Stackexchange iconStackexchangeSep 29, 2026 ~1 min source read

Why does Bitcoin use both a transaction ID and a witness transaction ID?

While learning Bitcoin transactions and SegWit, I came across the distinction between the traditional transaction ID (txid) and the witness transaction ID (wtxid). I understand that the txid is the double-SHA256 hash of the serialized transaction excluding the witness data.

Share this story

Send the public story page.

Useful takeaways from this story.

While learning Bitcoin transactions and SegWit, I came across the distinction between the traditional transaction ID (txid) and the witness transaction ID (wtxid).

I understand that the txid is the double-SHA256 hash of the serialized transaction excluding the witness data.

Bitcoin needs both identifiers instead of simply replacing txid with a hash that always commits to the witness data.

Building the complete brief

The page is ready to read now. The fuller skim-friendly version will appear here automatically.

The useful part

While learning Bitcoin transactions and SegWit, I came across the distinction between the traditional transaction ID (txid) and the witness transaction ID (wtxid). I understand that the txid is the double-SHA256 hash of the serialized transaction excluding the witness data. Bitcoin needs both identifiers instead of simply replacing txid with a hash that always commits to the witness data.

How it works

  • For example, suppose a SegWit transaction has the same inputs and outputs but different witness data.
  • Is the separation primarily a backwards-compatibility decision, a consequence of how SegWit fixes malleability, or are there deeper protocol reasons?
  • andd wtxid commits to the transaction including the witness data.
  • How does this distinction affect the mempool and transaction relay?
  • Why do transaction inputs continue to refer to previous outputs using txid:vout rather than wtxid:vout?

What to take from it

Why does the witness merkle tree in a block use wtxids while the normal merkle tree uses txids? I am particularly interested in the historical/design reasoning rather than just the definitions of txid and wtxid. References I've been reading so far include BIP141 and the Bitcoin transaction/SegWit sections of Mastering Bitcoin.

Details worth keeping

SegWit introdduced wtxid partly to solve transaction malleability issues. The txid remains unchanged while the wtxid changes. I would like to understand the design consequences of this distinction...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app