Hermes / BIP-340 FROST

BIP-340 FROST: a Taproot t-of-n vault

Demo 15's FROST is faithful to RFC 9591, but that ciphersuite's challenge isn't BIP-340's, so its signature can't spend a coin. Re-skin the same threshold protocol to BIP-340's x-only, even-y conventions and the aggregate becomes a genuine 64-byte signature. Wrap the group key in a TapTweak and you get a bc1p… address that any 2 of 3 officers can key-path spend, settled in one signature that looks exactly like a lone wallet's. The threshold is real; on-chain, invisible.

1 · The vault

vault address  · bc1p, from a 2-of-3 FROST group key + TapTweak
–

A trusted dealer Shamir-splits one group key across the three officers (demo 15). Its x-only form is a Taproot internal key; tweaked, it's the address above. New vault re-deals.

2 · Spend it: any two officers

tick any two officers
pick two officers to sign

Each present officer contributes a BIP-340 signature share (with the even-y sign flips FROST-over-BIP-340 needs); the coordinator adds the tweak and sums them. Out comes a single (R.x ‖ z) that schnorrVerify accepts under the vault's output key.

The spending signature

64-byte BIP-340 signature: the entire witness
sign to produce…
tweaked output key: what the bc1p commits to
–

vs demo 15 (RFC 9591)

RFC 9591 FROST

65 B · off-chain
faithful to the IETF spec, but its challenge isn't BIP-340, so it can't spend a Taproot coin.

BIP-340 FROST

64 B · on-chain
a real key-path spend of a bc1p vault, verified by the same schnorrVerify as demo 11.

Invisible on-chain

The witness is one 64-byte signature; the output is a plain bc1p key. Nothing says "2-of-3", nothing says "FROST". A 3-of-5 board vault, a 2-of-3 exchange and a single hardware wallet are byte-for-byte indistinguishable: the privacy Taproot promised, extended to thresholds.

Things to notice

Same protocol, new challenge

Keygen, nonces, binding factors and Lagrange interpolation are demo 15's, unchanged. Only the challenge hash (now BIP0340/challenge) and the even-y sign flips on R, the group key and the tweaked output key differ. That's all it takes.

The secret still never forms

As in demo 15, no one ever holds the whole group key. The Lagrange-weighted shares combine only inside the signature, now producing a spend of a real address.

No official vectors (yet)

There's no finalised BIP for FROST, so this is validated by self-consistency: the aggregate verifies under the vault's output key via the (BIP-340-vector-anchored) schnorrVerify, across every signing pair and key parity.