Setting Up a Multisig Wallet: When Two of Three Keys Are Worth It for You
A multisig wallet demands several keys for a transfer and so makes a single theft worthless. We show which threshold fits you, what you have to back up besides the keys, and why most setups fail at the configuration.

Table of Contents
Table of Contents



Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
A multisig wallet is a wallet that requires several keys for a transfer. Instead of a single signature, a transaction needs the consent of several keys, and you set the number in advance. The usual notation for this is m of n: in a 2-of-3 wallet three keys exist, any two of them are enough to pay, and a single stolen key does no damage.
That sounds like a pure security question, but it is above all a question of organisation. Multisig shifts the risk away from the fear of losing a key and towards the duty of managing a configuration. Anyone who does not know this sets up a multisig wallet and then loses their Bitcoin to a misplaced file rather than to a hacker. This article shows you when the effort pays off, what you have to back up besides the keys, and at which point most setups go wrong.
What a multisig wallet is and what 2 of 3 means exactly
An ordinary Bitcoin transfer is a single-key transaction: whoever holds the private key to an address can move the balance. The Bitcoin protocol does, however, allow conditions that require several signatures, and such spending conditions are called m-of-n (Bitcoin Wiki on multi-signature).
The two numbers mean different things, and this is exactly where the most common confusion arises:
- n is the number of keys that exist in total. With 2 of 3 that is three.
- m is the number of signatures a transfer needs. With 2 of 3 that is two.
- n minus m is your buffer: that is how many keys you may lose without losing access. With 2 of 3 it is exactly one.
A second point matters more than it looks: the three keys of a 2-of-3 wallet are not copies of each other. Each is a secret of its own with its own recovery phrase. A multisig wallet with three keys therefore means three backups that you store separately, and not one backup in triplicate.
Which three problems multisig actually solves
Multisig is often sold as safer across the board. More precisely: it solves three concrete problems that a single wallet does not solve.
Theft of a device. Whoever gets hold of one of your devices, or finds one of your backups, still has nothing with 2 of 3. They need a second key from another location. This protection also works against tampered devices, because a single compromised device cannot send the transfer on its own.
A single point of failure. With a normal wallet, everything hangs on one recovery phrase. If it burns, the balance is gone. With 2 of 3, one key including its backup may disappear completely and you still reach your money with the remaining two.
Shared responsibility. Two people holding funds together need no solution in which one of them alone can move everything. A threshold of two signatures among three participants delivers exactly that.
If you have been securing your keys on paper or metal so far, the article storing a seed phrase safely is the foundation multisig builds on. Without clean individual backups, multisig only multiplies the confusion.
Where multisig does not help and when a single wallet is the better choice
This trade-off is missing from most guides, and for the majority of readers it is the actual answer. Multisig expressly does not help you against:
- Coercion. Whoever forces you to transfer also forces you to fetch two keys. The protection only bites when one key is out of your own short-term reach.
- Wrong recipient addresses. A transfer to the wrong address is just as final with two signatures as with one.
- Your own mistakes during setup. Here multisig even raises the risk, because more parts have to fit together.
An uncomfortable recommendation follows from that: if you hold a manageable amount, decide alone and still feel unsure with wallet technology, a cleanly backed-up single wallet is in practice usually safer than a half-understood multisig. The effort pays off when the amount would hurt you, when several people decide together, or when you have to plan access across years and across a change of address. Which devices come into question at all is shown by our hardware wallet comparison; for purely software-based solutions there is the software wallet comparison.
Choosing the threshold: 2 of 3, 3 of 5 or 2 of 2
The numbers are no matter of taste. They are a trade between theft protection and loss protection. The higher m, the harder the theft and the greater the risk of locking yourself out.
2 of 2 requires both keys and forgives no loss. This choice suits a joint account in which nothing should happen without the consent of both parties, and it absolutely needs a contingency plan.
2 of 3 is the standard case for private investors: one key within everyday reach, one at a second location, one with a person you trust or in a safe deposit box. A loss is planned for, and a theft achieves nothing.
3 of 5 is worth it for associations, companies and larger amounts. Two keys may be lost, and no pair acting alone can act at all. The price is five backups and five locations that you have to keep an eye on permanently.

