Skip to main content
£0.00 0

Basket

No products in the basket.

ASIC mining articles and advice

BIP 70 Bitcoin Payment Protocol Explained: Security and Legacy Risks

BIP 70 Payment Protocol explained: understand PaymentRequest, Payment and PaymentACK messages, X.509 identity, refunds and legacy security risks.

BIP 70 Payment Protocol guide cover

This guide explains BIP 70 Payment Protocol in plain English. It covers the problem behind the BIP, why it matters and whether the proposal is part of Bitcoin today.

TL;DR

  • What it is: BIP 70 defined a merchant-to-wallet payment protocol using Protocol Buffers, HTTP or HTTPS and optional X.509 identity. PaymentRequest described outputs and expiry, Payment carried signed transactions and refund outputs, and PaymentACK confirmed receipt.
  • Why it matters: BIP 70 offered authenticated requests and immediate acknowledgements, but its PKI, parser and refund model brought lasting operational risk. Existing records may require careful legacy interpretation; new payment systems should use maintained protocols with narrower trust boundaries.
  • Current position: Where the feature is closed or legacy, isolate the parser and record that limitation before testing.

BIP 70 Payment Protocol in simple English

BIP 70 Payment Protocol: The BIP set size recommendations for request, payment and acknowledgement messages. Protocol Buffer parsers, certificate libraries and HTTP clients expanded the wallet attack surface.

Simple example

A node operator is checking BIP 70 Payment Protocol. Wallets had to reject unsupported networks, expired requests and oversized messages before asking for authorisation. A merchant returned a PaymentRequest, the wallet validated and displayed it, the customer authorised payment, and the wallet optionally posted a Payment to the payment URL.

Key terms in plain English

BIP:
Bitcoin Improvement Proposal: a document describing a proposed rule, standard or process. Its status must be checked separately.
Bitcoin Core:
Widely used software that validates Bitcoin and can provide wallet, network and operator tools.
Node:
A computer running Bitcoin software that checks data and communicates with other peers.

Three-message sequence

A merchant returned a PaymentRequest, the wallet validated and displayed it, the customer authorised payment, and the wallet optionally posted a Payment to the payment URL. The merchant answered with PaymentACK. Broadcast and merchant acknowledgement were related but separate; a failed HTTP response did not necessarily mean the Bitcoin transaction was absent.

PaymentRequest contents

PaymentDetails named the network, one or more amount-and-script outputs, creation time, optional expiry, memo, payment URL and opaque merchant data. A wrapper added version, PKI type, certificate data and signature. Wallets had to reject unsupported networks, expired requests and oversized messages before asking for authorisation.

Merchant identity and X.509

The optional PKI mode signed the serialised request with a key certified through the web public-key infrastructure. Successful validation associated the request with a certificate identity, not with the truth of every commercial claim. Certificate expiry, revocation, compromised authorities, hostname interpretation and legacy SHA-1 support all affected assurance.

BIP 70 Payment Protocol technical diagram
Merchant identity and X.509: the fields, validation boundary and operational evidence that implementations need to agree.

Payment and refund outputs

Payment carried the satisfying transaction or transactions, merchant data, a memo and refund_to outputs. Refund destinations supplied by a compromised client or altered connection could divert later refunds. A merchant needed to authenticate order state and use a current, independently confirmed refund process rather than treating old refund outputs as timeless authority.

Acknowledgement and retry

PaymentACK echoed the Payment and could include a status memo. Servers were expected to acknowledge repeated identical Payment messages so a transport failure could be retried. Idempotency is essential: a retry must not create a second order, refund or accounting event merely because the client did not receive the first acknowledgement.

Resource and dependency risks

The BIP set size recommendations for request, payment and acknowledgement messages. Protocol Buffer parsers, certificate libraries and HTTP clients expanded the wallet attack surface. Redirects, MIME handling and payment URLs required strict controls. A checkout should not revive unmaintained parsing code simply to support a historical merchant flow.

How specialists test it

Developers test the proposal with made-up data on an isolated test network. They check normal cases and deliberately invalid cases. Different implementations should reach the same result before anyone relies on the proposal.

Frequently asked questions

What is the main point of BIP 70 Payment Protocol?

BIP 70 Payment Protocol: The BIP set size recommendations for request, payment and acknowledgement messages.

For BIP 70 Payment Protocol, what should a beginner know about three-message sequence?

A merchant returned a PaymentRequest, the wallet validated and displayed it, the customer authorised payment, and the wallet optionally posted a Payment to the payment URL.

For BIP 70 Payment Protocol, what should a beginner know about paymentrequest contents?

PaymentDetails named the network, one or more amount-and-script outputs, creation time, optional expiry, memo, payment URL and opaque merchant data.

For BIP 70 Payment Protocol, what should a beginner know about merchant identity and X.509?

The optional PKI mode signed the serialised request with a key certified through the web public-key infrastructure.

Conclusion

BIP 70 offered authenticated requests and immediate acknowledgements, but its PKI, parser and refund model brought lasting operational risk. Existing records may require careful legacy interpretation; new payment systems should use maintained protocols with narrower trust boundaries.

Primary sources

Check the current specification status and the documentation for the exact implementation you operate before moving production funds or changing a mining node.

ASIC MINER PICKS

Recommended ASIC Mining Hardware

Compare three of our highest ranked ASIC miners currently available, with live product details and pricing.
Overall ranking
Equihash
·
ZEC
Overall rank#1of 100AvailableAll: #3 / 831
Bitmain Antminer Z15K 525KSol Equihash Zcash Miner
Bitmain
Pre-Order
Hashrate
525KSOL
Efficiency
4.73W/KSOL
Power
2483W
Earns/kWh
41.5p
Free Shipping
Price · delivered
£6,050.00
ex VAT
Est. per month
£751.05
Payback 8.1 Months
Overall ranking
Equihash
·
ZEC
Overall rank#2of 100AvailableAll: #4 / 831
Bitmain Antminer Z15 Pro 800KSol Equihash Zcash Miner
Bitmain
In stock
Hashrate
800KSOL
Efficiency
3.3W/KSOL
Power
2640W
Earns/kWh
59.4p
Price · delivered
£11,925.00
ex VAT
Est. per month
£1144.46
Payback 10.4 Months
Overall ranking
SHA-256
·
BTC
Overall rank#6of 100AvailableAll: #9 / 831
Bitmain Antminer S23e Hydro 2U 865Th SHA-256 Bitcoin Miner
Bitmain
Pre-Order
Hashrate
865TH
Efficiency
10W/TH
Power
8650W
Earns/kWh
13.2p
Free Shipping
Price · delivered
£9,382.50
ex VAT
Est. per month
£835.74
Payback 11.2 Months
Browse all ASIC miners
MORE MINING ADVICE

More ASIC Mining Articles

Read practical advice about choosing hardware, calculating electricity costs, setting up miners, hosting and maintenance.
MINER COMMUNITY

Join the ASIC Mining Discussion

Ask a question or share what has worked for you. Your experience may help another miner make a better decision.

Members can read and join the discussion

Log in to read comments from other miners. Create a free account if you would like to ask a question or share your experience.

Log in to read comments Register to join the discussion

Membership helps us protect the discussion from spam and keep answers useful.

ASIC MINING SUPPORT

Need Help Choosing an ASIC Miner?

Tell us what you want to mine, your electricity cost and where the machine will run. We can help you compare hardware, power requirements, hosting and repairs.
Contact our mining team
Browse ASIC miners