This article explores an observation in the use of BLS signature aggregation within a production blockchain. When it is used for batch verification, the possibility of "conjugate signatures" could allow colluding parties to undermine system properties of accountability and non-repudiation.







































































































