Demo 15's FROST is faithful to RFC 9591, but that ciphersuite's challenge isn't BIP-340's, so its signature can't spend a coin. Re-skin the same threshold protocol to BIP-340's x-only, even-y conventions and the aggregate becomes a genuine 64-byte signature. Wrap the group key in a TapTweak and you get a bc1p… address that any 2 of 3 officers can key-path spend, settled in one signature that looks exactly like a lone wallet's. The threshold is real; on-chain, invisible.
A trusted dealer Shamir-splits one group key across the three officers (demo 15). Its x-only form is a Taproot internal key; tweaked, it's the address above. New vault re-deals.
Each present officer contributes a BIP-340 signature share (with the even-y sign flips FROST-over-BIP-340 needs); the coordinator adds the tweak and sums them. Out comes a single (R.x ‖ z) that schnorrVerify accepts under the vault's output key.
The witness is one 64-byte signature; the output is a plain bc1p key. Nothing says "2-of-3", nothing says "FROST". A 3-of-5 board vault, a 2-of-3 exchange and a single hardware wallet are byte-for-byte indistinguishable: the privacy Taproot promised, extended to thresholds.
Keygen, nonces, binding factors and Lagrange interpolation are demo 15's, unchanged. Only the challenge hash (now BIP0340/challenge) and the even-y sign flips on R, the group key and the tweaked output key differ. That's all it takes.
As in demo 15, no one ever holds the whole group key. The Lagrange-weighted shares combine only inside the signature, now producing a spend of a real address.
There's no finalised BIP for FROST, so this is validated by self-consistency: the aggregate verifies under the vault's output key via the (BIP-340-vector-anchored) schnorrVerify, across every signing pair and key parity.