bitcoin-dev

Schnorr signatures BIP

Schnorr signatures BIP

Original Postby Andrew Poelstra

Posted on: September 13, 2018 18:46 UTC

In a Bitcoin-dev mailing list, Erik Aronesty has mentioned that Musig is prone to loss as it is M of N.

The possibility of creating threshold MuSig signatures for any M and N with zero security assumptions has always been there. An example is given where three parties have created one signature from three keys. But, if one key is lost then the signature can't be created anymore. It is also mentioned that if one participant aborts during signing, the signature cannot be constructed. Therefore, the loss of a key or an aborting participant can lead to the failure of the whole process.