← back to the blog

Bitcoin Explained · September 24, 2026

By Adam Whistler

What Is Taproot? Bitcoin's 2021 Privacy Upgrade

Tree roots gripping a rock

Taproot activated on the Bitcoin network on November 12, 2021, at block 709,632, and it's one of those upgrades that most Bitcoin users benefit from constantly without ever noticing. It didn't change how many coins exist, didn't touch the 21 million cap, and didn't split the network the way Bitcoin Cash did in 2017. What it did was quietly rewrite how complicated Bitcoin transactions, multisig wallets, Lightning channels, inheritance vaults, all of it, appear on the public blockchain: instead of looking different from an ordinary payment, they now look identical to one. That single change is the reason two separate technologies already covered on this blog, Bitcoin Ordinals and Lightning's ability to carry Tether, exist at all, and it's worth understanding on its own terms, not just as a footnote to whatever it later enabled.

Where it actually came from

Bitcoin Core developer Gregory Maxwell formally proposed Taproot in January 2018, building on ideas that had circulated for years among developers including Pieter Wuille and Andrew Poelstra. It took nearly four years of public review, testing, and debate before activation, a pace that's normal for a change to Bitcoin's consensus rules rather than a sign anything was wrong with the proposal. Getting the technical content agreed on turned out to be the easy part; how to actually activate it produced a real fight. Developers spent months debating between a BIP8-style year-long signaling period with an automatic activation backstop and a faster alternative, eventually settling on a compromise called Speedy Trial: a three-month window in which miners could signal readiness, needing 90% support within that window for the upgrade to lock in, with no automatic fallback if it failed. Not everyone agreed with that compromise. Luke Dashjr, the same Bitcoin Core developer who later became Ordinals' most vocal critic, argued publicly that the community had already reached consensus on the BIP8 approach and that switching to Speedy Trial without broader agreement amounted to "an attack on Bitcoin." He was in the minority. The 90% threshold was hit in May 2021, and activation followed six months later once the required block height was reached. Taproot is a soft fork, meaning it tightens Bitcoin's rules in a way that's backward compatible: a node that never upgraded keeps following the same chain and never gets forced to split off, which is exactly the property Bitcoin Cash's 2017 hard fork lacked. The activation mechanism had real disagreement behind it. The outcome, once the dust settled, didn't.

The three changes bundled into one upgrade

Taproot is actually three separate Bitcoin Improvement Proposals activated together, not a single change, and each one does a specific job.

BIP 340 introduces Schnorr signatures, replacing the ECDSA signature scheme Bitcoin had used since its creation. Schnorr signatures are smaller, 64 bytes against ECDSA's roughly 71 to 73 bytes, and they support a mathematical property called linear aggregation: multiple people signing a transaction together can combine their individual signatures into a single combined signature before it ever touches the blockchain. A wallet requiring five separate signatures to spend can broadcast a transaction that looks, to anyone watching the chain, exactly like one person signing with one key.

BIP 341 defines Taproot itself and introduces a structure called a Merklized Alternative Script Tree, or MAST. Every Taproot output actually commits to two ways it could be spent at once: a simple key path, where the owner just signs normally, and a script path, a hidden tree of alternative conditions, timelocks, backup keys, multisig fallbacks, dispute resolution rules, any of which could be exercised instead. The clever part is what happens when nobody needs the complicated version: if the owner just signs normally, none of those alternative conditions ever get revealed on-chain at all. Only if a specific alternative branch actually gets used does it show up in the transaction, along with a small cryptographic proof that it was part of the original setup. A vault with a dozen contingency rules costs nothing in block space beyond an ordinary payment, right up until the moment one of those contingencies actually gets triggered.

BIP 342, known as Tapscript, updates Bitcoin's scripting language to work with the other two changes and removes some legacy restrictions in the process, while deliberately leaving room for future upgrades that hadn't been designed yet. Rather than a new language built from scratch, it's Bitcoin Script with the constraints loosened enough to make Schnorr signatures and MAST actually usable in practice.

In practice, all of this shows up to an ordinary user as a new address format. Taproot addresses start with the prefix "bc1p" and use an encoding called Bech32m, defined in a companion proposal, BIP 350, specifically to avoid a subtle bug in the original Bech32 encoding that SegWit addresses use. Sending to a "bc1p" address only works if the sender's wallet or exchange has actually added Taproot support, which is why adoption still depends on individual services choosing to upgrade rather than happening automatically the moment the network activated the soft fork.

The private key for every Bitcoin wallet on Earth is on this website, even Satoshi's. But even if you try for a million years, you'll never find a funded one.

Try the key collider now

What this actually changes for a real user

The headline benefit is privacy, and it compounds as more of the network actually uses it. Before Taproot, chain analysis tools could often tell a multisig wallet, a Lightning channel, or another complex setup apart from an ordinary payment just by how the transaction looked on-chain. Taproot collapses that distinction: a five-of-five multisig vault, a two-party Lightning channel, and a simple person-to-person payment can all be indistinguishable from each other. The anonymity this creates gets stronger as more of the network adopts Taproot outputs, since every additional simple-looking transaction, whether it's actually simple or not, adds to the pool that a complex transaction can hide inside. The second benefit is cost: Bitcoin fees are charged per byte, and smaller Schnorr signatures, aggregated multi-party signing, and script branches that never touch the chain unless they're used all push the cost of complex transactions down toward the cost of a simple one. The third benefit, which turned out to matter the most in practice, is flexibility: Taproot made it dramatically cheaper and more practical to build directly on top of Bitcoin's base layer, rather than working around its limitations.

