bc1q
Address
The chain records a hash. A break of ECDSA needs the public key, which this output does not contain.
scriptPubKey
OP_0
PUSH20 HASH160(pubkey)
HASH160(x) = RIPEMD160(SHA256(x))
Witness version 0. The program is 20 bytes.
Bech32. Not wrapped in a pay-to-script-hash.
It shows up in the witness only when this address spends.
How the 20 bytes are built
Start from the compressed public key, 33 bytes, prefix 02 or 03 plus the x coordinate. SHA-256 that. RIPEMD-160 the digest. The result is 20 bytes. Those 20 bytes are the witness program. Nothing in that program is the private key, and nothing in it is the public key either.
Bech32 encodes the witness version and the program into the address string. Version 0 with a 20-byte program is a bc1q address. A 32-byte program at version 0 is P2WSH, a hash of a script. Version 1 is taproot and uses bech32m, which is why those addresses start with bc1p.
What a spend reveals
The witness for a P2WPKH spend is two items: the ECDSA signature, then the public key. Nodes hash the key and check it against the 20 bytes in the output. After that check, the key is public forever. Any later coin sent back to the same address can be attacked by anyone who can turn that key into a private key. That is why a move before H0 pays the whole balance to a new bc1q and leaves the old address at zero.
| Type | Address | In the output | Key visible before spend |
|---|---|---|---|
| P2WPKH | bc1q, 20 bytes | HASH160(pubkey) | No |
| P2WSH | bc1q, 32 bytes | SHA256(script) | Only if the script itself contains a key, and only at spend |
| P2TR | bc1p | Tweaked public key | Yes |
| P2PKH | 1… | HASH160(pubkey) | No, until the scriptSig reveals it |
| P2PK | Early outputs | Raw public key | Yes |