BIP 66 — Strict DER signatures
Restricts ECDSA signatures in Bitcoin scripts to strict DER encoding, removing OpenSSL's implicit role in consensus validity and reducing transaction malleability.
Bitcoin Core developer behind BIP-32, libsecp256k1, SegWit, and Taproot

Hierarchical deterministic wallets. Segregated Witness. Schnorr signatures. Taproot. The four BIPs that define how every modern Bitcoin wallet derives keys, how every modern transaction escapes malleability, how block capacity expanded, and how Taproot’s privacy and script flexibility work — all four were authored or co-authored by Pieter Wuille (known on GitHub and IRC as sipa). He also started libsecp256k1 in 2013, the purpose-built elliptic-curve library that replaced OpenSSL as Bitcoin Core’s signature backend. The archive’s architecture-evolution page lists all four of these changes among the handful that transformed Bitcoin’s cross-cutting design since v0.1.
Wuille is a Belgian software engineer. His first contribution to bitcoin/bitcoin was PR #122 on March 17, 2011; six weeks later he received commit access, making him the second long-term maintainer after Gavin Andresen. He co-founded Blockstream in 2014 and later joined Chaincode Labs.
Wuille’s first contribution to bitcoin/bitcoin is PR #122 on March 17, 2011 — a wallet-structure change to track spentness per transaction output, enabling partially-spent transactions. On May 1, 2011, Gavin Andresen granted him GitHub commit access, making him the second long-term maintainer after Andresen himself and before Wladimir van der Laan.
Wuille authored or co-authored four BIPs that between them cover a remarkable share of Bitcoin’s post-Satoshi evolution:
During the 2015–2017 block-size war, Wuille was named as one of three lead figures of the “Core developers” faction that opposed the large-block proposals in favor of SegWit and Lightning — see the block-size war overview for the full account of that dispute.
On March 5, 2013, Wuille started libsecp256k1, initially as a performance experiment around the GLV-method endomorphism. Gregory Maxwell soon joined, and the library grew into a full purpose-built replacement for OpenSSL’s secp256k1 implementation. It shipped as the default backend in Bitcoin Core v0.12 on January 15, 2016.
Wuille was a co-founder of Blockstream in 2014 alongside Gregory Maxwell and others, and later joined Chaincode Labs. Throughout, he has remained among the most consistent Bitcoin Core reviewers and cryptographic designers.
Between the four BIPs and libsecp256k1, Wuille’s direct design work underpins the way every modern Bitcoin wallet derives keys, every modern transaction verifies signatures, every modern payment can escape on-chain malleability, and every Taproot output achieves its privacy and script flexibility. Few post-Satoshi contributors have had so broad a sphere of influence on the protocol itself.
21 entries
Restricts ECDSA signatures in Bitcoin scripts to strict DER encoding, removing OpenSSL's implicit role in consensus validity and reducing transaction malleability.
Pieter Wuille ↔ Peter Todd, Greg Maxwell, Rusty Russell
Defines the original version-bits mechanism for signaling and activating soft forks in parallel via the block nVersion field, using median-time-past thresholds and a fixed timeout.
New SegWit v0 signature-hash algorithm: commits to the input's spent amount, fixes O(n^2) quadratic hashing, and changes OP_CODESEPARATOR/FindAndDelete handling.
Fixes ECDSA signature malleability with two consensus rules: LOW_S, requiring the lower-half S value, and NULLFAIL, requiring failing signatures be empty byte arrays.
Defines Bech32, a checksummed base32 format, and the segwit address encoding (bc1.../tb1...) built on it for native v0-16 witness outputs.
Dhruv Mehta ↔ Tim Ruffing, Jonas Schnelli, Pieter Wuille
Defines the v2 P2P transport: unauthenticated opportunistic ChaCha20Poly1305 encryption over ElligatorSwift-encoded ECDH key exchange, producing a pseudorandom bytestream with v1 fallback.
Pieter Wuille ↔ Jonas Nick, Anthony Towns
Specifies tapscript — the taproot script-path validation rules: Schnorr signature checks via OP_CHECKSIG/OP_CHECKSIGADD, OP_SUCCESS upgrade opcodes, and a per-input sigops budget.
Specifies Bech32m, a checksum variant of Bech32 that fixes an insertion-error weakness, and mandates its use for native SegWit v1+ (Taproot) addresses while v0 keeps Bech32.
Defines the general syntax, checksum, and key/script expression grammar for Output Script Descriptors, the language wallets use to describe and reproduce sets of output scripts.
Bitcoin Institute ↔ Gregory Maxwell, Adam Back, Pieter Wuille, Mike Hearn, Roger Ver, Jihan Wu, Satoshi Nakamoto
Weighing the 'Blockstream controls Bitcoin' charge against the documentary record: where it comes from, and how each link in the chain holds up.
Bitcoin Institute ↔ Mike Hearn, Gavin Andresen, Roger Ver, Jihan Wu, Amaury Séchet, Mike Belshe, Gregory Maxwell, Pieter Wuille, Wladimir van der Laan
Cross-cutting reading of Bitcoin's 2015–2017 block-size war by phase, faction, and turning point: Bitcoin XT, BIP148 UASF, the New York Agreement, Bitcoin Cash, SegWit2x cancellation.
Bitcoin Institute ↔ Nils Schneider, Gavin Andresen, Wei Dai, Pieter Wuille, Satoshi Nakamoto
On November 20, 2011, Bitcoin v0.5 shipped with the Crypto++ SHA-256 subset removed and replaced by OpenSSL. Wei Dai's library, a direct codebase dependency since v0.1, was gone.
Bitcoin Institute ↔ Pieter Wuille, Gregory Maxwell, Satoshi Nakamoto
On January 15, 2016, Bitcoin Core v0.12 replaced OpenSSL with libsecp256k1 — Wuille and Maxwell's custom elliptic-curve library — for consensus-critical ECDSA verification.
PR #122 thread starter by sipa in bitcoin/bitcoin.
Comment by sipa in bitcoin/bitcoin PR #1367. context for Satoshi mention.
PR #2161 thread starter by sipa in bitcoin/bitcoin.
Bitcoin Project ↔ Gavin Andresen, Chris Moore, Pieter Wuille, Jeff Garzik, Wladimir van der Laan, Nils Schneider
Bitcoin's migration from SourceForge SVN to GitHub, and the chronological record of developers who received commit access to the GitHub repository in 2011.
Introduced hierarchical deterministic (HD) wallets — an entire tree of key pairs derived from a single master seed. Eliminated frequent-backup needs and enabled organized parent-child key derivation.
Eric Lombrozo ↔ Johnson Lau, Pieter Wuille
Segregated Witness (SegWit) — Bitcoin's most significant protocol upgrade since creation. Separates signature from transaction data, fixing malleability, enabling Lightning, raising block capacity.
Pieter Wuille ↔ Jonas Nick, Tim Ruffing
Schnorr signatures replacing ECDSA for Taproot. Provably secure, non-malleable, with efficient multi-signature aggregation — complex scripts become on-chain indistinguishable from simple payments.
Pieter Wuille ↔ Jonas Nick, Anthony Towns
Taproot — Bitcoin's most significant protocol upgrade since SegWit. Combines Schnorr (BIP 340) with MAST so complex spending conditions look like simple payments on-chain.