CHIPs · CHIP-2022-05 · activated

Pay-to-Script-Hash-32 (P2SH32)

Adds a 32-byte-hash version of P2SH (OP_HASH256 <32 bytes> OP_EQUAL) to close off 80-bit collision attacks on contract addresses.

Verified

Summary

P2SH32 adds a longer version of the classic pay-to-script-hash template. See P2SH.

  • Existing P2SH20: OP_HASH160 <20-byte hash160(redeem_script)> OP_EQUAL
  • New P2SH32: OP_HASH256 <32-byte hash256(redeem_script)> OP_EQUAL

Both are unlocked the same way: push the data, then push the redeem script.

Motivation

A 20-byte hash gives only about 80 bits of security against collisions. That matters for contracts built by more than one party. If an attacker helps build a shared contract, they can search for two scripts with the same hash, one fair and one that pays them, and swap them later. The work to do this keeps getting cheaper.

bitcoincashautist wrote the CHIP in May 2022, continuing a discussion started by bitjson and johoe. The goal was to fix this at minimum cost, by enabling a longer version of the existing template rather than a new system. bitjson’s 2023 upgrade summary notes the problem “has been well understood since before the BCH/BTC split, but solving it has recently become more important.”

On privacy, the author’s view in the thread: existing wallets have no reason to switch, and P2SH32 is best used where a contract actually needs it.

What it specifies

From the May 2023 upgrade, locking bytecode of the form OP_HASH256 OP_DATA_32 <hash> OP_EQUAL (raw aa 20 … 87) is evaluated with P2SH semantics, like the 20-byte form.

Current status

Activated on 15 May 2023, alongside CashTokens. The 2026 P2S CHIP later gave contracts a third option: a bare locking script with no hash at all.

No formal stakeholder table was found for this CHIP.

Sources

  1. CHIP-2022-05 P2SH32 discussion (Bitcoin Cash Research)
  2. P2SH32: a long-term solution for 80-bit P2SH collision attacks (Bitcoin Cash Research)
  3. 2023-05-15 Network Upgrade Specification
  4. Bitcoin Cash Upgrade 2023 (bitjson's blog)