Browser-based MuSig2 demo — BIP-327 over secp256k1. n signers aggregate their public keys into one key and their nonces into one nonce, producing a single Schnorr signature indistinguishable from a lone signer's. Real curve arithmetic. No backend.
MITTypeScriptcrypto-labcryptographymultisignaturemusig2rogue-key-attackschnorr-signaturessecp256k1bip-327
systemslibrarian.github.io/crypto-lab-musig-gate