Schnorr signature
A digital signature scheme that Bitcoin introduced with Taproot in 2021, alongside ECDSA. Schnorr signatures are compact (64 bytes), provably secure and can be combined into a single joint signature.
AlsoSchnorr signaturesBIP 340MuSig2key aggregation
With a digital signature, you prove that you hold the private keyGlossaryPrivate keyA secret, randomly generated number that you use to sign transactions and so control your bitcoin. Anyone who knows the private key can spend the bitcoin that belongs to it – it must never fall into anyone else’s hands.On the learning path: Stage 5 · Step 3 – Backing up your seed phrase →In the glossary → for an address without revealing it. Bitcoin originally used only ECDSA for this. The TaprootGlossaryTaprootA soft fork from November 2021 that introduced Schnorr signatures and more flexible spending conditions. Complex arrangements such as multisig can look like a simple payment. Taproot addresses start with bc1p.In the glossary → upgrade added Schnorr signatures on 14 November 2021, named after the mathematician Claus-Peter Schnorr.[1],[2]
What they do better
- More compact: A signature is exactly 64 bytes, a public key 32 bytes. ECDSA signatures are up to 72 bytes long.
- Provably secure: Under recognised assumptions, it can be shown that nobody can forge signatures without the private key.
- Non-malleable: Third parties can’t turn a valid signature into a different valid one.
- Combinable: Several participants can create a joint signature for the sum of their public keys; many signatures can be verified faster together.[1]
What this brings in practice
MuSig2 builds on this: several people form a joint key and sign with a single Schnorr signature. On the blockchain, this looks like an ordinary single-key Taproot payment. However, MuSig2 requires every participant to sign; a 2-of-3 multisigGlossaryMultisig (multi-signature)A wallet in which several keys jointly control the bitcoin – for example 2 of 3. If one key is lost or stolen, the bitcoin stays safe. In return, setting it up and backing it up is considerably more demanding.On the learning path: Stage 6 · Step 4 – Inheritance & emergency plan →In the glossary → needs other methods.[3]
You don’t need to do anything: if your wallet uses a Taproot address (bc1p…), it signs with Schnorr. More under Keys, addresses & seed phrases.
Related terms
These terms are closely connected.
- This termSchnorr signature
- TaprootA soft fork from November 2021 that introduced Schnorr signatures and more flexible spending conditions. Complex arrangements such as multisig can look like a simple payment. Taproot addresses start with bc1p.
- Private keyA secret, randomly generated number that you use to sign transactions and so control your bitcoin. Anyone who knows the private key can spend the bitcoin that belongs to it – it must never fall into anyone else’s hands.
- Public keyCalculated from the private key and used to check your signatures. The calculation only works in one direction: the private key cannot be worked out from the public key.
- Multisig (multi-signature)A wallet in which several keys jointly control the bitcoin – for example 2 of 3. If one key is lost or stolen, the bitcoin stays safe. In return, setting it up and backing it up is considerably more demanding.
- Soft forkA change to the consensus rules that only tightens them. Blocks that follow the new rules remain valid for old nodes – so Bitcoin can be developed further without a chain split, as with SegWit and Taproot.
Explained in depth
These articles go into more detail:
- Deep dive · Stage 5Keys & addressesPrivate key, public key, address and seed phrase: how they fit together, why the path only runs one way and what 1, 3, bc1q and bc1p mean.
- Deep dive · Stage 6MultisigWhat a 2-of-3 multisig wallet is, who it’s worth it for, how to set it up and why you need to back up the descriptor as well as the seeds.
- Deep dive · Stage 1Forks & controversiesSoft forks, hard forks, the block size war, Bitcoin Cash, OP_RETURN and BIP-110 – explained neutrally, with both sides and what to do if the chain splits.
More from „Technology“
Sources3 sources · 2 publishers
The superscript numbers in the text refer to these sources.
- BIP 340: Schnorr Signatures for secp256k1 – Bitcoin Improvement Proposals, 19.01.2020 (accessed 28/09/2026)
- mempool.space API: Block 709,632 (first block with Taproot rules) – mempool.space (accessed 28/09/2026)
- BIP 327: MuSig2 for BIP340-compatible Multi-Signatures – Bitcoin Improvement Proposals, 22.03.2022 (accessed 28/09/2026)
This entry is for education only and is not investment, tax or legal advice.