Improve WabiSabi anonymity with MuSig #12729
BTCparadigm
started this conversation in
General & Publications
Replies: 1 comment
-
Just a note that for 2-of-2 multisig another alternative to MuSig2 with P2TR is 2P-ECDSA with P2WPKH. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Discussed in #5136
Originally posted by lontivero February 4, 2021
Alice needs to pay Carol
x
satoshis. Bob needs to pay Davey
satoshis. Alice and Bob want to make their payments using WabiSabi but the output amounts (x
andy
) can be easy to identify in an unequal output coinjoin so, Alice and Bob compute a aggregated public key (P = Pa + Pb) and send their satoshis to the corresponding address in a coinjoin. The coordinator will optimize the outputs and consolidate those two in only one.At signing phase, once Alice and Bob receive the coinjoin transaction, they verify everything is okay and they know the outpoint of the consolidated output, they build and sign a transaction that spends the coinjoin output and pays
x
to Carol andy
to Dave. After that the sign the coinjoin transaction.In this way, no matter how much computation power an adversary have, the real payment is not in the coinjoin transaction and none of the subset transactions is valid. The coinjoin transaction is cheaper for Alice and Bob and given the payment transaction doesn't look like a multiparty transaction (it looks like a normal payment + change transaction) then it is not possible for an external observer to know what is going on there.
Beta Was this translation helpful? Give feedback.
All reactions