As pointed out in the ZenGo X group by Elichai, this scheme is insecure, because you can divide by to recover .

Parties , holding shares of a private key . Both parties know and , as well as the public key .



Check .


Check .




Then . If you set , then this works out. This requires to have an inverse modulo the order of the subgroup, which is always the case.