What you have to back up besides the keys
This is the section on which most multisig setups later founder, and it has nothing to do with attackers. A multisig wallet consists of two things: the private keys and the wallet configuration. The configuration describes how the keys belong together, and it contains at least:
- the extended public keys of all participants, usually labelled xpub or zpub
- the derivation path of each key, meaning the route along which the addresses are computed from the key
- the threshold, that is m and n
- the script type, which determines how the addresses are technically built
Without these details your addresses cannot be reconstructed, even if you hold every recovery phrase in full. The configuration is no secret in the same sense as a private key, because on its own it lets nobody spend. What it does reveal is your entire payment history, so the configuration does not belong in an open cloud either. A practical rule: place a copy of the configuration with every single key backup. One reachable storage location is then enough to start over at all.
Which hardware wallet fits your setupHow a multisig transfer works technically
With a single wallet, one device signs and sends. With multisig, an unfinished transaction travels from device to device, and there is a format with its own standard for that: the partially signed Bitcoin transaction, or PSBT for short. The relevant specification carries the number 174 and the title Partially Signed Bitcoin Transaction Format; it describes a format containing all the information a signer needs in order to sign, so that the signing device can stay permanently offline.
The process has four steps, and you should have seen it through once in full before larger amounts sit in the wallet:
- Create the draft. The wallet software builds an unfinished transaction from recipient, amount and fee.
- First signature. You hand the draft to the first device, check recipient and amount on that device's own display, and sign.
- Second signature. The same on the second device, which may stand at another location. The draft travels as a file, as a QR code or on a memory card.
- Send. As soon as the threshold is reached, the transaction becomes complete and goes out to the network.
Two things stand out immediately. First, a transfer takes more time, especially when one key sits in a deposit box. Second, checking the recipient address on the device display is no optional convenience. It is the actual protection: two devices displaying the same address independently expose malware that swapped the address on the computer.
Derivation paths and compatibility between manufacturers
A multisig wallet built from devices by different manufacturers is expressly desirable, because it additionally protects against a fault in a single product line. For the devices to work together they have to use the same conventions, and those are standardised.
The relevant standard carries the number 48 and defines a hierarchy of its own for deterministic multisig wallets. The path takes the form m / purpose' / coin_type' / account' / script_type' / change / address_index. The purpose is constantly 48, and the script type distinguishes two variants: 1 stands for nested SegWit, 2 for native SegWit. As the recommended default the standard expressly names the path for native SegWit (BIP-48, section on path levels).
A second convention comes on top of that: the public keys are sorted into a defined order before an address is built from them. That sounds like a side issue, yet it decides whether two programmes compute the same address from the same keys. In practice this means: note the full path and the script type for every key. When a recovery later finds no balance, the fault almost always lies here, and not with the keys themselves.
Multisig on Ethereum and other smart contract chains
With Bitcoin, multisig sits in the protocol: the condition that two of three signatures are required is part of the spending condition itself. With Ethereum and most smart contract chains, multisig arises instead in a contract that sits on the chain and maps the rules in program code.
This difference is no detail, because it moves the question of trust. A contract can bring extra functions along, such as swapping out signers or daily limits, which makes it more flexible. At the same time your security hangs on that contract's code and on its audit, and not only on the cryptography of the signatures. A fault in the contract is a risk that protocol-native multisig does not carry. Anyone using both should assess them separately and should not assume that two of three keys means the same thing everywhere.

