Paper 2025/388

Fair Distributed Exchange via Threshold Adaptor Signatures

Ruben Baecker, Friedrich-Alexander Universität Erlangen-Nürnberg
Paul Gerhart, TU Wien
Jonathan Katz, Google (United States)
Dominique Schröder, TU Wien, Friedrich-Alexander Universität Erlangen-Nürnberg
Abstract

Adaptor signatures enable scriptless protocols on blockchains such as Bitcoin by allowing a buyer to lock a coin based on an NP statement and release payment to any party that reveals the corresponding witness. They underlie a broad class of layer-2 protocols, including payment channels, cross-chain swaps, and coin-mixing services, which today secure billions of dollars in locked value. Fairness for existing adaptor-signature constructions, however, is inherently two-party, so does not apply to deployments in which the buyer or witness holder is operated by a committee. In this work, we formalize and solve the fair exchange problem in that setting. We consider a buyer group holding shares of a signing key controlling a coin, and a seller group holding shares of a secret witness. The goal is to guarantee fairness both between groups (ensuring that each group obtains its asset if and only if the other does), as well as within groups (ensuring that all honest buyers learn the witness and all honest sellers receive payment), even in the presence of malicious insiders and/or partial information leakage. We present efficient protocols achieving these guarantees under standard cryptographic assumptions on scriptless blockchains with timelocks. Our construction introduces two new primitives of independent interest, threshold adaptor signatures and certified witness encryption, which we define, analyze, and instantiate efficiently.

Metadata
Available format(s)
PDF
Category
Applications
Publication info
A major revision of an IACR publication in ASIACRYPT 2026
Keywords
Threshold Adaptor SignatureCertified Witness EncryptionFair Exchange
Contact author(s)
mail @ paul-gerhart de
History
2026-09-14: last of 2 revisions
2025-02-28: received
See all versions
Short URL
https://ia.cr/2025/388
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/388,
      author = {Ruben Baecker and Paul Gerhart and Jonathan Katz and Dominique Schröder},
      title = {Fair Distributed Exchange via Threshold Adaptor Signatures},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/388},
      year = {2025},
      url = {https://eprint.iacr.org/2025/388}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.