Your Multisig Is Only as Good as Its Recovery Plan

In this article:
If the company involved in your multisig disappeared tomorrow, could you still recover your Bitcoin?
For a surprising number of people, that question is harder than it should be. Multisig has become so closely associated with collaborative custody that many Bitcoin holders now assume the two are basically the same thing: you want multisig, so naturally you find a company, hand them one of the keys and let them help manage the arrangement. But that company is optional.
Multisig is a Bitcoin capability. Collaborative custody is a service built around it. In a conventional 2-of-3 setup, three keys are created and any two can authorize a transaction. Those three keys can all belong to you, stored on different hardware and stored in different places so that one lost key or compromised device doesn’t automatically decide the fate of your Bitcoin.
A collaborative custody provider takes that same underlying structure and becomes one of the participants. Perhaps you hold two keys and the provider holds the third. They may then help with setup, recovery, inheritance and ongoing support. Those services can be useful, and later we’ll look closely at what you receive in exchange for bringing that provider into the setup.

Bitcoin doesn’t know whether a key belongs to you, your spouse or a collaborative custody company. It only checks whether enough valid signatures have been provided. It’s easy to assume you’re still independent because you hold two keys while the provider holds only one. Two signatures are enough to spend. What could possibly go wrong?
Quite a lot, depending on the recovery path. Having enough keys to authorise a transaction and having everything you need to rebuild the wallet from scratch aren’t necessarily the same thing. You may still control two valid keys, but if the provider disappears you also need to know which keys belong together and how the wallet was originally set up. If you haven’t preserved that recovery information yourself, owning two keys may not make you as independent from the provider as you thought.

So before deciding whether collaborative multisig improves your security, there’s a more useful question. When one part of the setup fails, what still has to work for you to recover your Bitcoin?
Three Keys Only Help If They Fail Differently
Multisig gives you redundancy, but the number of keys only tells part of the story.
Imagine a 2-of-3 setup where all three keys were generated on hardware from the same manufacturer. At first glance, three separate devices can look reassuringly independent. But separation at the device level doesn’t guarantee separation underneath. If the same defect affects enough of them, the weakness has been duplicated along with the hardware, and the apparent redundancy starts looking rather less impressive.
The recent Coldcard incident gave that distinction some uncomfortable relevance. If enough keys in a multisig arrangement had been generated using affected Coldcard firmware, separating those keys across different devices wouldn’t remove the weakness they shared. You would have multiple signers, but they could still fail for the same reason.

Using hardware from different manufacturers can reduce that kind of correlated risk. In a 2-of-3 setup spread across three genuinely different devices, a vulnerability confined to one vendor shouldn’t be enough on its own to compromise the wallet. Apparently, buying the same thing three times isn’t quite the diversification strategy it sounds like. That’s one of the real strengths of a well-designed multisig setup. You can distribute signing authority across different hardware and avoid making the security of the entire wallet depend on one manufacturer getting everything right forever.
There is a trade-off. More moving parts create more opportunities for human error, and other dependencies can cut across the entire arrangement. Three recovery backups stored in the same drawer still have an awkward tendency to disappear together. Three independently generated keys can still depend on one person knowing how the whole arrangement is recovered. Different devices may also come with different backup and recovery procedures, which means a little more discipline is required to keep the setup understandable over time.

That doesn’t make multi-vendor multisig less secure. Done properly, it can be an extremely resilient way to hold Bitcoin. It simply means the extra protection comes with some extra complexity, which helps explain why some people eventually decide they’d rather have someone else help manage part of it.
Collaborative Custody Is a Trade, Not an Upgrade
The extra complexity of multisig helps explain why collaborative custody exists. Plenty of people like the resilience of a 2-of-3 setup but don’t particularly fancy becoming their own technical support department, inheritance planner and emergency recovery specialist at the same time. Fair enough. A good provider can guide the setup, hold a recovery key, help when something goes wrong and give your family someone competent to call if you’re no longer around. For the right person, that support can be worth every sat.
It also comes with terms. Exactly what those terms look like varies considerably. In some arrangements you keep enough keys to spend independently and receive the information needed to rebuild the wallet elsewhere. Others place more of the signing process in professional hands. Some providers require extensive identification, while others collect much less. Recovery procedures, waiting periods, account requirements and the circumstances in which a provider will supply its signature can all differ.

Then there are the fees. A fixed annual charge for ongoing support is easy enough to understand. Percentage-based pricing is a different animal. Some collaborative arrangements charge according to the size of your Bitcoin balance, and some can also attach an early termination fee calculated against that balance. One percent has a wonderfully harmless appearance when written with a small number and a % sign. It becomes rather more interesting as the stack grows. An exit charge based on the Bitcoin you’re trying to take with you adds another little flourish to the concept of financial independence.
That doesn’t mean the service has no value. Setup assistance, recovery support, inheritance planning and ongoing availability all require real time and expertise. The point is simply to understand the trade: you’re paying for support around the multisig, and in return you may accept recurring costs, identification, some loss of financial privacy, provider procedures and an ongoing commercial relationship. For some holders that’s worth it. Others may prefer to learn how to operate the same underlying structure independently.

