LibraryScaling2023Design paperCorpus record
Silent Payments
BIP 352. josibake.
BIP 352, Silent Payments. We use the following functions and conventions: ''outpoint'' (36 bytes): the COutPoint of an input (32-byte txid, least significant byte first || 4-byte vout, least significant byte first) '''Why are outpoints little-endian?''' Despite using big endian throughout the rest of the BIP, outpoints are sorted and hashed matching their transaction serialization, which is little-endian.
Status in the source: Complete. A reading of the public specification, not a copy of it and not a certification.
Silent Payments is worth reading for the rule it actually adds: We use the following functions and conventions: ''outpoint'' (36 bytes): the COutPoint of an input (32-byte txid, least significant byte first || 4-byte vout, least significant byte first) '''Why are outpoints little-endian?''' Despite using big endian throughout the rest of the BIP, outpoints are sorted and hashed matching their transaction serializa...
The five-minute read
The rule
We use the following functions and conventions: ''outpoint'' (36 bytes): the COutPoint of an input (32-byte txid, least significant byte first || 4-byte vout, least significant byte first) '''Why are outpoints little-endian?''' Despite using big endian throughout the rest of the BIP, outpoints are sorted and hashed matching their transaction serialization, which is little-endian.
What was already failing
An underpriced or ambiguous EVM rule is not a feature. It is a block that takes longer than the gas limit claimed, or a client that disagrees about the result.
What the number does not mean
The source marks this complete. That is a statement about the text, not a promise that every wallet or node has shipped it.
What a builder should be able to point at
An implementation either constrains SEC1, BIP340, SHA256 or it is a different design.
One action, walked through
- Open BIP 352 and read the status line before the examples.
- Write down the rule in one sentence. A fair version of that sentence is: We use the following functions and conventions: ''outpoint'' (36 bytes): the COutPoint of an input (32-byte txid, least significant byte first || 4-byte vout, least significant byte first) '''Why are outpoints little-endian?''' Despite using big endian throughout the rest of the BIP, outpoints are sorted and hashed matching their transaction serialization, which is little-endian.
- Name the object that changes: SEC1, BIP340, SHA256.
- Ask what an old client, an old contract, or an offline counterparty does. If the document is silent, the silence is part of the design.
The argument, unpacked
What the text is allowed to settle
Bitcoin Improvement Proposal 352 can settle the shape of Silent Payments. It cannot settle whether a later client, a later fork, or a later wallet still does this.
What this page will not pretend
There is no benchmark, no adoption number, and no claim that the mechanism is safe outside the assumptions written in the source.
What has to be true
- You are implementing BIP 352 at the status the text itself states: Complete.
- The object that has to change is SEC1, BIP340, SHA256. A neighbouring document with a similar name is not this one.
- Constants in the text can be superseded by a later fork. Cite the EIP number and the fork you mean.
What happened after the paper
The source marks this complete. That is a statement about the text, not a promise that every wallet or node has shipped it. Later documents can narrow, replace, or ignore this one. Cite the number you mean.
What to check before you use the idea
- What does Silent Payments charge, reject, or redefine on the first touch versus a later one?
- Does a reverted subcall roll the change back?
- Can you point at the object in a client: SEC1, BIP340, SHA256?
Terms
- BIP 352
- The public text titled Silent Payments.
- Complete
- The document's own label for how finished the text is. It is not a market fact.
The problem the paper names
An underpriced or ambiguous EVM rule is not a feature. It is a block that takes longer than the gas limit claimed, or a client that disagrees about the result.
What the design proposes
- We use the following functions and conventions: ''outpoint'' (36 bytes): the COutPoint of an input (32-byte txid, least significant byte first || 4-byte vout, least significant byte first) '''Why are outpoints little-endian?''' Despite using big endian throughout the rest of the BIP, outpoints are sorted and hashed matching their transaction serialization, which is little-endian.
- This allows a wallet to parse a serialized transaction for use in silent payments without needing to re-order the bytes when computing the input hash.
- Note: despite outpoints being stored and serialized as little-endian, the transaction hash (txid) is always displayed as big-endian.
How the mechanism is specified
- Taken from the specification, the next constraint is: This allows a wallet to parse a serialized transaction for use in silent payments without needing to re-order the bytes when computing the input hash.
- Locate SEC1, BIP340, SHA256 in BIP 352 and apply it to one transaction or call.
- Then check the failure the class of rule always has: a node that did not upgrade, a reverted call, a replayed signature, or a peer that does not speak the message.
What this page does not treat as proven
- A gas or opcode change is not a throughput benchmark. It is a relative price and a validity rule.
- Constants in the text can be superseded by a later fork. Cite the EIP number and the fork you mean.
- The source marks this complete. That is a statement about the text, not a promise that every wallet or node has shipped it.
Why a venture studio still reads it
Use BIP 352 when a pitch says 'Silent Payments' without saying whether the rule is consensus, policy, or an interface. The number is the citation. The pitch is not.
This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.
Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.
