The prefractal module landed on main in parallel with the branches that established the current module conventions, so it never picked up the integration points every other experimental module has.01379624covered the CMake experimental gate and EXTRA_DIST; these two are what remained. The CI gap is the more consequential of the pair. ci/ci.sh had no PREFRACTAL plumbing at all, so no CI job has ever passed --enable-module-prefractal -- the flag was reachable only by configuring by hand, and the module has been built and tested exclusively outside CI since it landed. - ci/ci.sh: PREFRACTAL joins FROST, CHILLDKG and ICEBERG in the reproduction header's variable list, and configure gains --enable-module-prefractal="$PREFRACTAL" after the iceberg line. Unlike2473c768there is no bench-step counterpart: prefractal ships neither a bench binary nor an example program, so the BENCH block needs nothing. - .github/workflows/ci.yml: a PREFRACTAL: 'no' default alongside the other module defaults, then PREFRACTAL: 'yes' in the 21 places that already enable FROST (11 inline matrix entries and 10 job-level env blocks). The default is not cosmetic -- ci.sh runs under set -eux, so an undefined PREFRACTAL would abort every job at the configure step, including the ones that build no modules at all. FROST-enabled jobs are the right target because enabling prefractal implies frost (configure.ac:539, mirrored in src/CMakeLists.txt:90): adding PREFRACTAL to a job that sets FROST: 'no' would silently turn frost on and change what that job covers. Every job that already builds frost also enables musig, schnorrsig, extrakeys and experimental, which is the remainder of prefractal's dependency chain, so no job needed any other variable adjusted. This is a slightly wider set than CHILLDKG and ICEBERG cover. The x86_64-debian matrix entry at line 117 sets FROST: 'yes' without CHILLDKG or ICEBERG, and2473c768deliberately left it alone; it gets PREFRACTAL here, on the rule above. The consequence is that no job now builds frost without prefractal. If that standalone-frost combination is worth preserving, that one entry is the place to drop it. README.md gains the doc/prefractal.md link beside the frost, chilldkg and iceberg entries. This is the exact inverse of the bug42f827a7fixed: there the documents were linked from README.md but missing from EXTRA_DIST, so the tarball's README pointed at files it did not carry. Here doc/prefractal.md has been in EXTRA_DIST since01379624but nothing referenced it, so it shipped unreferenced. All four module documents this fork adds are now both linked and distributed. Verified with ./autogen.sh, ./configure --enable-experimental --enable-module-prefractal and make -j: all exit 0 with no warnings, and the configure summary shows the implication chain resolving, with prefractal = yes pulling in frost = yes and musig = yes. nm confirms run_prefractal_api_test is linked into ./tests, and the suite passes. make dist succeeds and the tarball carries doc/prefractal.md next to doc/iceberg.md, src/modules/frost/frost.md and src/modules/chilldkg/chilldkg.md. ci/ci.sh passes sh -n. Verified programmatically for the workflow, as in2473c768: the YAML parses, 33 effective job contexts set FROST: 'yes', all 33 of them now also set PREFRACTAL: 'yes', every one has MUSIG, SCHNORRSIG, EXTRAKEYS and EXPERIMENTAL set to 'yes', and no context sets PREFRACTAL without FROST. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
6.2 KiB
libsecp256k1-zkp
A fork of libsecp256k1 with support for advanced and experimental features
Added features:
- Experimental module for ECDSA adaptor signatures.
- Experimental module for ECDSA sign-to-contract.
- Experimental modules for Confidential Assets (Pedersen commitments, range proofs, and surjection proofs).
- Experimental module for address whitelisting.
- Experimental module for Schnorr signature half-aggregation.
- Experimental module for FROST (BIP 445).
- Experimental module for ChillDKG, distributed key generation for FROST (bip-frost-dkg draft).
- Experimental module for Iceberg, a threshold scheme that lets a group of parties stand in for a single MuSig2 (BIP 327) participant.
- Experimental module for Prefractal, a nested FROST+MuSig2 signer that lets a FROST group occupy one participant slot of an ordinary MuSig2 (BIP 327) session.
Experimental features are made available for testing and review by the community. The APIs of these features should not be considered stable.
Build steps
Obtaining and verifying
The git tag for each release (e.g. v0.6.0) is GPG-signed by one of the maintainers.
