Skip to content

Shelf 7 · Context · 29 / 45

Bitcoin Glossary & Script Primer

Essential Bitcoin terminology and the Script language explained. From blocks and nodes to PoW, UTXO, and opcodes.

Check this article’s sources (6)

Article brief

UTXO, nonce, mempool: unfamiliar words are not a wall. They are labels on the parts of one very large machine.

A useful mental model

Use the glossary like a museum map and audio guide, moving through rooms for money, keys, transactions, the network, and Script.

Where the analogy stops

A short definition is an entrance, not the full implementation or its context. Similar terms can play different protocol roles, and software details change over time.

You will gain a reference that lets you keep reading official documents and block explorers without getting stuck on a single word.

Open the glossary
Article contents12 chaptersJump to a chapter

1Basic terms

Block: A bundle of verified transactions. A new block is produced roughly every 10 minutes and cryptographically linked to the previous one.

Blockchain: The chain formed when each block contains the hash of the block before it. It is what guarantees transaction verification and irreversibility.

Node: Software connected to the Bitcoin network. Full nodes keep the entire blockchain and verify every rule.

Miner: Software that computes hashes over and over to produce new blocks. A miner that succeeds receives the block reward.

Mempool (Memory Pool): Temporary storage for unconfirmed transactions waiting to be included in a block. Each node keeps its own mempool independently.

Block Height: A block's position in the chain, counted from the genesis block as zero. Many things, halvings and upgrade activation points among them, are specified by block height rather than by date.

Genesis Block: The first block, created on January 3, 2009 (height 0). The Times headline is embedded in its coinbase, and because of how the block is handled in the implementation, its 50 BTC reward cannot be spent.

2Cryptographic terms

Hash: The output of a cryptographic hash function. It generates a fixed-length "fingerprint" from arbitrary data. The same input always produces the same output, but reversing the process is computationally infeasible.

Proof of Work: Data that is "costly to produce but easy to verify." Bitcoin uses the Hashcash system, requiring a block's hash to fall below a specific threshold.

Nonce: An otherwise meaningless number used to alter the hash outcome. Miners iterate through nonces to find a hash that meets the difficulty condition.

Merkle Root: A single hash that recursively summarizes all transaction hashes in a block. Included in the block header, it enables efficient tamper detection.

Difficulty: A parameter adjusted every 2,016 blocks (~2 weeks) that represents how hard it is to generate a block. It auto-adjusts based on the network's total hash rate.

Schnorr Signature: The signature scheme introduced with Taproot (BIP-340). Verification is simpler than ECDSA, and its linearity makes aggregating several keys and signatures into one mathematically straightforward.

3Mining terms

Mining: Repeatedly hashing a block header while varying its fields until the result falls below the difficulty target. Whoever finds it first gets to propose the next block, which orders transactions and issues new coins at the same time.

Hash Rate: How many hash attempts the whole network makes per second. It cannot be observed directly, so it is estimated from the observed block pace and the current difficulty, and expressed in units such as EH/s (10^18 hashes per second).

Difficulty Adjustment: Every 2,016 blocks, the time the period actually took is compared with the 20,160-minute (14-day) target and the difficulty is recalculated. A single adjustment is capped at a factor of four in either direction, which keeps the average block interval near 10 minutes even as hash rate moves.

ASIC (Application-Specific Integrated Circuit): A chip designed to do nothing but SHA-256 computation. Its efficiency is orders of magnitude beyond general-purpose CPUs and GPUs, and mining today assumes ASICs.

Mining Pool: An arrangement where many miners combine hash power and split the reward for any block found in proportion to contribution. It smooths out individual income variance, but it also concentrates the power to decide block contents in the pool operator, which is a recurring decentralization concern.

Block Reward: What a miner receives for producing a block: the newly issued subsidy (3.125 BTC since the 2024 halving) plus the fees of the transactions included in that block. The subsidy halves on schedule until only fees remain.

4Transaction terms

Transaction: A record of Bitcoin transfer. Composed of inputs (consuming UTXOs) and outputs (creating new UTXOs).

UTXO (Unspent Transaction Output): An unspent transaction output. A Bitcoin "balance" is the sum of all UTXOs associated with an address, which is fundamentally different from an account balance model.

