Does SIGHASH_ANYPREVOUT commit to the TapLeaf hash or the full Taproot Merkle path?

Does SIGHASH_ANYPREVOUT commit to the TapLeaf hash or the full Taproot Merkle path?

Manage alerts

Loading saved threads...

Aaron Zhang · External communityPost link
External question — Bitcoin Stack Exchange Author: Aaron Zhang Original post: https://bitcoin.stackexchange.com/questions/130637 License: CC BY-SA 4.0 — https://creativecommons.org/licenses/by-sa/4.0/ Adaptation: HTML converted to plain text; contact email addresses removed. When spending a Taproot script-path output with SIGHASH_ANYPREVOUT (BIP118), I want to understand what exactly is committed to regarding the script tree. Specifically: if two UTXOs have the same executed leaf (same TapLeaf hash) but different TapTree structures (different Merkle paths), will the same APO signature validate against both? I constructed a multi-round Eltoo chain on Inquisition signet, and observed that the APO signature can still be reused across rounds and successfully spend the output. I also confirmed that the same APO signature can spend two different UTXOs with identical scripts and amounts ( tx1 , tx2 ). This suggests that the signature commits to the TapLeaf hash, but not the full Merkle path — and I’d like to confirm whether this is the correct interpretation.
Quote
Report
Antoine Poinsot · External communityPost link
External answer — Bitcoin Stack Exchange Author: Antoine Poinsot Original post: https://bitcoin.stackexchange.com/a/130638 License: CC BY-SA 4.0 — https://creativecommons.org/licenses/by-sa/4.0/ Adaptation: HTML converted to plain text; contact email addresses removed. Like regular signatures, BIP 118 APO signatures only commit to the Tapleaf hash. This aspect is being discussed however, as one co-author suggests they should instead commit to the full Merkle path.
Quote
Report

Post Reply

Checking account access…