A joint wallet for couples, companies and associations
For several participants, multisig is the obvious form, and here the benefit lies less in the technology than in the clarity of the arrangements. Three questions deserve a written answer before you set anything up.
Who holds which key, and who knows about it? With two people and three keys, the third key is the decisive spot. If it sits with one of the two, that person can act alone together with their own key, and the threshold is effectively defeated.
What happens in a dispute or a separation? A threshold of two of two means nothing moves without agreement, not even in part. That may well be intended, and it is a reason to discuss it beforehand.
Who checks the balance, and how often? A joint wallet needs a watch-only version with which all participants see inflows and outflows without being able to sign. This watch-only version arises from the configuration and the public keys, and it belongs to the setup.
Inheritance: how heirs reach a multisig wallet
A multisig wallet is harder for heirs than a single wallet, and this hurdle is an argument against having too many keys. Without instructions, nobody works out how many keys exist, where they are and how they belong together. What your estate therefore needs is a description that deliberately reveals no secrets: the number of keys and the threshold, the storage locations, the wallet configuration and the name of the software used to restore the wallet.
A second point comes from practice: recoveries frequently fail because a device is no longer available or its firmware is too old. How to read a key into another manufacturer's device is set out in our article on restoring a seed on another manufacturer's device. Test that route yourself once, rather than hoping heirs will find it.
Document transfers and holding periods without gapsTax in Germany: moving into a multisig wallet
The most common worry first: if you transfer your Bitcoin from one wallet of your own into a multisig wallet of your own, the owner does not change. A transfer between your own wallets is neither a sale nor a swap, so no private disposal under Section 23 of the Income Tax Act arises from it. The holding period continues to run and does not start afresh because of the move.
What matters is the documentation, and for a practical reason: to the tax office, an outflow from a wallet address initially looks like any other outflow. For every move you should therefore record which address transferred to which address, when that happened, and that both addresses are yours. The acquisition dates of the individual holdings travel with them unchanged, because the original purchase decides the holding period and not the move. With several wallets and a multisig setup this bookkeeping grows quickly; which programmes correctly classify transfers between your own addresses as non-taxable is shown by the comparison of crypto tax tools and portfolio trackers. A tax adviser is responsible for the binding classification of your individual case.
The test run you must not skip
A multisig setup only counts as finished once you have restored it in full at least once. The test costs an hour and spares you the one mistake that really gets expensive.
- Deposit a small amount. Take an amount whose loss would not bother you.
- Send once. Carry out a complete transfer with both signatures, so that you know the process and the handover between the devices.
- Practise recovery without the everyday device. Rebuild the wallet on another computer using nothing but the configuration and two recovery phrases. If the same set of addresses appears, the setup holds up.
- Play through the loss case. Set one key aside and check that the remaining two suffice.
Only after step three do you know that your configuration is complete. Every report of lost multisig holdings that does not trace back to theft traces back to a skipped recovery drill.
Setting up a multisig wallet: what to take away
- First decide whether you need multisig at all. With small amounts and a single person, a cleanly backed-up single wallet wins. Which devices are up to the job is set out in the hardware wallet comparison.
- Back up the configuration as carefully as the keys. Xpubs, derivation paths, script type and threshold belong with every single backup as a copy, because the keys alone will not reconstruct your addresses.
- Practise the recovery before amounts move in. And document every move between your own addresses, so that the holding period stays provable later; the comparison of crypto tax tools and portfolio trackers helps with that.
(As of September 26, 2026. This article is not investment advice. Prices and fee structures change; check the terms with the provider before you buy.)
Transparency note: This article was produced with the assistance of artificial intelligence and reviewed by our editorial team before publication. All figures and claims were checked against the primary sources linked in the text. The feature image was generated with AI.
Related articles
- How to Set Up a Crypto Wallet: Securing Your Coins in Seven Steps
- How to Store a Seed Phrase Safely: What Steel, a Passphrase and Multisig Do for Your Wallet Backup
- Restoring a Seed on Another Manufacturer's Wallet: What BIP39 Guarantees and What It Does Not
- Wallet App Without BaFin Authorisation: When Holding Crypto-Assets Requires a Licence
- Crypto Withdrawal to Your Own Wallet: Ten Providers Checked, Three Will Not Let Your Coins Out
Which topics should we dive deeper into?
Select what genuinely interests you. Your picks feed directly into our editorial planning.
Crypto news that's actually worth your time.
Weekly. 60 seconds. Carefully curated by our editors: no hype, no promo flood, no spam.
August 21, 2026 4:17 PM

Crypto Withdrawals to Your Own Wallet: Why Exchanges Demand Proof of Address Ownership Above €1,000
Above €1,000 your provider has to establish whether the destination address really belongs to you. Article 14(5) of the transfer of funds regulation, five permitted methods, and the reason a withdrawal stalls without this step.
September 26, 2026 4:11 AM

