Same Bitcoin.
New assumptions.
Twenty-one million reasons to look ahead.
Explore the keys Bitcoin reveals — and the research rethinking what comes next.
A little less trust.
A little more proof.
A message becomes a hash. A hash joins a tree.
Change one byte and the proof tells a different story.
Follow the bytes.
Build a real Merkle commitment in your browser. Inspect the path, then alter the message to see verification fail.
A hash proof demonstrates integrity. It is not a post-quantum signature or a Bitcoin transaction.
leaf = H(message)parent = H(left || right)path = siblings[0…2]root′ == committed rootWaiting for computation…——What does an
output actually reveal?
The locking script is the starting point.
Read its structure before making assumptions.
Paste a public output script or select an example below.
20-byte key hash.
The script commits to a public-key hash. The signing public key is revealed in the witness when this output is spent.
This pattern alone cannot establish prior key exposure, address reuse or quantum safety.
An open question.
An open record.
Follow the proposals, not a countdown.
The next step still needs consensus.
Where Bitcoin is today.
Taproot outputs contain a 32-byte public key. Key-path and script-path spending share that output structure.
A commitment without the key path.
P2MR proposes committing to a script-tree root. It addresses long key exposure; it does not add post-quantum signatures.
The harder part is the transition.
A draft migration and legacy-signature sunset framework, dependent on a future post-quantum signature proposal.