bc1q · witness version 0

After block H0, an ECDSA signature does not spend.

A native segwit address stores a 20-byte hash of the public key. The key is not in the output. From block H0 on, nodes reject an ECDSA signature even when the math is valid.

See the cutoff

What is stored

A normal receive address does not contain a public key. Native segwit, the bc1q form called P2WPKH, stores 20 bytes: HASH160 of the compressed public key. HASH160 is RIPEMD160(SHA256(pubkey)). The output script is OP_0, then those 20 bytes.

The public key is published later, in the witness, and only when that address signs. Until then a break of ECDSA has nothing to recover. Taproot (bc1p) is different: the output itself is a tweaked public key, so the key is already on chain at receipt. Old pay-to-pubkey outputs print the key in the script. This project does not use either of those.

What changes at H0

H0 is a block height published in advance. Before it, one ECDSA signature can still move coins, and that move should pay the full balance to a new bc1q address. At H0 and after, nodes accept a spend only with a hash-based signature, SPHINCS over SHA-256 or BLAKE. An ECDSA signature is rejected even when the math checks out. A recovered private key can still sign. Miners following the rule do not include that transaction.

Bitcoin does not enforce this today. A valid ECDSA signature still spends. The pages here are the rule as specified, not a claim that mainnet has activated it. The explorer reads the live chain so you can see real block hashes and which outputs are already bc1q.