One-Time Verifiably Encrypted Signatures A.K.A. Adaptor Signatures My attempt to formalize "adaptor signatures". see main.pdf TODO Rewrite final section. Improve ECDSA EUF-CMA[VES] proof so it only needs a CDH orcale for the signing key.