Post
Topic
Board Development & Technical Discussion
Merits 1 from 1 user
Re: Ring signatures (monero-style) in Bitcoin: is it possible?
by
tromp
on 14/05/2025, 21:15:17 UTC
⭐ Merited by stwenhao (1)
a) what about the efficiency in terms of fees and speed?
Basic ring signatures take up space proportional to ring size which makes them rather inefficient.
Newer designs [1] get by with logarithmic size which support large ring sizes much more efficiently.

But in either case the real efficiency problem is the impact on UTXO size. Since one can never tell which is the real input and which are the decoys, no output can be known to be definitely spent. So the UTXO set balloons to the entire TXO set, with very detrimental impact on node efficiency. It's not so noticeable on Monero yet because daily tx volumes are about 15x smaller than Bitcoin.
Zcash suffers from the same problem, but with only 10% of Monero's tx volume, it's even less noticeable there.

[1] https://eprint.iacr.org/2024/921