Opcodes · crypto · enabled
OP_CHECKMULTISIG (0xae)
Checks m-of-n signatures and pushes 1 or 0. Since November 2019 it accepts Schnorr signatures when the dummy item is a bitfield that names which keys signed; ECDSA mode requires a null dummy.
Verified
- Stack in → out
- dummy sig… m pubkey… n → ok
- Since
- Original Bitcoin script
- Cost
- Base instruction cost 100 plus 26,000 per signature check, plus hashing cost for the signing serialization (2025 VM limits). Schnorr mode counts one check per signature (M). ECDSA mode counts one per public key (N), or none if every signature is empty. Also counted by the 2020 SigChecks limit. Before 2025 it also added n to the 201-operation count; that limit is gone.
- Bitcoin status
- Behaves differently in Bitcoin (BTC)BTC has no Schnorr multisig mode and disables OP_CHECKMULTISIG in Tapscript in favor of OP_CHECKSIGADD (BIP-342).
Example
OP_0 <sigA> <sigB> OP_2 <pkA> <pkB> <pkC> OP_3 OP_CHECKMULTISIG Step through it opcode by opcode in Bitauth IDE, the in-browser BCH VM debugger.