Library · Crypto, word by word · Cryptography

What is a Schnorr signature?

A Schnorr signature is a type of digital signature, standardised for Bitcoin in BIP-340, that proves a private key approved a transaction. It uses the same curve as Bitcoin's older ECDSA signatures, is always 64 bytes, and lets several keys combine into one ordinary-looking signature.

What it means for you

Schnorr signatures apply only to Taproot outputs; coins held in older Bitcoin address types still sign with ECDSA. A Taproot payment approved by several people can look on chain like a payment from a single key, so a block explorer cannot always show how a coin was controlled.

How it works

BIP-340 defines Schnorr signatures over secp256k1 with 64-byte signatures and 32-byte public keys that encode only the x-coordinate. Its motivation lists provable security (strong unforgeability under chosen-message attack, in the random oracle model), non-malleability, so a third party cannot turn a valid signature into a different valid one, and linearity: collaborating parties can produce a signature valid for the sum of their public keys, the basis for multisignature and threshold schemes. It also supports batch verification, checking many signatures together faster than one by one. BIP-341 makes it the signature used by Taproot.

Sources: BIP-340: Schnorr Signatures for secp256k1, BIP-341: Taproot · checked 4 October 2026

Often confused with

Schnorr signature vs ECDSASchnorr signature vs Multisig

Related words

TaprootECDSADigital signatureThreshold signatureMultisig

Educational content, not financial advice. Written by hand and checked against the source named above. Something wrong? Tell us and we reply within two business days.