Hermes / Taproot & Schnorr

Taproot & Schnorr

Bitcoin launched with ECDSA. Schnorr's cleaner scheme had spent so long under patent that in 2009 it had no standard and no library support. The 2021 Taproot upgrade finally brought it home (BIP-340). Same curve, same keys, but the equation is linear, so signatures and keys can add; and every output hides behind one tweaked key, so a plain payment, a multisig vault and a secret script tree all look identical on-chain: bc1p…

1 · Schnorr sign & verify

R.x =– s =–
not signed yet

ECDSA (old)

s = k⁻¹(z + r·d)
verify needs s⁻¹ too

Schnorr (Taproot)

s = k + e·d
s·G == R + e·P

No modular inverse anywhere: e is a tagged hash of R.x ‖ P.x ‖ m, and the nonce is derived deterministically from the key and message, so the PS3 nonce-reuse bug (demo 3) is gone by construction.

2 · The superpower: signatures add

Because signing is linear, two cosigners can sum their keys and produce one ordinary signature for the sum. The verifier (and the blockchain) sees a single key, a single 64-byte signature.

AAlice  –
BBob    –
joint key  (dA+dB)·G · one point, two owners
–
not signed yet

This is the door to MuSig2: an n-of-n vault that costs and looks exactly like a single-sig payment, against the ~250-byte witness a 2-of-3 script spend like demo 9's carries. (Real MuSig adds hashing so a cosigner can't craft a malicious "rogue" key; the algebra shown here is the heart of it.)

Your key pair

P.x–

An x-only pubkey: 32 bytes, no 02/03 prefix. Of the two curve points with this x, the even-Y one is implied.

The Taproot address

internal key  P.x
–
↓  t = tagged_hash("TapTweak", P.x)
tweak  t
–
↓  Q = P + t·G
output key  Q.x
–
↓  witness v1 + bech32m
address
–

The tweak can also commit to a whole tree of scripts, but a key-path spend never reveals whether one exists. Your wallet's bc1p… addresses are built exactly like this (BIP-86).

Things to notice

Cleaner math, provable security

ECDSA's k⁻¹ was a patent workaround with a folklore security argument. Schnorr's linear s = k + e·d has a clean proof, and it's why signatures can be batch-verified and aggregated.

Everyone looks the same

Single sig, 2-of-2 MuSig vault or a key hiding a script tree: every key-path spend is the same 34-byte output and one 64-byte signature. Privacy for the vault, cheaper fees for everyone.

Tamper-proof, still

Edit one character after signing and verification fails, exactly as with ECDSA. The challenge e binds the signature to the message and to both points. Different scheme, same guarantee.