NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
crates.io · #964 most downloaded on crates.io
Rust wrapper library for Pieter Wuille's `libsecp256k1`. Implements ECDSA and BIP 340 signatures for the SECG elliptic curve group secp256k1 and related utilities.
Last release 1 months ago
29 Aug 2026
Release timing varies
gaps range from 2 weeks to 10 months
Most releases are documented
notes for 42 of the last 60 stable releases
9 versions withdrawn
withdrawn after publishing
11 years old
100 releases · first in 2015
Metadata-only release; no code changes.
Metadata-only release; no code changes.
repository/homepage metadata of both crates at
https://git.rust-bitcoin.org/rust-bitcoin/rust-secp256k1 instead of GitHub
(secp256k1-sys released as 0.14.1).master from README.md so it is prominent on
crates.io.(Note, to help with the upgrade path we left the methods on the context in place but deprecated.)
We released 0.32.0-beta.0, 0.32.0-beta.1, 0.32.0-beta.2 before
working out that this number scheme does not play nicely with cargo;
this release supersedes those betas and 0.32.0 will never be released.
Secp256k1 from public API functionsThis one is massive, we came up with an solution to the global context that works in both std and no-std environments. With this release you don't have to create and pass in a context object in all the APIs - BOOM!
(Note, to help with the upgrade path we left the methods on the context in place but deprecated.)
And we also did:
bitcoin-hashes feature (and dependency) #837Arbitrary crate and add PublicKey arbitrary impl #826PSBTs #828verify_ecdsa args to match those of verify_schnorr (sig now comes before msg) #751secp256k1-sys: Fix lowmemory feature #799RecoveryId conversion functions #800RecoveryId value #801from_secret_bytes, to_secret_bytes, and as_secret_bytes to SecretKey; deprecate from_slice and secret_bytes #842ThirtyTwoByteHash, ElligatorSwiftParty, Message::from_slice, and FFI as_ptr/as_mut_ptr methods) #854secret_bytes to to_secret_bytes (in Keypair and ecdh::SharedSecret) #863non_secure_erase to musig::SessionSecretRand, musig::SecretNonce, and ElligatorSwiftSharedSecret #883ElligatorSwift::from_byte_array and ElligatorSwift::to_byte_array #888AsRef<[u8]> for ElligatorSwiftSharedSecret #890ElligatorSwift::from_pubkey in favor of from_pubkey_with_rnd #895Verification generic from XOnlyPublicKey::verify #916str::FromStr and serde::{Serialize, Deserialize} for Scalar #931Keypair::from_key_parts to cheaply construct Keypair #940secp256k1-sys v0.14.0) #943AsRef and Borrow impls from SecretKey and ecdh::SharedSecret #944Hash for SecretKey #944XOnlyPublicKey::to_byte_array, Keypair::from_secret_bytes, and ecdh::SharedSecret::as_secret_bytes/from_secret_bytes; deprecate XOnlyPublicKey::serialize, Keypair::from_seckey_byte_array, and ecdh::SharedSecret::from_bytes #944musig::SessionSecretRand Debug output and rename its byte accessors to to_secret_bytes/as_secret_bytes #944Done as an initial PR #716 then a bunch of follow up PRs:
If you used the MuSig2 API in the 0.32.0 betas, note the following changes:
SessionSecretRand::assume_unique_per_nonce_gen
recommended using the output of a stable monotonic counter as the session
randomness. This is only safe when secret key material is mixed into the
nonce derivation; otherwise a co-signer who can predict these bytes can
recompute your secret nonce and extract your secret key from your partial
signature. The constructor now takes a &SecretKey and mixes it in
(matching BIP-327's NonceGen), and KeyAggCache::nonce_gen now takes the
signer's Keypair along with a non-repeating counter #941.
The old unkeyed behavior remains available as
SessionSecretRand::assume_uniformly_random and
KeyAggCache::nonce_gen_with_uniform_randomness for callers who genuinely
have uniformly random, secret bytes.SessionSecretRand API was changed to better match the SecretKey
API: the byte accessors are now to_secret_bytes/as_secret_bytes, the
Debug output is redacted, and the AsRef/Borrow impls were removed
#944.musig module docs; users may
find it worthwhile rereading them #933,
#934,
#936.One column per quarter.
secp256k1-0.32.0-beta.2
secp256k1-0.32.0-beta.2
secp256k1-0.32.0-beta.1
secp256k1-0.32.0-beta.1
rust-secp 0.32.0-beta.0
rust-secp 0.32.0-beta.0
Update deprecation notes with since instead of TBD.
