Oddbean new post about | logout
 Pay ln invoice to receive ecash. Can that be  made atomic with PTLCs? Instead of hash preimage buy a private key as the proof of payment. If the mint pre-commits to the (blind) signature nonce R (similar to DLCs) the lightning invoice could use s*G as the point to pay to. The payer would verify that this point is hash(R,msg)*P+R to know that the proof of payment will actually be the expected ecash (signature)