Coinbase: The first transaction in a block. It contains the mining reward, and miners can embed arbitrary data in its input. The Times headline in the genesis block was recorded here.

Confirmation: The block that included the transaction, plus every block stacked on top of it. The including block itself counts as one, so a transaction has one confirmation the moment it lands in a block. By convention, 6 confirmations is treated as "final."

Double Spending: Attempting to spend the same coins twice. Bitcoin's consensus mechanism prevents this.

Transaction Fee: An optional fee attached to a transaction. What miners prioritize is not the absolute fee but the fee rate per unit of size (sat/vB); at the same rate, the amount being sent does not affect priority.

Witness: The unlocking data (signatures, public keys) that SegWit separates from the transaction body. Because it falls outside the transaction ID (txid) computation, rewriting a signature can no longer change the ID, which is what solved transaction malleability.

vB / WU (virtual byte, weight unit): The units used to measure block capacity. Non-witness data counts as 4 WU per byte and witness data as 1 WU per byte, with a block limit of 4,000,000 WU (= 1,000,000 vB). Since 1 vB = 4 WU, this accounting is exactly why SegWit transactions cost less in fees.

nLockTime / nSequence: nLockTime is the field specifying the block height or time at which the whole transaction becomes valid. nSequence is a per-input field used to signal RBF and to express relative timelocks via OP_CHECKSEQUENCEVERIFY.

PSBT (Partially Signed Bitcoin Transaction): The standard format (BIP-174) for passing unsigned or partially signed transactions between wallets and signing devices. It is what hardware-wallet signing and multisig signature collection are built on.

5Network terms

Main Chain: The valid chain carrying the greatest cumulative proof of work. It is usually called "the longest chain," but what nodes actually compare is accumulated work (nChainWork), not the number of blocks.

Orphan Block: A block whose parent is unknown. A Stale Block was once part of the main chain but is no longer included.

Reorganization (Reorg): When a chain with greater cumulative work appears, nodes switch over to it. Small reorgs of 1–2 blocks occur naturally.

Seed Nodes: The starting point a client uses to find peers on first launch. By default it queries DNS seeds (domain names built into the client that return a list of peer addresses) and only falls back to the hardcoded list of IP addresses (fixed seeds) when no DNS seed answers.

SPV (Simplified Payment Verification): Verifying only block headers and the Merkle path for the transaction in question, rather than the whole blockchain. Introduced in section 8 of the whitepaper, it is the basis of lightweight wallets. Because it does not validate the transaction itself, it rests on trusting the chain with the most accumulated work.

Satoshi: The smallest unit of Bitcoin. 1 satoshi = 0.00000001 BTC. Named after Bitcoin's creator.

6What is Bitcoin Script?

Bitcoin Script is the programming language that controls Bitcoin transactions. It's a stack-based language similar to Forth, intentionally designed to be Turing-incomplete (no loops).

Scripts consist of two parts: scriptPubKey (sets spending conditions) and scriptSig (provides inputs to satisfy those conditions). If execution completes with a true (non-zero) value on top of the stack, the transaction is valid.

Since SegWit there is a third component: the witness. For P2WPKH and P2TR the scriptSig is left empty, and the signatures, public keys, and the script to be executed all live in the witness, where the spending conditions are evaluated.

This design enables flexible spending conditions: "only the owner of a specific private key can spend," "requires multiple signatures," or "cannot be spent until a certain time has passed."

The Turing-incomplete design is deliberate. It prevents infinite loops and resource-exhaustion attacks, and guarantees that every script completes in finite time.

7Standard transaction types

P2PKH (Pay-to-Public-Key-Hash): The most common format. Requires a public key matching the hash and a corresponding signature. Addresses starting with "1" use this type.

P2SH (Pay-to-Script-Hash): Sends to the hash of a script. Enables multisig and more complex conditions. Addresses start with "3."

P2WPKH / P2WSH (SegWit): Uses Segregated Witness. Separates signature data from the transaction body for improved block capacity efficiency. Addresses start with "bc1q."

