One move
Spend
The owner moves while their current key still works. The recovered key shows up after the network has stopped honoring it.
-
1. Publish H0
The height is public, with time for cold storage to move. Activation is not a surprise.
-
2. Move once
Before H0, one ECDSA spend. The whole balance pays a new bc1q. Nothing stays on the key that was just published.
-
3. Hold the hash
The new output is OP_0 and 20 bytes. The next public key is not on the chain.
-
4. Spend after H0
The witness carries a SPHINCS signature. ECDSA is not enough, so nodes do not mine it.
Coins that miss H0 are frozen against ECDSA. The attacker cannot move them. The owner cannot move them with ECDSA either. Moving before H0 is how the owner keeps a way to spend.
What the transaction contains
The migration has inputs from the address you are leaving. The witness on each of those inputs carries the ECDSA signature and the public key, which is how the key becomes public. The outputs are a new bc1q address, witness version 0, 20-byte HASH160. There is no output back to the address that just signed. Dust left behind is still a balance on a revealed key, so it fails the rule.
After H0 the next spend of that new output does not repeat this shape. The witness carries a SPHINCS signature instead of ECDSA. The output you are spending is still a hash. The public key used for the hash signature is not an elliptic-curve point, and it is not published as one.