Zeeka saysBLS signatures can be added together: thousands of validators signing the same block collapse into one short signature checked with a single pairing.
BLS signatures have a superpower: they aggregate. A signature is σ = H(m)^sk and a public key is g^sk. Multiply all the signatures together and you get one short signature; multiply all the public keys and you get one aggregate key. A single pairing equation then verifies that the whole crowd signed — which is why Ethereum's consensus layer can fold tens of thousands of validator attestations into something checkable.
The catch is rogue-key attacks: a malicious validator can craft a key that cancels others unless you require proof of possession or message-distinct aggregation. The toy demo shows the aggregation arithmetic — the product of signatures equals H(m) raised to the sum of the secret keys — which is the exact identity a pairing checks at full scale.
Power-ups you unlock
Signature σ = H(m)^sk; public key = g^sk
Aggregate signature = the product of all signatures
Aggregate key = the product of all public keys
One pairing verifies the whole aggregate — huge for consensus
Ethereum uses BLS over bls12-381 for validator attestations
The Collision attacks — common mistakes
Aggregating over different messages carelessly (rogue-key attacks)
Skipping proof-of-possession checks on public keys
Assuming aggregation hides who signed — it does not by itself
Reusing nonces or keys across domains
Boss battleShow that the product of three BLS signatures on one message equals H(m) raised to the sum of the three secret keys.
Example code
<!doctype html><html><head><meta charset="utf-8"></head>
<body style="background:#06040d;color:#e6e0ff;font-family:monospace;padding:20px"><pre id="o"></pre>
<script>
// ILLUSTRATIVE BLS aggregation (toy): real BLS needs pairings. We show the
// arithmetic that lets ONE short signature verify many signers.
const p = 1009, g = 11;
const pw=(a,e,m)=>{ let r=1; a%=m; while(e>0){ if(e&1) r=(r*a)%m; a=(a*a)%m; e>>=1; } return r; };
const Hm = 7; // H(message) mapped to an exponent
const sk = [3, 5, 9]; // three validators' secret keys
const sig = sk.map(s => pw(Hm, s, p)); // σᵢ = H(m)^skᵢ
const aggSig = sig.reduce((a,b)=>(a*b)%p, 1); // ∏ σᵢ
const sumSk = sk.reduce((a,b)=>a+b, 0); // Σ skᵢ
document.getElementById('o').textContent = [
'3 validators sign the same block',
'individual σ = ' + sig.join(', '),
'aggregate σ (one value!) = ' + aggSig,
'H(m)^(Σ sk) = H(m)^' + sumSk + ' = ' + pw(Hm, sumSk, p) + ' ← equals aggregate σ',
'match? ' + (aggSig === pw(Hm, sumSk, p)) + ' → one sig + one agg key verifies all 3'
].join('\n');
</script></body></html>