P2TR (Taproot): Activated in 2021, and still the newest address format users receive funds with. It combines Schnorr signatures with MAST (Merklized Abstract Syntax Tree, also rendered "Merklized Alternative Script Trees" in the Taproot context) for improved privacy and efficiency. Addresses start with "bc1p." Note that Bitcoin Core 28 (2024) recognized P2A (Pay-to-Anchor) as an additional standard output type, but that is a special-purpose output for fee bumping, not an address format for receiving payments.

OP_RETURN: An opcode that creates provably unspendable outputs. Used for data embedding. Allows recording metadata on the blockchain without polluting the UTXO set. The data size is governed by node relay policy (not consensus); its default cap was long ~80 bytes, but Bitcoin Core v30 (2025) raised that default dramatically, effectively removing the limit (configurable per node).

8Key opcodes

Crypto operations: OP_SHA256 (SHA-256 hash), OP_HASH160 (double hash: SHA-256 + RIPEMD-160), OP_CHECKSIG (signature verification), OP_CHECKMULTISIG (multisig verification). Note that OP_CHECKMULTISIG is disabled inside Taproot's script environment (tapscript, BIP-342), which instead uses OP_CHECKSIGADD to accumulate successful signature checks on the stack.

Stack operations: OP_DUP (duplicate top item), OP_DROP (discard top item), OP_SWAP (swap top two items).

Flow control: OP_IF / OP_ELSE / OP_ENDIF (conditional branching), OP_VERIFY (abort script on verification failure).

Timelocks: OP_CHECKLOCKTIMEVERIFY (absolute timelock), OP_CHECKSEQUENCEVERIFY (relative timelock). These are the building blocks the Lightning Network depends on.

Disabled opcodes: OP_CAT (string concatenation), OP_MUL (multiplication), and a number of others were disabled together in 2010. This was not because each one had a confirmed bug; it was a precautionary blanket measure against unexpected behavior and resource consumption. Re-enabling OP_CAT in tapscript is proposed as BIP-347, but it has not been activated as of 2026. Adding new opcodes requires careful softfork implementation.

9Protocol upgrade terms

BIP (Bitcoin Improvement Proposal): The document format used to propose and record changes and standards for Bitcoin. BIPs are cited by number: BIP-32 (HD wallets), BIP-39 (seed phrases), BIP-141 (SegWit). A BIP is only a proposal; having a number does not mean it is active.

Soft Fork: A backward-compatible upgrade that only tightens the rules. Blocks made under the new rules still look valid to older nodes, so not every node has to upgrade at once. Both SegWit and Taproot were deployed as soft forks.

Hard Fork: A non-backward-compatible upgrade that makes previously invalid blocks valid. Nodes that do not upgrade end up on a different chain, so without broad agreement it results in a chain split, as it did with Bitcoin Cash.

SegWit (Segregated Witness): The soft fork activated in August 2017 (BIP-141). By separating signature data (the witness) from the transaction body and changing how it is counted, it effectively raised block capacity and removed transaction malleability, which is what made the Lightning Network practical.

Taproot: The soft fork activated in November 2021 (BIP-340 / 341 / 342). It introduced Schnorr signatures, MAST, and tapscript, making a simple payment and a complex conditional spend harder to tell apart on-chain.

10Security concepts

51% Attack: An attack in which an entity controls over half the network's computing power. They can reverse their own transactions and block others' confirmations, but cannot steal anyone else's coins.

Sybil Attack: Creating numerous fake nodes to manipulate the network. Bitcoin mitigates this in layers: outbound connections are generally limited to one per /16 subnet, the peer address book is spread across many buckets, and block-relay-only connections are maintained alongside normal ones.

Race Attack: A zero-confirmation double spend in which two conflicting transactions are broadcast at nearly the same moment: one paying the merchant, one paying the attacker back. A merchant can reduce the risk somewhat by waiting a few seconds to see whether a conflicting transaction shows up, by listening on a well-connected node, and by refusing incoming connections.

Finney Attack: The attacker mines a block containing a payment to themselves, withholds it, pays a merchant with the same funds at zero confirmations, and then releases the withheld block to void the payment. Because the weapon is a pre-mined block, watching the network reveals nothing and the race-attack countermeasures (waiting a few seconds, tuning connectivity) do not neutralize it. Waiting for confirmations is the only reliable defense.

