Logo MASTR ufficiale MASTR
Menu

Bitcoin: recupero e Lightning

Schnorr and MuSig2: several signers, one Bitcoin signature

Compact signatures change what is visible on-chain, not the need for a sound custody policy.

Aggiornato il 30 settembre 2026 · MASTR Labs

Articoli e grafici tecnici sono in inglese. La navigazione è disponibile in 7 lingue.

Guide di riferimento
  1. The signature and the protocol
  2. N-of-N is not automatically a threshold
  3. Less visible structure
  4. What a wallet review should ask
  5. Esempio concreto
  6. Fonti e originali

The signature and the protocol

BIP-340 specifies Schnorr signatures over secp256k1 for Bitcoin. MuSig2, specified in BIP-327, is a multiparty signing protocol built around compatible signatures. These are separate layers: a signature format does not by itself coordinate signers, secure devices or recover lost keys. MuSig2 combines cooperating signers into a signature that can be checked against an aggregate public key. 1 2

N-of-N is not automatically a threshold

In the ordinary MuSig2 arrangement, all participating signers are needed. This is not the same policy as ‘any 2 of 3’. A wallet may add alternative Taproot script paths or another recovery design, but those choices must be inspected separately. A polished ‘multisig’ label can conceal a very different availability trade-off. Ask what happens when one device, participant or coordinating service is permanently unavailable.

Less visible structure

A successful Taproot key-path spend using aggregation need not reveal each participant as a separate on-chain signature. That can reduce transaction data and the amount of policy information disclosed by that spend. It does not make every payment unlinkable. Amounts, timing, input selection, address reuse and subsequent transactions can still expose relationships. Off-chain coordination can also know more than an outside observer.

What a wallet review should ask

Secure nonce handling is an essential part of Schnorr signing protocols. Use established implementations instead of inventing an aggregation scheme. For custody review, record the participant set, the fallback policy, how devices display the destination and how recovery has been tested. A compact transaction is a property of the signing path, not evidence that the operational arrangement is resilient.

A compact signature does not change the policy
Diagramma esplicativo. Apri a grandezza intera. Credits ↗ Normal path: both signers. Recovery must be designed separately.

Esempio concreto

A company uses a 2-of-2 aggregated signing path. Both devices work, and the normal spend appears as one key-path signature. One device is then lost. The remaining device cannot turn that 2-of-2 policy into 1-of-2. Recovery depends on a separately designed alternative, if one exists.

Fonti e originali

  1. BIP-340: Schnorr signatures
  2. BIP-327: MuSig2

Continua a leggere

Bitcoin: recupero e Lightning →

MASTR

Sostieni la ricerca indipendente

Le indagini, le prove originali e le guide sono accessibili gratuitamente. Le donazioni volontarie contribuiscono a finanziare la ricerca e a mantenere disponibili gli strumenti MASTR.

Apri wallet