P2WOTS: Post Quantum UTXO Winternitz Signatures

Not a blocker, but the P2MR proposal (BIP360) is also using witness version 2.

Since your proposal commits to the nonce in the output script, this would still only allow signing a single time for each UTXO, but Bitcoin requires the ability to sign more than once for a UTXO without leaking the private key in case addresses are reused, users want to participate in multi-user transactions, or simply need to replace a prior spending attempt.

1 Like