How to Verify Bitcoin Message Signatures? Format, Text, and Proof Boundaries

 / 
1

To verify a Bitcoin message signature, you need to check three things at the same time: the address, the original message, and the signature text. If any one of these is off, verification will fail. The most easily overlooked item is signature format — different wallets may produce signatures using different encoding standards, and verification tools usually only support one of them.

OKX Exchange
A leading global cryptocurrency platform,suitable for both beginners and experienced traders.
New user benefit: 20% off trading fees upon registration!!

First, Check the Signature Format: 65 Bytes or DER

The most common format for Bitcoin message signatures is the 65-byte compact signature, which is the format required by Bitcoin Core's verifymessage command. It consists of three parts: a 1-byte header, a 32-byte r value, and a 32-byte s value. The whole thing is Base64 encoded and shown as a string of characters.

Another format is the DER encoded signature, usually 70–72 bytes long and presented as a hexadecimal string. This format is common in transaction signatures, but it cannot be used directly for Bitcoin Core message verification. If you try to verify a DER signature with verifymessage, the command will return failure — not because the signature is invalid, but because the format does not match.

The signature header byte determines the address type. According to the Bitcoin Wiki definition: 27–30 correspond to uncompressed P2PKH addresses, 31–34 correspond to compressed P2PKH addresses, 35–38 correspond to P2WPKH-P2SH (SegWit-compatible) addresses, 39–42 correspond to native P2WPKH addresses, and 43–46 correspond to Taproot (P2TR) addresses.

If the signature you have is not 65 bytes after Base64 decoding, or if the header byte is outside the above ranges, it is probably not a standard Bitcoin Core compatible format.

Three Ways to Verify

Path 1: Use Bitcoin Core Command Line

This is the most authoritative verification method. The verifymessage command takes three parameters: address, signature, and message.

bitcoin-cli verifymessage "your address" "Base64 signature" "original message"

It returns true if verification passes, and false if it does not. Note that verifymessage processes the message with exact byte-for-byte matching. Spaces, line breaks, punctuation, and capitalization in the message must be exactly the same as when it was signed. One extra space will cause verification to fail.

Path 2: Use an Online Verification Tool

There are some zero-dependency browser-based verification tools available. For example, the verify-bitcoin-message npm package provides a web version that can run verification offline directly in the browser. The advantage of such tools is that you do not need to install a node, making them suitable for quick checks.

The key when using them is to fill in the three elements accurately. Take the Bitpie wallet verification flow as an example: in the address field, enter the address that was originally used for signing; in the original message field, enter the complete original text used at signing time; in the signature field, paste the Base64 signature text. After clicking verify, the tool will show "verification passed" or a failure message.

Path 3: Use the Wallet's Built-in Verification Feature

Trezor Suite, Electrum, and other desktop wallets have built-in message signing and verification functions. In Trezor Suite, select the corresponding account and find the "Sign and Verify" option, then enter the message and address to complete verification. The hardware device will show the beginning of the message for you to check. This method is suitable when you signed the message with the same wallet, because the toolchain is consistent and the chance of error is lower.

Common Reasons for Verification Failure

Message text mismatch. This is the most common problem. If the message contained line breaks when signed, those line breaks must be preserved during verification. If the message was copied from a chat record or webpage, it may contain invisible characters such as zero-width spaces. It is recommended to use the original text saved at signing time rather than retyping it.

Address type does not match the signature header. For example, if you use a native SegWit address (starting with bc1q) but the signature header byte corresponds to a Legacy address type, verification will fail. This usually happens when wallet software misjudges the address type, or when you manually changed the address format.

The signature has been re-encoded or truncated. If the Base64 signature contains line breaks, some tools may not parse it correctly. Make sure the signature text is one complete line with no extra spaces or line breaks.

Using a BIP-322 signature with a Legacy tool. BIP-322 is a newer signature standard that supports more complex address types, including multisig and Taproot, but the signature format it produces is different from the traditional 65-byte compact signature. If you signed with a BIP-322-compatible wallet, you need to verify with a tool that supports that standard.

A Real Example: The Genesis Block Signature Format Problem

There is a frequently cited case that shows how critical format issues can be. Someone provided a signature that was supposedly Satoshi's signature on a Genesis block message. The Base64 string looked normal. But after decoding, it turned out to be a 70-byte DER signature rather than a 65-byte compact signature. Trying to verify it with bitcoin-cli verifymessage would cause the command to reject it directly, because that command only accepts the 65-byte format.

The lesson from this case is: a signature that "looks right" does not mean the format is correct. Before verifying, first confirm the signature length. Only if it is 65 bytes after Base64 decoding is it suitable for verification with Bitcoin Core's standard command.

Proof Boundaries: What Message Signatures Can and Cannot Prove

What a message signature can prove is: the signer controls the private key corresponding to a certain address. A successful verification means that the person holding the private key for that address did indeed sign that specific message content.

What it cannot prove includes: that the signer "owns" the assets in the address, because they may have only controlled it in the past or the private key may have been leaked to someone else; that the message content itself is true, because a signature only proves "who said this sentence," not "whether the sentence is factual"; and the time of signing, unless the message text includes time information that is covered by the signature.

A common misconception is that "a signed message can prove ownership of funds." In reality, proving ownership of funds requires another mechanism, such as the BIP-322 Proof of Funds extension or an on-chain transaction. A simple message signature accomplishes only one thing: binding a piece of text to control of the private key for an address.

OKX Exchange
A leading global cryptocurrency platform,suitable for both beginners and experienced traders.
New user benefit: 20% off trading fees upon registration!!

References

  1. Zenodo·BLACK PAPER 2048 SATOSHI DEFEATS RSA BEDFORD NAKAMOTO MURRAY RSA RETROFUNCTION, page undated; checked on 2026-10-08.
  2. Zenodo·CLAUDE BLACK PAPER 2048 SATOSHI DEFEATS RSA BEDFORD NAKAMOTO MURRAY RSA RETROFUNCTION, page undated; checked on 2026-10-08.
  3. Bitcoin Wiki·Message signing, page published or updated on 2022-08-05; checked on 2026-10-08.
  4. Bitcoin Developer Documentation·verifymessage, page undated; checked on 2026-10-08.
  5. NPM·verify-bitcoin-message, page published or updated on 2025-09-26; checked on 2026-10-08.
  6. Bitpie·How to sign a message, page published or updated on 2025-04-23; checked on 2026-10-08.
  7. Kraken·Signing a message on a private crypto wallet, page published or updated on 2025-03-31; checked on 2026-10-08.
  8. GitHub·bitcoin-bips-book, page undated; checked on 2026-10-08.