Most people start with one hardware wallet and one set of recovery words, and for a while that is the right setup. The trouble is that everything then rests on a single key: one seed, one device, one company's code. This guide explains multisig in plain terms, the different ways you can split the keys, what each arrangement protects you from, and how to tell when it is time to make the move. If you would rather watch than read, the video version with Heidi is on the way.
Disclosure: we earn affiliate commission from Trezor and Ledger through links in our videos. No multisig app, service or company mentioned here pays us. This is education, not personalised security or financial advice. Facts were checked on 30 September 2026.
What problem does multisig solve?
A normal wallet has a single point of failure. Whoever holds your recovery words holds your coins, and if those words are lost, the coins are gone. A hardware wallet protects that one key very well, but it is still one key.
July 2026 showed what that means in practice. From 30 July, an attacker began emptying thousands of Bitcoin wallets that had been created on Coldcard devices. Nobody's device, PIN or paper backup was stolen. A firmware mistake dating back to March 2021 meant affected devices had produced recovery words with far too little randomness, so the attacker could simply work through the possibilities. TRM Labs estimates about 1,816 BTC was taken, roughly $116 million, across four waves. Owners did everything they had been told to do and still lost their coins.
Multisig was the setup that held. Owners whose Coldcard key was only one of several keys in a multisig were told to replace that key and move to a fresh wallet, but their coins had not moved, because one guessed key was not enough. We cover the incident in full in our Trezor safety review and in the video below.
Our August 2026 breakdown of the Coldcard flaw: the one-character bug, how the attacker found the wallets, and what affected owners should do. Watch it on our CryptoTips channel.
How does multisig work?
Think of a safe deposit box with three locks, where any two keys will open it. A multisig wallet works the same way. You create several keys, set a rule such as "any 2 of 3", and from then on the network will only accept a transaction signed by enough of them. The shorthand is M-of-N: M signatures needed, out of N keys in total.
Each key is an ordinary wallet on its own device, with its own recovery words. The multisig is the rule that ties them together. On Bitcoin that rule is written into the address itself, so it is enforced by the network rather than by any app or company. On Ethereum and similar networks, the rule lives in a smart contract; Safe is the standard one.
That design is where the security comes from. A thief who steals one device, finds one set of words or breaks one maker's firmware gets one key, and one key does nothing. You can also lose a key without losing your coins, because the other two still meet the threshold.
| Setup | Keys needed | Keys you can lose | Keys a thief needs |
|---|---|---|---|
| Single-key wallet | 1 | 0 (the backup is your only spare) | 1 |
| 2-of-2 | 2 | 0 | 2 |
| 2-of-3 | 2 | 1 | 2 |
| 3-of-5 | 3 | 2 | 3 |
The table shows why 2-of-3 is the usual starting point. It is the smallest setup that survives losing a key and also stops a thief with one key. A 2-of-2 looks stronger than it is: it has two points of failure instead of one, so losing either key locks the coins for good.
What are the ways to split the keys?
Once you choose a threshold, the real decision is who holds each key and where it lives. There are five common arrangements.
The five common ways to split a multisig. The first is where most people should start.
All three keys yourself. Three hardware wallets, each with its own recovery words, kept in three separate places. This is the arrangement we would point most people to first. Nobody else is involved, nobody else knows your balance, and no single burglary, fire or faulty device can reach your coins. The cost is that you manage three locations and three backups.
Two keys yours, one with someone you trust. You keep two keys, and a family member or a lawyer keeps a third, sealed. They cannot move anything on their own, but if you lose a key, or something happens to you, there is a route back to the coins. It pairs naturally with a crypto inheritance plan.
3-of-5 for larger sums. Five keys, any three to sign. It tolerates losing two keys and stops any single person acting alone, which suits couples, families and larger holdings. There are more devices to keep track of, so write the arrangement down clearly.
One key on your phone. Some apps let one of the three keys live on your phone, which makes signing much quicker. Treat that key as a hot key, because the phone is online. It is acceptable as one of three when the other two are on hardware wallets, and never as a key that matters on its own.
Should a company hold one of your keys?
Several companies now offer to hold one key in a 2-of-3, with you holding the other two. The appeal is obvious. They walk you through setup, and if you lose a key they help you replace it. Our view is simple: we would never recommend handing a company a key, with one exception. If you do it, it must be a single key out of three, with the other two held only by you, and you must understand what you are giving up.
- Privacy. The company can see your addresses and your balance, and it will usually know who you are.
- Your data is a target. Customer lists of known bitcoin holders are exactly what criminals want, and data leaks happen even at careful firms.
- It can refuse to sign. It cannot move your coins alone, but it can be pressured, ordered or simply decide not to co-sign.
- It can fail or change. Prices rise, terms change and companies close. You need to be able to leave without them.
- Scammers copy them. Fake support messages from custody firms are a common way in.
If you still go ahead, download the wallet file (the descriptor) on day one and practise rebuilding the wallet without the company's app. If you can't do that, you do not fully control the coins. For most people, a multisig you set up yourself gives the same protection without these trade-offs, and it is less work than it looks. Our step-by-step setup guide walks you through it.
Why should the keys come from different makers?
This is the lesson Coldcard taught everyone. The flaw sat in how the devices created recovery words, so what mattered was how many of your keys came from one maker.
