• Market Cap: $3,214,108,530,155.16
  • 24h Vol: $102,699,640,754.38
  • BTC Dominance: 57.49%
XBT.Market
Advertisement
  • Home
  • Coins MarketCap
  • Crypto Exchanges
  • Crypto Calculator
  • Top Gainers and Loser
  • News
  • Contact Us
No Result
View All Result
XBT.Market
No Result
View All Result
Home Bitcoin

Why Multisig Is Essential For Anyone Who Believes In Bitcoin

Jon Hartney by Jon Hartney
February 6, 2023
in Bitcoin, Blockchain, Business, Market
0
Why Multisig Is Essential For Anyone Who Believes In Bitcoin
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter

Anyone holding a non-trivial amount of bitcoin should consider multisignature security, including how to mitigate potential attacks.

Related articles

Bitcoin Price Crashes Nearly $4,000 in Two Hour Market Sell-Off

Bitcoin Price Crashes Nearly $4,000 in Two Hour Market Sell-Off

January 19, 2026

Scaramucci says stablecoin yield prohibition undermines US dollar

January 18, 2026

This is an opinion editorial by Anant Tapadia, a computer engineer and contributor to Bitcoin self-custody projects Bitcoin Keeper and Hexa Wallet.

Multisignature security, or “multisig,” offers a different set of security guarantees than single-signature (singlesig) solutions cannot. While I believe that singlesig is a great form of custody when one is just getting started with bitcoin or managing small amounts, in my opinion, anyone holding a non-trivial amount of bitcoin for the long term should evaluate a multisig option.

Defining Multisig

A three-of-five multisig with sample signing devices, managed by a coordinating software

It is imperative to understand what we mean by “wallet” before I lay my case for one type versus another. A multisig wallet is referred to as a “vault” in apps like Bitcoin Keeper and Blue Wallet, while some also refer to it as the “coordinator” or “coordinating software.” It is basically a wallet that can talk to multiple signing devices and coordinate between them for signing transactions (generally using the PSBT format). In comparison, a singlesig wallet talks to one signer only. The singlesig wallet is also often the signer, meaning the keys are hot.

So, the attack surface exposed due to a singlesig wallet and vault is similar as they both have similar roles. Having a signing device in both cases adds to the security and introduces new attack surfaces.

A multisig is often referred to as an “m-of-n,” where you need “m keys out of n” to sign a transaction. An output descriptor or bitcoin secure multisig setup (BSMS) is a format that is used to define the configuration of a multisig. This can be used to recreate your setup on other coordinators or to register the multisig with the signing devices.

Considerations For Bitcoin Custody

Minimizing Trust

The obvious advantages of having multiple signers are to reduce single points of failure and increase redundancy in your setup. With the help of the common examples of attacks on multisig included below, I will explain why those attacks are applicable, even with singlesig custody. However, with multisig, you can minimize trust in any one entity as multiple entities are involved.

Operational Effort

Setting up and using multisig can be operationally more time consuming and include more pitfalls if not done correctly. Therefore, I recommend that users only consider multisig for long-term HODLing, where regular transactions are not anticipated.

Setup Costs

A robust, multi-vendor multisig (such as one with three-of-five custody) can be achieved for anywhere between $250 to $600. So, if you have around 0.5 BTC (about $11,000 at the time of writing this piece), spending less than 10% on securing it is not a bad idea, because this bitcoin’s value can appreciate very quickly.

The costs of signing devices are also reducing, e.g., Tapsigner from Coinkite. Plus, using non-hardware-based soft keys gives you zero-cost options, but it is not recommended that these are used for more than one key in a multisig setup.

Mitigating Common Attacks

I will now look at some attacks that can happen if a custody key coordinator tries to act maliciously. Then, I will explain how this is no different from the threats in a singlesig setup and what multisig wallets can do to mitigate these risks. The ultimate responsibility inevitably lies with the user to ensure that they take the proper steps, as suggested below.

The Wrong Receive Address

The most direct attack I’ll outline is one where the user tries to receive funds, and the coordinator app shows an attacker’s address instead. In such scenarios, the software could still show that the funds were received where the user intended. This attack is theoretically possible with any singlesig wallet because the user is relying on the wallet to generate an address for them. There is no way to manually derive addresses from your 12- or 24-word recovery phrase.

A SeedSigner displaying a bitcoin receive address in QR form 

In the case of a multisig wallet, this can be mitigated by checking the address on the signing devices where the multisig has been registered. You could also use another coordinating software, import the same configuration and check the address that way.

Send-To Address Replacement

Like in the previous attack scenario, a multisig coordinator can replace the address you are trying to send funds to while constructing the PSBT. The situation will be no different in the case of a regular singlesig wallet.

