Bitcoin Forum
September 30, 2026, 04:47:02 PM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Bitcoin multisig setup  (Read 193 times)
entryway440187 (OP)
Newbie
*
Offline

Activity: 2
Merit: 0


View Profile
September 20, 2026, 12:08:18 PM
 #1

Dear fellow Bitcoiners,

I have a few BTC, just starting my journey (< 10k $). I do DCA on a regular basis, and expect my portfolio to grow. For the moment, everything is on a single Ledger wallet. I do have multiple backups. No worries here.

On the light of the Coldcard Exploit and the explosion of Physical Bitcoin Attacks, I strongly consider setting up a multisig wallet. I though of creating a 2/2 wallet with Sparrow Wallet, with one the wallets being my current Ledger device. The idea would be to store each wallet in a different physical location such as work or a bank safety deposit box (not the seedphrase though).

For the second one, I consider the Keycard Shell using the two cards (one card + one backup + seedphrase hidden somewhere). Another option would be the Trezor Safe 3 (or 5) Bitcoin-only. I consider the 7 overpriced for my usage.

What are your thoughts / experience on multisig with these devices ? 
Any comments/advice on this project ? 
Further, where would you safely store your seedphrases with a multisig wallet ?

Kinds regards
OmegaStarScream
Staff
Legendary
*
Offline

Activity: 4340
Merit: 7708



View Profile
September 20, 2026, 12:43:39 PM
Merited by Pmalek (3)
 #2

A single wallet key (a Trezor safe 5) with a passphrase would be more than enough in my opinion.

If the goal is to protect yourself from wrench attacks, a multisig setup sound like it would be more suspicious and harmful compared to having a standard wallet with some funds in it (as a decoy) while the large amount sits in the wallet with the passphrase.

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
█████▀██████████████▀█████
████████▄▄██████▄▄████▀███

██████████████████████████
██▄▄██████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
███▄████▀▀██████▀▀████████
█████▄██████████████▄█████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
██████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀█▄
▄██▀█▄██
█████▀▀█
████████
████████
▀██▄████
▄████▄▄█
▄█████▀███
▄█████▀████▀
█████▀███████
▀██▀█████████
|..BTC......XMR...
..USDT.....LTC...
....Fees  0.8%.....
entryway440187 (OP)
Newbie
*
Offline

Activity: 2
Merit: 0


View Profile
September 20, 2026, 01:51:29 PM
 #3

I get your point. Here is my view, however :
  • 5$ wrench attack : passphrase => you can be forced to give out your passphrase, multisig => you cannot unlock your funds without multiple keys which may be kilometers away (or not even in your possession)
  • single vendor => an attacker (up to with physical access) only has to compromise one device, multi vendor => multiple devices
  • And for the decoy wallet, if the attacker manage to find your main wallet adress / amount or just the fact you bought several devices (e.g. through data breaches from third party), you are screwed
RGBTC
Legendary
*
Offline

Activity: 2800
Merit: 1149


Vega.Bet


View Profile WWW
September 22, 2026, 08:34:56 AM
 #4

And for the decoy wallet, if the attacker manage to find your main wallet adress / amount
How often do you intend to access your primary wallet? A general security recommendation is that the less frequently you access it, the lower the risk of exposing your wallet to danger.

Quote
or just the fact you bought several devices (e.g. through data breaches from third party), you are screwed
I believe the idea is not to involve multiple separate devices, but each device or mnemonic phrase setup has a "decoy" version. You fund the wallet derived from the mnemonic phrase plus a passphrase, with your main holdings; while the wallet using the same mnemonic phrase without the passphrase holds only a small amount. This method is intended to work if an attacker assumes the decoy wallet is where you keep your primary assets.

.◼.◼.Vega.bet.◼.◼.██
██
██
██
██
██
██
██
██
██
██
██
██

...100 FS + 750% BONUS..MAX.WIN.$5,000...

███...FAST PAYOUTS  |  NO KYC  |  10% LOSSBACK...███
██
██
██
██
██
██
██
██
██
██
██
██
██

...Play Now...
OmegaStarScream
Staff
Legendary
*
Offline

Activity: 4340
Merit: 7708



View Profile
September 22, 2026, 08:56:10 AM
 #5

I get your point. Here is my view, however :
  • 5$ wrench attack : passphrase => you can be forced to give out your passphrase, multisig => you cannot unlock your funds without multiple keys which may be kilometers away (or not even in your possession)

-snip-

You may not be able to access the second device, but that does ont mean that the attacker would leave you alone. IMO, a multisig setup screams "I have good amount of money" more than a standard wallet does.

