bitcoinjs-lib
The classic JS/TS library for Bitcoin. Browser + Node compatible.
Repo: github.com/bitcoinjs/bitcoinjs-lib.
Install
npm install bitcoinjs-lib ecpair tiny-secp256k1
As of 15 September 2026 the npm latest tag is 7.0.2 (published
2026-09-07); the newest git tag and CHANGELOG entry is 7.0.1 (January
2026), so 7.0.2 is an npm-only patch with no release notes. The v6 line is
still published under the maintenance-v6 dist-tag (6.1.8, 2026-09-07)
and v5 under maintenance-v5 (5.2.1). Examples below target 7.x, which
requires Node >= 18.
Quick examples
Address generation
import * as bitcoin from "bitcoinjs-lib";
import ECPairFactory from "ecpair";
import * as ecc from "tiny-secp256k1";
const ECPair = ECPairFactory(ecc);
const network = bitcoin.networks.bitcoin;
const keyPair = ECPair.makeRandom({ network });
const { address } = bitcoin.payments.p2wpkh({
pubkey: keyPair.publicKey, network // Uint8Array in 7.x
});
Tx construction (modern: psbt)
const psbt = new bitcoin.Psbt({ network });
psbt.addInput({
hash: "txid...",
index: 0,
witnessUtxo: { script: spk, value: 100000n } // bigint in 7.x
});
psbt.addOutput({ address: dest, value: 99000n });
psbt.signInput(0, keyPair);
psbt.finalizeAllInputs();
const tx = psbt.extractTransaction();
console.log(tx.toHex());
BIP32
import { BIP32Factory } from "bip32";
import * as ecc from "tiny-secp256k1";
const bip32 = BIP32Factory(ecc);
const root = bip32.fromSeed(seedBytes);
const child = root.derivePath("m/84'/0'/0'/0/0");
v6 -> v7 breaking changes
From the 7.0.0 CHANGELOG entry (7.0.0 published to npm 2025-10-02):
- Buffer -> Uint8Array. Every public API returns
Uint8Array(payments,Transaction,Psbt,Block,script).Bufferis still accepted as input, because it subclassesUint8Array. - Satoshi values are
bigint.Transaction.Output.value, PSBT output values,witnessUtxo.valueandPsbt.getFee(). Migration per the changelog:value: 10000becomesBigInt(10000)or10000n. - typeforce -> valibot. All typeforce re-exports were removed
(
Satoshi,BufferN,UInt32,Hex, ...); valibot*Schemaexports replace them. - Dual CJS/ESM.
"type": "module", anexportsmap,.cjsfiles for the CJS build, and.jsextensions required on internal import paths. - Node >= 18 (was 8).
- Dependency majors:
bip1742.x -> 3.x,bs58check3.x -> 4.x,varuint-bitcoin1.x -> 2.x;valibotanduint8array-toolsadded.
Staying on v6 is still viable via the maintenance-v6 dist-tag, but new
code should target 7.x.
Companion packages
bip32— HD derivation.ecpair— ECPair signer; split out of the main package in v6.bip39— mnemonic.bip174— PSBT wire codec. Still an external runtime dependency of 7.x (^3.0.0, latest 3.0.1 September 2026); only the user-facingPsbtclass lives in bitcoinjs-lib, and it wraps aPsbtBaseinstance from this package, exposed aspsbt.data.tiny-secp256k1— secp256k1 ops.bolt11— BOLT11 invoice decode.
Network constants
bitcoinjs.networks:
bitcoin(mainnet).testnet.regtest.
Compared
| Aspect | bitcoinjs-lib | @scure/btc-signer |
|---|---|---|
| Maturity | Old, well-tested | Newer (npm since Sept 2022; @scure scope March 2023) |
| Style | OO + functional | Pure functional |
| Audit | Community-reviewed | Audited (cure53, Feb 2023); self-audited Apr 2026 |
| Bundle size | Larger | Smaller |
| Dependencies | Many | Minimal |
| Browser-friendly | Some legacy quirks | Excellent |
@scure/btc-signer audit history as of September 2026: cure53 audited
v0.3.0 in February 2023, when the package was still named
micro-btc-signer (report:
https://cure53.de/audit-report_micro-btc-signer.pdf); v2.2.0 was
self-audited by the maintainer in April 2026. MuSig2 and UTXO selection
are documented as not yet audited.
Use cases
- Web wallets, browser extensions.
- Node.js Bitcoin services.
- React Native apps (with polyfills).
Common pitfalls
bitcoin.ECPairwas removed in 6.0.0, not merely deprecated. Install the separateecpairpackage and build it withECPairFactory(ecc), or usebip32.tiny-secp256k1is the ECC backend you pass into those factories, not a drop-in replacement for the keypair type.- Mixing
numberandbigintamounts under 7.x: adding an output with anumbervaluethrowsError adding output.. Every satoshi amount must be a bigint. - Browser bundlers (Webpack 5+, Vite): 7.x imports no
cryptoorbuffernode builtin and returnsUint8Arrayfrom every public API, so aBufferpolyfill is only needed for your own code that still handsBuffers in. v6 commonly needed both shims. - Network mismatch errors when switching mainnet/testnet.