrote up a d= raft and submitted a = PR. If you have a chance, I would love feedback.

=
Thanks,
Liam

On= Tuesday, June 9, 2026 at 11:14:50=E2=80=AFPM UTC Sean Gilligan wrote:
Thanks Murch!

We will start work on a Draft. Worrying about the test vectors later= =20
sounds like a great idea. They are important and probably the hardest= =20
part of the effort, but aren't necessary for a draft.

As recommended in BIP 3, we'll create a PR against our fork of the BI= Ps=20
repo and report back when we have made some progress.

Regards,

Sean


On 6/9/26 1:48 PM, Murch wrote:
> Hi Sean,
>
> Thanks for proposing this idea. It would be splendid if someone = were=20
> to write up the best practices for low-r signature grinding. You= don=E2=80=99t=20
> need to worry about test vectors too much in advance, they are o= nly=20
> required for advancing a BIP to the Complete status, so if peopl= e have=20
> more suggestions, those could also added to the document after t= he PR=20
> is open or even after it has been published in Draft.
>
> Cheers,
> Murch
>
> On 2026-06-09 00:02, Sean Gilligan wrote:
>> Hi Everyone,
>>
>> I would like to propose a new informational BIP to formally = document=20
>> the Low-R signature algorithm used by Bitcoin Core and many = other=20
>> wallets.
>>
>> It was implemented in 2018 in Bitcoin Core by PR 1366 [0]. T= he Low-r=20
>> grinding page on Bitcoin Optech [1] references several other= =20
>> implementations.
>>
>> While working on secp256k1-jdk [2] (a new wrapper for secp25= 6k1 for=20
>> Java/JDK/JVM-languages) we ended up looking at the C++ imple= mentation=20
>> for reference and at rust-secp256k1 for a test vector. Since= all=20
>> wallets should implement the algorithm identically (for priv= acy=20
>> reasons) it would be helpful to have the behavior clearly do= cumented=20
>> in an informational BIP.
>>
>> I have spoken with a handful of developers who think having = a BIP=20
>> would be a good idea and it was suggested on PR 13666.
>>
>> It should be short and relatively simple and also have a nic= e=20
>> collection of test vectors.
>>
>> What do people think? Any suggestions on what should be incl= uded or=20
>> pointers to test vectors?
>>
>> Thanks,
>>
>> Sean
>>
>> [0] https://github.com/bitcoin/bitcoin/pul= l/13666
>> [1] https://bitcoinops.org/en/topics/lo= w-r-grinding/
>> [2] https://github.com/bitcoinj/secp256k1-jdk<= /a>
>>
>

--
You received this message because you are subscribed to the Google Groups &= quot;Bitcoin Development Mailing List" group.
To unsubscribe from this group and stop receiving emails from it, send an e= mail to
bitcoind= ev+unsubscribe@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/bitcoind= ev/88bb6722-401a-4a6c-81cb-40c804924684n%40googlegroups.com.
------=_Part_806045_427323194.1785250894029-- ------=_Part_806044_1888640547.1785250894029--