BIP-327 is a Bitcoin Improvement Proposal that specifies MuSig2, a two-round multi-party Schnorr signature protocol that enables a group of n signers to collaboratively produce a single aggregated Schnorr signature indistinguishable from a single-party signature. BIP-327 provides a cryptographically secure specification for key aggregation and signature combination compatible with BIP-340 Schnorr signatures and the Taproot upgrade, enabling private and efficient threshold custody and collaborative signing workflows on Bitcoin.
Content
- MuSig2 was introduced in a research paper by Jonas Nick, Tim Ruffing, and Yannick Seurin published in 2020, building on the original MuSig (MuSig1) protocol that required three rounds of communication. MuSig2’s primary contribution was reducing the signing protocol to two rounds by allowing signers to pre-generate and share nonce commitments before the message to be signed is known, enabling offline pre-signing workflows. The Bitcoin Improvement Proposal formalising MuSig2 as BIP-327 was authored by Jonas Nick, Tim Ruffing, Elliott Jin, and others, advancing through review from 2021 and achieving Final status in 2023.
- Technically, MuSig2 proceeds in two phases: a nonce generation and exchange phase, in which each signer generates two nonce pairs and shares the corresponding public nonces with co-signers; and a signing phase, in which a linear combination of the shared nonces is computed deterministically from the message and all public nonces, and each signer produces a partial signature using their secret key and the combined nonce. Partial signatures are summed to produce the final aggregated Schnorr signature. Security is proved under the one-more discrete logarithm assumption in the random oracle model. The protocol is extended to support adaptor signatures and signature tweaking required by Taproot’s key tweaking mechanism.
- BIP-327 is deployed in Bitcoin custody solutions targeting institutional and collaborative self-custody use cases. Libraries implementing MuSig2 include libsecp256k1 (the reference implementation maintained by Bitcoin Core contributors), bitcoin-dev Python tooling, and commercial SDKs from Blockstream, Unchained Capital, and Casa. Hardware wallet manufacturers including Ledger and Trezor are integrating MuSig2 support to enable on-device participation in multi-party signing ceremonies with secure nonce generation and storage.
- As of 2024–2025, BIP-327 has achieved Final status and is increasingly adopted for collaborative custody schemes that replace legacy P2SH and P2WSH multisig. Its privacy advantage—that n-of-n Taproot key-path spends appear identical to single-key spends—is particularly valuable for exchanges and custodians seeking to conceal custody structure from chain analysts. Research is ongoing into FROST (Flexible Round-Optimised Schnorr Threshold Signatures), a related threshold scheme supporting t-of-n configurations that BIP-327 does not natively cover, with BIP drafts under active development.