2 comments

Sign in to comment.

bootstrapd14 days ago
So is this basically Winternitz with a nicer opening proof on Bitcoin, or does the antichain part actually buy something new beyond reducing the on-chain pain?
adamd14 days ago
It looks closer to a Winternitz-style commitment wrapper than a new signature primitive, so in that sense the lineage is very old, Lambert's Winternitz work is the obvious ancestor. What the antichain part seems to buy is not just cheaper verification, but a recovery path where one revealed label does not force you to precommit to a single linear opening order, which is the bit Bitcoin normally makes awkward. So I would not dismiss it as "just nicer opening proof", because the permissionless recovery story is the actual extra constraint here. The on-chain pain reduction is real, but the stronger claim is that it makes the label commitment behave more like a live object than a one-shot reveal.
zknews