A Ledger displaying a send-to address for confirmation 

To mitigate this risk, the user is always advised to check for the address on the signing devices. Since the signing devices sign the transaction containing the recipient’s address (in PSBT format), it will show the address it is signing. Unless there is some collusion between the coordinator app and the signing devices, this is an excellent way to minimize trust in any one of them.

Changing The Change Address

A less-obvious attack is one where a coordinator app replaces the change address in your transaction. This means that the change from the transaction will go to an attacker’s address. Unlike the send-to address, the user may not check for the change address when sending funds, making this attack less obvious. Again, there is no difference when it comes to a singlesig solution.

A Coldcard can register a multisig and store the details for verification 

This is where the registration of multisig on signing devices is highly necessary. If registration is done, the signing device will not sign the transaction if it does not identify the change address.

Altering The Registration

As the coordinator also coordinates the registration step, a different multisig may be registered such that the attacker controls “n” or more keys. In this case, the signing device will not be able to identify the receive address or change the address correctly. The user will see the same (the attacker’s) receive address on the signing device as well, and the change address will be passed as correct by the signing device as it has no way of confirming if the other cosigners were altered or not. 

A three-of-five multisig with sample signing devices, where three hold multisig registration 

It is therefore recommended that there are “n” registered devices in your setup. Moreover, you confirm the setup details on all such devices during registration. Another way to verify proper registration is to set up the same multisig on other coordinator software and check if it shows the exact details.

So, you could have a multisig with one register vault signing device and two blind signers. Repeat the same process with another coordinator. Now, check for the configuration on both the coordinators and the multisig-registering signing device. You can add more coordinators to the mix to rule out collusion.

Ransom Attack

This type of attack is similar to the above one, but the attacker controls fewer than “n” keys, so it cannot control the funds. But in a situation where you lose some of the keys, the attacker can hold you for ransom, as now you do not have the minimum quorum needed. This attack can also be performed by key insertion, where additional cosigners are added to the setup. This has the same effect as replacing some of the cosigners.

A Foundation Devices Passport confirming multisig registration 

Again, checking the cosigner details on multiple registration-needing coordinators will reduce the chances of these attacks.

Utilizing Multisig Custody For Your Bitcoin

To repeat: Having a minimum quorum of multisig-registered signing devices and checking transaction details (when you have to make them) would be a good rule of thumb when using multisig.

When checking for addresses or vault setup details, do not just check the beginning and end of the string, as the attacker may have a similar-looking string.

Checking if the custody app is open source and reviewing its code (if you can) is also a good idea for some. Support of common standards like BSMS and PSBT ensures that the multisig setup or transaction can be ported to other apps for verification.

I also believe one can never go wrong with testing the setup. Once you have your multisig ready, duplicate the setup on more coordinators. Receive a small amount on one app and send a part of it from another. Check that the balances are appropriately reflected across all the coordinators after each step.

Duplicating a multisig setup on another coordinating software 

References and further reading:

  • “10x Security Bitcoin Guide”
  • “How Nearly All Personal Hardware Wallet Multisig Setups Are Insecure”

This is a guest post by Anant Tapadia. Opinions expressed are entirely their own and do not necessarily reflect those of BTC Inc or Bitcoin Magazine.

Read Entire Article
Tags: bitcoinMagzineCryptocurrencyInvestmentMining Bitcoin
Share76Tweet47

Related Posts

Bitcoin Price Crashes Nearly $4,000 in Two Hour Market Sell-Off

Bitcoin Price Crashes Nearly $4,000 in Two Hour Market Sell-Off

by Jon Hartney
January 19, 2026
0

Bitcoin Magazine Bitcoin Price Crashes Nearly $4,000 in Two Hour Market Sell-Off The bitcoin price slid nearly $4,000 in a...

Scaramucci says stablecoin yield prohibition undermines US dollar

by Jon Hartney
January 18, 2026
0

The expanded prohibition on stablecoin yield in the CLARITY Act makes the US dollar less competitive than the Digital Yuan,...

More XRP Than Cash? “You’re A Genius”, Analyst Says

More XRP Than Cash? “You’re A Genius”, Analyst Says

by Jon Hartney
January 18, 2026
0

A sharp comment from a well-known XRP Ledger developer has sparked fresh debate around savings, inflation, and what smart money...

The CLARITY Act stalling is positive for the crypto industry: Analyst

by Jon Hartney
January 18, 2026
0

Overregulation of the crypto industry would negatively impact markets and gut decentralized finance (DeFi), according to Michaël van de PoppeThe...