How the Coldcard flaw played out by setup. Loss estimates from TRM Labs; multisig outcomes from providers' advisories of 31 July to 2 August 2026.
A multisig with one Coldcard key was safe, because the attacker could only guess one key. A multisig with two Coldcard keys was in trouble, because both keys shared the same weakness and together they met the 2-of-3 threshold. Owners in that position were told to move their coins at once.
The rule is that no single maker should supply enough keys to sign. In a 2-of-3 that means three different makers. Two makers is still far better than one, but the maker supplying two keys could reach the threshold in a Coldcard-style failure. Trezor devices work well as keys in a multisig, so a Trezor plus hardware wallets from two other makers is a sensible pattern. Our Trezor vs Ledger comparison covers how the main devices differ.
What are the pros and cons of multisig?
| Pros | Cons |
|---|---|
| No single point of failure. One lost, stolen or faulty key cannot move or lock your coins | More to set up: several devices, several backups, several locations |
| A thief who finds one set of recovery words, or forces you to open one device, gets nothing | The recovery words alone cannot rebuild the wallet. You also need the wallet file (descriptor) on Bitcoin, or the Safe address on Ethereum |
| A bug in one maker's firmware reaches only one key | Every payment needs more than one device, so spending takes longer |
| Natural routes for inheritance and shared control | Slightly higher network fees, and fewer apps support it |
What catches people out is the wallet file. On Bitcoin, your wallet is defined by all three keys together, so two sets of recovery words are not enough to find the coins unless you also have the descriptor, a short piece of text listing every key's public half and the 2-of-3 rule. It cannot spend anything, so it is safe to keep a copy next to each set of words. Losing it is a common way people lock themselves out.
Is multisig better than a passphrase or a split backup?
These are the other common ways to go beyond a single key, and they solve different problems. A passphrase adds a secret extra word to your recovery words, creating a hidden wallet that a thief with the words alone cannot open. A split backup, which Trezor calls Shamir backup, breaks your recovery words into several shares, so no single share reveals anything.
| Passphrase | Split backup (Shamir) | Multisig | |
|---|---|---|---|
| Stops a thief who finds your words | Yes, if the passphrase is kept apart | Yes, unless they find enough shares | Yes |
| Stops a flaw in one device's key creation | Sources disagree | No, it is still one key | Yes, if you mix makers |
| Signing still happens on one device | Yes | Yes | No, several devices sign |
| Effort | Low | Low to medium | Medium |
On Coldcard specifically, reports differ on whether a passphrase saved affected owners, so we would not rely on one. Multisig is the step up because it is the only option where no single device, seed or maker is ever enough. A passphrase on each key of a multisig is possible too, but every extra secret is something else to back up.
When should you move to multisig?
Most people don't need multisig on day one. They need one hardware wallet, used well, with the recovery words on metal. Our guide to using a cold wallet covers that first step. The question is what happens as your holdings grow. An amount that feels small today can become life-changing over a few years, and the moment you realise that is the worst time to be learning a new setup under pressure.
A better test than any dollar figure is this: would losing this change your life? If the answer is yes, a single key is carrying too much. Learn the process now with a small amount. Build a 2-of-3, send a little in, move it out with two devices, and rebuild the wallet from your backups. Then, when the day comes, moving your savings across is a routine job rather than a leap of faith. Members can keep every wallet, single-key or multisig, in view without touching a key through the Portfolio Tracker. More guides are in the Wallets and Custody hub.
Frequently asked questions
Is multisig safer than a hardware wallet?
They work together rather than compete. A hardware wallet protects one key by keeping it offline. Multisig changes the rules so that one key is never enough, which is why the strongest setup uses hardware wallets as the keys inside a multisig. That combination survives a stolen device, a lost backup and a flaw in one maker's firmware. A single hardware wallet survives the first two only.
What happens if I lose one key in a 2-of-3 multisig?
Nothing is lost, as long as you still have the other two keys and the wallet file. Use those two keys to move the coins to a fresh multisig with a new third key, then retire the old setup. Do it promptly, because until you do, you have no spare left. This is exactly the situation a 2-of-3 is designed to survive.
Do I need the wallet file as well as the recovery words?
On Bitcoin, yes. The wallet file, called the output descriptor, records every key's public half and the signing rule. Without it, two sets of recovery words cannot find the coins, because the wallet also depends on the third key. It cannot spend anything, so keep a copy with each set of words. On Ethereum, record your Safe's address and networks instead.
Is it safe to keep a multisig key on my phone?
Only as one key among several. A phone is connected to the internet, so treat that key as a hot key that could one day be compromised. In a 2-of-3 where the other two keys are on hardware wallets, a hacked phone alone still cannot move your coins. Never let the phone key be one of only two, and never keep its backup on the same phone.
Should a company hold one of my multisig keys?
We would not recommend it. If you choose to, it should only ever be one key out of three, with you holding the other two. Understand that the company can see your balance, holds your personal data, can refuse to co-sign and can change its terms or close. Keep the wallet file and practise recovering without them, so you can always leave.
Did multisig protect people in the Coldcard hack?
According to the advisories published by multisig providers between 31 July and 2 August 2026, yes. No losses were reported from multisig wallets where only one key came from an affected Coldcard, because one guessed key could not meet the threshold. Setups with two Coldcard keys were told to move their coins immediately. No independent chain analysis has yet broken losses down by wallet type.






