Skip to content
Satnam SatoshiIn service of humanityFind your place ↗
Menu

Sikh Bitcoin · Advanced · Lesson 12 of 21

Taproot and Schnorr: useful, not magical

Understand spend paths and the boundaries of privacy gains.

About 14 minutes with practice. You only need something to take notes with. No real wallet details or payments are part of this lesson.

Course contents · Lesson 12 of 21
  1. Read the whitepaper as an argument
  2. Hashes and Merkle commitments
  3. UTXOs, change and accounting
  4. Scripts describe spending conditions
  5. Signatures and what they authorize
  6. Block headers and the chain of work
  7. Difficulty, hashrate and noisy observations
  8. Issuance, fees and incentives
  9. Mempools and policy are not consensus
  10. Fee changes: RBF and CPFP
  11. SegWit and transaction weight
  12. Taproot and Schnorr: useful, not magical
  13. HD wallets and derivation paths
  14. PSBT: separate construction from signing
  15. Descriptors make a wallet policy portable
  16. Full nodes, pruning and verification
  17. Reorganizations and lightweight evidence
  18. Lightning channels and HTLCs
  19. Lightning liquidity has direction
  20. Soft forks, proposals and human coordination
  21. Capstone: trace a payment end to end

What you will learn

  • Distinguish key-path and script-path spending.
  • Avoid overstating Taproot privacy or wallet support.

A new spending structure

Taproot combines a key-based spending path with the ability to commit to script alternatives. BIP 340 describes the Schnorr signature construction, and BIP 341 specifies Taproot output and spending rules. A cooperative key-path spend can avoid exposing unused script alternatives. A script-path spend reveals the used script and information needed to validate its commitment.

Privacy depends on what happens

Unused branches can remain hidden, but a Taproot transaction is not automatically anonymous. Network observation, address reuse, transaction amounts and other metadata still matter. Script-path usage can reveal additional structure. Distinguish a privacy improvement in a particular construction from a claim that all transactions are indistinguishable under all circumstances.

Do not invent a signing protocol

The algebraic properties of Schnorr signatures support useful constructions, but safely combining participants’ keys and signatures requires an appropriate protocol. A homemade scheme that adds public keys is not a security review. For an organization, wallet support, backup information and recovery behavior matter as much as the elegance of the script tree. Study the rules with synthetic examples before considering any production policy.

Practice on paper

A backup says only “Taproot wallet,” but the recovery plan relies on an alternative script path. What information is missing?

Reveal the worked answer

The spending policy, relevant keys, derivation and script-tree information may be required. A format label alone does not describe the complete recovery arrangement or prove that a replacement wallet can reconstruct it.

Check your understanding

Choose an answer in your head or on paper, then reveal the explanation. Retry whenever you like. Answers are not submitted or scored; completion marks are your own learning notes.

1. Does a key-path spend reveal every unused script branch?

  • Yes
  • No
Reveal answer 1

No. Avoiding that disclosure is one of the useful properties.

2. Does Taproot eliminate all privacy concerns?

  • Yes
  • No
Reveal answer 2

No. Transaction and network metadata can still identify patterns.

Take this with you

Evaluate the actual spend path and complete recovery policy.

Your learning, at your pace

Read every lesson freely. Optional progress tracking needs JavaScript and browser storage; it does not require an account or wallet.