Nov 15, 2018 · activated · block 556,767

November 2018: CTOR, OP_CHECKDATASIG and the BSV split

Canonical transaction ordering (CTOR), OP_CHECKDATASIG, a 100-byte minimum transaction size, push-only and clean-stack rules. A rival group forked off as Bitcoin SV.

Verified

What changed

Activation came when the median time past reached Unix time 1542300000 (15 November 2018, 16:40 UTC). The first block under the new rules is height 556,767.

Consensus changes:

  • Canonical transaction order (CTOR). After the coinbase, transactions in a block must be sorted by transaction ID. The old rule (a child after its parent) was dropped.
  • OP_CHECKDATASIG and OP_CHECKDATASIGVERIFY. These check a signature against any message and public key, not just the spending transaction.
  • Minimum transaction size: 100 bytes. This blocked a known Merkle-tree weakness that lets an attacker fool SPV wallets with a 64-byte transaction.
  • Push-only scriptSig. Unlocking scripts may only push data (BIP 62 rule 2).
  • Clean stack. Exactly one true value must remain after script execution (BIP 62 rule 6).

Why

  • CTOR was pushed by developers who expected a fixed transaction order to help future scaling work, such as block propagation and validation.
  • CHECKDATASIG was the headline smart-contract feature. It lets a script accept data signed by an outside party, such as an oracle publishing a price.
  • Push-only and clean-stack closed off third-party malleation of transactions.

The split

Not everyone agreed. A group backed by Craig Wright and Calvin Ayre opposed CTOR and OP_CHECKDATASIG. They released Bitcoin SV with a 128 MB block limit and no replay protection. The chain split on 15 November 2018. Both sides spent hashpower at a loss for weeks in a “hash war”. The chain following these rules kept the Bitcoin Cash name and ticker; the other became BSV.

What it enables

  • Oracle contracts. A contract can pay out based on a signed price or event, checked on-chain.
  • Early covenants. Checking the same signature with both OP_CHECKDATASIG and OP_CHECKSIG lets a script see parts of its own spending transaction. Contracts used workarounds like this until native introspection arrived in 2022.

The 100-byte minimum later proved too strict and was lowered to 65 bytes in 2023.

Sources

  1. 2018 November 15 Network Upgrade Specification (BCHN upgrade specs)
  2. OP_CHECKDATASIG and OP_CHECKDATASIGVERIFY Specification
  3. Bitcoin Cash Node chainparams.cpp (magneticAnomalyHeight)
  4. Bitcoin Satoshi Vision (Wikipedia)
  5. The November 2018 Bitcoin Cash Fork (Bitwise)