Ethereum Network Activity Explodes, Market Structure Points To Upside Continuation

Ethereum Network Activity Explodes, Market Structure Points To Upside Continuation

by Jon Hartney
January 18, 2026
0

Ethereum is showing signs of strength on two critical fronts at the same time On-chain activity has climbed to record...

Load More
  • Trending
  • Comments
  • Latest
SUI Price Hits All-Time High – But Questions About Valuation Remain

SUI Price Hits All-Time High – But Questions About Valuation Remain

October 17, 2024
Dogecoin Holder Base Falls To 6-Month Low, But Analyst Believes DOGE Price Is Headed To $10

Dogecoin Holder Base Falls To 6-Month Low, But Analyst Believes DOGE Price Is Headed To $10

October 17, 2024
Solana Targets $160 Resistance As TVL Hits New Yearly Highs

Solana Targets $160 Resistance As TVL Hits New Yearly Highs

October 17, 2024
Bitcoin Price Holds Firm: Can It Power Toward New Gains?

Bitcoin Price Holds Firm: Can It Power Toward New Gains?

October 17, 2024
All aboard! Elon Musk’s Vegas Loop now taking Dogecoin payments

All aboard! Elon Musk’s Vegas Loop now taking Dogecoin payments

0
Crypto owners banned from working on US Government crypto policies

Crypto owners banned from working on US Government crypto policies

0
Korean startup Uprise lost $20M shorting LUNC

Korean startup Uprise lost $20M shorting LUNC

0
Ethereum testnet Merge mostly successful — ‘Hiccups will not delay the Merge.’

Ethereum testnet Merge mostly successful — ‘Hiccups will not delay the Merge.’

0
Bitcoin Price Crashes Nearly $4,000 in Two Hour Market Sell-Off

Bitcoin Price Crashes Nearly $4,000 in Two Hour Market Sell-Off

January 19, 2026

Scaramucci says stablecoin yield prohibition undermines US dollar

January 18, 2026
More XRP Than Cash? “You’re A Genius”, Analyst Says

More XRP Than Cash? “You’re A Genius”, Analyst Says

January 18, 2026

The CLARITY Act stalling is positive for the crypto industry: Analyst

January 18, 2026

XBT.Market

This website is an automated news feed powered by the Nebulome cloud system. The site is made possible by YYC TECH Consulting and Alberta Digital Mining Company. As a team with major crypto and bitcoin enthusiasm, we have curated major sources of news, trading and financial data to bring you, our viewer, an unbiased source of truth.

Recent Posts

  • Bitcoin Price Crashes Nearly $4,000 in Two Hour Market Sell-Off January 19, 2026
  • Scaramucci says stablecoin yield prohibition undermines US dollar January 18, 2026
  • More XRP Than Cash? “You’re A Genius”, Analyst Says January 18, 2026
  • The CLARITY Act stalling is positive for the crypto industry: Analyst January 18, 2026
  • Ethereum Network Activity Explodes, Market Structure Points To Upside Continuation January 18, 2026

News Categories

  • Bitcoin
  • Blockchain
  • Business
  • Market

Tags

bitcoinMagzine Cointelegraph Cryptocurrency insidebitcoins Investment Mining Bitcoin NewsBTC

Quicklinks

  • Home
  • Coins MarketCap
  • Crypto Exchanges
  • Crypto Calculator
  • Top Gainers and Loser
  • News
  • Contact Us

© 2022 Xbt.Market - Powered by YYC Tech Consulting & ADMCO.

No Result
View All Result
  • Home
  • Coins MarketCap
  • Crypto Exchanges
  • Crypto Calculator
  • Top Gainers and Loser
  • News
  • Contact Us

© 2022 Xbt.Market by Nebulome.

