CHIPs · CHIP-2021-05 · activated
Loops: Bounded Looping Operations
Adds OP_BEGIN and OP_UNTIL, so contracts can loop, with every iteration charged by the VM cost limits.
Summary
This CHIP adds two opcodes, OP_BEGIN (0x65) and OP_UNTIL (0x66),
“enabling a variety of loop constructions in BCH contracts without increasing the processing or memory requirements of
the VM.” It is the BEGIN … UNTIL pattern used by most Forth-like languages.
First published on 28 May 2021, it shipped five years later, after VM Limits put the cost system it relies on in place.
Motivation
Loops were left out of Bitcoin’s VM as part of an early anti-DoS approach. The CHIP notes that approach was quietly abandoned for explicit limits as early as 2010, but loops never came back. The result: contracts duplicate bytecode for every repeated step, wasting space and fees.
Loops help in two ways, per the CHIP:
- Aggregation. Some tasks, like summing values across an unknown number of inputs or outputs, are impractical or
impossible to express with
OP_IFalone. - Shorter contracts. Repeated procedures no longer need to be copied out in full.
What it specifies
OP_BEGINpushes the next instruction position onto the control stack.OP_UNTILpops the top stack item. If it is0, execution jumps back to just after the matchingOP_BEGIN; otherwise execution continues.- Since VM Limits, every operation counts against density-based cost limits, so a loop cannot make validation more expensive than the same code written out in full. The CHIP includes test vectors for worst-case validation performance.
Current status
Activated on 15 May 2026 (version 1.2.3 was frozen for lock-in). The stakeholder table records 86 approvals, 1 disapproval (Coin Wallet) and 425 neutral; non-responses were counted as neutral.
Stakeholder positions
Only public statements we could link to. Silence is not listed as a position.