There’s one trade-off that’s particularly easy to underestimate. A provider can give you a perfectly legitimate route to recover without them, complete with backups, configuration information and detailed instructions, while you remain completely unprepared to use any of it. If your recovery plan is essentially “I’ll call support”, the existence of a twenty-page recovery guide doesn’t make you independent. It means someone has thoughtfully documented the procedure you haven’t learned yet.
While your keys are intact and the support desk is answering, everything can feel reassuringly straightforward. The nastier scenario is the one worth planning for: the company disappears, the support desk goes with it, and then one of your own keys is lost. That’s when you find out whether you actually have a recovery plan, or just a phone number.

What Happens After You Lose One Key?
Here’s what that scenario actually does to a typical 2-of-3 arrangement. You hold keys A and B, while the provider holds key C. Before anything goes wrong, A and B give you the two signatures required to spend without involving the provider.
Then A is lost and the provider disappears. You’re left with B. The provider’s C may still exist somewhere in theory, but if the company is gone and nobody can access or use it, that doesn’t help you much. B is still your key. It’s still valid. It just can’t manufacture a second signature out of corporate insolvency. Unless A can be recovered or the setup includes another recovery route, you no longer have the two signatures Bitcoin requires.

Now change the scenario slightly. The provider disappears, but you still have both A and B. At first glance, that sounds fine: two keys, two signatures, problem solved. Perhaps. If the wallet is already open and working, the software already knows how the multisig was put together. You can use A and B to sign and move your Bitcoin without the provider.
But imagine the company is gone and the computer or app you used for the wallet is gone too. You’re starting again on a blank machine with your backups in front of you. Those backups can restore your signing keys, but the new software also needs to recreate the original multisig wallet. It needs the information required to recreate the same wallet: which keys belonged together, that it was a 2-of-3 arrangement and how it was originally constructed. If you preserved that configuration, you can rebuild the wallet elsewhere and carry on. If you didn’t, and no other copy of that information survives, your two seed backups alone aren’t enough to recreate the wallet. At that point recovery can become impossible, even though you still possess two valid signing keys.

That’s the difference between having enough keys to spend from a wallet that already exists and having everything required to recreate that wallet after the original setup has disappeared. It’s easy to miss because, while everything is working, the software handles most of that information for you.
A well-designed collaborative setup may give you all the recovery information you need and a clear route to use it elsewhere. Great. But the useful part isn’t that a PDF exists somewhere. It’s that you have your own copy, understand what it’s for and could actually use it when the provider, the app and the support desk are no longer available. Bitcoin will enforce the 2-of-3 rule exactly as designed. Corporate insolvency doesn’t lower the threshold to 1-of-3.
Judge the Setup by the Recovery Path
A custody setup shouldn’t be judged by how sophisticated it looks when everything is working. The more revealing test is what remains after something disappears.
A well-designed single-sig setup, with a strong passphrase and sound backup and recovery procedures, can be extremely robust. Sovereign multisig can distribute signing authority across different hardware and locations, reducing the damage one failure can cause. Collaborative custody can add experienced support, inheritance planning and another party able to help when things go wrong. Each can be a sensible choice when it matches the risks you’re actually trying to manage.

The useful exercise is to walk through the failures before they happen. If a device dies, what survives? If a backup is lost, can you still recover? If the computer holding the wallet disappears, do you have everything required to rebuild it elsewhere? And if a company sits anywhere in that recovery path, what happens if the company disappears too?
You don’t need a setup designed to survive every conceivable disaster short of civilization ending. You need one where the failures you’ve chosen to protect against are understood, the recovery information is actually in your possession and the people who may eventually need to use it aren’t discovering the plan for the first time during an emergency. That’s where multisig becomes genuinely powerful. It lets you distribute authority in ways single-key arrangements can’t. But adding keys, devices or professional signers only improves the outcome when you understand what each one is protecting you from and what happens when it’s no longer available.
Whether single sig is right for you today, you’re considering multisig, or you already use a more complex arrangement, we can help you work out what actually fits your situation. That might mean strengthening a single-sig setup, deciding whether multisig would meaningfully improve your security, choosing between sovereign and collaborative options, or pressure-testing an arrangement you already rely on. We’ll look at how signing authority is distributed, how recovery works, what information needs to be preserved and where dependencies could cause problems later.

Book a free 30-minute introductory call with one of our advisers and we’ll help you work out the right custody setup for where you are now and where you’re going next.