Skip to content
Banking on Bitcoin

Technology

What Is Taproot? Bitcoin's 2021 Upgrade Explained

Taproot is a Bitcoin upgrade that took effect in November 2021. Learn what Schnorr signatures and hidden spending conditions add, and what bc1p means for you.

By · Published

Illustration of a microchip with a glowing bitcoin coin at its center

Key takeaways

  • Taproot is a Bitcoin upgrade that took effect in November 2021. It was a soft fork, so software that had not upgraded kept working.
  • It added Schnorr signatures, which can be combined, and a way to commit to several spending conditions while revealing only the one that is used.
  • When everyone cooperates, a complex payment such as a multisig spend can look like an ordinary single-key payment on the blockchain. That helps privacy and can save block space.
  • For most people the visible change is one more address type, starting with bc1p. Nothing about holding or sending bitcoin has to change.
  • Taproot does not make Bitcoin anonymous, and it does not make it quantum-proof.

What is Taproot?

Taproot is a Bitcoin upgrade, activated in November 2021, that adds a new kind of output and a new signature scheme so that complex payments reveal less when they are spent. It follows SegWit, the 2017 upgrade that introduced bc1q addresses.

Formally, Taproot is a bundle of three improvement proposals, BIP 340, 341 and 342, activated together as one soft fork. They cover Schnorr signatures, the Taproot output itself and an update to Bitcoin’s scripting language called Tapscript.

The problem it addresses is visibility. Before Taproot, a payment with special conditions, such as needing two of three signatures, had to publish those conditions on the blockchain when it was spent. Anyone could see that it was a multisig payment, and often how it was set up. Taproot lets the spender prove they met the rules while showing much less.

An analogy helps. Picture a building with a main door and a locked binder of backup entry procedures. Normally the owner uses the main door, and a passerby learns nothing about the binder. If the door cannot be used, the owner opens one page of the binder and shows only that procedure. The other pages stay private. A Taproot output behaves much like that.

What are Schnorr signatures?

Schnorr signatures are a digital signature scheme that Bitcoin gained with Taproot. They do the same job as the older signatures, proving you hold a private key without revealing it, but their mathematical structure makes keys and signatures easier to combine.

Before Taproot, Bitcoin used a different elliptic-curve scheme called ECDSA. How Does Bitcoin Work? explains keys and signatures in plain terms. If you only use a wallet, the change is invisible: the wallet still signs and the network still checks.

Two practical gains follow from the structure. First, with a suitable signing protocol, several people can each hold a key and together produce one signature that matches one combined public key. To the network it looks like a single person signing. Second, Schnorr signatures can be checked in batches, which can help nodes verify many signatures faster.

There is a catch. Combining keys requires the signers to coordinate while signing, which is more involved than signing alone, and wallet support varies. The scheme makes the technique possible, and each wallet decides whether to use it.

How does Taproot hide spending conditions?

A Taproot output holds one main public key plus, optionally, a tree of backup spending conditions, and only the path used when spending is ever revealed. There are two ways to spend such an output.

PathWhat happensWhat the blockchain shows
Key pathThe owner, or all the owners together, sign with the main keyOne signature, like any single-key payment
Script pathSomeone satisfies one of the backup conditionsThat one condition and a short proof it was part of the original setup; the other conditions stay hidden

The backup conditions sit in a Merkle tree, a structure in which any branch can be proven to belong to one committed value without showing the rest. That commitment is built into the output’s key, so the unused branches never need to appear on the chain.

Here is a concrete case. Three people share a savings wallet. They set it up so that all three cooperating can sign through the key path, and so that any two can spend through a script path if the third is unavailable. On an ordinary day the spend shows a single signature. Only in the fallback case does the chain reveal that a two-person condition existed, and it shows only the one that was used.

This is one possible design. How a particular multisig wallet works depends on its software, and many still use older formats. Bitcoin Multisig Explained covers the basic idea of needing more than one key.

Why does Taproot matter for privacy and efficiency?

Taproot matters for privacy because many kinds of spends can look alike on the blockchain, and for efficiency because less data has to be published. Both gains depend on how widely it is used.

