Non interactive anti-exfil (airgap compatible)

Calling it a vector commitment is perhaps a bit confusing, as that term exists in cryptography with a very different meaning.

I believe this is roughly Scheme 2 from [bitcoin-dev] Overview of anti-covert-channel signing techniques, for ECDSA instead of Schnorr (which is based on an idea posted by Greg Maxwell in 2014).