官方的 MASTR 标志 MASTR
菜单

比特币:恢复与闪电网络

Schnorr and MuSig2: several signers, one Bitcoin signature

Compact signatures change what is visible on-chain, not the need for a sound custody policy.

更新于 2026 年 9 月 30 日 · MASTR Labs

文章正文和技术图表为英语,导航提供 7 种语言。

参考指南
  1. The signature and the protocol
  2. N-of-N is not automatically a threshold
  3. Less visible structure
  4. What a wallet review should ask
  5. 具体示例
  6. 来源与原始资料

The signature and the protocol

BIP-340 specifies Schnorr signatures over secp256k1 for Bitcoin. MuSig2, specified in BIP-327, is a multiparty signing protocol built around compatible signatures. These are separate layers: a signature format does not by itself coordinate signers, secure devices or recover lost keys. MuSig2 combines cooperating signers into a signature that can be checked against an aggregate public key. 1 2

N-of-N is not automatically a threshold

In the ordinary MuSig2 arrangement, all participating signers are needed. This is not the same policy as ‘any 2 of 3’. A wallet may add alternative Taproot script paths or another recovery design, but those choices must be inspected separately. A polished ‘multisig’ label can conceal a very different availability trade-off. Ask what happens when one device, participant or coordinating service is permanently unavailable.

Less visible structure

A successful Taproot key-path spend using aggregation need not reveal each participant as a separate on-chain signature. That can reduce transaction data and the amount of policy information disclosed by that spend. It does not make every payment unlinkable. Amounts, timing, input selection, address reuse and subsequent transactions can still expose relationships. Off-chain coordination can also know more than an outside observer.

What a wallet review should ask

Secure nonce handling is an essential part of Schnorr signing protocols. Use established implementations instead of inventing an aggregation scheme. For custody review, record the participant set, the fallback policy, how devices display the destination and how recovery has been tested. A compact transaction is a property of the signing path, not evidence that the operational arrangement is resilient.

A compact signature does not change the policy
解释性图表。点击查看完整尺寸。 Credits ↗ Normal path: both signers. Recovery must be designed separately.

具体示例

A company uses a 2-of-2 aggregated signing path. Both devices work, and the normal spend appears as one key-path signature. One device is then lost. The remaining device cannot turn that 2-of-2 policy into 1-of-2. Recovery depends on a separately designed alternative, if one exists.

来源与原始资料

  1. BIP-340: Schnorr signatures
  2. BIP-327: MuSig2

继续阅读

比特币:恢复与闪电网络 →

MASTR

支持独立研究

这里的调查、原始证据和指南均可免费阅读。自愿捐赠帮助支付研究成本,让 MASTR 能够继续提供工具。

打开钱包