NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
crates.io · #964 most downloaded on crates.io
Rust wrapper library for Pieter Wuille's `libsecp256k1`. Implements ECDSA and BIP 340 signatures for the SECG elliptic curve group secp256k1 and related utilities.
Last release 1 months ago
29 Aug 2026
Release timing varies
gaps range from 2 weeks to 10 months
Most releases are documented
notes for 42 of the last 60 stable releases
9 versions withdrawn
withdrawn after publishing
11 years old
100 releases · first in 2015
Put PublicKey::combine back because it is currently needed to implement Lightning BOLT 3
PublicKey::combine back because it is currently needed to implement Lightning BOLT 3Update rand to 0.4 and gcc 0.3 to cc 1.0. (rand 0.5 exists but has a lot of breaking changes and no longer compiles with 1.14.0.)
rand to 0.4 and gcc 0.3 to cc 1.0. (rand 0.5 exists but has a lot of breaking changes and no longer compiles with 1.14.0.)PublicKey::combine from API since it cannot be used with anything else in the APIOne column per quarter.
A complete API overhaul to move many runtime errors into compiletime errors
1e6f1f5ad5e7f1e3ef79313ec02023902bf8. Should be no visible changes.PublicKey::new() and PublicKey::is_valid() since new was unsafe and it should now be impossible to create invalid PublicKey objects through the APINothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Removed previously deprecated function aliases secp256k1_ec_privkey_negate, secp256k1_ec_privkey_tweak_add and secp256k1_ec_privkey_tweak_mul. Use sec…
secp256k1_objs interface library to allow parent projects to embed libsecp256k1 object files into their own static libraries.SECP256K1_NO_API_VISIBILITY_ATTRIBUTES preprocessor flag (CMake option: SECP256K1_ENABLE_API_VISIBILITY_ATTRIBUTES) that disables explicit "visibility" attributes for API symbols. Defining this macro enables the user to control the visibility of the API symbols via -fvisibility=<value> when building libsecp256k1. (All non-API declarations will always have hidden visibility, even with SECP256K1_ENABLE_API_VISIBILITY_ATTRIBUTES defined.) For instance, -fvisibility=hidden can be useful even for the API symbols, e.g., when building a static libsecp256k1 which is linked into a shared library, and the latter should not re-export the libsecp256k1 API.secp256k1_context_static and secp256k1_context_no_precomp to the constant context objects are now const.SECP256K1_WARN_UNUSED_RESULT attribute (defined as __attribute__ ((__warn_unused_result__))) from several API functions that always return 1. Compilers will no longer warn if the return value is unused.secp256k1_ec_privkey_negate, secp256k1_ec_privkey_tweak_add and
secp256k1_ec_privkey_tweak_mul. Use secp256k1_ec_seckey_negate, secp256k1_ec_seckey_tweak_add and
secp256k1_ec_seckey_tweak_mul instead.The symbols secp256k1_ec_privkey_negate, secp256k1_ec_privkey_tweak_add, and secp256k1_ec_privkey_tweak_mul were removed.
The pointers secp256k1_context_static and secp256k1_context_no_precomp have been made const.
Otherwise, the library maintains backward compatibility with version 0.6.0.
Nothing published for this version
Nothing published for this version
Nothing published for this version
New module musig implements the MuSig2 multisignature scheme according to the BIP 327 specification. See:
musig implements the MuSig2 multisignature scheme according to the BIP 327 specification. See:
include/secp256k1_musig.h which defines the new API.doc/musig.md for further notes on API usage.examples/musig.c.SECP256K1_APPEND_LDFLAGS for appending linker flags to the build command.secp256k1_foo can now be forward-declared using typedef struct secp256k1_foo secp256k1_foo; (or also struct secp256k1_foo; in C++).bin/ for executables, lib/ for libraries) to improve build output structure and Windows shared library compatibility.secp256k1_scratch_space struct and its associated functions secp256k1_scratch_space_create and secp256k1_scratch_space_destroy because the scratch space was unused in the API.The symbols secp256k1_scratch_space_create and secp256k1_scratch_space_destroy were removed.
Otherwise, the library maintains backward compatibility with versions 0.3.x through 0.5.x.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Added usage example for an ElligatorSwift key exchange.
--ecmult-gen-kb (SECP256K1_ECMULT_GEN_KB for CMake).--with-ecmult-window and --with-ecmult-gen-kb configure options (this also applies to SECP256K1_ECMULT_WINDOW_SIZE and SECP256K1_ECMULT_GEN_KB in CMake). To achieve the same configuration as previously provided by the "auto" value, omit setting the configure option explicitly.The ABI is backward compatible with versions 0.5.0, 0.4.x and 0.3.x.
New function secp256k1_ec_pubkey_sort that sorts public keys using lexicographic (of compressed serialization) order.
secp256k1_ec_pubkey_sort that sorts public keys using lexicographic (of compressed serialization) order.--ecmult-gen-precision was replaced with --ecmult-gen-kb (SECP256K1_ECMULT_GEN_KB for CMake).The ABI is backward compatible with versions 0.4.x and 0.3.x.
