← Bitcoin Encyclopedia

MuSig2 & FROST

🌳 Advanced

💡 The Plain-English Definition

MuSig2 and FROST are advanced multisig protocols that let several parties jointly control bitcoin using a single combined signature — one that looks on-chain exactly like an ordinary single-key payment. They make multisig more private, more efficient, and much cheaper all at once.

🤔 But Why Though?

Traditional multisig (requiring several keys to authorise a transaction) has always been visible on-chain. A standard 2-of-3 multisig transaction is noticeably larger than a single-key one, its multisig nature is plain in the blockchain data, and anyone watching knows those addresses probably hold more bitcoin than average — which makes them targets. Taproot, the 2021 upgrade, introduced Schnorr signatures, which have a crucial property: they can be added together, so several Schnorr signatures can be mathematically combined into one signature that’s indistinguishable from a single key’s.

MuSig2 (formalised as BIP327 in 2023, developed by Jonas Nick and Tim Ruffing at Blockstream) is an n-of-n scheme — every signer must take part. A 3-of-3 MuSig2 wallet needs all three keyholders to sign together, and the result appears on-chain as a single signature from a single key. If any one keyholder is unavailable, the transaction can’t proceed.

FROST (Flexible Round-Optimized Schnorr Threshold, developed by researchers Chelsea Komlo and Ian Goldberg) extends this to true threshold setups, where any M of N keyholders can sign. A 2-of-3 FROST wallet needs any two of the three, and the third one’s absence is invisible on-chain. FROST is being standardised through the “ChillDKG” specification as of 2025–2026.

The practical benefits are substantial. Fees drop roughly 30–43% versus legacy multisig formats, because only one signature appears in the transaction no matter how many parties signed. Privacy improves: attackers hunting for multisig wallets with larger balances can no longer pick them out by transaction type. And complex nested arrangements become possible — a 2-of-2 wallet where one key is your phone and the other is itself a 3-of-5 FROST group of family members, all hidden behind a single on-chain key. Major institutional custodians, including BitGo and Ledger (as of v2.4.0), have adopted MuSig2 for their hot wallets.

🌍 The Real-World Analogy

Standard multisig is like a door with three visible keyholes — anyone passing by can see this is a vault that needs several keys. MuSig2 and FROST are like a door with one ordinary keyhole that, when opened, secretly required two or three people to each insert their invisible portion of the key at the same time. From the outside, it looks like any other door. The security is the same or greater; the signal to would-be attackers is gone.

⚡ So What?

MuSig2 is production-ready and being adopted by professional custody operations. If your hardware wallet supports it, MuSig2 multisig gives you better privacy and lower fees than standard multisig, with no security tradeoff. FROST is still being standardised and isn’t yet widely available to end users, but it’s the path toward fully threshold-based private multisig that will likely become standard within a few years. For anyone making custody decisions for significant holdings, understanding both is essential context for where multisig is heading.

📩 The Daily Bit · free

Get one plain-English Bitcoin email each morning.

The Daily Bit — free, two minutes, unsubscribe anytime.

The Bitcoin Family GuidePrefer a book? The Bitcoin Family Guide