The actual adoption curve is worth being honest about, because it doesn't match a clean story of steadily rising organic use. Taproot transactions peaked at roughly 40 to 42% of daily Bitcoin activity in 2024, but that peak was driven almost entirely by Ordinals inscriptions using Taproot's witness space to embed data, not by wallets and services broadly switching their default address format. Once inscription activity cooled, Taproot's share of transactions fell back to somewhere between 15% and 20% by early 2026, well below SegWit's steady 85 to 90% adoption rate, which climbed gradually as infrastructure upgraded rather than spiking with a specific use case and receding with it. That contrast says something honest about how upgrades actually spread in practice: SegWit's fee savings applied to nearly every transaction, so nearly every wallet eventually adopted it. Taproot's biggest real-world pull turned out to be a specific, controversial application nobody designed it for, and everyday privacy-driven adoption from ordinary wallets has been slower and less dramatic than the 2021 pitch implied.

The multisig and Lightning uses that actually shipped

Away from Ordinals, Taproot's aggregation properties did find real, quieter adoption. MuSig2, a practical signature-aggregation protocol built on Schnorr, lets multiple parties collaboratively produce a single valid signature without any one of them ever seeing the others' private keys, and Lightning implementations including LND shipped experimental support for Taproot and MuSig2 channels starting in 2023, letting a Lightning channel between two parties look like an ordinary single-signature payment on the base chain rather than revealing itself as a channel open or close. Bitcoin Core itself began enforcing Taproot rules on essentially all blocks with SegWit active starting in 2022, treating it as foundational infrastructure rather than an optional feature. There's also an active, unresolved research question sitting underneath all of this: a 2025 academic paper examined the security of Taproot's commitments specifically against quantum computers, part of a broader conversation that has produced proposals like BIP-360 for quantum-resistant address formats. That's a separate, longer-horizon question from anything Taproot itself was built to solve, and it's the same underlying concern covered in more depth elsewhere on this site.

What it enabled, whether anyone intended it or not

Taproot's flexibility is directly responsible for two things this blog has already covered in detail, and neither was the headline pitch during the four years developers spent building it. Bitcoin Ordinals, the protocol that lets arbitrary data get inscribed onto individual satoshis, exists because Taproot made it cheap and practical to embed large amounts of data inside a transaction's witness section, a capability nobody originally designed Taproot around but that fell directly out of how flexible Tapscript turned out to be. That single side effect produced one of Bitcoin's more contentious ongoing arguments about what block space is actually for. Separately, Lightning Network's Taproot Assets protocol, which lets Tether's USDT move over Lightning channels rather than bitcoin itself, depends on Taproot's signing and scripting primitives to work at all. In both cases, an upgrade sold on privacy and efficiency turned out to be, more than anything else, an upgrade in what Bitcoin's base layer was capable of hosting, for better or worse depending on who you ask.

The quieter application: vaults and inheritance planning

Away from the more publicized uses, Taproot's MAST structure made a category of custody tool practically viable that was clunky and expensive to build before: a Bitcoin vault with genuine contingency logic baked in, a normal spending key for everyday use, a separate recovery path that only activates after a time delay, and an emergency key held by someone else entirely, all committed to in a single output, with only the branch that actually gets used ever appearing on-chain. That's precisely the kind of structure the custody and inheritance services covered elsewhere on this site rely on, and Taproot is a meaningful part of why building that kind of contingency plan got cheaper and more private rather than staying a bespoke, expensive setup only available to sophisticated holders. It also feeds a live, currently unresolved debate among Bitcoin developers over covenants, restrictions on how a coin can be spent in the future, built into the coin itself rather than enforced by trusting a keyholder's good behavior. The most advanced proposal, OP_CHECKTEMPLATEVERIFY (BIP 119, authored by Jeremy Rubin), would let an output commit to the exact structure of whatever transaction eventually spends it, enabling genuine vaults and Lightning improvements without the recursive risk of a coin becoming permanently, unpredictably restricted. As of 2026, CTV has concrete activation parameters on the table for the first time since it was proposed, a signaling start date of March 30, 2026 and a required 90% miner threshold, the same activation mechanism Taproot itself used. Whether it actually activates remains an open question. Taproot didn't settle that argument. It made the argument possible to have in concrete, buildable terms rather than a purely theoretical one.

For the argument over what Taproot's biggest side effect actually means for Bitcoin, see whether Ordinals are the best or worst thing to happen to Bitcoin's block space, or for the plain technical explanation of how inscriptions work, see what Bitcoin Ordinals and BRC-20 tokens actually are. For how Lightning uses Taproot to carry more than just bitcoin, see what the Lightning Network actually does, and for the earlier upgrade that made Taproot possible in the first place, see what a Bitcoin fork actually is. For more on the specific security guarantees Taproot's cryptography actually provides, see how absurd Bitcoin's security margin really is.