Vector76 Attack: A hybrid of the race and Finney attacks in which a withheld block is delivered directly to the target node alone, manufacturing an apparent one confirmation. It is the standard reason not to rush acceptance even at one confirmation, let alone zero.

Timejacking: Manipulating a node's sense of time to affect block validity judgments. Bitcoin Core clamps the offset derived from peers to ±70 minutes, and BIP-113 evaluates timelocks against the median time past (MTP) of the last 11 blocks, so no single peer's claim can move the clock.

DoS Attack: Overloading nodes with excessive data to disrupt normal operations. Bitcoin clients respond with layered defenses: message size caps, disconnecting and banning misbehaving peers, limits on connection count and bandwidth, and rate limiting on requests.

11Wallet & custody terms

Address: A string identifying where bitcoin is sent. It is derived from a public key or a script and encodes the conditions required to spend those coins. Depending on the format, it begins with "1", "3", "bc1q", or "bc1p".

Private Key: The only data that can produce the signature needed to spend coins. It is effectively a very large random number, and whoever knows it can move those coins.

Public Key: A key derived from the private key through a one-way elliptic-curve computation. The public key (or its hash) becomes the basis of an address and is used to verify signatures. No practical recovery of the private key is known with classical computation. The Shor risk from a sufficiently large fault-tolerant quantum computer is covered in "Can Quantum Computers Break Bitcoin?"

Base58Check / Bech32 and Bech32m: The character encodings used for addresses. Legacy addresses starting with "1" or "3" use Base58Check, SegWit addresses starting with "bc1q" use Bech32 (BIP-173), and Taproot addresses starting with "bc1p" use Bech32m (BIP-350). All of them carry a built-in checksum that catches typos.

Seed Phrase (Recovery Phrase): The word sequence that serves as a wallet backup. BIP-39 defines five lengths (12, 15, 18, 21, and 24 words), of which 12 and 24 are what wallets actually use in practice. Every private key in the wallet can be regenerated from it.

Passphrase: An optional extra secret added on top of the seed phrase, informally called the "25th word." Adding one produces an entirely different wallet, so forgetting it makes recovery impossible.

HD Wallet (Hierarchical Deterministic Wallet): A scheme that derives an unlimited tree of keys and addresses from a single seed (BIP-32). It is what allows a fresh address to be used for every receipt.

Hot Wallet / Cold Wallet: A hot wallet handles private keys on an internet-connected device; a cold wallet keeps them completely disconnected. The choice is a trade-off between convenience and security.

Hardware Wallet: A dedicated device that stores private keys internally and performs signing inside the device, so the keys are never exposed to a general-purpose PC or phone. It is the most common implementation of cold storage.

Paper Wallet / Steel Wallet: Storing keys or a seed phrase by printing them on paper or stamping them into metal. Both are fully offline, but paper is vulnerable to fire and decay, which is exactly the weakness metal is used to cover.

Multisig (Multi-signature): A setup requiring m signatures out of n keys before funds can move. It builds in redundancy so that losing a single key does not mean losing the coins.

Custodial / Non-custodial (Self-custody): Custodial means a third party such as an exchange holds the private keys; non-custodial means the user holds them. Self-custody grants full control and full responsibility at the same time.

KYC (Know Your Customer): The identity-verification process that operators such as exchanges perform on their users. Required in most jurisdictions as an anti-money-laundering measure, it links the addresses used through that account to a real identity.

CoinJoin: A technique in which several users' inputs and outputs are combined into a single transaction, making it harder for an outside observer to tell which input corresponds to which output. Participants only cooperate in building one transaction; each keeps control of their own funds throughout.

12Ecosystem & market terms

Halving: The rule that cuts the mining reward in half every 210,000 blocks (roughly four years). The fourth halving, in 2024, reduced the reward to 3.125 BTC.

Lightning Network: A Layer 2 that uses payment channels and HTLCs to move value off-chain, instantly and at low cost. Only channel opens and closes are recorded on-chain.

HTLC (Hash Time-Locked Contract): A conditional payment that says "claimable by whoever reveals the preimage of a given hash, and otherwise refunded to the sender after a set time." Multi-hop Lightning routing uses it to make an entire path settle or fail as a unit without trusting the intermediate nodes.

