Multisig simply explained: several keys, one wallet
What a 2-of-3 multisig wallet is, who it’s worth it for, how to set it up and why you need to back up the descriptor as well as the seeds.
In short~37 sec
- 01With multisig, a payment needs several signatures. With 2 of 3, there are three keys and two are enough.
- 02If one key is lost or stolen, your funds aren’t gone: no single device or backup can move anything.
- 03The price: more devices, backups and procedures, slightly higher fees, no Lightning. Multisig is for large amounts, not for getting started.
- 04As well as the seed phrases, you have to back up the wallet configuration (the descriptor or all xpubs). Without it, you can’t spend even with enough keys.
- 05Software such as Sparrow or Nunchuk coordinates the devices. The keys are best kept on hardware wallets from different manufacturers.
Good to read firstHardware wallets compared
With a normal wallet, everything hangs on one seed phrase: whoever finds it has access. If you lose it along with the device, your funds are gone. Multisig spreads control across several keys – like a safe that only opens when two of three keys are turned. It sounds like a tool for professionals – we’ll walk you through it with an example of three keys.
The principle: m of n
With a multisigGlossaryMultisig (multi-signature)A wallet in which several keys jointly control the bitcoin – for example 2 of 3. If one key is lost or stolen, the bitcoin stays safe. In return, setting it up and backing it up is considerably more demanding.On the learning path: Stage 6 · Step 4 – Inheritance & emergency plan →In the glossary → wallet (short for multi-signature), every payment needs signatures from several keys: there are n keys, and m of them have to sign.[1] A common setup is 2 of 3: three keys, two are enough.[2]
Anyone sending you bitcoin doesn’t have to do anything special: the conditions sit behind an address and are only revealed when the coins are spent.[3]
What 2 of 3 means in everyday life
Say your three keys are on three hardware walletsTermHardware walletA small dedicated device that keeps your private keys offline and signs transactions internally.On the learning path: Stage 6 · Step 1 – Hardware wallets compared →In the glossary →AdManufacturers with a paid linkProviders from our comparisonBitBox02Hardware wallet · SwitzerlandVisit BitBox (paid link, opens in a new window)No paid link for your countryNo partnership · Profile →Trezor SafeHardware wallet · Czech RepublicVisit Trezor (paid link, opens in a new window)No paid link for your countryNo partnership · Profile →Blockstream JadeHardware wallet · Canada/USAVisit Blockstream Jade (paid link, opens in a new window)No paid link for your countryNo partnership · Profile →COLDCARDHardware wallet · CanadaNo partnership · Profile →LedgerHardware wallet · FranceNo partnership · Profile →SeedSignerHardware wallet · Open-source project (international)No partnership · Profile →All 6 compared – including non-partners →Only buy hardware wallets from the manufacturer or an authorised reseller.*Paid link: if you sign up or buy through it, we earn a commission. Your price stays the same. How we make money → from different manufacturers: one at home, one with a trusted person, one in a bank safe deposit box. Each has its own seed phrase.
| What happens | Single-sig (one seed phrase) | Multisig 2 of 3 |
|---|---|---|
| A device breaks or gets lost | Restore with the seed phrase | Still usable with the other two keys |
| A backup is stolen | Thief has full access | Thief has only one key; you still move your funds soon |
| A device has a manufacturer flaw | Funds are at risk | Only one key affected; you move your funds without rushing |
| Two keys are lost | – | Funds lost |
| Wallet configuration is missing | – | Spending practically impossible, despite enough keys |
Manufacturer flaws aren’t a theoretical risk: in July 2026 it emerged that a firmware bug in COLDCARDProvider · Hardware walletCOLDCARDBitcoin-only signing device from Coinkite (Canada) with an air gap via microSD, NFC and QR – more for advanced users.Hardware manufacturer – no financial licence required · reviewed Sept 2026Price: Q $319, Mk5 $219 (promotional prices, as of Sept 2026)On the learning path: Stage 6 · Step 1 – Hardware wallets compared →Our profile →Official website ↗Only buy hardware wallets from the manufacturer or an authorised reseller. devices had weakened seed generation; attackers recalculated keys and stole funds.[4] With devices from different manufacturers, a flaw like that hits only one of three keys.
So multisig doesn’t eliminate risks, it shifts them: instead of one backup, you look after several – plus the wallet’s configuration.
