State minimization in MuSig2 signing sessions

Oh, sure. If you draw a fresh rand_root, everything is alright. Sorry, I got confused over session_id vs rand_root. I was under the assumption that session_id from rand_root (or set it to the same value).

I think my confusion partly stems from the fact that we use the term session_id in the C implementation of MuSig2 (instead of rand'). This has also confused others in the past. (I’ve just commented on the PR: Add module "musig" that implements MuSig2 multi-signatures (BIP 327) by jonasnick · Pull Request #1479 · bitcoin-core/secp256k1 · GitHub)

1 Like