Shielded Bitcoin: what the privacy proposal means for your Bitcoin addresses
Three researchers published a draft for encrypted Bitcoin transfers without a soft fork on September 24, 2026. What Shielded Bitcoin hides, what stays public and which points you can check on your own wallet today.
August 4, 2026 1:21 PM

Coldcard Losses Near $114 Million as a Fourth Sweep Hits: Why Is Bitcoin Rising Anyway?
A fourth wave of Coldcard sweeps took another 449 BTC on Monday, yet Bitcoin climbed back toward $64,000. Here is what changed and who is still exposed.
September 7, 2026 7:26 PM

Stolen Keys Beat Code Flaws: Why the Private Key Is the Way In for 2026 Crypto Hacks
Compromised private keys overtook smart contract code flaws as the most common attack route for the first time in 2026. What sits behind the shift, and how to check your own setup for its single point of failure.
August 5, 2026 10:33 PM

$130 Million Gone Because the Randomness Was Predictable: Which Hardware Wallet You Can Still Buy
The Coldcard flaw proved the most respected wallet is not the safest. Which vendor has which track record – and why now is the wrong moment to pause your savings plan.
July 31, 2026 3:54 PM

594 BTC Gone in 25 Minutes: The Coldcard Flaw That Made Seed Phrases Guessable
A firmware bug from March 2021 let an attacker drain $38 million from around 500 Bitcoin wallets. Here is what broke, who is exposed and what to do now.
October 2, 2026 10:36 AM

Hot Wallet or Cold Wallet: the Private Key Decides How Safe Your Coins Are
Hot wallet or cold wallet: the difference rests solely on whether the private key is online. What separates the two forms, where the limits of hardware lie and why moving to your own device triggers no tax.
September 16, 2026 7:39 PM

Deutsche Bank to Custody Bitcoin and Ether: Why Retail Clients Are Missing and What to Check in Your Own Custody
Deutsche Bank will custody Bitcoin, Ether and three stablecoins, but addresses corporates and institutions only. What the launch under supervisory reservation means, and the four questions you should put to any custody arrangement.
August 31, 2026 10:14 PM

Trust Wallet Drops 25 Networks: What Users Should Know After September 15
Recap as of September 27, 2026: Trust Wallet had announced it would remove built-in support for 25 blockchain networks from its app on September 15, 2026, among them MultiversX, Polygon zkEVM and Moonbeam. Your coins stay yours, the convenient access does not: this article shows how to add a chain by hand and for which nine networks that route is not open.
August 24, 2026 1:22 PM

Phantom Wallet Ends Sui and Monad Support: What to Do Before the Deadlines
Phantom Wallet removes Monad from its app on August 26 and Sui on September 24. The balances are not lost, but only one of the two ways out leaves your tax position untouched.
September 17, 2026 4:14 PM

D'CENT App Wallet: How to Tell If Your Recovery Phrase Has to Move Now
Manufacturer IoTrust reports suspicious asset transfers in the D'CENT app wallet and asks users to move their holdings. One question decides the matter: has your recovery phrase ever been entered into the app?
September 16, 2026 4:12 AM

Wallet Drops a Network: How to Rescue Your Coins Before the Deadline
Phantom is ending Sui support on September 24, 2026, and Trust Wallet has already removed 25 networks: five shutdowns of this kind in four weeks alone. What really happens to your balance, which two routes you have before the deadline and where the move most often fails.
September 2, 2026 10:31 PM

ECX Fork of Bitcoin: When the Snapshot at Block 973,728 Really Lands
Layertwo Labs is copying Bitcoin's ledger onto a new chain and crediting every bitcoin with one ECX. Our own measurement shows the three fork stages hang on difficulty periods, and the snapshot reported for October 31 will most likely fall on November 1.
September 2, 2026 7:44 AM

MyDoge Ends Doginals and DRC-20 Support: What Holders Should Know After September 17
Recap as of September 27, 2026: infrastructure provider Maestro had announced it would discontinue its Dogecoin services on September 18, 2026, with MyDoge withdrawing support for Doginals and DRC-20 a day earlier. Our own survey of September 2 showed that nothing about the shutdown could be found on the public pages of those involved.
April 17, 2026 10:14 PM

