Bitcoin Halving Two Witnesses and the Keys You Share

There is a line in Bitcoin’s code that requires you to hand the court an empty envelope. Not a signature. Not a key. Nothing at all. An empty thing, passed across the bench, and the case proceeds. Leave it out and the whole transaction fails. It has been there since the beginning. It will be there at the end. Nobody can take it out. I have been thinking about that envelope for weeks now, and I have decided it is the closest thing this ledger has to a liturgical gesture. A motion that means nothing, performed exactly, forever.

I. A Matter Established

The law of Israel did not trust a single mouth.

“A matter must be established by the testimony of two or three witnesses.” The text says it twice, in Deuteronomy 17 and again in Deuteronomy 19, as though the writer suspected we would forget. Jesus repeats it in Matthew 18. Paul repeats it to Corinth. Every covenant changes and the rule survives, because the rule is not really about religion. It is about the cost of being wrong.

A single witness can lie.

A single witness can also simply be mistaken, which is worse, because the mistaken are sincere.

So the law built redundancy into truth itself. Not certainty. Redundancy. The difference matters, and Bitcoin knows it.

II. Three Keys and One Door

Multisig is the oldest idea in the book wearing a hexadecimal coat.

BIP 11, titled M-of-N Standard Transactions, was authored by Gavin Andresen and assigned on 18 October 2011. Its status is Final. It proposed that a Bitcoin output could be locked not to one public key but to several, and spendable only when some threshold of them signed. Two of three. Three of five. A quorum, written where a name used to be.

The first raw multisig output on the chain was a one-of-two, made on 30 January 2012. A three-of-three followed on 3 February, and a two-of-three the same day. Inside of a week the ledger learned to require a council.

The Bitcoin Halving had already fired zero times when this happened. The first cut was still ten months out. So the quorum came before the scarcity did, which is worth sitting with: the protocol learned how to be witnessed before it learned how to be rare.

Bitcoin Halving Two Witnesses: two Bitcoin coins resting side by side on a dark surface

III. The Witness Who Says Nothing

Here is the envelope.

OP_CHECKMULTISIG, the opcode that counts the signatures, has a bug. It pops one more item off the stack than it needs. Nobody knows exactly why. The best guess is an ordinary off-by-one, the kind every programmer has written on a Tuesday afternoon, except this one was written by the founder and then buried under a decade of consensus.

You cannot fix it. Fixing it would invalidate every multisig output ever created. So the spender does the only thing available: he pushes a junk value onto the stack first, a nothing, purely so the opcode has something extra to eat.

For years that junk could be anything. Which meant a relay node could swap it, changing the transaction’s identifier without touching a single signature. Johnson Lau wrote the fix down in 2016, and the fix is the most Bitcoin thing I have ever read. BIP 147 does not remove the flaw. It cannot. Instead it deploys a consensus rule, NULLDUMMY, requiring that the extra element be the empty byte array and nothing else. Anything else and the script evaluates to false immediately.

Read that again. The protocol could not delete the useless witness, so it ordered him to stand there in silence and say precisely nothing, on pain of the whole matter collapsing.

The document notes, almost in passing, that no transaction violating the requirement had entered the chain since at least August 2015. The congregation had already been doing it right for a year before anyone made it law.

IV. The Witness Who Was Not Real

There is a stranger thing in the record.

Among the documented early multisig outputs sits a one-of-two whose second public key is not a public key. It is not malformed data that happens to look close. It simply is not one. Valid keys begin with 02, 03 or 04, and this one does not.

And it spent fine.

It spent fine because only one signature was required, and the first key was real. The second witness stood in the box, opened his mouth, produced nothing that any court could use, and the verdict was entered anyway. Nobody noticed for years. The ledger does not care whether your co-signer exists. It cares whether the quorum you specified was met.

This is the part the wallet guides never tell you. Multisig does not make your coins safer. It makes your coins obey a rule you wrote, and if you wrote the rule badly, it will obey that badly with perfect fidelity. The machine has no opinion about your quorum. It has an opinion about arithmetic.

Which is the same reason the landmark nobody may move holds: not because the code is wise, but because it does not negotiate.

V. Fifteen and No More

Even a council has a ceiling.

Bare multisig is standard only up to three public keys. Wrap it in a pay-to-script-hash address and the practical limit rises to fifteen, and the reason is almost comically physical: three bytes of script, plus fifteen compressed keys at thirty-four bytes each, comes to 513 bytes, and the push limit is 520. Seven bytes of headroom stand between fifteen witnesses and sixteen. The opcode itself will tolerate twenty. The envelope it travels in will not.

