Phase 2BIP352 + OrdinalsBIP352 + Runes

Privacy
ordinals / runes.

Send an inscription or a rune balance to someone's sp1 wallet. The sats land in a one-time taproot output that only they can find, so the collection stays off the public map of who owns what.

Infographic
UTXO flow of a privacy ordinals transaction
one transaction · sender signs · recipient scans
Inputs
Sender · payment wallet
Inscription UTXO
P2TR
546 satsbc1p…

Carries the ordinal (sat #) or the rune balance

Funding UTXO
P2WPKH
48,210 satsbc1q…

Pays network fees and postage

Transaction
Built in the browser
1
Resolve the name

Decode sp1q… into the recipient's scan key B_scan and spend key B_spend.

2
Shared secret

ecdh = a · B_scan, where a is the sum of the sender's input private keys and the input hash.

3
One-time key

P = B_spend + hash(ecdh ‖ 0) · G. Output 0 pays P2TR(P) with the inscription sats, or the rune edict points at it.

4
Sign and broadcast

Unisat or Xverse signs all inputs. The chain sees an ordinary taproot transfer.

Outputs
Recipient · private wallet
vout 0
Inscription → recipient
One-time P2TR
546 satsbc1p…

Fresh key derived from the recipient's sp1 address. Nothing on chain links it to them.

vout 1
OP_RETURN runestone
Runestone
0 sats—

Edict: move the rune balance to output 0. Only for runes.

vout 2
Change → sender
P2WPKH
46,980 satsbc1q…

Back to the sender's payment wallet

Recipient finds it

Their private wallet scans block tweaks with the scan key and recognises output 0 without ever revealing the key to a server.

Ordinal stays intact

The inscribed sat travels at offset 0 of output 0. Coin selection never spends inscription UTXOs as fees.

Nothing to link

No address reuse, no on-chain hint of the sp1 wallet. Explorers see a fresh bc1p… output like any other taproot spend.

Address types involved
Four kinds of keys, one that never touches the chain
sp1q…
Silent payment address
  • bech32m, version 0, scan key ‖ spend key (66 bytes)
  • Shared like a domain name; reusable forever
  • Never appears on chain
bc1p…
One-time taproot output
  • P = B_spend + hash(ecdh ‖ k)·G, unique per payment
  • Holds the inscription or rune balance
  • Only the recipient can recognise or spend it
bc1q… / bc1p…
Payment wallet
  • Your Unisat or Xverse account (P2WPKH or P2TR)
  • Public alias target behind your sp1 wallet today
  • Funds fees, receives change
scan + spend keys
Private wallet
  • Derived from one wallet signature at m/352'
  • Scans block tweaks to find one-time outputs
  • Spends them with the tweaked spend key
Coming soon

Privacy ordinals and runes

Phase 2 unlocks the private wallet: scanning, inscription-aware coin selection, and sending ordinals or runes to any sp1 wallet. The wallet page already derives your keys; the rest follows.