Offizielles MASTR Logo MASTR
Menü

Bitcoin: Wiederherstellung und Lightning

Schnorr and MuSig2: several signers, one Bitcoin signature

Compact signatures change what is visible on-chain, not the need for a sound custody policy.

Aktualisiert am 30. September 2026 · MASTR Labs

Artikeltexte und technische Grafiken sind auf Englisch. Die Navigation ist in 7 Sprachen verfügbar.

Fachartikel
  1. The signature and the protocol
  2. N-of-N is not automatically a threshold
  3. Less visible structure
  4. What a wallet review should ask
  5. Konkretes Beispiel
  6. Quellen und Originale

The signature and the protocol

BIP-340 specifies Schnorr signatures over secp256k1 for Bitcoin. MuSig2, specified in BIP-327, is a multiparty signing protocol built around compatible signatures. These are separate layers: a signature format does not by itself coordinate signers, secure devices or recover lost keys. MuSig2 combines cooperating signers into a signature that can be checked against an aggregate public key. 1 2

N-of-N is not automatically a threshold

In the ordinary MuSig2 arrangement, all participating signers are needed. This is not the same policy as ‘any 2 of 3’. A wallet may add alternative Taproot script paths or another recovery design, but those choices must be inspected separately. A polished ‘multisig’ label can conceal a very different availability trade-off. Ask what happens when one device, participant or coordinating service is permanently unavailable.

Less visible structure

A successful Taproot key-path spend using aggregation need not reveal each participant as a separate on-chain signature. That can reduce transaction data and the amount of policy information disclosed by that spend. It does not make every payment unlinkable. Amounts, timing, input selection, address reuse and subsequent transactions can still expose relationships. Off-chain coordination can also know more than an outside observer.

What a wallet review should ask

Secure nonce handling is an essential part of Schnorr signing protocols. Use established implementations instead of inventing an aggregation scheme. For custody review, record the participant set, the fallback policy, how devices display the destination and how recovery has been tested. A compact transaction is a property of the signing path, not evidence that the operational arrangement is resilient.

A compact signature does not change the policy
Erklärende Grafik. In voller Grösse öffnen. Credits ↗ Normal path: both signers. Recovery must be designed separately.

Konkretes Beispiel

A company uses a 2-of-2 aggregated signing path. Both devices work, and the normal spend appears as one key-path signature. One device is then lost. The remaining device cannot turn that 2-of-2 policy into 1-of-2. Recovery depends on a separately designed alternative, if one exists.

Quellen und Originale

  1. BIP-340: Schnorr signatures
  2. BIP-327: MuSig2

Weiterlesen

Bitcoin: Wiederherstellung und Lightning →

MASTR

Unabhängige Recherche unterstützen

Die Untersuchungen, Originalbelege und Anleitungen hier sind frei zugänglich. Freiwillige Spenden finanzieren die Recherche mit und helfen, die MASTR-Tools weiterhin anzubieten.

Wallet öffnen