You also said "you are forced to give your passphrase". But how would the attacker know you have a passphrase? That's the whole point from having the decoy wallet.

You would basically have two wallets:

- Seedphrase ---> load it with let's say 10% of what you own.
- Seedphrase+ passphrase --> the rest (90%).

If you're forced to give anything, you should give your original seedphrase. I don't see why would the attacker instantly think "he must have a another wallet with a passphrase" unless of course, the attacker knows you personally (IRL or online), and you do talk about your setup often.

▄▄████████████████████▄▄
▄███████▀▀██████▀▀███████▄
█████▀██████████████▀█████
████████▄▄██████▄▄████▀███

██████████████████████████
██▄▄██████████████▄▄██████
██▀▀██████████████████▄▄██
██████▀▀██████████████▀▀██
██████████████████████████
███▄████▀▀██████▀▀████████
█████▄██████████████▄█████
▀███████▄▄██████▄▄███████▀
▀▀████████████████████▀▀
 
 DΞX.fo 
▄▄██████
█████████
██████████
██████████
██████████
█████████
▀▀██████

▄███████
▄██████████
████████████
█████████████
█████████████
|
▄▄█
▄████▀
▄███▀█▄
▄██▀█▄██
█████▀▀█
████████
████████
▀██▄████
▄████▄▄█
▄█████▀███
▄█████▀████▀
█████▀███████
▀██▀█████████
|..BTC......XMR...
..USDT.....LTC...
....Fees  0.8%.....
Lucius
Legendary
*
Offline

Activity: 4102
Merit: 7825


A swap that needs a hand? zeto.cash@proton.me


View Profile WWW
September 22, 2026, 02:05:32 PM
Merited by BlackHatCoiner (4), DYING_S0UL (1)
 #6

Dear fellow Bitcoiners,

I have a few BTC, just starting my journey (< 10k $). I do DCA on a regular basis, and expect my portfolio to grow. For the moment,
everything is on a single Ledger wallet. I do have multiple backups. No worries here.
~snip~

It seems that you are not aware of the extremely bad reputation of the company whose HW you use. In addition to multiple leaks of their users' databases (including names, addresses and phone numbers), in the end they decided to allow users to share their seed (remotely) with third parties (this option is paid for).

The very fact that the seed can be extracted remotely is a big red flag, but obviously not for all users.

dkbit98
Legendary
*
Offline

Activity: 3094
Merit: 8888



View Profile WWW
September 22, 2026, 10:53:45 PM
 #7

For the second one, I consider the Keycard Shell using the two cards (one card + one backup + seedphrase hidden somewhere). Another option would be the Trezor Safe 3 (or 5) Bitcoin-only. I consider the 7 overpriced for my usage.
Keycard Shell is not a bad choice, it's open source and I really like their approach with removable cards.
As alternative you can also consider Seedsigner device, that can also work with cards and combined with Satochip cards.
Satochip cards can also be used as standalone, or used for multisig setup, and Trezor is reliable and first company that created hardware wallets.
Whatever you choose I would prefer buying everything locally in physical shops, to avoid potential leak of personal information.

▄▄██████▄░░░▄██████▄▄
██▀▀░░░░▀░░░░░▀░░░░▀▀██
▄▄██████▄░▄██████▄▄
▄████▀▀▀▀█████▀▀▀▀████▄
▄███░░░▄▄░░░█░░░▄▄░░░███▄
▄▄▄███░░░░██░░░░░░░██░░░░███▄▄▄
████████░░░░██░░░░░░░██░░░░████████
██████████░░░▀▀░░░█░░░▀▀░░░██████████
████▀▀██████▄▄▄▄█████▄▄▄▄██████▀▀████
▀███▄░░▀▀███████████████████▀▀░░▄███▀
▀████▄▄░░░░▀▀▀▀▀▀▀▀▀▀▀▀▀░░░░▄▄████▀
▀███████▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄███████▀
▀▀█████████████████████▀▀
  
