PSBT/MuSig2 coordination over Nostr relays: transport invariants for nonce safety under at-least-once delivery

Sep 1 - Sep 2, 2026

  • The complexities of multi-party custody arrangements, particularly those that involve advanced configurations like 2-of-3 multisig, MuSig2 Taproot aggregates, and covenant-free time-locked vaults, reveal intricate challenges in the movement and management of Partially Signed Bitcoin Transactions (PSBTs).

These systems often rely on a centralized coordinator, generally operated by the wallet vendor, to manage signing rounds. This centralization can introduce potential points of failure or surveillance, which contradicts the decentralized ethos of such technologies.

Recent advancements suggest that Nostr relays could significantly decentralize the coordination aspect of digital custody. Platforms such as Joinstr, Munstr, Smart Vaults, and Nunchuk have already begun integrating Nostr relays to handle parts of their transaction processes. A pivotal publication from August details the employment of PSBT and MuSig2 over a network of independent relays, following the remote-signer pattern established in NIP-46 and integrating with BSMS (BIP-129) to ensure secure, non-transparent relay operations. This structure is designed to prevent any single relay from accessing key material, decrypting transaction fragments, or viewing the spending graph. The primary vulnerability identified with this system is the risk of denial of service attacks by adversarial relays. Further insights into these mechanisms are available through resources such as PSBT Coordination over Nostr Relays and Vault Construction and Coordination Transport, which also provide a SHA-256 digest for verification.

The document raises significant concerns about nonce safety under adversarial conditions and the inherent risks posed by relay-based message delivery systems, including issues like message duplication, retries, and reordering. These issues place substantial demands on managing nonce states and sequencing messages to maintain security integrity. It questions the adequacy of client-side sequencing controls in securing nonce uniqueness and explores the possibility of developing garbage-resistant transport layers that do not enforce censorship. Additionally, it considers whether cryptographic structures can be established to allow for misbehavior proofs without the need for global observation, highlighting the ongoing need for research and development to close these gaps and enhance the robustness of decentralized digital custody solutions.

From the perspective of wallet users, understanding the operational reliability in scenarios where a relay fails or sends duplicate messages is crucial. Users are interested in knowing whether the wallet can recover autonomously or if a new signing session is necessary. Transparent information regarding status updates and recovery procedures will be essential for gaining user trust, particularly for managing larger transaction amounts.

Link to Raw Post
Bitcoin Logo

TLDR

Join Our Newsletter

We’ll email you summaries of the latest discussions from high signal bitcoin sources, like bitcoin-dev, lightning-dev, and Delving Bitcoin.

Explore all Products

ChatBTC imageBitcoin searchBitcoin TranscriptsSaving SatoshiDecoding BitcoinWarnet
Built with 🧡 by the Bitcoin Dev Project
View our public visitor count

We'd love to hear your feedback on this project.

Give Feedback