Logótipo oficial do MASTR MASTR
Menu

Bitcoin: recuperação e Lightning

Schnorr and MuSig2: several signers, one Bitcoin signature

Compact signatures change what is visible on-chain, not the need for a sound custody policy.

Atualizado em 30 de setembro de 2026 · MASTR Labs

Os artigos e gráficos técnicos estão em inglês. A navegação está disponível em 7 idiomas.

Guias de referência
  1. The signature and the protocol
  2. N-of-N is not automatically a threshold
  3. Less visible structure
  4. What a wallet review should ask
  5. Exemplo concreto
  6. Fontes e originais

The signature and the protocol

BIP-340 specifies Schnorr signatures over secp256k1 for Bitcoin. MuSig2, specified in BIP-327, is a multiparty signing protocol built around compatible signatures. These are separate layers: a signature format does not by itself coordinate signers, secure devices or recover lost keys. MuSig2 combines cooperating signers into a signature that can be checked against an aggregate public key. 1 2

N-of-N is not automatically a threshold

In the ordinary MuSig2 arrangement, all participating signers are needed. This is not the same policy as ‘any 2 of 3’. A wallet may add alternative Taproot script paths or another recovery design, but those choices must be inspected separately. A polished ‘multisig’ label can conceal a very different availability trade-off. Ask what happens when one device, participant or coordinating service is permanently unavailable.

Less visible structure

A successful Taproot key-path spend using aggregation need not reveal each participant as a separate on-chain signature. That can reduce transaction data and the amount of policy information disclosed by that spend. It does not make every payment unlinkable. Amounts, timing, input selection, address reuse and subsequent transactions can still expose relationships. Off-chain coordination can also know more than an outside observer.

What a wallet review should ask

Secure nonce handling is an essential part of Schnorr signing protocols. Use established implementations instead of inventing an aggregation scheme. For custody review, record the participant set, the fallback policy, how devices display the destination and how recovery has been tested. A compact transaction is a property of the signing path, not evidence that the operational arrangement is resilient.

A compact signature does not change the policy
Diagrama explicativo. Abrir em tamanho completo. Credits ↗ Normal path: both signers. Recovery must be designed separately.

Exemplo concreto

A company uses a 2-of-2 aggregated signing path. Both devices work, and the normal spend appears as one key-path signature. One device is then lost. The remaining device cannot turn that 2-of-2 policy into 1-of-2. Recovery depends on a separately designed alternative, if one exists.

Fontes e originais

  1. BIP-340: Schnorr signatures
  2. BIP-327: MuSig2

Continuar a leitura

Bitcoin: recuperação e Lightning →

MASTR

Apoiar a investigação independente

As investigações, as provas originais e os guias são de acesso livre. Os donativos voluntários ajudam a financiar a investigação e a manter disponíveis as ferramentas MASTR.

Abrir carteira