When multisig is worth it
The Bitcoin Design Guide recommends multisig for large amounts and for funds that several people control together; it considers it unsuitable for newcomers and small amounts.[1] SparrowProvider · Software walletSparrow WalletBitcoin desktop wallet with no purchase price and full transparency: coin control, PSBT, multisig and support for most hardware wallets.Non-custodial software – no financial licence required · reviewed Sept 2026Price: no purchase price (donations welcome); network fee when sending (as of Sept 2026)On the learning path: Stage 5 · Step 2 – Setting up your first wallet →Our profile →Official website ↗ places multisig at the top of its three-level model: when a significant share of your wealth is in bitcoin and losing it would noticeably affect your future.[5]
+Reasons for
- A single backup being found or lost would seriously hurt you
- You don’t want to rely on one device or one manufacturer
- Several people should decide together, such as a couple or an association
- You want to involve trusted people for inheritance without giving them sole access
−Reasons against
- You’ve only just set up your first wallet
- The amount doesn’t justify three devices and the extra effort
- You want to make frequent payments with it
- You’re not sure you’ll still master the procedures in years to come
What multisig costs you:
- Complexity. More parts mean more sources of error – up to losing access.[1],[2]
- No Lightning. A Lightning node’s keys have to be available at all times, so they can’t be secured with multisig.[1]
- Slightly higher fees. Several signatures make the transaction larger.[2]
Dive deeperHow much more? The calculation in vbytes
According to Bitcoin Optech, the witness data (signatures plus script) of a 2-of-3 input takes up 63.5 vbytes, compared with 27 vbytes for a simple SegWit wallet.[6] That’s 36.5 vbytes more per input: around 365 sats at an example rate of 10 sat/vB, or just under $0.30 at an example price of $80,000. It only becomes noticeable with high fees or many small inputs. How fees come about and where they currently stand is explained in Transactions & fees.
The building blocks of a multisig wallet
Signing devices: the keys
Each key is created on its own device, usually a hardware walletGlossaryHardware walletA small dedicated device that keeps your private keys offline and signs transactions internally. The key never leaves the device, so malware on your computer can’t get at it.On the learning path: Stage 6 · Step 1 – Hardware wallets compared →In the glossary →, with its own seed phraseGlossarySeed phrase (recovery phrase)A sequence of usually 12 or 24 words from which your wallet derives all its private keys. Anyone who knows the words has full access to your bitcoin – so they belong in an offline backup and never in anyone else’s hands.On the learning path: Stage 5 · Step 3 – Backing up your seed phrase →In the glossary →. Sparrow recommends devices from different manufacturers.[5] Which ones are available is shown in the hardware wallet comparison.
Buy each device directly from its manufacturer or from a retailer the manufacturer names.
Coordinator software: the control centre
Software on a computer or phone combines the devices into one wallet, shows the balance and addresses, and passes payments from device to device for signing. It doesn’t need any private keys for this. Two widely used examples that we earn nothing from (as of September 2026):
- Sparrow: desktop wallet, open source (Apache 2), single-sig and multisig, all common hardware wallets, signing via USB or QR code.[7]
- Nunchuk: wallet for phone and desktop with a focus on multisig, supports many hardware wallets, optional inheritance features.[8] The desktop and Android apps are open source (GPL-3.0).[9]
Signing uses a PSBTGlossaryPSBT (partially signed Bitcoin transaction)A standard format for Bitcoin transactions that are not yet fully signed. It lets a wallet app, a hardware wallet and co-signers pass a payment between them without sharing private keys.On the learning path: Stage 6 · Step 1 – Hardware wallets compared →In the glossary → (partially signed Bitcoin transaction): the software creates the payment, two devices sign one after the other, then it goes out to the network – with air-gappedGlossaryAir gapAn air-gapped signing device has no cable or wireless connection to other devices. Transactions travel back and forth by QR code or memory card – so the private key stays completely offline.On the learning path: Stage 6 · Step 1 – Hardware wallets compared →In the glossary → devices, also without a cable via QR code.[7]
The wallet configuration: the often-forgotten backup
The wallet consists not only of the three seed phrases but also of a blueprint: which three keys, how many signatures, which address type, which derivation pathGlossaryDerivation pathThe route a wallet follows to calculate individual keys from your seed phrase, for example m/84'/0'/0'. If another wallet uses a different path when you restore, it looks empty – even though nothing has been lost.In the glossary →. It includes the extended public keys of all participants (xpubsGlossaryxpub (extended public key)An extended public key from which all the addresses of a wallet account can be calculated. Nobody can spend bitcoin with it – but anyone who knows it can see your entire account history.In the glossary →) along with their fingerprints and paths.[1]
Modern wallets summarise the blueprint in a descriptor, a standardised line of text. It solves exactly this problem: from the private keys alone, a restored wallet doesn’t know which addresses to generate.[10]
How to back it up:
- A copy with every seed backup. Then any two storage places are enough for recovery.
