Ed25519 was introduced in the following paper:

The following paper extends EdDSA to handle more curves:

The following paper analyzes reductions between multi-key attacks and single-key attacks for several variants of the Schnorr signature system, including EdDSA:

