Seems Legit
Dennis E. Jackson, Cas J. F. Cremers, Katriel Cohn-Gordon, Ralf Sasse · 2019
The standard definition of security for digital signatures - existential unforgeability - does not ensure certain properties that protocol designers might expect. For example, in many modern signature schemes, one signature may verify against multiple distinct public keys. It is left to protocol designers to ensure that the absence of these properties does not lead to attacks.