For a fully verified build of this project, it is recommended to obtain this repository
via git, obtain the GPG keys of the signing maintainer(s), and then verify the release
tag's signature using git.
This can be done with the following steps:
- Obtain the GPG keys listed in SECURITY.md.
- If possible, cross-reference these key IDs with another source controlled by its owner (e.g. social media, personal website). This is to mitigate the unlikely case that incorrect content is being presented by this repository.
- Clone the repository:
git clone https://github.com/bitcoin-core/secp256k1 - Check out the latest release tag, e.g.
git checkout v0.7.1 - Use git to verify the GPG signature:
% git tag -v v0.7.1 | grep -C 3 'Good signature' gpg: Signature made Mon 26 Jan 2026 07:42:46 PM UTC gpg: using RSA key 2840EAABF4BC9F0FFD716AFAFBAFCC46DE2D3FE2 gpg: Good signature from "Pieter Wuille <pieter@wuille.net>" [unknown] gpg: aka "Pieter Wuille <pieter.wuille@gmail.com>" [full] gpg: aka "[jpeg image of size 5996]" [undefined] gpg: WARNING: This key is not certified with a trusted signature! gpg: There is no indication that the signature belongs to the owner. Primary key fingerprint: 133E AC17 9436 F14A 5CF1 B794 860F EB80 4E66 9320 Subkey fingerprint: 2840 EAAB F4BC 9F0F FD71 6AFA FBAF CC46 DE2D 3FE2
Building with Autotools
$ ./autogen.sh # Generate a ./configure script
$ ./configure # Generate a build system
$ make # Run the actual build process
$ make check # Run the test suite
$ sudo make install # Install the library into the system (optional)
To compile optional modules (such as Schnorr signatures), you need to run ./configure with additional flags (such as --enable-module-schnorrsig). Run ./configure --help to see the full list of available flags. For experimental modules, you will also need --enable-experimental as well as a flag for each individual module, e.g. --enable-module-rangeproof.
Building with CMake
To maintain a pristine source tree, CMake encourages to perform an out-of-source build by using a separate dedicated build tree.
Building on POSIX systems
$ cmake -B build # Generate a build system in subdirectory "build"
$ cmake --build build # Run the actual build process
$ ctest --test-dir build # Run the test suite
$ sudo cmake --install build # Install the library into the system (optional)
To compile optional modules (such as Schnorr signatures), you need to run cmake with additional flags (such as -DSECP256K1_ENABLE_MODULE_SCHNORRSIG=ON). Run cmake -B build -LH or ccmake -B build to see the full list of available flags.
Cross compiling
To alleviate issues with cross compiling, preconfigured toolchain files are available in the cmake directory.
For example, to cross compile for Windows:
$ cmake -B build -DCMAKE_TOOLCHAIN_FILE=cmake/x86_64-w64-mingw32.toolchain.cmake
To cross compile for Android with NDK (using NDK's toolchain file, and assuming the ANDROID_NDK_ROOT environment variable has been set):
$ cmake -B build -DCMAKE_TOOLCHAIN_FILE="${ANDROID_NDK_ROOT}/build/cmake/android.toolchain.cmake" -DANDROID_ABI=arm64-v8a -DANDROID_PLATFORM=28
Building on Windows
The following example assumes Visual Studio 2022. Using clang-cl is recommended.
In "Developer Command Prompt for VS 2022":
>cmake -B build -T ClangCL
>cmake --build build --config RelWithDebInfo
Usage examples
Usage examples can be found in the examples directory. To compile them you need to configure with --enable-examples.
- ECDSA example
- Schnorr signatures example
- Deriving a shared secret (ECDH) example
- ElligatorSwift key exchange example
- MuSig2 Schnorr multi-signatures example
To compile the examples, make sure the corresponding modules are enabled.
Benchmark
If configured with --enable-benchmark (which is the default), binaries for benchmarking the libsecp256k1-zkp functions will be present in the root directory after the build.
To print the benchmark result to the command line:
$ ./bench_name
To create a CSV file for the benchmark result :
$ ./bench_name | sed '2d;s/ \{1,\}//g' > bench_name.csv
Reporting a vulnerability
See SECURITY.md
Contributing to libsecp256k1
See CONTRIBUTING.md