Hermes / MuSig2

MuSig2: n signatures become one

Demo 11 showed Schnorr keys add, but naively summing keys is a trap: the last cosigner to reveal theirs can craft a rogue key and own the sum. MuSig2 (BIP-327) fixes that with hashed per-key coefficients, then runs a two-round ceremony: swap nonce pairs, swap partial signatures, add them up. The result is one ordinary 64-byte BIP-340 signature: an n-of-n vault that looks, and costs, exactly like a lone signer.

1 · The cosigners and their ONE key

KeyAgg  Q = Σ ai·Pi · one x-only key, three owners
–

Each coefficient ai = H(L ‖ pki) hashes the whole ordered key list L, so no cosigner can aim the sum at a key they control. This aggregate becomes the internal key of a perfectly normal bc1p… address (right).

2 · The two-round ceremony

run round 1 to begin

Partial signatures are checked individually before combining, so a bad share is caught and its author named. Try the corrupt button after round 2. And every nonce is single-use: signing zeroizes it, because reusing one leaks the key (demo 3).

The vault's address

internal key  = the aggregate Q.x
–
↓  TapTweak (BIP-341, demo 11)
address
–

Nothing marks this as multisig. Not the address, not the spend: on-chain it is indistinguishable from demo 11's single-key payment.

The receipt vs demo 9's vault

2-of-3 P2WSH (demo 9)

~253 B
witness carries every signature + the whole script, for all to see

MuSig2 key path

64 B
one signature. no script, no key list, no headcount

Cheaper and more private: the rare trade that costs nothing. The catch: MuSig2 is n-of-n (everyone signs). Thresholds like 2-of-3 need script-path fallbacks or FROST.

Why two nonces each?

With a single nonce, an attacker who opens many signing sessions in parallel can steer the combined challenge with a generalized birthday attack and forge a signature. The pair (R₁, R₂) + the binding hash b kill the steering. That's the "2" in MuSig2, and why it still needs only two rounds.

Things to notice

The signature is boring, and that's the point

The final (R.x ‖ s) passes the exact schnorrVerify from demo 11. The verifier needs no idea MuSig exists: aggregation happens entirely off-chain, among the signers.

Accountable misbehaviour

Every partial signature verifies on its own (si·G == Ri + e·ai·Pi), so a corrupt share is pinned on its author before combining. BIP-327's error model names the culprit: coordinators must know who to kick.

All or nothing

Missing one partial signature, the sum is garbage: n-of-n means every key must sign. That's perfect for a 2-of-2 (you + your hardware wallet) or an exchange's internal sign-off, and it composes with Taproot script paths for recovery fallbacks.