MuSig2 (demo 12) was n-of-n: every cosigner had to sign. FROST (RFC 9591) is t-of-n: any threshold, say 2 of 3, can produce one signature, and any 1 alone cannot. The group secret is Shamir-shared once and never reassembled; signing folds the shares into the signature through Lagrange interpolation. Lose a key and the treasury is safe; a thief with one share has nothing. It's the cryptographic shape of a real corporate vault, delivered as one ordinary Schnorr signature.
A trusted dealer draws one random group secret, splits it across a degree-1 polynomial (so any 2 points recover it), and hands each officer a share. The dealer then forgets the secret. New group re-runs the deal.
Two rounds (like MuSig2): each present officer commits a nonce pair, then returns a signature share zi weighted by their Lagrange coefficient λi. The coordinator adds the shares, and out comes a single signature the whole group could have made.
Both produce one Schnorr signature. FROST adds fault-tolerance: the difference between "everyone, always" and "enough of us."
Shamir places the secret at f(0) of a hidden polynomial; each officer holds one point f(i). Any two points fix the line and thus f(0), but no single point reveals anything. FROST does this recombination inside the signature math, so f(0) is never actually computed anywhere.
Select a single officer and the ceremony can't even start: below the threshold there's no valid Lagrange set. Two is enough; the third is redundant. That's the "flexible" in FROST.
Officers {1,2}, {1,3} or {2,3} all sign for the same group key and produce a valid signature under it. The verifier can't tell which two showed up, or even that it was a threshold scheme at all.
Each share zi verifies on its own before aggregation (RFC 9591's identifiable abort), so a faulty or malicious signer is named rather than just producing a dud signature.