Stratum V2

How Silent Payments Could Reach Mining Payouts

Bitcoin developers are designing a way to pay silent payment addresses inside a mining coinbase over Stratum V2. Here's the plain four-step mechanism.

Diagram of a rig sending a silent payment address over an encrypted Stratum V2 channel to a pool, which pays a fresh output in each block

A proposal posted to Bitcoin's protocol-design forum in late August asks a narrow, practical question: can a mining pool pay a miner's silent payment address directly in the coinbase transaction, the one transaction in every block that mints the new coins, without ever seeing that miner's real spending activity? A silent payment mining payout sounds like a small technical detail, but it targets a real privacy gap in how pools have paid miners for years, and it does it by leaning on exactly the kind of encrypted channel that Stratum V2 already opens between a rig and a pool. The idea is being discussed in the open on that forum and was summarized in the September 4 issue of Bitcoin Optech's newsletter, a technical publication developers use to follow exactly this kind of change. Here is the mechanism, one step at a time, and why it matters to anyone who solo mines.

Step one: see the problem with the old way

Most pools that support automatic per-block payouts ask a miner for an extended public key, an xpub, and derive a fresh receiving address from it for every payment. That spares the miner from re-entering an address each time, but it means the pool's own database now holds a key that can generate every address that miner will ever be paid to. If that database is ever compromised, leaked, or subpoenaed, a miner's entire payout history becomes traceable from a single piece of pool-side data, even though the miner never gave anyone their spending wallet directly. The privacy leak is not in the payout itself. It is in the fact that the pool had to hold the means to reproduce it.

Step two: understand what a silent payment mining payout address actually does

BIP352 silent payments let a recipient publish one fixed-looking address while every payment sent to it lands on a different, unlinkable on-chain output. The trick is a shared secret computed between the sender and the receiver, normally derived from the public keys attached to the transaction's own inputs. A coinbase transaction, the one that pays a mining reward, has no ordinary input with a spendable public key to borrow that secret from, which is exactly why silent payments and mining payouts have not been an obvious fit until this proposal. The forum post walks through a workaround: the pool uses a sender key of its own, ideally an ephemeral one, and the block height stands in for the missing input data. The pool commits to that key together with the height, which stops it from grinding through many keys until it finds one that benefits it.

Step three: see where Stratum V2 fits into the handoff

The remaining question is mundane but important: how does a miner ever tell the pool which silent payment address to use, without leaking it to an eavesdropper on the way? The proposal's answer is to piggyback on a channel Stratum V2 already opens. Stratum V2's Mining Protocol Channel is encrypted and authenticated end to end between the rig and the pool from the moment it opens, which is the same encrypted transport described on NexusPool's technology page, alongside the same-port auto-detection that lets an older Stratum V1 firmware and a newer Stratum V2 one connect without any manual configuration. Under the design being discussed, a miner would hand over its silent payment address once, inside that already-encrypted channel, and the pool would register it in its own accounting the same way it already registers any other payout address today.

Step four: watch what the pool has to do with it afterward

Once the pool has the address, nothing about how a block gets built or paid actually changes. The coinbase transaction still needs to name a real destination for the reward, and a solo pool that pays the finder's own address directly, with no pool-held balance sitting in between, does not gain any new custody role just because that address happens to be a silent payment one. What does change is what a curious observer of the blockchain can reconstruct afterward. Instead of one visibly reused payout address tying a rig's history together block after block, each payment lands on a fresh output that is hard to link, while the miner never had to hand the pool anything beyond a single address. This is also exactly the kind of transaction NexusPool's Payout Preflight tool already exists to make visible before the fact: entering an address and seeing the precise coinbase that would pay it on the current block, built by the same code that would build the real one.

What this does not claim, and where things stand

This is a design discussion, not a shipped feature. The author's own test-vector repository says it is not a specification and has not been reviewed, and the post itself notes that steady, consistent payout amounts could still fingerprint a miner across the blocks a pool finds. The pool also still knows who it pays. Nothing here changes what any pool, NexusPool included, does with a payout today, and nothing about it changes a miner's chances of finding a block in the first place: block-finding is governed entirely by network difficulty, the same for every rig at every pool, and no protocol change to how a reward is addressed touches that math. It also is not an investment claim of any kind; silent payments protect the privacy of a payout, not its size. Anyone who wants to track where this idea goes next can follow the same open discussion this post drew from, a proposal on Bitcoin's protocol-design forum, where the ephemeral-key mechanism above is worked through in full.

The path here, in four steps: a pool cannot see spendable keys from a coinbase, so it manufactures a height-bound ephemeral one; a miner hands over a silent payment address once, over an already-encrypted Stratum V2 channel instead of an xpub; the pool registers that address exactly like any other payout destination; and the resulting payments become much harder for an outside observer to link even though nothing about custody changed at all. If you solo mine today and want to see what any of this actually looks like on the wire before trusting a claim about it, the one thing worth checking first is whether your own pool publishes the coinbase it would build for your address before a block is ever found, which is what Payout Preflight does for a Bitcoin address today, while the Glass Ledger covers the other half by signing an hourly receipt of what the pool counted from each rig.

Trust nothing. Verify how your own payout address would actually appear on-chain.