Best Practices for Setting Up a Secure Multisig Wallet

best practices for multisig

✓ Top answer Community-sourced, written up by
Best Practices for Setting Up a Secure Multisig Wallet

To set up a multisig wallet securely, you should distribute your keys geographically, use hardware wallets from different vendors, and back up your wallet descriptor and public keys. Users emphasize careful planning to avoid losing funds due to the complexity of the setup.

A 2-of-3 setup is recommended over a 2-of-2 configuration for individuals. If one key is compromised or lost in a 2-of-3 arrangement, you can still access your funds using the remaining two keys and move them to a new wallet.

You must store the descriptor file at each backup location because recovering funds requires both the private keys and all public keys. Practicing recovery drills and sharing the recovery process with trusted family members will prevent permanent loss of funds.

key steps

  1. Distribute keys geographically Store each key and its backup in different physical locations to prevent a single point of failure.
  2. Use a 2-of-3 setup Avoid 2-of-2 for individuals so losing one key does not lock you out of your funds.
  3. Back up descriptors and public keys Keep the descriptor file at each backup location to ensure you can recover the wallet.
  4. Mix hardware vendors Use wallets from different manufacturers to protect against single vendor vulnerabilities.
  5. Practice recovery drills Simulate losing a key and spending with the remaining keys to ensure you understand the process.
  6. Share recovery knowledge Teach trusted family members how to recover the wallet to prevent loss of funds after your death.
Best Practices for Setting Up a Secure Multisig Wallet — infographic

Key Management and Distribution

Geographical separation is crucial for keys and backups. Store each key and its backup in different physical locations to prevent a single point of failure. "Geographically distribute keys and backups across a variety of physical security setups."
Avoid 2-of-2 multisig for individuals. While it works for joint owners, a 2-of-2 setup for a single person means losing one key locks you out, negating a core benefit of multisig. "2 of 2 multisig provides no value for an individual."
Consider a 2-of-3 or higher setup. If one key is compromised or lost, you can still access funds with the remaining keys, allowing you to move funds to a new, secure wallet. "In a 2-of-3 setup, if one seed is compromised, it doesn't matter. You ignore the compromised key entirely, use your other two safe devices, and move your funds to a new wallet cleanly and safely without a race."

Wallet Descriptors and Public Keys

Back up your wallet descriptor and all public keys. Losing this information can prevent you from recovering your multisig wallet, even if you have the private keys. "Biggest pitfall of multisig, to spend from an m of n wallet, you need m private keys and all n public keys (plus a passphrase, if you set one up)."
Store descriptor files with each key/backup. This ensures that all necessary information for recovery is available, regardless of which key set is being used. "You would want the descriptor file at each location."
Understand that public keys are not secret but are vital for privacy. While a compromised public key doesn't lead to fund loss, it can reveal your balance and transaction history. "If your xpub gets compromised, you lose privacy of your transactions, but you do not lost your money."

Hardware and Software Choices

Use hardware wallets from different vendors. This protects against vulnerabilities specific to a single manufacturer. "Multisig using wallets from different vendors solves this. An attacker would need to exploit two wallet models at the same time before you move your funds."
Sparrow and Nunchuk are popular software coordinators. Users often recommend these for managing multisig setups due to their features and user experience. "Sparrow: Excellent desktop coordinator for DIY multisig. Clear coin control, PSBT flow, descriptor exports, robust labeling. Great for power users on Bitcoin."
A strong passphrase can enhance security for single-sig wallets. For those who find multisig too complex, a robust passphrase adds a significant layer of protection. "A strong passphrase is enough protection for most people."

Operational Considerations

Practice recovery drills. Simulate losing keys and performing transactions to ensure you understand the process and can execute it under pressure. "Practice 'worst day' drills: simulate loss of one key and spend with the remaining two."
Keep recovery instructions clear and share knowledge. Ensure trusted family members or heirs understand the setup and recovery process to prevent funds from being lost after your death. "Your spouse and at least one trusted family member or friend should learn the basics with you — not just where the backups are, but how to recover the wallet if something ever happens to you."

Are you considering setting up a multisig wallet for personal use or for a shared fund?

Bottom line

To set up multisig securely, distribute keys geographically, use multiple hardware wallet vendors, and back up your wallet descriptor and public keys alongside your seed phrases. Multisig can be complex, and Users emphasize careful planning and understanding to avoid losing funds.

