While learning Bitcoin transactions and SegWit, I came across the distinction between the traditional transaction ID (txid) and the witness transaction ID (wtxid).
I understand that the txid is the double-SHA256 hash of the serialized transaction excluding the witness data. andd wtxid commits to the transaction including the witness data. SegWit introdduced wtxid partly to solve transaction malleability issues.
What I am having trouble understanding is why Bitcoin needs both identifiers instead of simply replacing txid with a hash that always commits to the witness data. For example, suppose a SegWit transaction has the same inputs and outputs but different witness data. The txid remains unchanged while the wtxid changes. I would like to understand the design consequences of this distinction…
What specifically would break if Bitcoin used only wtxid everywhere?
Why do transaction inputs continue to refer to previous outputs using txid:vout rather than wtxid:vout?
How does this distinction affect the mempool and transaction relay?
Why does the witness merkle tree in a block use wtxids while the normal merkle tree uses txids?
Is the separation primarily a backwards-compatibility decision, a consequence of how SegWit fixes malleability, or are there deeper protocol reasons?
I am particularly interested in the historical/design reasoning rather than just the definitions of txid and wtxid. References I’ve been reading so far include BIP141 and the Bitcoin transaction/SegWit sections of Mastering Bitcoin.












