What is Taproot in Bitcoin?
Taproot is a 2021 Bitcoin upgrade that added Schnorr signatures and new script rules, making complex transactions more private and efficient.
Taproot is an upgrade to Bitcoin that changed how transactions can be signed and how spending conditions are stored. It activated at block 709,632 on November 14, 2021, and was designed to improve privacy, efficiency and flexibility. It was a soft fork, which means older nodes still accept the new transactions even if they do not understand every detail.
What did the Bitcoin Taproot upgrade change?
Taproot bundled three Bitcoin Improvement Proposals. BIP 340 added Schnorr signatures. BIP 341 defined Taproot outputs and a way to store spending rules in a tree. BIP 342 introduced Tapscript, an updated scripting language built to work with the other two.
It was activated through a community-driven mechanism known as Speedy Trial. For background on how this kind of upgrade differs from a chain split, see hard fork vs soft fork.
What are Schnorr signatures?
Before Taproot, Bitcoin used ECDSA signatures. Schnorr signatures are a different scheme with useful math properties. The most important is that several signatures can be combined into one. The Bitcoin Wiki notes that this makes a 2 of 2 multisig transaction look like a regular single signature transaction, and says aggregation can reduce multisig transaction size by up to 25 percent. Smaller transactions take up less block space, which can mean lower fees.
How does Taproot improve privacy?
Taproot lets a coin have more than one way to be spent. Under BIP 341, there are two paths.
The key path is spent with a single Schnorr signature. It looks the same whether or not other spending rules exist, so nothing extra is revealed.
The script path is used when one of the backup conditions is needed, such as a timelock or a different set of signers. Those conditions are stored in a Merkle tree, a structure built from hashes. Only the condition actually used is revealed, while the unused ones stay hidden.
The result is that many complex transactions can look like ordinary payments on the blockchain. The Bitcoin Wiki notes that chain analysis can still sometimes spot Taproot use through other patterns, so it does not make Bitcoin fully private.
What is a Taproot address?
A Taproot output is a native SegWit output with version number 1, also called pay to Taproot or P2TR. Under BIP 350, addresses for SegWit version 1 and above use an encoding called Bech32m. On Bitcoin's main network, Taproot addresses begin with bc1p, as in the BIP 350 example address.
Sending to a bc1p address only works if your wallet supports Bech32m, so check before you send. For more on address formats in general, see what is a wallet address.
This guide explains how things work. It is not financial, legal or tax advice. Last updated .