Fwd: Post-Schnorr lightning txes



Summary:

In a message posted on March 6th, Andrew Poelstra explained how after creating a new state i, parties A and B revoke state i-1. Specifically, A sends an adaptor signature for s^2_{A,i-1} which reveals her half of AB_{i-1} if she publishes that signature, while B sends an adaptor sig for s^1_{B,i-1} which reveals his half of AB_{i-1}. If either party completes tx_{i-1} to post the (i-1)th state to the chain, the other party will learn the secret key to AB_{i-1} and can take the coins. Andrew Poelstra is part of the Mathematics Department at Blockstream and can be reached at apoelstra@wpsoftware.net.


Updated on: 2023-05-24T21:34:31.721152+00:00