Does SIGHASH_ANYPREVOUT commit to the TapLeaf hash or the full Taproot Merkle path?
Does SIGHASH_ANYPREVOUT commit to the TapLeaf hash or the full Taproot Merkle path?
Loading saved threads...
Aaron Zhang · External communityPost link
External question — Bitcoin Stack Exchange
Author: Aaron Zhang
Original post: https://bitcoin.stackexchange.com/questions/130637
License: CC BY-SA 4.0 — https://creativecommons.org/licenses/by-sa/4.0/
Adaptation: HTML converted to plain text; contact email addresses removed.
When spending a Taproot script-path output with SIGHASH_ANYPREVOUT (BIP118), I want to understand what exactly is committed to regarding the script tree.
Specifically: if two UTXOs have the same executed leaf (same TapLeaf hash) but different TapTree structures (different Merkle paths), will the same APO signature validate against both?
I constructed a multi-round Eltoo chain on Inquisition signet, and observed that the APO signature can still be reused across rounds and successfully spend the output. I also confirmed that the same APO signature can spend two different UTXOs with identical scripts and amounts (
tx1
,
tx2
).
This suggests that the signature commits to the TapLeaf hash, but not the full Merkle path — and I’d like to confirm whether this is the correct interpretation.
Quote
Report
Antoine Poinsot · External communityPost link
External answer — Bitcoin Stack Exchange
Author: Antoine Poinsot
Original post: https://bitcoin.stackexchange.com/a/130638
License: CC BY-SA 4.0 — https://creativecommons.org/licenses/by-sa/4.0/
Adaptation: HTML converted to plain text; contact email addresses removed.
Like regular signatures, BIP 118 APO signatures only commit to the Tapleaf hash. This aspect is being discussed however, as
one co-author suggests
they should instead commit to the full Merkle path.
Quote
Report
Post Reply
Quoted from Forex.com.bd-Editorial External question — Bitcoin Stack Exchange Author: Aaron Zhang Source score (net votes, not local likes): 1 Original post: https://bitcoin.stackexchange.com/questions/130637 License: CC BY-SA 4.0 — https://creativecommons.org/licenses/by-sa/4.0/ Adaptation: HTML converted to plain text; contact email addresses removed. When spending a Taproot script-path output with SIGHASH_ANYPREVOUT (BIP118), I want to understand what exactly is committed to regarding the script tree. Specifically: if two UTXOs have the same executed leaf (same TapLeaf hash) but different TapTree structures (different Merkle paths), will the same APO signature validate against both? I constructed a multi-round Eltoo chain on Inquisition signet, and observed that the APO signature can still be reused across rounds and successfully spend the output. I also confirmed that the same APO signature can spend two different UTXOs with identical scripts and amounts ( tx1 , tx2 ). This suggests that the signature commits to the TapLeaf hash, but not the full Merkle path — and I’d like to confirm whether this is the correct interpretation.
Checking account access…