OrangeFren
  
██
██
██
██
██
██
██
██
██
██
██
  
▄▄█████▄▄
▄████▀▀▀████▄
███▀░░░░░░░▀███
███▀░░░▄█░░░░▀███
███░░░░░█░░░░░███
███▄░░░▄█▄░░░▄███
███▄░░░░░░░▄███
▀████▄▄▄████▀
█████████
▐█████████▌
█████░█████
▐████▌░▐████▌
▀▀░▀█░░░█▀░▀▀
 
Pmalek
Legendary
*
Offline

Activity: 3626
Merit: 9591


View Profile
September 25, 2026, 04:42:45 PM
 #8

I get your point. Here is my view, however :
  • 5$ wrench attack : passphrase => you can be forced to give out your passphrase, multisig => you cannot unlock your funds without multiple keys which may be kilometers away (or not even in your possession)
  • single vendor => an attacker (up to with physical access) only has to compromise one device, multi vendor => multiple devices
  • And for the decoy wallet, if the attacker manage to find your main wallet adress / amount or just the fact you bought several devices (e.g. through data breaches from third party), you are screwed
I have always considered multisig to be kind of an overkill. I agree with OmegaStarScream when he says that a seed phrase (of 24 words) coupled with one or more long and complex passphrases should be enough for most people.

When it comes to protecting yourself from $5 wrench attacks, your priority is to not have other people know or find about your bitcoin wealth. Keep it private. It should never become a topic of discussion where others can hear about it. If it comes to that, I think you could be in more danger with a multisig setup and keys stored in different geographical locations than with a seed + passphrases.

Let me explain why. The thief wants to rob you. He wants a financial reward. He may not believe you if you say that you can't give him what he is looking for because the other seed is located 40km away. He may not care. He may become even more angry and frustrated that he is not getting what he wants to the point that he hurts you more than he intended. And you wouldn't want that to happen.

But if you are protected with multiple passphrases, you could give the attacker access to the one that holds some of your coins, while the majority of your stash is tucked away behind a different passphrase. The thief can't know that you have multiple passphrases unless you told someone exactly how you store your coins and how much you have. That's why I said that your priority is to keep your wealth a private matter.
BlackHatCoiner
Legendary
*
Offline

Activity: 2156
Merit: 10136


A swap that needs a hand? zeto.cash@proton.me


View Profile
September 25, 2026, 05:03:01 PM
 #9

5$ wrench attack : passphrase => you can be forced to give out your passphrase
Another thing you need to know about the passphrase is that, unless it is super strong, it can be cracked. And usually, whatever passphrase you can memorize is not strong enough. A 2-of-2 multi-sig is another way of having a passphrase but being sure the passphrase is secure.

Also, as Lucius said, I'd stay 100 miles away from Ledger wallet. It's probably the last wallet I'd choose after Coldcard. Ever since I joined Bitcoin, I consider it the most suspicious one.

Lucius
Legendary
*
Offline

Activity: 4102
Merit: 7825


A swap that needs a hand? zeto.cash@proton.me


View Profile WWW
September 26, 2026, 12:48:26 PM
 #10

~snip~
Also, as Lucius said, I'd stay 100 miles away from Ledger wallet. It's probably the last wallet I'd choose after Coldcard. Ever since I joined Bitcoin, I consider it the most suspicious one.


Just imagine that after so many scandals coming from that company, probably hundreds of thousands of people are still using their devices. I don't want to use a stronger word, but to me that's complete madness.

I had no doubts at the beginning and I bought their devices, but I must admit that they deeply disappointed me, not so much perhaps with what happened, but with their reaction after everything.

BlackHatCoiner
Legendary
*
Offline

Activity: 2156
Merit: 10136


A swap that needs a hand? zeto.cash@proton.me


View Profile
September 27, 2026, 09:01:21 AM
 #11

Just imagine that after so many scandals coming from that company, probably hundreds of thousands of people are still using their devices. I don't want to use a stronger word, but to me that's complete madness.
It is complete madness. What's even crazier is trusting the device after all these incidents, and after the fact that the code is not open-source. Rapid AI development asides, why would you use a Bitcoin wallet that does not allow for public scrutiny? Is it truly self-custodial if nobody apart from the company can prove it?