Community answers 28

What others in the community said:

88% upvoted

I’m exploring way to upgrade my security from a single Ledger hardware wallet (HW) to a 2/3 multisig setup.

What’s the minimum requirement for HW? Correct me if i’m wrong, but i shouldn’t need 3 physical HWs, should I?. Instead, i can set one wallet with one seed phrase at a time, then partially sign a transaction. Then reset HW and do it again with the 2nd or 3rd seed phrase to sign as the 2nd or 3rd co-signer. If that’s true, I think 2 HW devices (ie. 1 Ledger and 1 Jade) are minimum requirements for a good setup. 2 HWs instead of 1 for multi-vendor reason. Do I miss anything important with this setup? Instead of having a 3rd HW in a remote place and never need it except for possibly recovery, it’s cheaper and less maintenance to do away with HW and just safeguard the 3rd seed phrase (and its backup) instead.

Maybe there’s a flaw in this reasoning somewhere. I wonder why i haven’t found any discussion of this setup!?

Also regarding the recovery of a non-custodial 2/3 multisig wallet, what are the minimum pieces of secrets needed for recovery? I read that 2 seed phrases are enough to sign a spend transaction, but having those 2 only are not enough to recover your multisig wallet. What else does one need as a minimum requirement to recovery?

Please point me to a good guide for best practices. Unchained has good articles but more focus on custodial multisig.

TIA 🙏

79% upvoted

I see alot of posts worried about different wallets. Just get multi sig. Its really not hard at all. Just spend some weeks learning about it. I learned it in one day, but i do know alot about hard ware wallets already, so I had a leg up. That being said a person who does not know much can seriously learn and be very comfortable with multi sig in about a week. I put it off because I heard it was too technical. I was totally wrong and would have been fine during the cold card incident. I didnt lose anything "Thank God" but it was alot of stress that I could have avoided by multi sig. So just learn it, you can even use your cold card with it "with dice rolls" and be almost 100% certain your crypto will be fine. Seed storage also feels amazing. Safety deposit box has 2, 2 more are in another place. 3/4 multi so i mo longer worry about someone finding my seeds and will never again worry about a "bug" in a hardware wallet.

Biggest pitfall of multisig, to spend from an m of n wallet, you need m private keys and all n public keys (plus a passphrase, if you set one up). People think, oh, as long as I have m keys I'm good, many have lost money that way.

90% upvoted

I am trying to get my head around multisig today (long overdue) and my understanding is that if you are using multi-sig with "2 of 3" or "3 of 5", every time you need to have the multiple devices on hand PLUS their respective passphrases correctly entered to unlock your multiple devices.

My question is, is multisig + passphrase(s) overkill? unnecessary complexity?
Is multisig good enough on it's own?

I've been single sig + pin for years and it "just works".

Maxis on twitter are all screaming "multisig" but no one is really saying how to roll it cleanly without screwing yourself out of life savings.

Electrum or sparrow on desktop? And all devices have to be 24 word? (or 25 with passphrase)?

Who has the best guide (vendor agnostic) for setting up multisig without needing a specialist degree in cryptography?

89% upvoted

It does look like multi-sig is the only way out. I’d say a 3/5 or a n-n with multiple hardware wallets. I know it’s over engineering but it’s more secure and less vulnerable to the CC fiasco. The only downside I am seeing is the multiple seeds and keeping in keeping in tabs with it every couple of months or so.

80% upvoted

Personal wallet compromises doubled in 2025 compared with the previous high year, targeting higher-value holders, highlighting why multisig should be the new norm for asset security.

We’ve been building a new multisig based treasury tool that lets teams and individuals to:

  • Manage assets across Solana, EVM, and Cosmos using a single team setup for all chains
  • Avoid juggling different multisigs, wallet setups, or approval processes on each chain.
  • Execute parallel transactions on different chains using only one signature.
  • Operate private treasury setups that prevent balance and activity tracking from the public. You can send and receive assets as usual, while we break the on-chain link between senders and final recipients.

Open for discussions and feedbacks, and we’re inviting a small number of teams to try the MVP and see if it fits their workflows.

If anyone interested and want to see how it works, you can join the waitlist here 

73% upvoted

I’ve been a Bitcoiner since 2017 and recently got married, which made me rethink how I store Bitcoin for the very long term (and eventually for my future family).