On privacy: observers use patterns to group and label transactions. A multisig spend that used to stand out from ordinary payments no longer has to. The more wallets and services use Taproot outputs, the larger the crowd any one user blends into. Is Bitcoin Private? What Transactions Reveal covers what the public ledger shows and why.

On efficiency: publishing one signature instead of several signatures and a script takes less space in a block. Network fees depend on a transaction’s size in bytes, not on the amount sent, as Bitcoin Fees Explained describes. So smaller complex transactions can cost less. For a plain single-key payment the difference is small, and fee levels change, so check your wallet’s estimate.

The third benefit is room to grow: the script path and Tapscript were designed so that future features can be added without redesigning the output type. Developers have also pointed to systems built on Bitcoin, such as the Lightning Network, as places where these tools can help once software adopts them.

What does Taproot not change?

Taproot does not change Bitcoin’s supply, its ten-minute block pace or the basic way you hold coins, and it leaves several common worries untouched.

  • It does not make Bitcoin anonymous. Reusing addresses, withdrawals tied to an exchange account and spending patterns still reveal a great deal.
  • It does not make Bitcoin quantum-proof. Schnorr signatures rely on the same kind of elliptic-curve math as before, and a Taproot output publishes a key, as Could Quantum Computers Break Bitcoin? An Honest Explainer explains.
  • It does not force anyone to switch. Every older address type keeps working.

What does Taproot mean for an ordinary user?

For most users, Taproot means one more address type and little else. A Taproot address starts with bc1p, and a wallet that supports it can generate one when you choose “receive.” What Is a Bitcoin Address? Types, Reuse and Safety compares it with the other formats.

  • Wallet support. You need a wallet that can create Taproot addresses, and the wallet decides which type it uses by default. Most modern wallets support it.
  • Sending to a bc1p address. The sending wallet or service has to support the format. If a service rejects an address, ask what it supports rather than altering the address by hand.
  • Existing coins. Moving coins to a new address type is optional and costs a network fee. For larger sums, a qualified professional can help you weigh any change to your custody setup.
  • Same habits. Check the start and end of an address before sending, send a small test amount first and keep your seed phrase backed up.

How did Taproot become part of Bitcoin?

Taproot became part of Bitcoin through a soft fork: a rule change that tightens what is valid, so blocks that follow the new rules are still accepted by software that has not upgraded. Bitcoin has no central authority, so the change needed broad support.

The proposals were published and reviewed in the open. Node software was then released with activation rules, and miners signaled readiness in the blocks they produced during a window in 2021. Once enough had signaled, the upgrade locked in, and it took effect in November 2021. Developers, miners and node operators all took part, and nobody could impose it alone.

Node operators matter here. A node that did not upgrade still follows the chain, but it does not enforce the new Taproot rules itself, which is one reason people who run nodes are encouraged to keep their software current. What Is a Bitcoin Node? What Running One Means explains that role. Bitcoin Forks Explained contrasts soft forks with hard forks and chain splits, and The History of Bitcoin places upgrades on the longer timeline. If you are new to all of this, the Start Here path covers the fundamentals in order.

Where to go next

Frequently asked questions

What is Taproot?

Taproot is a Bitcoin upgrade that took effect in November 2021. It added Schnorr signatures and a new output type that can commit to several spending conditions while revealing only the one that is used, so complex payments can look like ordinary ones on the blockchain.

What is a Taproot address?

A Taproot address is a Bitcoin address that starts with bc1p. A wallet that supports Taproot can generate one when you choose to receive bitcoin, and you can pay to it from any wallet or service that supports the format.

Does Taproot make Bitcoin transactions private?

It improves privacy in one specific way, because complex spends such as multisig can look like ordinary single-key payments. It does not make Bitcoin anonymous. Address reuse, exchange links and spending patterns can still reveal a lot.

Do I need to move my bitcoin to a Taproot address?

No. Older address types still work, and Taproot is optional. Moving coins to a new address type costs a network fee, so it is a choice for you and your wallet rather than a requirement.

Was Taproot a hard fork?

No. Taproot was a soft fork, which tightens the rules so that blocks following the new rules are still accepted by software that has not upgraded. It was activated after a signaling period in which miners showed support.

Related articles