also note that there is no way to prove the relationship between b from B=b·G and H(b), but that is why you have the HTLC as a fallback.
on the happy path if Bob is playing honestly Alice can spend without revealing this was a swap. it just looks like a taproot keyspend. if not, then it is an HTLC plain and simple.
Login to reply
Replies (1)
It sounds like you like it! Consider writing your own version with this improvement implemented. And help me convince @Boltz - Non-Custodial Bitcoin Bridge to implement this, or maybe write a real version and compete with them