Opcodes · control · enabled

OP_UNTIL (0x66)

Closes a loop. It pops the top stack item: if false (0), execution jumps back to just after the matching OP_BEGIN; if true, execution continues. This byte was the disabled OP_VERNOTIF before May 2026. OP_BEGIN and OP_UNTIL must pair up even inside an unexecuted branch, and an OP_IF block cannot cross a loop boundary.

Verified
Stack in → out
cond → ∅
Cost
Base instruction cost 100. Every repeated instruction pays its cost again, so the operation cost limit bounds total loop work.
Bitcoin status
Not in Bitcoin (BTC)BTC has no loops. 0x66 is OP_VERNOTIF there, which fails even in an unexecuted branch.

Example

OP_0 OP_BEGIN OP_1ADD OP_DUP OP_10 OP_EQUAL OP_UNTIL

Step through it opcode by opcode in Bitauth IDE, the in-browser BCH VM debugger.

Sources

  1. CHIP-2021-05 Loops: Bounded Looping Operations
  2. Libauth BCH_2026_05 opcodes (bch-2026-opcodes.ts)
  3. Announcing Bitcoin Cash Node v29.0.0
  4. BCHN script interpreter (interpreter.cpp)