FIBE Berlin 2026 Review: Bitcoin, AI Trading & Tokenization at Europe's Biggest FinTech Conference
FIBE Berlin 2026 brought together the future of finance — from AI-powered crypto portfolios to Bitcoin self-custody and tokenized real-world assets.
September 7, 2026 1:27 PM

Liquid Network: Around 4,000 Bitcoin Drained via a Peg-Out, and What L-BTC Holders Must Check Now
Around 4,000 Bitcoin drained out of the Liquid Network federation wallet on September 6, even though no key was stolen. The network is halted and redemption is blocked. Here is what you should check now as an L-BTC holder.
September 4, 2026 10:26 PM

Pocket Bitcoin Data Breach: When Name, Home Address and Bitcoin Address Circulate Together
The Swiss Bitcoin service Pocket Bitcoin closed its investigation on September 3, 2026: 5,411 people affected, and for 291 of them the Bitcoin addresses they used along with copies of identity documents. Why this one data pairing has lasting effect, and what you should check with your own provider.
September 11, 2026 1:26 PM

Alby Hub Security Flaw: How to Check Whether Your Bitcoin Lightning Node Is Reachable From the Internet
Alby confirmed a critical flaw in Alby Hub v1.7.0 through v1.18.5 on September 9, 2026; it is only exploitable if the management interface sits openly on the internet. What to check on your node, why the fix is a good twelve months older than the warning, and which step comes before the update.
August 31, 2026 1:22 PM

Cosmostation Wallet Shutdown on September 1: What Cosmos Wallet Users Should Know Now the Deadline Has Passed
Recap as of September 27, 2026: Cosmostation had announced it would discontinue its wallet apps on September 1, 2026, leaving only the export of the recovery phrase and the private key. This article describes the situation before the deadline and how to move Cosmos holdings, including delegated ATOM.
August 30, 2025 11:00 PM

OKX Brings Wallet & Onchain Services to Europe
OKX expands its Wallet and onchain services to Europe, giving users secure self-custody, smart trading tools, and seamless access to DeFi and dApps.
October 2, 2026 4:32 AM

NEAR Intents halts withdrawals after a $3.8 million exploit: here are the reasons
NEAR Intents confirms an exploit of more than $3.8 million and holds deposits and withdrawals on eleven networks. Reimbursement is promised, a date for it is not.
September 29, 2026 10:28 PM

Customers Pull $463 Million From Bitget: The Consequences for Reserves and Custody
After the attack of September 24, customers pulled around $463 million out of Bitget within a day, the largest single-day outflow since DefiLlama began tracking reserves. The user protection fund fell from $464 million to below $200 million in the process.
September 23, 2026 10:27 PM

Crypto in a divorce: what happens to bitcoin in the equalisation of accrued gains
What is divided in a divorce is not the coins but the increase in assets, and it is divided as a sum of money. We set out the three key dates, the duty to disclose wallets and the point at which the equalisation of accrued gains turns into a taxable disposal.
September 4, 2026 10:15 PM

Trezor Data Breach: Am I Affected and What Should I Do Now?
Trezor widened the ShipMonk data breach on September 4, 2026: around 67,000 further people affected, just over 80,000 in total, from orders placed between November 2019 and August 2021. How to check in two minutes whether you are among them, and what an exposed home address means for self-custody.
September 4, 2026 10:17 AM

Cypher Shutdown on September 6: What Users Should Know Now the Withdrawal Deadline Has Passed
Recap as of September 27, 2026: Cypher had announced it would take its app, dApp and withdrawal window offline on September 6, 2026 and end the token protocol. This article describes the situation before the deadline, how the payout worked and what our own measurement showed at the time about what was left of the CYPR token.
August 13, 2026 4:59 PM

Trezor Data Breach: First 13,689 Customers, Then Roughly 67,000 More Exposed
A breach at Trezor shipping partner ShipMonk exposed names, phone numbers and home addresses of 13,689 customers in August; in September Trezor reported roughly 67,000 more in the US. Devices are safe, phishing risk is not.
More from CryptoTicker

