BIP340 Schnorr Signatures Quick refs : pseudocode.md, batch-verify.md, pitfalls.md Schnorr is the signature scheme used in Taproot. Discovered in 1989, patent-encumbered until 2008, finally proposed for Bitcoin in 2018 (BIP340), activated 2021. Why Schnorr over ECDSA | Property | ECDSA | Schnorr (BIP340) | |----------|-------|------------------| | Signature size | 71-72 bytes (DER) | 64 bytes flat | | Linearity | No | Yes | | Batch verification | No | Yes (sub-linear) | | Malleability | Yes (low-s normalization required) | No (canonical by construction) | | Provable security | requires assump…