Demo 11 showed Schnorr keys add, but naively summing keys is a trap: the last cosigner to reveal theirs can craft a rogue key and own the sum. MuSig2 (BIP-327) fixes that with hashed per-key coefficients, then runs a two-round ceremony: swap nonce pairs, swap partial signatures, add them up. The result is one ordinary 64-byte BIP-340 signature: an n-of-n vault that looks, and costs, exactly like a lone signer.
Each coefficient ai = H(L ‖ pki) hashes the whole ordered key list L, so no cosigner can aim the sum at a key they control. This aggregate becomes the internal key of a perfectly normal bc1p… address (right).
Partial signatures are checked individually before combining, so a bad share is caught and its author named. Try the corrupt button after round 2. And every nonce is single-use: signing zeroizes it, because reusing one leaks the key (demo 3).
Nothing marks this as multisig. Not the address, not the spend: on-chain it is indistinguishable from demo 11's single-key payment.
Cheaper and more private: the rare trade that costs nothing. The catch: MuSig2 is n-of-n (everyone signs). Thresholds like 2-of-3 need script-path fallbacks or FROST.
With a single nonce, an attacker who opens many signing sessions in parallel can steer the combined challenge with a generalized birthday attack and forge a signature. The pair (R₁, R₂) + the binding hash b kill the steering. That's the "2" in MuSig2, and why it still needs only two rounds.
The final (R.x ‖ s) passes the exact schnorrVerify from demo 11. The verifier needs no idea MuSig exists: aggregation happens entirely off-chain, among the signers.
Every partial signature verifies on its own (si·G == Ri + e·ai·Pi), so a corrupt share is pinned on its author before combining. BIP-327's error model names the culprit: coordinators must know who to kick.
Missing one partial signature, the sum is garbage: n-of-n means every key must sign. That's perfect for a 2-of-2 (you + your hardware wallet) or an exchange's internal sign-off, and it composes with Taproot script paths for recovery fallbacks.