Sum of the keys attack on taproot



Summary:

In a discussion on the bitcoin-dev mailing list, vjudeu suggested that producing a signature matching the sum of public keys used in taproot would be sufficient. However, Tim Ruffing corrected this statement, stating that taproot does not enable cross-input aggregation or spending multiple UTXOs with a single signature. Ruben added to the conversation by suggesting reading about MuSig, a key aggregation scheme using Schnorr signatures. The link provided leads to a blog post on Blockstream's website explaining the details of MuSig.


Updated on: 2023-06-14T21:56:56.911863+00:00