‹ CHAPTER 16, ALL LESSONS

MASTER · CHAPTER 16 · LESSON 1 OF 5

Script & upgrades

Bitcoin Script

What is actually written in an output to lock it? 6 min

Every output carries a small program, its locking script. To spend it, an input provides an unlocking part. Nodes run the two together: if the program ends with true, the spend is valid.

A stack machine

Script works on a stack: items are pushed, and operations take items off the top and push results. The classic legacy payment reads: OP_DUP OP_HASH160 <public key hash> OP_EQUALVERIFY OP_CHECKSIG. In words: copy the public key provided, hash it, check that it matches the one in the output, then check the signature against it.

Limited on purpose

Script has no loops and no general purpose memory. Every program finishes, quickly, and every node can predict what it costs to check. That makes it far less expressive than the languages of some other blockchains, and far easier to reason about.

  • Multisig: require several signatures out of a set of keys.
  • Hash locks: require revealing a secret whose hash is known, as Lightning does.
  • Time locks: forbid spending before a date or a block height.

What to remember

  • Outputs are locked by small stack based programs.
  • Script has no loops: every check finishes predictably.
  • Signatures, hashes and times are its building blocks.

Quick check

When is a spend valid at the Script level?

Why does Script have no loops?