I’ve been trying to set up a clean, reliable 2-of-3 multisig using Sparrow/Electrum + hardware wallets, but the whole process still feels:
– too technical and easy to mess up
– fragmented across multiple apps
– hard to explain to a non-technical spouse or heir
– stressful when thinking about backups and inheritance

I also looked at Casa, Unchained, Nunchuk — great tools — but each has limitations for my situation (EU-based, prefer holding all keys myself, want a simple and clear inheritance workflow).

I’m a software developer, and because nothing fully fit my needs, I started tinkering with a small prototype on testnet just to improve my own setup. Nothing public, no launch or anything — just trying to solve my personal workflow first.

My question:
Do you think there are still gaps in multisig + inheritance tools?
Are current solutions “good enough,” or do you also feel like something is still missing in terms of simplicity or clarity?

I’m trying to understand whether my struggle is unique or if other long-term holders run into the same issues.

Would appreciate any experiences or thoughts from people who’ve gone through this process.

I was against creating a multisig setup simply due to operational complexity and if I am handing this off to my wife I am not full confident I could do so in a way she would be able to recover it. I wish I could find the source for this information but in my initial research these are notes that I took down and copied from somewhere. I am definitely going to move to a multisig setup and drill it into her every quarter going forward in light of this issue.

I do have a feeling these were comments that I saved and copied from users comments...wisdom of the users hive mind

You have to backup :

All of your private 12-24 words mnemonics AND All of your cosigners' XPUBs

Ideally your multisig wallet descriptor (wallets like Specter can export this as a .PDF for you) - essentially your multisig derivation path + all of the cosigners' XPUBs

Never upload your private 12-24 word mnemonics to the cloud or even type them into your PC/phone password manager or email or photo roll. These must never exist in digital form outside of your hardware wallet.

Never enter your private 12-24 words into your phone or PC to recover, even if you get an email claiming your hardware wallet is corrupted, click on this link and enter your mnemonic words into your web browser to restore your hardware wallet.

Optionally you could store your XPUBs (you need all of them), or your wallet file (electrum, sparrow, specter), or your Specter wallet descriptor backup PDF on the cloud. An thief with access to your cloud will know your multisig wallet balance, but they won't be able to steal your coins.

Well, remember what you need for single sig:

  • Private key (encoded as a seed phrase)
  • Derivation path
  • Script type (Legacy address? Segwit address? Taproot address?)

So now, here's what you need for multi-sig:

  • Private keys (encoded as seed phrases)
  • Derivation path
  • Script type (Segwit address? Taproot address?)
  • XPub

Now private keys need to be secret, Derivation paths and script types can be completely public, and xpubs will reveal how many coins you have on all your addresses, but won't result in a loss of funds. Plan appropriately.

Now, Liana wallet is a neat tool for thinking about multi-sig setups, so I'll get you that link:

However, if we did the classic multi-sig, here's what I think we would do.

First, we need to think about why we're doing multi-sig. A great guide on thinking about why you want each type of security measure is glacier protocol:

So each private key is not going to be located in the same building as another private key in this set up. If it were me, I would keep the derivation paths, script type, and xpubs in their entirety with each and every private key storage location. That way, our backups work the way we're expecting them to work (Lose one private key, you can still spend)

Is it best practice in that case to store your multi sig wallet file on the cloud so you can access the file on a new computer, thus still accessing the money?

There's a config file you can download, the wallet software should have an option to create this for you somewhere. If I remember right, it's called the wallets "descriptors". Search online, double check the details you need to save. It includes all 3 wallets xpubs, derivation paths, fingerprints, etc. It's also a good idea to record the first 5 addresses of this multisig wallet so you can be sure you've restored the correct wallet in future.

I wouldn't say there's a best practice for where to store the setup/descriptors. No one can access your funds with these details but they can probably see some balances. If you want it offline then carefully write it down or print it off. Do a test restore.

Rebuilding the wallet: You need all three xpubs to rebuild the wallet in a new software, even if you have 2 of 3 working keys.

Do not forget this, keep a copy of the entire wallet setup details with each seed if you are storing seeds in different locations.

And if one hardware wallet breaks, my initial thought would be to but another 3rd one, set up a new multi sig adress and then make a transaction with the remaining 2 from the old set up. Or should I restore the current wallet and just add the new hardware device?

