MuSig2 · BIP-327
Step through the real two-round MuSig2 protocol — n public keys collapsing into one, n nonce pairs into one nonce, n partial signatures into one — then watch a plain BIP-340 verifier accept the result, and try to break both the key and nonce aggregation yourself.