You got it mostly correct the first time.
So it’s the Claimant unlocking their Tapigner locally, signing a PSBT, then Nunchuk adding its key to comprise the 2 of 3 for transfer of fund and initiate the send?
  1. Encrypted file downloaded onto Beneficiary's device
  2. Decryption happens locally
  3. Recovered Tapsigner's private key now is in Beneficiary's device
  4. Beneficiary selects a withdrawal address
  5. Sweep transaction is created
  6. Beneficiary signs the sweep transaction with the recovered Tapsigner key
  7. Platform Key co-signs the sweep transaction
  8. Sweep transaction is broadcast
You can test this flow out on testnet for free by the way.
Fantastic. Thank you Hugo for the more in-depth answer.
I think your overall solution is very well thought out., and applaud you for your efforts.
I’d also encourage you to add more of this info to your website, to allow potential clients of Nunchuk to have a more complete picture, as this should only serve to have people gain more confidence in what you’ve built.
reply