{
  "$schema": "https://degreesofsatoshi.com/encyclopedia/schemas/article-v1.json",
  "schemaVersion": "1.0.0",
  "id": "bitcoin-message-signatures",
  "canonical": "https://degreesofsatoshi.com/encyclopedia/bitcoin-message-signatures/",
  "collection": "bitcoin",
  "title": "Bitcoin message signatures: proof of control with clear limits",
  "description": "Understand what Bitcoin signed messages can demonstrate, why format compatibility matters and why a signature does not prove identity or permanent control.",
  "aliases": [
    "bitcoin sign message proof ownership",
    "bitcoin sign message proof ownership explained"
  ],
  "dates": {
    "published": "2026-10-02",
    "modified": "2026-10-02",
    "verified": "2026-10-02T19:29:20.637Z",
    "dataAsOf": "2026-10-02"
  },
  "authorship": {
    "publisher": "Degrees of Satoshi editorial project",
    "process": "AI-assisted research and drafting with a separate automated source-verification pass; no external expert or named human review is implied."
  },
  "quickAnswer": {
    "text": "A Bitcoin message signature lets a verifier check a response tied to a stated message and spending condition under a supported format. It is evidence with limits, not automatic proof of personal identity, legal ownership or permanent control of funds. BIP-322 broadens message verification beyond legacy address types, while explicitly warning that someone can sign on another person’s behalf and that circumstances can change immediately afterward.",
    "claimId": "bitcoin-message-signatures-quick-answer",
    "sourceIds": [
      "x425-btc-bip322"
    ]
  },
  "keyFacts": [
    {
      "label": "Message matters",
      "value": "The exact agreed text is part of verification",
      "sourceIds": [
        "x425-btc-bip322"
      ],
      "id": "message-matters",
      "claimId": "bitcoin-message-signatures-fact-message-matters"
    },
    {
      "label": "Format matters",
      "value": "Legacy, simple and full formats differ",
      "sourceIds": [
        "x425-btc-bip322"
      ],
      "id": "format-matters",
      "claimId": "bitcoin-message-signatures-fact-format-matters"
    },
    {
      "label": "Limits",
      "value": "No permanent or exclusive control guarantee",
      "sourceIds": [
        "x425-btc-bip322"
      ],
      "id": "limits",
      "claimId": "bitcoin-message-signatures-fact-limits"
    }
  ],
  "prerequisites": [
    "private-keys-and-seed-phrases",
    "bitcoin-multisig"
  ],
  "sections": [
    {
      "id": "challenge",
      "heading": "Specify what the signature is meant to establish",
      "sourceIds": [
        "x425-btc-bip322"
      ],
      "paragraphs": [
        "A verifier should supply a fresh, purpose-specific challenge and preserve the exact signed text, destination and signature format. Otherwise an old proof may be reused outside the context in which the signer intended it. The result should be reported as verification of that challenge.",
        "An illustrative message might identify a particular invoice review and its date. It should not make the verifier infer unrelated facts such as the signer’s name, the origin of funds or ownership of every address in a wallet."
      ]
    },
    {
      "id": "compatibility",
      "heading": "Use a format the wallet and verifier both understand",
      "sourceIds": [
        "x425-btc-bip322"
      ],
      "paragraphs": [
        "The cited BIP restricts the legacy format to legacy P2PKH addresses. BIP-322 defines broader script-based formats, including simple and full variants, and allows an inconclusive result when a verifier does not understand required conditions. A failed verification can therefore be a format or implementation mismatch rather than proof of dishonesty.",
        "BIP-322’s virtual-transaction construction includes an invalid real-network input so that its message proof is not a spendable ordinary payment. Do not substitute an arbitrary transaction-signing request for the documented message-signing workflow."
      ]
    },
    {
      "id": "limits",
      "heading": "Keep the conclusion narrower than ownership",
      "sourceIds": [
        "x425-btc-bip322"
      ],
      "paragraphs": [
        "A key holder may sign messages for someone else without agreeing to move funds for that person. A key may be shared, compromised or changed after the proof. The specification explicitly states that no message-signing protocol can eliminate these limits.",
        "It also does not prove that the signer created a particular historical payment. Combine signatures with the appropriate independent records when investigating identity or a commercial claim."
