I have a few BTC, just starting my journey (< 10k $). I do DCA on a regular basis, and expect my portfolio to grow. For the moment, everything is on a single Ledger wallet. I do have multiple backups. No worries here.
That is precisely the cause for concern. How would backups help you if Ledger wallet were compromised? For instance, it has a questionable Ledger Recovery feature, and the source code is closed (who knows what backdoors might be in that code or who could exploit them - hackers or the employees themselves).
On the light of the
Coldcard Exploit and the explosion of
Physical Bitcoin Attacks, I strongly consider setting up a multisig wallet. I though of creating a 2/2 wallet with Sparrow Wallet, with one the wallets being my current Ledger device.
The idea would be to store each wallet in a different physical location such as work or a bank safety deposit box (not the seedphrase though).
In my view, it is essential to keep the hardware wallet close at hand, as you might need it (buying, selling, unforeseen expenses). After all, would you really go to the bank just to retrieve this HW device (for the sake of a couple of transactions)? You can store the seed phrase (split into several parts) at a bank, or elsewhere, for long-term safekeeping, since under normal circumstances, you might only need those keys once or twice in your lifetime.
A single wallet key (a Trezor safe 5) with a passphrase would be more than enough in my opinion.
If the goal is to protect yourself from wrench attacks, a multisig setup sound like it would be more suspicious and harmful compared to having a standard wallet with some funds in it (as a decoy) while the large amount sits in the wallet with the passphrase.
Multisig doesn't protect against torture (inflicted on the victim or their loved ones). Therefore, if the OP insists, one could have 2 hardware wallet setups. The 1st device (a decoy) would hold a small amount of funds in both the main and hidden wallets (why does everyone assume attackers wouldn't know about hidden wallets? Especially when the topic is discussed publicly). The 2nd device would be used in a multisig configuration if the OP specifically wants that functionality. Alternatively, one could simply use a separat HW device + a passphrase to store the main balance.
I get your point. Here is my view, however :
- 5$ wrench attack : passphrase => you can be forced to give out your passphrase, multisig => you cannot unlock your funds without multiple keys which may be kilometers away (or not even in your possession)
But that doesn't stop them from hurting you (repeatedly) while you travel miles to retrieve those multisig keys. Then again, few robbers are "disfigured" by an excess of intellect; they might simply be unaware of multisig (or how it works) and could try to "very insistently persuade" you (using a $5 wrench) to hand over those keys (something impossible to carry out). Is that something you really want? How long will you be able to endure it?
- single vendor => an attacker (up to with physical access) only has to compromise one device, multi vendor => multiple devices
Yes, using hardware wallets from different manufacturers looks like risk diversification. However, it also doubles the risks mention below.
- And for the decoy wallet, if the attacker manage to find your main wallet adress / amount or just the fact you bought several devices (e.g. through data breaches from third party), you are screwed
Therefore, shouldn't keep all your crypto at a single address. What’s stopping from splitting them up? It is advisable to use varying amounts and intervals, and even to add intermediate addresses and transactions to slightly obscure the trail.
I doubt that attackers would go to such lengths and analyzing the specific HW devices you purchased (and the quantities involved). Unless, of course, you manage to get them really interested. However, if you own hardware wallet from various manufacturers, the likelihood of a leak increases in proportion to the number of HW devices you possess.
Purchase HW devices discreetly, for example, from local authorized vendors, to avoid leaving a "digital footprint" (but without forgetting that there are already counterfeits capable of emptying your wallet). Alternatively, wait for the rollout of the hidden purchase feature currently being developed by Trezor.
I don't see why would the attacker instantly think "he must have a another wallet with a passphrase" unless of course, the attacker knows you personally (IRL or online), and you do talk about your setup often.
Because the guys on bitcointalk were discussing it.

And he’ll think, "You know what? Just to be safe, let’s torture the victim a bit more - maybe he’ll confess to having a 2d wallet with a hidden passphrase".
There is no "hidden from the bad guys" filter on this forum.