On Tue, Mar 06, 2018 at 08:58:51PM +0000, Andrew Poelstra wrote: > After creating a new state i, A and B revoke state i-1 as follows: > > 3. A sends an adaptor signature for s^2_{A,i-1} which reveals her half > of AB_i if she publishes that signature. Similarly B sends an > adaptor sig for s^1_{B,i-1} which reveals his half of AB_{i-1}. > > Now if either party completes tx_i and to post the (i-1)th state > to the chain, the _other_ party will learn the secret key to AB_i > and can take the coins. >

Oof I messed up this paragraph. _i should be _{i-1} everywhere. Here is a correct version: > 3. A sends an adaptor signature for s^2_{A,i-1} which reveals her half > of AB_{i-1} if she publishes that signature. Similarly B sends an > adaptor sig for s^1_{B,i-1} which reveals his half of AB_{i-1}. > > Now if either party completes tx_{i-1} to post the (i-1)th state > to the chain, the _other_ party will learn the secret key to AB_{i-1} > and can take the coins. > -- Andrew Poelstra Mathematics Department, Blockstream Email: apoelstra at wpsoftware.net Web: https://www.wpsoftware.net/andrew "A goose alone, I suppose, can know the loneliness of geese who can never find their peace, whether north or south or west or east" --Joanna Newsom