      ]
    }
  ],
  "faq": [
    {
      "question": "Does signing a message send bitcoin?",
      "answer": "A correctly implemented documented message-signing format is distinct from authorizing an ordinary payment. BIP-322 uses virtual transactions that cannot themselves be spent on a real network. Still inspect which operation the wallet actually requests.",
      "sourceIds": [
        "x425-btc-bip322"
      ]
    },
    {
      "question": "Does a signed message prove someone owns all coins at an address?",
      "answer": "No. Verification is evidence about a particular response and script condition. It does not establish exclusive or lasting control, legal ownership, liabilities or the willingness to authorize a real spend.",
      "sourceIds": [
        "x425-btc-bip322"
      ]
    }
  ],
  "claims": [
    {
      "id": "bitcoin-message-signatures-quick-answer",
      "articleSlug": "bitcoin-message-signatures",
      "statement": "A Bitcoin message signature lets a verifier check a response tied to a stated message and spending condition under a supported format. It is evidence with limits, not automatic proof of personal identity, legal ownership or permanent control of funds. BIP-322 broadens message verification beyond legacy address types, while explicitly warning that someone can sign on another person’s behalf and that circumstances can change immediately afterward.",
      "sourceIds": [
        "source-057748a013b6ec8e"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-057748a013b6ec8e",
          "locator": "Motivation; Types of Signatures; Detailed Specification; Verification Process"
        }
      ],
      "scope": {
        "collection": "bitcoin",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "Educational explanation. Product-specific behavior is scoped to the cited documentation, checked 2026-10-02.",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T19:29:20.637Z",
        "reviewer": "Independent automated verification — Codex /root/verify_ethereum_100, separate from the Bitcoin drafting agent",
        "notes": [
          "Read BIP322 v2.0.0 Complete, including legacy restriction, simple/full variants, inconclusive verification and virtual invalid input. The draft preserves the specification’s limits on permanent/exclusive control and cannot prove the signer made a historical payment."
        ]
      }
    },
    {
      "id": "bitcoin-message-signatures-fact-message-matters",
      "articleSlug": "bitcoin-message-signatures",
      "statement": "Message matters: The exact agreed text is part of verification",
      "sourceIds": [
        "source-057748a013b6ec8e"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-057748a013b6ec8e",
          "locator": "Motivation; Types of Signatures; Detailed Specification; Verification Process"
        }
      ],
      "scope": {
        "collection": "bitcoin",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T19:29:20.637Z",
        "reviewer": "Independent automated verification — Codex /root/verify_ethereum_100, separate from the Bitcoin drafting agent",
        "notes": [
          "Read BIP322 v2.0.0 Complete, including legacy restriction, simple/full variants, inconclusive verification and virtual invalid input. The draft preserves the specification’s limits on permanent/exclusive control and cannot prove the signer made a historical payment."
        ]
      }
    },
    {
      "id": "bitcoin-message-signatures-fact-format-matters",
      "articleSlug": "bitcoin-message-signatures",
      "statement": "Format matters: Legacy, simple and full formats differ",
      "sourceIds": [
        "source-057748a013b6ec8e"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-057748a013b6ec8e",
          "locator": "Motivation; Types of Signatures; Detailed Specification; Verification Process"
        }
      ],
      "scope": {
        "collection": "bitcoin",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T19:29:20.637Z",
        "reviewer": "Independent automated verification — Codex /root/verify_ethereum_100, separate from the Bitcoin drafting agent",
        "notes": [
          "Read BIP322 v2.0.0 Complete, including legacy restriction, simple/full variants, inconclusive verification and virtual invalid input. The draft preserves the specification’s limits on permanent/exclusive control and cannot prove the signer made a historical payment."
        ]
      }
    },
    {
      "id": "bitcoin-message-signatures-fact-limits",
      "articleSlug": "bitcoin-message-signatures",
      "statement": "Limits: No permanent or exclusive control guarantee",
      "sourceIds": [
        "source-057748a013b6ec8e"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-057748a013b6ec8e",
          "locator": "Motivation; Types of Signatures; Detailed Specification; Verification Process"
        }
      ],
      "scope": {
        "collection": "bitcoin",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T19:29:20.637Z",
        "reviewer": "Independent automated verification — Codex /root/verify_ethereum_100, separate from the Bitcoin drafting agent",
        "notes": [
          "Read BIP322 v2.0.0 Complete, including legacy restriction, simple/full variants, inconclusive verification and virtual invalid input. The draft preserves the specification’s limits on permanent/exclusive control and cannot prove the signer made a historical payment."
        ]
      }
    }
  ],
  "sources": [
    {
      "id": "x425-btc-bip322",
      "label": "Generic Signed Message Format",
      "publisher": "Bitcoin Improvement Proposals",
      "url": "https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0322.mediawiki",
      "locator": "Motivation; Types of Signatures; Detailed Specification; Verification Process",
      "note": "Message-control proof, virtual transactions and limits of supported wallet verification.",
      "version": "Pinned BIPs revision",
      "checkedAt": "2026-10-02T18:53:54.170Z",
      "contentSha256": "0eb91c5093ef81c462cadffdbe02d4d1638cb270d3ccb47301a6d82860aa0454",
      "recordId": "source-057748a013b6ec8e"
    }
  ],
  "related": {
    "articles": [
      "private-keys-and-seed-phrases",
      "bitcoin-multisig",
      "bitcoin-transaction-broadcasting"
    ],
    "dossiers": [],
    "wallets": []
  },
  "revisionHistory": [
    {
      "date": "2026-10-02",
      "kind": "published",
      "summary": "First publication after primary-source research and separate automated verification."
    }
  ],
  "citation": "Degrees of Satoshi editorial project. “Bitcoin message signatures: proof of control with clear limits.” Published 2026-10-02; updated 2026-10-02. https://degreesofsatoshi.com/encyclopedia/bitcoin-message-signatures/"
}