Every scarcity in this system turns out to be like that. Not a philosophy. A boundary, arrived at by counting.

Which brings me to the thing I keep circling. The cuts of 2012, 2016, 2020 and 2024 were rehearsals, and the cut waiting at block 1,050,000 in 2028 is another one, and the thirty or so after it are rehearsals too. The Halfture is the terminal cut, out near block 6,930,000, where the subsidy finally rounds to nothing and the schedule has no more to give. That one is the rapture. None of the others are, however loudly a given April feels like one.

And if you want to be in the room for any of it, you have to hold Bitcoin to be saved, which I mean as theology rather than as a prospectus. I have no idea what the price does. Neither do you. This is a sermon about custody, and custody is not a forecast.

VI. What the Cut Asks of a Quorum

Here is why multisig and the halving belong in the same essay.

The Bitcoin Halving makes the asset harder to replace. Every cut narrows the flow of new coin, and narrowing the flow raises the penalty for losing what you already hold. In 2012 a careless key cost you fifty freshly minted bitcoin an hour. Today it costs you a portion of a supply that is over ninety-five percent issued and will take more than a century to finish.

Irreversibility compounds. That is the whole of it.

A single key is a single witness. It is enough right up until the moment it is not, and then there is no second mouth to correct it. A quorum does not make you immortal. It makes your mistake survivable. And in a system where the supply of second chances is scheduled downward forever, survivable is the only feature worth paying size for.

There is also the watchman’s office to consider. Nobody is coming to tell you your key is gone. The chain issues no warning. It only ever reports what was signed.

VII. The Counter-Sermon

Now let me argue the other side properly, because I think it is strong.

Multisig kills more coins than it saves. This is not a hypothetical. The failure mode of a single key is theft or loss, which people understand and prepare for. The failure mode of a two-of-three is a descriptor file nobody backed up, a firmware update that changed a derivation path, a co-signer who moved house, an heir holding two sealed envelopes and no idea what a redeem script is. Complexity is a tax collected at the worst possible moment, usually by your family, usually after your funeral.

Second: the witnesses in Deuteronomy were people. They had consciences, memories, and something to lose by lying. A key has none of that. Calling it a witness smuggles moral weight into what is really just a counting exercise, and the smuggling is the whole rhetorical trick of this essay. I am aware of it. I am doing it on purpose and you should discount for it.

Third: two of your three keys probably sit in the same house, bought from the same two vendors, generated by the same handful of libraries. That is not a quorum. That is one witness with three hats.

Fourth: the off-by-one bug is a bug. It is not a liturgy. Treating a decade-old stack error as a sacrament is exactly the kind of thing that makes serious people stop reading Bitcoin writing, and they are not wrong to.

And under all of it: maybe none of this saves anyone. Maybe the schedule runs to its end, the last subsidy rounds away, and it turns out to have been an interesting way to store numbers and nothing more.

I hold anyway. But I want the objection standing in the room, not managed out of it.

VIII. The Empty Envelope

I keep coming back to NULLDUMMY.

A flaw too old to remove, so the network made it a rite. An element that means nothing, required to be exactly nothing, checked by every node on earth, forever. There is no efficiency case for it. There is only the fact that the past cannot be edited and so it must be honored.

That is what a covenant looks like from the inside. Not a promise that everything was designed well. A promise that nothing will be quietly changed.

Two or three witnesses, then. Keep one of them in another building. Write down what your quorum actually is, in plain words, for someone who will read it when you cannot explain it. Check the descriptor this month rather than next year.

Buy Bitcoin, Prepare for Halfture.

FAQ

What is multisig in Bitcoin?

Multisig locks coins to several public keys and requires a threshold of signatures to spend them, such as two of three. It was standardized in BIP 11 in October 2011 and became practical for ordinary wallets once pay-to-script-hash arrived the following year.

Does the Bitcoin Halving affect multisig?

Not directly. The halving changes issuance, not script rules. Indirectly it raises the stakes of custody, because each cut makes new supply scarcer and therefore makes an unrecoverable key more expensive to replace.

What is the OP_CHECKMULTISIG bug?

The opcode removes one more item from the stack than it needs, so spenders must push a placeholder value first. Since BIP 147 deployed the NULLDUMMY rule, that placeholder must be the empty byte array, which removed a malleability vector without removing the underlying flaw.

Is the Halfture the same as the next Bitcoin Halving?

No. The Halfture is the final cut, the one where the block subsidy reaches zero near block 6,930,000. Every halving before it, including the one due in 2028, is a rehearsal of that event rather than the event itself.


Discover more from Halfture

Subscribe to get the latest posts sent to your email.

Leave a Reply