since instead of TBD.Deprecate ElligatorSwiftParty in favor of Party #752
rand to 0.9 #788from_u8_masked RecoveryId constructor #7780cdc758a56360bf58a851fe91085a327ec97685a (secp256k1-sys 0.6) #764Keypair::sign_schnorr_no_aux_rand #762Message with Into<Message> in ECDSA signing API #755ElligatorSwiftParty in favor of Party #752Deprecate Message::from_digest_slice in favor of Message::from_digest #712
Message::from_digest_slice in favor of Message::from_digest #712SecretKey; tighten bitcoin_hashes dependency version #722KeyPair::from_str on global-context or alloc #728schnorr::Signature from byteslices #730RecoveryId an enum rather than integer #743Because the reexport can have any of the *incompatible* versions using it is prone to breakage. The bitcoin_hashes crate is not used in our API anyway
Deprecate hashes reexport
Because the reexport can have any of the incompatible versions using it is prone to breakage.
The bitcoin_hashes crate is not used in our API anyway, so you should just depend on it yourself
using a version range that's appropriate for your crate.
Fix version range of the bitcoin_hashes crate.
Deprecate ThirtyTwoByteHash #686
Deprecate ThirtyTwoByteHash #686
This trait turned out to be problematic during upgrade because we support a ranged dependency for
bitcoin_hashes. Consider implementing From<T> for Message for your type iff your type is a 32
byte hash (ie, output from a hash algorithm that produces a 32 byte digest like sha256). When
using the impl, consider using Message::from instead of hash.into() because we will be
introducing generics in a future version and the compiler will not be able to work out the target
type.
Bump MSRV to Rust v1.56.1 #693
Upgrade hashes using range dependency version = ">= 0.12, <= 0.14" #690
Depend on latest secp256k1-sys (vendors secp256k1 v0.4.1) #688
Implement Ord and PartialOrd for RecoverableSignature #611
Update secp265k1-sys to 0.9.2 (contains some fixes for WASM and a FFI binding fix)
SerializedSignature type #658 #659Add bindings to the ElligatorSwift implementation #627
bitcoin_hashes v0.13.0 #621PublicKey #618PartialEq, Eq, PartialOrd, Ord, and Hash from the
impl_array_newtype macro. Users will now need to derive these traits if they are wanted.Depend on newly release `bitcoin_hashes` v0.12.
* Update libsecp25k1 to v0.2.0
Fix soundness issue with `preallocated_gen_new`
preallocated_gen_newsecp256k1-sys v0.7.0rustfmt to the codebase.ONE_KEY (consider using FromStr as a replacement).Nothing published for this version
Nothing published for this version
Fix broken deserialization logic of `KeyPair` that previously always panicked. After the patch deserialization only panics if neither the global-conte
KeyPair that previously always panicked. After the patch deserialization only panics if neither the global-context nor the alloc (default) feature is active.Upgrade to new release of bitcoin_hashes.
Nothing published for this version
Disable automatic rerandomization of contexts under WASM
Add must_use for mut self key manipulation methods
Move `cbor` to dev-dependencies
Enable "rand/std_rng" feature when the crate's "rnd-std" feature is enabled.
Enable "rand/std_rng" feature when the crate's "rnd-std" feature is enabled.
The major change in this version is the increase of the Minimum Supported Rust Version (MSRV) from 1.29 to 1.41.1, this is a big change because it int
The major change in this version is the increase of the Minimum Supported Rust Version (MSRV) from 1.29 to 1.41.1, this is a big change because it introduces Rust Edition 2018 to the codebase along with all the benefits that brings.
