On this page
OP_RETURN: writing data into the ledger
Bitcoin transactions exist to move coins — but people have wanted to etch other things into the ledger almost from the start. The genesis block itself carries a newspaper headline in its coinbase data, and early users smuggled messages into outputs disguised as public keys. The protocol’s sanctioned answer for arbitrary data is an output built around the opcode.
Standard Explanation
OP_RETURN (opcode 0x6a) is the one instruction in Bitcoin Script whose job is to make a script fail: the moment it executes, evaluation stops and the output is marked invalid . That sounds broken, but it’s the point — an output that starts with OP_RETURN is provably unspendable, so nothing about it pretends to be money. The bytes after the opcode are a data push, and nodes relay them under standard policy: Bitcoin Core has treated OP_RETURN “null data” outputs as a standard transaction type since 2014 , with the default limit applying to the whole serialized script — 83 bytes, i.e. about 80 bytes of actual data .
Why “provably unspendable” matters: before OP_RETURN was standardized, data smuggled into fake keys or scripts had to sit in the — the database of spendable coins every full node must maintain forever, because no one can prove those outputs are junk. An OP_RETURN output fails immediately, so nodes can drop it from the UTXO set: the data lives on in the chain’s history without taxing every node’s working memory. You still pay fees for the block space — data competes with payments for every byte.
Where an OP_RETURN output goes
What actually goes in those bytes
- Proofs of existence: , commit the hash, and anyone can later verify the document existed on that date — without ever revealing it. OpenTimestamps aggregates thousands of timestamps and anchors the result into Bitcoin transactions .
- Token overlays: protocols that encode token movements in the data field. The — where Tether’s first USDT lived before Ethereum and Tron took over — rides on OP_RETURN, and early rivals like Counterparty hid their payloads in multi-signature scripts instead.
- Security anchoring: smaller chains stamp periodic attestations into Bitcoin to inherit its hash power (“proof-of-proof”). VeriBlock-style anchoring consumed a notable share of Bitcoin’s block space at its 2019 peak and reignited the “is Bitcoin a data layer?” fight.
- Plain messages: signatures, tributes, and graffiti — the bytes carry no special meaning unless reader and writer agree on one.
OP_RETURN data is readable by everyone, kept indefinitely by archival nodes, and attached to your address. Chain-analysis tools read the protocol markers in it just like anyone else — it’s one more signal for classifying a transaction. Never put keys, secrets, or personal data in one.
A null-data script is tiny. The hex 6a 0b 68656c6c6f20776f726c64 decodes as: 6a = OP_RETURN, 0b = “push the next 11 bytes”, and the rest is ASCII for “hello world”. The push never executes — OP_RETURN halts the script first — so the data just rides along. OP_RETURN sits in a deliberately small, non-Turing-complete opcode family (no loops; a handful of opcodes are disabled) alongside the everyday workhorses of ordinary payments like OP_DUP, OP_HASH160, and OP_CHECKSIG.
OP_RETURN is no longer the only way to write data into Bitcoin. Since 2022–2023, inscriptions tuck content into the witness portion of a Taproot spend — which is how NFT-like images and BRC-20/Runes tokens appeared without any protocol change. On Ethereum, the equivalent is a transaction’s field, which any transaction can carry. Different mechanisms, same idea: block space is the medium, and data competes with payments for every byte.