Detailed protocol design for routed multi-transaction CoinSwap



Summary:

ZmnSCPxj is concerned about the security of CoinSwap and raises the issue that the nonce `p` has to be given by the taker to the maker outright. If this happens, then the maker gets to know the values of the nonce and can use it to steal funds. He suggests using 2p-ECDSA to solve this problem. However, he also points out that hiding among the larger singlesig anonymity set is important. He advises that a single signature should be used instead of two signatures to achieve more privacy. ZmnSCPxj also discusses HTLCs in open-coded SCRIPTs as an option for increased privacy.


Updated on: 2023-06-14T03:14:06.005364+00:00