rand dependency to 0.8KeyPair::from_secret_key borrows SecretKey instead of taking ownershipSerializedSignature no longer implements Defaultsign_ecdsa_with_noncedata and sign_ecdsa_recoverable_with_noncedata can be used to add additional entropy to ECDSA signaturesTryFrom for ParitySharedSecret can be created from a slice, parsed from a hex string, or (de)serialized using serdeSerializedSignature implements IntoIterator (both owned and shared reference)std::hash::Hash for Signatureglobal-context-less-secure feature now activates global-context.githooks/ directory added for contributorsNothing published for this version
Reintroduce accidentally removed possibility to create SharedSecret from byte serialization
SharedSecret from byte serializationDisable bitcoin_hashes/std by default; add `bitcoin-hashes-std` feature to re-enable it
bitcoin_hashes/std by default; add bitcoin-hashes-std feature to re-enable itschnorrsig methods to schnorrSharedSecret string serializationSharedSecret API to use a 32-byte buffer; users of custom hashes should now use bare arrays rather than this type.Parity from i32 to u8; clean up error handlingDeprecate the `generate_schnorrsig_keypair` method (unclear value)
generate_schnorrsig_keypair method (unclear value)KeyPairParity type to more clearly match our desired semantics; the From<i32> impl on this type is now deprecated. Also #400.global-context-less-secure feature accordingly.Debug impl for RecoverableSignatureLowerHex and DisplayNothing published for this version
Nothing published for this version
Fix KeyPair::from_seckey_slice error return value
KeyPair::from_seckey_slice error return valuelowmemory precomp table sizeKeyPair::serialize_secbitcoin_hashes version to 0.10; rename secp256k1::bitcoin_hashes module to secp256k1::hashes to align with bitcoin crate namingPublicKey::combine_keysDisplay and Debug for secret keys to only output a truncated hashHash for schnorrsig::SignatureKeyPair typetweak_add_assign and tweak_add_check to use an opaque Parity type rather than a booleanFix `SecretKey` validation in `from_str`
SecretKey validation in from_strglobal-context-less-secure feature which creates a non-randomized global context (and does not require rand or std)schnorrsig::KeyPair::from_secret_key convenience functioncombine_keys function to PublicKeyalloc feature requiring rustc 1.36+ to enable context creation without stdAdd some missing `#derive`s to `Error`
#derives to ErrorNothing published for this version
remove `ffi::PublicKey::blank` and replace with unsafe `ffi::PublicKey::new` and `ffi::PublicKey::from_array_unchecked`; similar for all other FFI typ
ffi::PublicKey::blank and replace with unsafe ffi::PublicKey::new and ffi::PublicKey::from_array_unchecked; similar for all other FFI typesPublicKey which does not match the ordering used by Bitcoin Core (matching this would be impossible as it requires tracking a compressedness flag, which libsecp256k1 does not have)AlignedType in preallocated-context API to enforce alignment requirements; previously it was possible to get UB by using misaligned memory storesRUSTFLAGS instead* Update MSRV to 1.29.0
Add feature-gated bitcoin_hashes dependency and `ThirtyTwoByteHash` trait
bitcoin_hashes dependency and ThirtyTwoByteHash traitFix linking in the fuzztarget feature.
fuzztarget feature.Correctly prefix the secp256k1-sys links field in Cargo.toml.
Move FFI into secp256k1-sys crate.
external-symbols feature for not building upstream.Nothing published for this version
Nothing published for this version
Pin the cc build-dep version to < 1.0.42 to remain compatible with rustc 1.22.0.
rand-std feature.< 1.0.42 to remain
compatible with rustc 1.22.0.as_*ptr() to a new safer CPtr traitNothing published for this version
Add feature lowmemory that reduces the EC mult window size to require significantly less memory for the validation context (~680B instead of ~520kB),
lowmemory that reduces the EC mult window size to require
significantly less memory for the validation context (~680B instead of
~520kB), at the cost of slower validation. It does not affect the speed of
signing, nor the size of the signing context.Nothing published for this version
Implement hex human-readable serde for PublicKey
cc dependency requirementsImplemented FFI functions: secp256k1_context_create and secp256k1_context_destroy in rust.
secp256k1_context_create and secp256k1_context_destroy in rust.Feature-gate endormorphism optimization because of a lack of clarity with respect to patents
Update minimum supported rust compiler 1.22.
serialize_der function with SerializedSignature struct.no_std). std feature is on by default.Signatures and SecretKeys.Signature is less than 72 bytes.recovery is set (non-default).rand dependency from 0.4 to 0.6 and add rand_core 0.4 dependency.cc dependency requirements.* Fuzzer bug fix
Fixed cc crate version to maintain minimum compiler version without breakage
cc crate version to maintain minimum compiler version without breakagelibc dependency as it our uses have been subsumed into stdlibOverhaul API to remove context object when no precomputation is needed
ThirtyTwoByteHash trait which allows infallible conversions to MessagesMessage objects since signatures on them are forgeable for all keysops::Index implementations for SignatureZERO_KEY constantNothing published for this version
Use pub extern crate to export dependencies whose types are exported
pub extern crate to export dependencies whose types are exportedAdd FromStr and Display for Signature and both key types
FromStr and Display for Signature and both key typesbuild.rs for Windows and rustfmt configuration for docs.rsSignature Debug outputNo changes, just fixed docs.rs configuration
Correct endianness issue in RFC6979 nonce generation
Your coding agent can read these notes before it upgrades. Set up the MCP server →