Just realized that for the 'Blank Check' approach to work, we have to make sure that only a single party has access to a specific set of blank checks.
Otherwise, we run the risk that a check gets used twice but Carol can only redeem it once.
If we have to restrict access to the checks, that probably defeats the original purpose: 'An offline receiver could publish their public key and the online sender can prepare a suitable BlindSignature from the mint.'