Nothing published for this version
The point multiplication algorithm used for ECDH operations (module ecdh) was replaced with a slightly faster one.
ecdh) was replaced with a slightly faster one.--with-asm=x86_64 in GNU Autotools, -DSECP256K1_ASM=x86_64 in CMake), which is the default on x86_64. Benchmarks with GCC 10.5.0 show a 10% speedup for secp256k1_ecdsa_verify and secp256k1_schnorrsig_verify.The ABI is backward compatible with versions 0.4.0 and 0.3.x.
New module ellswift implements ElligatorSwift encoding for public keys and x-only Diffie-Hellman key exchange for them. ElligatorSwift permits represe
ellswift implements ElligatorSwift encoding for public keys and x-only Diffie-Hellman key exchange for them.
ElligatorSwift permits representing secp256k1 public keys as 64-byte arrays which cannot be distinguished from uniformly random. See:
include/secp256k1_ellswift.h which defines the new API.doc/ellswift.md which explains the mathematical background of the scheme.SECP256K1_STATIC macro before including secp256k1.h.This release is backward compatible with the ABI of 0.3.0, 0.3.1, and 0.3.2. Symbol visibility is now believed to be handled properly on supported platforms and is now considered to be part of the ABI. Please report any improperly exported symbols as a bug.
Nothing published for this version
…applications using libsecp256k1's ECDH module vulnerable to a timing side-channel attack. The fix avoids secret-dependent control flow during ECDH com…
We strongly recommend updating to 0.3.2 if you use or plan to use GCC >=13 to compile libsecp256k1. When in doubt, check the GCC version using gcc -v.
ecdh: Fix "constant-timeness" issue with GCC 13.1 (and potentially future versions of GCC) that could leave applications using libsecp256k1's ECDH module vulnerable to a timing side-channel attack. The fix avoids secret-dependent control flow during ECDH computations when libsecp256k1 is compiled with GCC 13.1.BUILD_SHARED_LIBS variable for controlling whether to build a static or a shared library.SECP256K1_INSTALL variable for the controlling whether to install the build artefacts.arm to arm32. Use --with-asm=arm32 instead of --with-asm=arm (GNU Autotools), and -DSECP256K1_ASM=arm32 instead of -DSECP256K1_ASM=arm (CMake).The ABI is compatible with versions 0.3.0 and 0.3.1.
Fix "constant-timeness" issue with Clang >=14 that could leave applications using libsecp256k1 vulnerable to a timing side-channel attack. The fix avo…
We strongly recommend updating to 0.3.1 if you use or plan to use Clang >=14 to compile libsecp256k1, e.g., Xcode >=14 on macOS has Clang >=14. When in doubt, check the Clang version using clang -v.
The ABI is compatible with version 0.3.0.
Added experimental support for CMake builds. Traditional GNU Autotools builds (./configure and make) remain fully supported.
./configure and make) remain fully supported.noverify_tests. This binary runs the tests without some additional checks present in the ordinary tests binary and is thereby closer to production binaries. The noverify_tests binary is automatically run as part of the make check target.__declspec(dllimport)). This fixes MSVC builds of programs which link against a libsecp256k1 DLL dynamically and use API variables (and not only API functions). Unfortunately, the MSVC linker now will emit warning LNK4217 when trying to link against libsecp256k1 statically. Pass /ignore:4217 to the linker to suppress this warning.secp256k1_context_static. Create a new context instead of cloning the static context. (If this change breaks your code, your code is probably wrong.)secp256k1_context_static. Randomizing a copy of secp256k1_context_static did not have any effect and did not provide defense-in-depth protection against side-channel attacks. Create a new context if you want to benefit from randomization.src/libsecp256k1-config.h. We recommend passing flags to ./configure or cmake to set configuration options (see ./configure --help or cmake -LH). If you cannot or do not want to use one of the supported build systems, pass configuration flags such as -DSECP256K1_ENABLE_MODULE_SCHNORRSIG manually to the compiler (see the file configure.ac for supported flags).Due to changes in the API regarding secp256k1_context_static described above, the ABI is not compatible with previous versions.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Deprecated context flags SECP256K1_CONTEXT_VERIFY and SECP256K1_CONTEXT_SIGN. Use SECP256K1_CONTEXT_NONE instead.
examples/ directory.secp256k1_selftest, to be used in conjunction with secp256k1_context_static.schnorrsig, extrakeys and ecdh by default in ./configure.secp256k1_nonce_function_rfc6979 nonce function, used by default by secp256k1_ecdsa_sign, now reduces the message hash modulo the group order to match the specification. This only affects improper use of ECDSA signing API.SECP256K1_CONTEXT_VERIFY and SECP256K1_CONTEXT_SIGN. Use SECP256K1_CONTEXT_NONE instead.secp256k1_context_no_precomp to secp256k1_context_static.schnorrsig: renamed secp256k1_schnorrsig_sign to secp256k1_schnorrsig_sign32.Since this is the first release, we do not compare application binary interfaces. However, there are earlier unreleased versions of libsecp256k1 that are not ABI compatible with this version.
Nothing published for this version
Nothing published for this version
This version was in fact never released. The number was given by the build system since the introduction of autotools in Jan 2014 (ea0fe5a5bf0c04f9cc9
This version was in fact never released. The number was given by the build system since the introduction of autotools in Jan 2014 (ea0fe5a5bf0c04f9cc955b2966b614f5f378c6f6). Therefore, this version number does not uniquely identify a set of source files.
Your coding agent can read these notes before it upgrades. Set up the MCP server →