Layer 1 / Layer 2: Layer 1 is the Bitcoin base chain itself. Layer 2 refers to protocols built on top of it that settle back to the base chain only for final results.

Sidechain: A separate chain linked to Bitcoin by a two-way peg, with its own consensus and block production. Liquid is the best-known example.

On-chain / Off-chain: On-chain transactions are recorded directly on the blockchain; off-chain transactions are settled on a Layer 2 or inside the internal ledger of a service provider.

Ordinals / Inscription: Ordinals is the scheme that assigns a serial number to each individual satoshi, and an inscription is data written onto one of those numbered satoshis. It required no protocol change, and later gave rise to token standards such as Runes.

Stablecoin: A crypto-asset designed to track the value of a fiat currency or similar reference. In Japan they are regulated as "electronic payment instruments," and domestic issuance is limited to banks, funds-transfer operators, and trust companies. For foreign-issued stablecoins, a Cabinet Office Ordinance amendment promulgated on May 19, 2026 and effective June 1, 2026 treats trust beneficiary rights under foreign law equivalent to Japan's framework as electronic payment instruments, setting out the criteria under which registered domestic electronic payment instruments service providers may handle them — so "only three kinds of Japanese institution may issue" is an incomplete picture of the market.

CBDC (Central Bank Digital Currency): Fiat currency issued in digital form by a central bank itself. Having a central issuer and administrator makes it a fundamentally different design from Bitcoin, which has no issuer at all.

Bitcoin ETF: An exchange-traded product tracking the bitcoin price. Spot ETFs hold the asset itself while futures ETFs track it through futures contracts, and U.S. spot ETFs were approved in January 2024.

CEX / DEX (Centralized / Decentralized Exchange): A CEX takes custody of user assets and performs identity verification, while a DEX lets users trade through a protocol without handing over custody. For bitcoin itself, non-custodial exchange is typically done through mechanisms such as atomic swaps.

RBF (Replace-By-Fee): A mechanism for replacing an unconfirmed transaction with a higher-fee one that spends the same inputs. For years it was opt-in under BIP-125, applying only to transactions that signaled replaceability via nSequence, but Bitcoin Core 28.0 (2024) flipped the mempoolfullrbf default so that full-RBF (relaying replacements regardless of signaling) is now the default. It is the standard remedy when a fee turns out to be too low to confirm.

CPFP (Child-Pays-For-Parent): Creating a high-fee "child" transaction that spends the output of a stuck low-fee parent, which gives miners an incentive to mine both together.

sat/vB (satoshis per virtual byte): The unit for expressing a fee rate: how many satoshis are paid per virtual byte. The total fee is the fee rate multiplied by the transaction size, which is why the amount being sent does not by itself affect the fee.

Dust: A UTXO so small that spending it would cost more in fees than it is worth. Most nodes and wallets apply a dust threshold below which such outputs are not relayed. Sending tiny amounts to probe how addresses are linked is known as a dusting attack.

Travel Rule: A requirement, based on FATF recommendations, that service providers share originator and beneficiary information when crypto-assets are transferred between them. Implementation proceeds jurisdiction by jurisdiction.

Virgin Bitcoin: Block rewards that have never been spent since they were mined. They are sometimes noted for regulatory reasons as coins with no transaction history. The term comes up only in narrow contexts, which is why this glossary keeps it here as an appendix entry.

Primary sources

Read next

Privacy & Anonymity8 min read
Share

Citation

Title
Bitcoin Glossary & Script Primer
Source
Bitcoin Library (bitcoin.ne.jp)
Canonical URL
https://bitcoin.ne.jp/en/learn/glossary
Author
KK siiiiiixth
Topic
glossary
Published
Updated
Last verified
Editorial policy
https://bitcoin.ne.jp/en/editorial-policy
About
https://bitcoin.ne.jp/en/about
License
Content reuse terms

Operator-owned article text, original diagrams, and public data may be used for citation, summarization, indexing, search, RAG, machine analysis, and AI model training. When content is presented to readers, identify Bitcoin Library and the applicable canonical URL where technically practicable.

Revision history

  1. Qualified public-key inversion as impractical for known classical computation and removed the absolute wording that conflicted with future Shor risk.
  2. Corrected 16 definitions against primary specifications and added roughly 20 terms, including the race attack.