I haven't yet understood about the seed phrase thing. Can they actually recover your seed if you lose it? Sounds like a custodial wallet.  Cheesy

Lucius
Legendary
*
Offline

Activity: 4102
Merit: 7825


A swap that needs a hand? zeto.cash@proton.me


View Profile WWW
September 27, 2026, 11:12:45 AM
 #12

~snip~
I haven't yet understood about the seed phrase thing. Can they actually recover your seed if you lose it? Sounds like a custodial wallet.  Cheesy


Is it possible you missed this topic? -> https://bitcointalk.org/index.php?topic=5452900.0 (Ledger Recovery - Send your (encrypted) recovery phrase to 3rd parties entities)

The service is obviously aimed at those who do not understand the concept of "not your keys, not your coins" or those who simply do not care that they use a hardware wallet from which it is possible to extract seed remotely. They believe that recovery only refers to voluntary consent to do so, and not that it is possible to extract every generated seed from every device. The fact that Ledger previously claimed it wasn't possible and then suddenly it became possible speaks for itself.

In today's time when AI is getting more advanced day by day, it is not impossible that someone will find a way to hack Ledger Recovery and make the coldcard case look ridiculous.

m2017
Legendary
*
Offline

Activity: 2618
Merit: 1737


keep walking, Johnnie


View Profile
September 29, 2026, 06:12:08 AM
 #13

I have a few BTC, just starting my journey (< 10k $). I do DCA on a regular basis, and expect my portfolio to grow. For the moment, everything is on a single Ledger wallet. I do have multiple backups. No worries here.
That is precisely the cause for concern. How would backups help you if Ledger wallet were compromised? For instance, it has a questionable Ledger Recovery feature, and the source code is closed (who knows what backdoors might be in that code or who could exploit them - hackers or the employees themselves).

On the light of the Coldcard Exploit and the explosion of Physical Bitcoin Attacks, I strongly consider setting up a multisig wallet. I though of creating a 2/2 wallet with Sparrow Wallet, with one the wallets being my current Ledger device. The idea would be to store each wallet in a different physical location such as work or a bank safety deposit box (not the seedphrase though).
In my view, it is essential to keep the hardware wallet close at hand, as you might need it (buying, selling, unforeseen expenses). After all, would you really go to the bank just to retrieve this HW device (for the sake of a couple of transactions)? You can store the seed phrase (split into several parts) at a bank, or elsewhere, for long-term safekeeping, since under normal circumstances, you might only need those keys once or twice in your lifetime.


A single wallet key (a Trezor safe 5) with a passphrase would be more than enough in my opinion.

If the goal is to protect yourself from wrench attacks, a multisig setup sound like it would be more suspicious and harmful compared to having a standard wallet with some funds in it (as a decoy) while the large amount sits in the wallet with the passphrase.
Multisig doesn't protect against torture (inflicted on the victim or their loved ones). Therefore, if the OP insists, one could have 2 hardware wallet setups. The 1st device (a decoy) would hold a small amount of funds in both the main and hidden wallets (why does everyone assume attackers wouldn't know about hidden wallets? Especially when the topic is discussed publicly). The 2nd device would be used in a multisig configuration if the OP specifically wants that functionality. Alternatively, one could simply use a separat HW device + a passphrase to store the main balance.


I get your point. Here is my view, however :
  • 5$ wrench attack : passphrase => you can be forced to give out your passphrase, multisig => you cannot unlock your funds without multiple keys which may be kilometers away (or not even in your possession)
But that doesn't stop them from hurting you (repeatedly) while you travel miles to retrieve those multisig keys. Then again, few robbers are "disfigured" by an excess of intellect; they might simply be unaware of multisig (or how it works) and could try to "very insistently persuade" you (using a $5 wrench) to hand over those keys (something impossible to carry out). Is that something you really want? How long will you be able to endure it?

  • single vendor => an attacker (up to with physical access) only has to compromise one device, multi vendor => multiple devices
Yes, using hardware wallets from different manufacturers looks like risk diversification. However, it also doubles the risks mention below.

  • And for the decoy wallet, if the attacker manage to find your main wallet adress / amount or just the fact you bought several devices (e.g. through data breaches from third party), you are screwed
Therefore, shouldn't keep all your crypto at a single address. What’s stopping from splitting them up? It is advisable to use varying amounts and intervals, and even to add intermediate addresses and transactions to slightly obscure the trail.

