Logo officiel du MASTR MASTR
Menu

Bitcoin : récupération et Lightning

Schnorr and MuSig2: several signers, one Bitcoin signature

Compact signatures change what is visible on-chain, not the need for a sound custody policy.

Mis à jour le 30 septembre 2026 · MASTR Labs

Les articles et schémas techniques sont en anglais. La navigation est disponible en 7 langues.

Guides de référence
  1. The signature and the protocol
  2. N-of-N is not automatically a threshold
  3. Less visible structure
  4. What a wallet review should ask
  5. Exemple concret
  6. Sources et originaux

The signature and the protocol

BIP-340 specifies Schnorr signatures over secp256k1 for Bitcoin. MuSig2, specified in BIP-327, is a multiparty signing protocol built around compatible signatures. These are separate layers: a signature format does not by itself coordinate signers, secure devices or recover lost keys. MuSig2 combines cooperating signers into a signature that can be checked against an aggregate public key. 1 2

N-of-N is not automatically a threshold

In the ordinary MuSig2 arrangement, all participating signers are needed. This is not the same policy as ‘any 2 of 3’. A wallet may add alternative Taproot script paths or another recovery design, but those choices must be inspected separately. A polished ‘multisig’ label can conceal a very different availability trade-off. Ask what happens when one device, participant or coordinating service is permanently unavailable.

Less visible structure

A successful Taproot key-path spend using aggregation need not reveal each participant as a separate on-chain signature. That can reduce transaction data and the amount of policy information disclosed by that spend. It does not make every payment unlinkable. Amounts, timing, input selection, address reuse and subsequent transactions can still expose relationships. Off-chain coordination can also know more than an outside observer.

What a wallet review should ask

Secure nonce handling is an essential part of Schnorr signing protocols. Use established implementations instead of inventing an aggregation scheme. For custody review, record the participant set, the fallback policy, how devices display the destination and how recovery has been tested. A compact transaction is a property of the signing path, not evidence that the operational arrangement is resilient.

A compact signature does not change the policy
Schéma explicatif. Ouvrir en pleine taille. Credits ↗ Normal path: both signers. Recovery must be designed separately.

Exemple concret

A company uses a 2-of-2 aggregated signing path. Both devices work, and the normal spend appears as one key-path signature. One device is then lost. The remaining device cannot turn that 2-of-2 policy into 1-of-2. Recovery depends on a separately designed alternative, if one exists.

Sources et originaux

  1. BIP-340: Schnorr signatures
  2. BIP-327: MuSig2

Pour aller plus loin

Bitcoin : récupération et Lightning →

MASTR

Soutenir la recherche indépendante

Les enquêtes, les preuves originales et les guides sont en accès libre. Les dons volontaires contribuent au financement de la recherche et au maintien des outils MASTR.

Ouvrir le portefeuille