Hi, this is probably a non-starter because it would encourage address reuse which has always been something we are trying to avoid. Also, you would get the same savings with Cross-Input Signature Aggregation of Schnorr signatures plus a lot more possible upside. I am a bit biased because I am working on it. And I am not very deep into the post-quantum stuff yet but for that scenario there is already a proposal called OP_CIV by Tadge Dryja that shares some similarities with your as well but is more flexible: https://groups.google.com/g/bitcoindev/c/oFbEQb_DB3I