Nuh's avatar
Nuh 1 year ago
OK but can't the old shares still sign things for the same public key? Maybe I am missing something.

Replies (1)

Signers have to agree on a polynomial to sign. My understanding is that once the leaked key signs with the wrong polynomial, the other signers can just reject that share.