LibraryMarkets2017Design paperCorpus record
Partially Signed Bitcoin Transactions
BIP 174. Andrew Chow.
A PSBT is a standard container for a transaction, the inputs' previous outputs, and the partial signatures. Roles are creator, updater, signer, combiner, finaliser and extractor.
A reading of the public document. Not a copy of it, and not a claim about a later network that reused the name.
A custody workflow that cannot show the PSBT's outputs to the signer has hidden the only thing the signer is for.
The five-minute read
The defect
A multi-signature transaction used to be a private file format for each wallet. Hardware wallets, coordinators and humans could not pass one object around.
The rule
A PSBT is a standard container for a transaction, the inputs' previous outputs, and the partial signatures. Roles are creator, updater, signer, combiner, finaliser and extractor.
How it is put together
The unsigned transaction and the signatures travel together. A signer does not have to trust a coordinator with keys. The format is versioned. v2 is a later BIP.
Where the claim stops
PSBT does not choose the policy. A 2-of-3 is still a wallet decision.
One action, walked through
- Create a PSBT with inputs and outputs.
- Each signer adds a partial signature.
- A finaliser attaches the witness and an extractor broadcasts.
- Which role is this software playing?
The argument, unpacked
Why it is still on the desk
A custody workflow that cannot show the PSBT's outputs to the signer has hidden the only thing the signer is for.
After the text
Hardware wallets standardised on this. BIP 370 updates the format. The roles are the 2017 idea.
What has to be true
- PSBT does not choose the policy. A 2-of-3 is still a wallet decision.
- A malicious creator can still propose a payment the signer must read.
- The format is not a custody model.
What happened after the paper
Hardware wallets standardised on this. BIP 370 updates the format. The roles are the 2017 idea.
What to check before you use the idea
- Which role is this software playing?
- Can the signer see every output?
- What is finalised before broadcast?
Terms
- Updater
- A party that adds input metadata the signer needs.
- Finaliser
- The party that turns partial signatures into a valid witness.
The problem the paper names
A multi-signature transaction used to be a private file format for each wallet. Hardware wallets, coordinators and humans could not pass one object around.
What the design proposes
- The unsigned transaction and the signatures travel together.
- A signer does not have to trust a coordinator with keys.
- The format is versioned. v2 is a later BIP.
How the mechanism is specified
- Create a PSBT with inputs and outputs.
- Each signer adds a partial signature.
- A finaliser attaches the witness and an extractor broadcasts.
What this page does not treat as proven
- PSBT does not choose the policy. A 2-of-3 is still a wallet decision.
- A malicious creator can still propose a payment the signer must read.
- The format is not a custody model.
Why a venture studio still reads it
A custody workflow that cannot show the PSBT's outputs to the signer has hidden the only thing the signer is for.
This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.
Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.