I doubt that attackers would go to such lengths and analyzing the specific HW devices you purchased (and the quantities involved). Unless, of course, you manage to get them really interested. However, if you own hardware wallet from various manufacturers, the likelihood of a leak increases in proportion to the number of HW devices you possess.

Purchase HW devices discreetly, for example, from local authorized vendors, to avoid leaving a "digital footprint" (but without forgetting that there are already counterfeits capable of emptying your wallet). Alternatively, wait for the rollout of the hidden purchase feature currently being developed by Trezor.


I don't see why would the attacker instantly think "he must have a another wallet with a passphrase" unless of course, the attacker knows you personally (IRL or online), and you do talk about your setup often.
Because the guys on bitcointalk were discussing it. Smiley And he’ll think, "You know what? Just to be safe, let’s torture the victim a bit more - maybe he’ll confess to having a 2d wallet with a hidden passphrase".

There is no "hidden from the bad guys" filter on this forum.

satscraper
Legendary
*
Offline

Activity: 1596
Merit: 3012



View Profile
Today at 12:42:56 PM
 #14

I get your point. Here is my view, however :
  • 5$ wrench attack : passphrase => you can be forced to give out your passphrase, multisig => you cannot unlock your funds without multiple keys which may be kilometers away (or not even in your possession)
  • single vendor => an attacker (up to with physical access) only has to compromise one device, multi vendor => multiple devices
  • And for the decoy wallet, if the attacker manage to find your main wallet adress / amount or just the fact you bought several devices (e.g. through data breaches from third party), you are screwed
I have always considered multisig to be kind of an overkill.


Generally agreed, but in some cases multisig may help a lot.

Consider the case when someone completely lost their memory due to some accident. If they were smart enough to create a decaying multisig like 2-of-3 which decays to 1-of-3 after a certain condition is met, and one of those 3 keys was controlled by their heir, the relevant stash could never be lost.

Sure, such case is an edge one, but it may happen to virtually anyone.

▄▄███████████████████▄▄
▄███████████████████████▄
███████████████████▄█████
█████████████████████████
███████████▀█████████████
█████████▀███▀██████▀████
██████████████████▄██████
█████████▄▄█▄▄███████████
██████████▄▄▄████████████
███████████████████▀█████
████████████████▀▀███████
▀███████████████████████▀
▀▀███████████████████▀▀
 
 EARNBET 
██
██
██
██
██
██
██
██
██
██
██
██
██
███████▄▄███████████
████▄██████████████████
██▄▀▀███████████████▀▀███
█▄████████████████████████
▄▄████████▀▀▀▀▀████████▄▄██
███████████████████████████
█████████▌████▀████████████
███████████████████████████
▀▀███████▄▄▄▄▄█████████▀▀██
█▀█████████████████████▀██
██▀▄▄███████████████▄▄███
████▀██████████████████
███████▀▀███████████
██
██
██
██
██
██
██
██
██
██
██
██
██


▄▄▄
▄▄▄███████▐███▌███████▄▄▄
█████████████████████████
▀████▄▄▄███████▄▄▄████▀
█████████████████████
▐███████████████████▌
███████████████████
███████████████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

 King of The Castle 
 $200,000 in prizes
██
██
██
██
██
██
██
██
██
██
██
██
██

 62.5% 

 
RAKEBACK
BONUS
Pmalek
Legendary
*
Offline

Activity: 3626
Merit: 9591


View Profile
Today at 04:27:58 PM
 #15

Generally agreed, but in some cases multisig may help a lot.

Consider the case when someone completely lost their memory due to some accident. If they were smart enough to create a decaying multisig like 2-of-3 which decays to 1-of-3 after a certain condition is met, and one of those 3 keys was controlled by their heir, the relevant stash could never be lost.

Sure, such case is an edge one, but it may happen to virtually anyone.
You would get the same result if your heir has a copy or inherits a standard singlesig wallet (with or without a passphrase) after your death. One difference being that if they have the seed (and passphrase), they could spend your coins at anytime. The same thing applies if a 2-of-3 multisig decays and becomes 1-of-3. The original multisig decayed and effectively became a singlesig wallet, not counting the master public keys. I don't know if you still need the master public keys for decaying multisig setups. Probably not.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!