Library · Crypto, word by word · Cryptography
What is a Schnorr signature?
A Schnorr signature is a type of digital signature, standardised for Bitcoin in BIP-340, that proves a private key approved a transaction. It uses the same curve as Bitcoin's older ECDSA signatures, is always 64 bytes, and lets several keys combine into one ordinary-looking signature.
What it means for you
Schnorr signatures apply only to Taproot outputs; coins held in older Bitcoin address types still sign with ECDSA. A Taproot payment approved by several people can look on chain like a payment from a single key, so a block explorer cannot always show how a coin was controlled.
How it works
BIP-340 defines Schnorr signatures over secp256k1 with 64-byte signatures and 32-byte public keys that encode only the x-coordinate. Its motivation lists provable security (strong unforgeability under chosen-message attack, in the random oracle model), non-malleability, so a third party cannot turn a valid signature into a different valid one, and linearity: collaborating parties can produce a signature valid for the sum of their public keys, the basis for multisignature and threshold schemes. It also supports batch verification, checking many signatures together faster than one by one. BIP-341 makes it the signature used by Taproot.
Sources: BIP-340: Schnorr Signatures for secp256k1, BIP-341: Taproot · checked 4 October 2026
Often confused with
Related words
Educational content, not financial advice. Written by hand and checked against the source named above. Something wrong? Tell us and we reply within two business days.