In the case of a lost/damaged wallet and it's seed is lost. You would use the 2 remaining keys you have to sign a txn that moves the funds to your brand new multisig wallet.

Some wallet software shows a "swap" option that makes it look like you can add a new signer into an existing multisig but it will create a brand new wallet, it won't just "swap" a key in your existing wallet. So you'll need to print or save the new config files etc for this too.

If it's just the hardware that's damaged and you have the seed for it still, as above, just replace the hardware with the damaged wallet's seed. As long as you have the seeds and wallet "descriptors" you can use pretty much any hardware wallet.

If you are going multisig anyway. I would make 3 wallets and make it a 2 out of 3.

2 out of 2 setup with 2 passphrases as well leaves zero room for human error, physical damage, or forgotten passphrases. Is just one of these four parts lost, your crypto is locked for ever. Unlike a 2 out of 3 multisig where you can lose a seed or a passphrase and still access your crypto.

I would just buy a Trezor Safe 3 at $47 and get all that extra security if you are going through the extra work of making a multisig anyway.

100% upvoted

Hi all,

Given Coldcard etc etc and everything saying multisig good etc how would people suggest doing this? Multiple Trezor 3s?

2 of 2 multisig is sort of silly and defeats one of the main benefits of multisig ie no single point of failure.

Asking people for their multisig setup situation isn't going to get a ton of responses I wouldn't think.

I migrated from single to multi sig today. Personally I wouldn't use a passphrase in addition to a 2-3 multisig. That is added complexity for little benefit.

I don't know the answer but don't reply to any dms

67% upvoted

If you're using multisig to secure your bitcoin lets assume you have three physical keys & backups plus your wallet descriptor. Or perhaps you're using a 2-2 multisig, if so, why and how did a 2-2 fit your security model?

How have you distributed your keys & backups and how have you stored your wallet descriptor.

Are you utilising family to hold backups, and how many of you are keeping more than one key in a single location?

Share what you're willing, etc. I'm just curious to learn about the practicalities of multisig from real people who use multisig today.

56% upvoted

Setup:

  1. Sparrow as the wallet organizer (unsure of technical term)
  2. ColdCard as signer 1 (using updated firmware and software generated seed)
  3. BitBox signing device as signer 2 with software generated seed
  4. Both keys use a 13th word (passphrase)
  5. Descriptor string stored securely separate from keys
  6. Backup seed phrases stored securely separately
  7. Both devices require a password (separete from passphrase) to unlock

What I am mostly conerned with is if 1 device gets comprimised in the same way the bugged ColdCards did, I would still be able to spend from the multi-sig wallet correct?

Even if BOTH devices were compromized but my passphrase was unknown to the atacker, i would STILL be able to spend from the multi-sig correct?

This feels like a pretty solid set up, I have gotten here since barely avoiding the Coldcard attack recently. I still think the Colcard device is a good device so I don't really want to get rid of it, but adding an additional device to the mix seems like a good solution.

Thoughts?

63% upvoted

This Coldcard Mk2/3 incident shows there can be critical bugs in hardware wallets from trusted companies.

Multisig using wallets from different vendors solves this. An attacker would need to exploit two wallet models at the same time before you move your funds.

Vulnerabilities like Coldcard Mk2/3’s are very rare. And it’s more lucrative for an attacker to exploit a single vendor’s wallets, before someone else finds the vulnerability, than to wait until a second vendor’s wallets are compromised. Multisig buys you precious time to move your UTXOs.

You can even use as many vendors as you want. 3-of-3, 4-of-4, etc. M-of-N means M wallets out of N need to be compromised before your funds are at risk. One word of advice: keep it simple and don’t lock yourself out by forgetting your wallets and seedphrase backups.

You are close, though for multi-sig you need 3 total wallets. Right now with 2, You need both devices to spend, which if one is compromised or lost, you are locked out of your funds forever.

Coldcard
Bixbox02
SeedSigner

You would want to store each key geographically separate. This way if one key or HW wallet was lost/compromised, you would use the other two to access your funds.

13th word (or 25) Passwords are good, though my only issue is that they are in your memory only, that's a fairly easy way to lock yourself out. Those 13th-word passphrases cannot be recovered if forgotten. Keeping passphrases purely in your memory is incredibly risky. Instead of memorizing them, write them down and store them in a separate geographic location from the seeds.

