I am making an attempt to ensure I perceive the query: Why Do We Use Change Descriptors when Constructing Wallets?
Context: I work on the Bitcoin Improvement Package, the place certainly one of our core sorts is the Pockets
sort. It has usually required 2 descriptors (an exterior descriptor and a change (inside) descriptor). This concept is commonplace observe and used extensively within the trade, however when urgent myself to put in writing about it in our documentation, I used to be left questioning if I actually knew why this was the case. Moreover, customers that request the Pockets be usable with just one descriptor had robust opinions about how the observe of utilizing 2 descriptors was possibly outdated and never required underneath sure circumstances. One person instructed us that it was a mistake to double down on the inner/exterior descriptor schism, and that it was a relic of the previous of folks that use electrum wallets.
As a library maintainer, that is the form of factor I need to have a stable grasp on. I am additionally main our documentation efforts, and plan on together with a web page on this.
Right here is my present understanding and questions.
Benefits of utilizing 2 descriptors
- It doubtlessly permits you settle for 0-conf cash when they’re coming to alter addresses, since you should have been the one to provoke that transaction and won’t double-spend your self.
- Privateness when utilizing a public electrum server: in circumstances the place you may ship a complete xpub to an electrum server, you are higher off not giving up your entire keychain however solely half? (at this level it appears trivial to reconstruct transaction historical past however nonetheless, I assume not giving it out is healthier than doing it).
- Having only one descriptor forces you to maintain monitor of addresses you have given out when constructing transactions, as a result of in any other case your pockets may use an exterior deal with already given out as change, and if this deal with given out to somebody finally ends up being utilized by them, you will double transactions at that deal with.
- In circumstances the place a pockets is recovered, change addresses can nonetheless be labeled as change.
Questions I Nonetheless Have
- Are there different pitfalls customers of single-descriptor wallets ought to concentrate on within the case the place wallets use extra personal sync instruments like personal Electrum servers and CBF, and utilizing fashionable pockets practices that by no means give out repeat addresses?
- Does the “change” keychain come into coin choice in any respect in Core? For instance, are there algos for coin choice the place realizing if a UTXO is a part of the change keychain slightly than the exterior keychain issues? In that case, how does it come into play?
- Another historic information that is good to know and take into accounts for builders of pockets can be appreciated.
Thanks!