Paper 2026/1568
Antichain Winternitz: Guaranteed Garbled-Circuit Label Revelation on Bitcoin with Permissionless Recovery
Abstract
Trust-minimized bridges on Bitcoin move SNARK verification off chain by evaluating the verifier as a garbled circuit. The bridge's on-chain spending condition obliges the Garbler to reveal the labels for one input without enabling the Evaluator to derive labels for any other input. Existing designs commit to each input bit with a Lamport signature which is costlier on chain, or with adaptors where there is no guarantee that the spend actually reveals the labels. We present Antichain Winternitz, a parametrized hash-chain construction whose admissible codewords form a constant-sum antichain. The on-chain locking script accepts an opening witness only if it encodes a valid codeword consistent with the committed chain terminals. Every accepted opening witness yields a valid codeword while the public off-chain table, verified during setup, maps every admissible codeword to its garbled-circuit labels, so any observer can recover them. Depending on the parameter set, we can obtain up to a 52.9% saving over Lamport signatures with only added off-chain storage of 43.8 kB per message bit.
Metadata
- Available format(s)
-
PDF
- Category
- Applications
- Publication info
- Preprint.
- Keywords
- SignaturesWinternitzBitcoinGarbled Circuits
- Contact author(s)
-
mukesh @ alpenlabs io
aaron @ alpenlabs io - History
- 2026-08-03: approved
- 2026-07-31: received
- See all versions
- Short URL
- https://ia.cr/2026/1568
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/1568,
author = {Mukesh Tiwari and Aaron Feickert},
title = {Antichain Winternitz: Guaranteed Garbled-Circuit Label Revelation on Bitcoin with Permissionless Recovery},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1568},
year = {2026},
url = {https://eprint.iacr.org/2026/1568}
}