Skip to content

LibraryPrivacy2020Design paperCorpus record

FROST: Flexible Round-Optimized Schnorr Threshold Signatures

FROST. Chelsea Komlo and Ian Goldberg.

A threshold Schnorr signature: any t of n signers can produce one ordinary-looking signature, and fewer than t cannot. The signing protocol is two rounds, or one if nonces were prepared earlier. The paper is the scheme, not a custody vendor.

FROST is a t-of-n Schnorr threshold signature. Any t signers produce one signature under one group key. Fewer than t learn nothing they can use to forge. Signing is two rounds, or one round if nonces were preprocessed. The chain cannot see the threshold. That is both the feature and the audit gap.

The five-minute read

Threshold, not n-of-n

The policy is any t of n. MuSig2 is the different tool, where every signer must participate. Swapping the names swaps the recovery story.

One signature on-chain

Verification is ordinary Schnorr under the aggregated key. Observers do not learn which subset signed, and do not learn t or n.

Two rounds, with a warning

The round structure exists because naive threshold Schnorr leaks or forges when nonces are handled casually. Preprocessing nonces is allowed and is also a way to get the implementation wrong.

Key generation matters

Distributed key generation is in the argument. A dealer who hands out shares and keeps a copy has reduced the threshold to one, off-chain, where the signature scheme cannot see it.

One action, walked through

  1. Signers run key generation and publish one group key.
  2. When a message is to be signed, t signers exchange nonce commitments.
  3. They exchange signature shares and combine them.
  4. Anyone verifies the result under the group key.
  5. An absent signer beyond the threshold is not required. A missing share below the threshold means there is no signature.

The argument, unpacked

Privacy against auditors

The chain record cannot answer 'which officers signed'. A custody design that needs that answer needs a different mechanism, or an off-chain log the signature will not provide.

The paper is not a control framework

FROST does not say who may propose a message, how a lost share is rotated, or what a court can seize. Those are outside the cryptographic game.

What has to be true

  • Key generation matches the scheme. Shares are not recombined somewhere else.
  • Nonce commitments are checked. A shortcut here is a known way to lose the key.
  • At least t signers are honest and available when a signature is required. The complement may be anything.
  • The verification key in the output script is the group key from this ceremony, not a key from a different one.

What happened after the paper

FROST became a widely implemented threshold Schnorr scheme, later specified in an RFC that should be cited separately when the implementation claims conformance. The 2020 paper is the scheme. It is not a vendor assessment.

What to check before you use the idea

  • What are t and n, and who holds shares?
  • Was key generation distributed, or did a dealer see every share?
  • Are nonces preprocessed, and are commitments verified?
  • Does the application need to know which subset signed? The chain will not say.

Terms

Threshold signature
A signature that can be produced by any t of n parties and that verifies under a single public key.
Nonce commitment
The first-round message that binds a signer to nonce material before signature shares are revealed.

The problem the paper names

A multisignature that puts n keys on-chain is visible and rigid. A threshold signature should look like one key, work when only a subset is online, and not take five rounds to produce.

What the design proposes

  • A distributed key generation gives each signer a share. The group has one public key.
  • Signing is two rounds in the general case. A signer who has pre-shared a nonce can finish in one.
  • The output verifies under the group key with ordinary Schnorr verification.

How the mechanism is specified

  • The security claim is that forging is as hard as Schnorr, under the paper's model, including the handling of rogue keys.
  • t-of-n is the policy. The chain sees neither t nor n.
  • A signer who reuses nonce material badly can still destroy the key. The paper's rounds exist to stop a known class of that failure. They do not stop an implementation from ignoring them.

What this page does not treat as proven

  • The chain cannot see the threshold. That privacy is also why an observer cannot audit who signed.
  • Key generation is part of the security argument. A dealer who knows every share is a single party, whatever the whitepaper says.
  • This is not a policy for recovery, legal ownership, or a qualified custodian. It is a signature scheme.

Why a venture studio still reads it

Ask who ran the key generation, what t and n are, and whether nonce commitments are actually checked. A product that cannot answer those is not offering FROST. It is offering a key somewhere.

This is Blockchain Lab's reading of a public design paper. It is not the paper, not a copy of it, and not an offer of tokens, equity, custody or a partnership. Later network behaviour can diverge from the text. Nothing here is investment, legal or technical advice.

Research status: Design paper. Last reviewed: 1 October 2026. This is a reading of a public paper, not investment, legal or security advice.