- On paper or as a file. Coordinators offer an export, NunchukProvider · Software walletNunchukMultisig wallet for smartphone and desktop – no subscription if you do it yourself, subscriptions for assisted multisig and inheritance.Non-custodial software – no financial licence required · reviewed Sept 2026Price: Basic version $0; subscriptions $120 to $2,100 a year (as of Sept 2026)On the learning path: Stage 5 · Step 2 – Setting up your first wallet →Our profile →Official website ↗ for example as a BSMS file.[11] Digital copies are acceptable here: the descriptor alone can’t spend anything.
- Treat it as confidential. Anyone who knows all the xpubs can see every incoming and outgoing payment of the wallet, but not a single secret key.[12]
Setting up a 2-of-3 wallet (example coordinator)
Illustrative example – real apps look different in detail.
Step by step
Plan the locations
Before you buy anything, decide where the devices and seed backups will be kept – in separate places.[5] No place may hold two of the three keys, whether as a device or as a seed backup.
Set up each device on its own
Buy directly from the manufacturer and set up each device like a normal wallet. Back up each seed phrase separately, as described in Backing up your seed phrase.
Create the wallet in the coordinator
Import the public keys of the three devices and create the 2-of-3 wallet. Note down the fingerprints so you can tell the keys apart later.
Back up the descriptor, check addresses
Keep a copy of the descriptor with each seed backup. If your device offers it, register the wallet there too, so it can check addresses and change itself. Then compare the first receiving address in the software with what at least two devices show.
Test before money flows
Send a small amount to the wallet and spend it again with two devices. Also restore the wallet in a fresh installation – using only two seed phrases and the descriptor. How to do it: Testing recovery.
Update your emergency plan
Record that a multisig wallet exists, which software you use and where the parts are kept – with no seed phrases in the letter. More in Inheritance & emergency plan.
Variant: a service provider holds one key
In some models, a provider keeps one of the three keys and helps with recovery, for example. Nunchuk states that it can’t move your funds on its own with that key (as of September 2026).[11] This cushions user errors but makes you more dependent: check that you can reach your funds without the provider. Inheritance solutions with a time lock are covered in Inheritance & emergency plan.
Quick check
In a 2-of-3 wallet, you have two seed phrases but no descriptor and no xpub for the third key. What applies?
A multisig wallet’s addresses depend on the public keys of all participants. If one is missing and the configuration wasn’t backed up, you can’t spend despite having two seeds. That’s why a copy of the descriptor goes with every seed backup.
What’s next?
Frequently asked questions
Do I need three hardware wallets for multisig?
For 2 of 3, you need three keys. They are best kept on three hardware wallets from different manufacturers. A key can also live in a software wallet, but it is less well protected there.
Can I convert an existing wallet into a multisig wallet?
No. A multisig wallet has its own addresses. You set it up from scratch, test it with a small amount and then send your funds there from the old wallet.
What happens if the coordinator software is discontinued?
Your bitcoin aren’t in the software but on the blockchain. With enough seed phrases and the backed-up wallet configuration, you can restore the wallet in other compatible software.
Is multisig the same as a passphrase?
No. A passphrase is an additional secret added to a single seed phrase – if it’s lost, the funds are gone. Multisig spreads control across several keys and can cope with losing one of them.
Your knowledge blockchain
Every article you complete becomes a block in your personal chain – stored only in your browser.
Sources12 sources · 7 publishers
The superscript numbers in the text refer to these sources.
- Multi-key – Bitcoin Design Guide (accessed 28/09/2026)
- Multisig Wallets: How Multi-Key Security Protects Your Bitcoin – Trezor (accessed 28/09/2026)
- BIP 16: Pay to Script Hash – Bitcoin Improvement Proposals, 03.01.2012 (accessed 28/09/2026)
- COLDCARD Security Status – Coinkite (accessed 28/09/2026)
- Best Practices – Sparrow Wallet (accessed 28/09/2026)
- Transaction size calculator – Bitcoin Optech (accessed 28/09/2026)
- Features – Sparrow Wallet (accessed 28/09/2026)
- Nunchuk – Bitcoin wallet with multisig and inheritance – Nunchuk (accessed 28/09/2026)
- nunchuk-io – source code (including nunchuk-desktop, nunchuk-android, libnunchuk) – Nunchuk (GitHub) (accessed 28/09/2026)
- BIP 380: Output Script Descriptors General Operation – Bitcoin Improvement Proposals (accessed 28/09/2026)
- Bitcoin inheritance – Nunchuk (accessed 28/09/2026)
- BIP 32: Hierarchical Deterministic Wallets – Bitcoin Improvement Proposals, 11.02.2012 (accessed 28/09/2026)
This article is for education only and is not investment, tax or legal advice.