You would want the descriptor file at each location. It is like the map of where you have your keys on the block chain. It does not allow one to access funds, even with one seed, though your privacy and balance will be compromised. If you lose this file completely, you would not be able to access funds. Print it or save it on encrypted USB drives kept alongside your physical key backups.

A really fun and educational experience to dig into is the DIY SeedSigner project. you build your own completely stateless and air gapped signing device using commodity parts (based on Raspberry Zero) and open source code to create analog entropy and hardened private keys. Once you have a robust and low cost private key generating system, you can experiment with multi-sig very easily. Create a multi-sig wallet in Sparrow/Electrum. Fund it with a nominal amount of sats and send and receive transactions with your wallet. Keep your xpubs securely stored especially for multi-sig. IMHO xpub storage can be placed in your password manager or encrypted on another digital device. If your xpub gets compromised, you lose privacy of your transactions, but you do not lost your money. To be clear, your private keys must NEVER touch an internet connected device.

You are definitely over thinking the complexity. Get very familiar with signing for and receiving transactions, burn a few sats in fees for the priceless learning and confidence it will build and you will be on your way.

And run a node and connect your wallet to it.

Geographically distribute keys and backups across a variety of physical security setups. Keep a copy of the wallet descriptor with each key / backup. Don't keep more than 1 key per location.

Exhaustive wallet security resources:

I only use an old android phone with no internet as a signer using either cupcake from cake wallet or electrum wallet and my phone with either electrum wallet or Cake Wallet as watch only and online broadcast, and a passphrase.

does not need to overcomplicate stuff really.

There are definitely still gaps in multisig + inheritance. The existing tools are powerful, but for long-term holders who want something simple, self-custodial, and family-friendly, things can still feel overly technical.

One thing that really helps is using devices that are purpose-built for secure, long-term storage (like a K210-based signer or any deterministic air-gapped device). But more importantly: don’t be the only one who understands the setup. Your spouse and at least one trusted family member or friend should learn the basics with you — not just where the backups are, but how to recover the wallet if something ever happens to you.

That alone removes a lot of the anxiety around inheritance. So no, your struggle isn’t unique — many Bitcoiners feel the same. Tools are improving, but the “human side” of the process (clear instructions + shared knowledge) is still what makes the biggest difference.

29% upvoted

Setting up 2-of-3 multisig across three Ledgers, likely using Sparrow or Nunchuk as coordinator. Plan: register all three signers, test with a small amount, then move the rest over.

Questions:

**•** Anything to watch for moving from an existing single-sig address into multisig? **•** Sparrow vs Nunchuk vs Unchained — preferences for a solo setup? **•** Any lessons learned from your own setups?

Thanks in advance.

35% upvoted

It seems like only bitcoin maxis are the only ones advocating for multisig. Anything else is vulnerable and at risk. Do crypto normies think multisig is overkill?

2 of 2 multisig provides no value for an individual.
In a 2-of-3 setup, if one seed is compromised, it doesn't matter. You ignore the compromised key entirely, use your other two safe devices, and move your funds to a new wallet cleanly and safely without a race.
Sparrow: Excellent desktop coordinator for DIY multisig. Clear coin control, PSBT flow, descriptor exports, robust labeling. Great for power users on Bitcoin.
A strong passphrase is enough protection for most people.
Practice 'worst day' drills: simulate loss of one key and spend with the remaining two.

Related questions

Is a 2-of-2 multisig setup good for a single person?
No, a 2-of-2 setup provides no value for an individual. If you lose one key, you are locked out of your funds entirely, which defeats the purpose of using multisig.
What is a wallet descriptor and why do I need to back it up?
A wallet descriptor contains the configuration details of your multisig wallet. To spend from an m-of-n wallet, you need m private keys and all n public keys, so losing the descriptor can prevent recovery even if you have your private keys.
Why should I use hardware wallets from different vendors?
Using different vendors protects against vulnerabilities specific to a single manufacturer. An attacker would need to exploit multiple wallet models simultaneously before you can move your funds.
What happens if my public key gets compromised?
A compromised public key does not result in lost funds. However, it does compromise your privacy by revealing your balance and transaction history.
What software do users recommend for multisig?
Users often recommend Sparrow and Nunchuk as software coordinators. Sparrow is noted for its clear coin control, PSBT flow, and robust labeling for power users.

People also asked

Replies (0)

No replies yet. Be the first to reply.