  • Steakhouse EURCV Morpho VaultSteakhouse EURCV Morpho Vault(STEAKEURCV)$0.000000-100.00%
  • FibSwap DEXFibSwap DEX(FIBO)$0.0084659.90%
  • TruFin Staked APTTruFin Staked APT(TRUAPT)$8.020.00%
  • bitcoinBitcoin(BTC)$84,372.003.58%
  • ethereumEthereum(ETH)$1,885.365.68%
  • tetherTether(USDT)$1.000.00%
  • rippleXRP(XRP)$2.186.84%
  • USDEXUSDEX(USDEX)$1.07-0.53%
  • binancecoinBNB(BNB)$617.995.03%
  • Wrapped SOLWrapped SOL(SOL)$143.66-2.32%
  • solanaSolana(SOL)$128.974.23%
  • usd-coinUSDC(USDC)$1.000.01%
  • dogecoinDogecoin(DOGE)$0.1736117.78%
  • cardanoCardano(ADA)$0.687.61%
  • tronTRON(TRX)$0.2342340.79%
  • staked-etherLido Staked Ether(STETH)$1,884.065.48%
  • Gaj FinanceGaj Finance(GAJ)$0.0059271.46%
  • Content BitcoinContent Bitcoin(CTB)$24.482.55%
  • USD OneUSD One(USD1)$1.000.11%
  • wrapped-bitcoinWrapped Bitcoin(WBTC)$84,309.003.84%
  • ToncoinToncoin(TON)$4.157.66%
  • UGOLD Inc.UGOLD Inc.(UGOLD)$3,042.460.08%
  • ParkcoinParkcoin(KPK)$1.101.76%
  • chainlinkChainlink(LINK)$14.027.76%
  • leo-tokenLEO Token(LEO)$9.211.17%
  • stellarStellar(XLM)$0.2743585.70%
  • avalanche-2Avalanche(AVAX)$19.647.71%
  • Wrapped stETHWrapped stETH(WSTETH)$2,256.395.40%
  • USDSUSDS(USDS)$1.00-0.01%
  • SuiSui(SUI)$2.429.03%
  • shiba-inuShiba Inu(SHIB)$0.0000137.71%
  • hedera-hashgraphHedera(HBAR)$0.17284810.00%
  • Yay StakeStone EtherYay StakeStone Ether(YAYSTONE)$2,671.07-2.84%
  • polkadotPolkadot(DOT)$4.257.34%
  • litecoinLitecoin(LTC)$85.265.04%
  • bitcoin-cashBitcoin Cash(BCH)$314.248.23%
  • mantra-daoMANTRA(OM)$6.301.94%
  • Pundi AIFXPundi AIFX(PUNDIAI)$16.000.00%
  • PengPeng(PENG)$0.60-13.59%
  • Bitget TokenBitget Token(BGB)$4.664.95%
  • wethWETH(WETH)$1,884.285.66%
  • Ethena USDeEthena USDe(USDE)$1.00-0.04%
  • Binance Bridged USDT (BNB Smart Chain)Binance Bridged USDT (BNB Smart Chain)(BSC-USD)$1.00-0.18%
  • MurasakiMurasaki(MURA)$4.23-13.71%
  • Black PhoenixBlack Phoenix(BPX)$3.351,000.00%
  • Pi NetworkPi Network(PI)$0.714.53%
  • HyperliquidHyperliquid(HYPE)$13.729.80%
  • Wrapped eETHWrapped eETH(WEETH)$2,003.675.53%
  • WhiteBIT CoinWhiteBIT Coin(WBT)$28.350.76%
  • moneroMonero(XMR)$217.841.31%
  • Zypto TokenZypto Token(ZYPTO)$0.037139-3.47%
  • uniswapUniswap(UNI)$6.217.66%
  • AptosAptos(APT)$5.395.79%
  • PepePepe(PEPE)$0.00000811.37%
  • daiDai(DAI)$1.00-0.01%
  • nearNEAR Protocol(NEAR)$2.635.26%
  • XT.comXT.com(XT)$3.08-1.65%
  • Layer One XLayer One X(L1X)$23.35454.66%
  • sUSDSsUSDS(SUSDS)$1.050.05%
  • okbOKB(OKB)$48.762.12%
  • gatechain-tokenGate(GT)$22.883.58%
  • crypto-com-chainCronos(CRO)$0.1015853.46%
  • Coinbase Wrapped BTCCoinbase Wrapped BTC(CBBTC)$84,342.003.68%
  • MantleMantle(MNT)$0.814.44%
  • Tokenize XchangeTokenize Xchange(TKX)$33.460.86%
  • internet-computerInternet Computer(ICP)$5.517.85%
  • ethereum-classicEthereum Classic(ETC)$17.074.81%
  • OndoOndo(ONDO)$0.817.47%
  • First Digital USDFirst Digital USD(FDUSD)$1.00-0.12%
  • aaveAave(AAVE)$168.6110.19%
  • Aerarium FiAerarium Fi(AERA)$7.14-13.11%
  • Ethena Staked USDeEthena Staked USDe(SUSDE)$1.170.30%
  • BSCEXBSCEX(BSCX)$237.310.49%
  • Official TrumpOfficial Trump(TRUMP)$10.354.36%
  • vechainVeChain(VET)$0.0233636.04%
  • cosmosCosmos Hub(ATOM)$4.538.09%
  • fantomFantom(FTM)$0.70-1.56%
  • BittensorBittensor(TAO)$231.277.72%
  • BlackRock USD Institutional Digital Liquidity FundBlackRock USD Institutional Digital Liquidity Fund(BUIDL)$1.000.00%
  • EthenaEthena(ENA)$0.3616194.37%
  • render-tokenRender(RENDER)$3.6710.91%
  • filecoinFilecoin(FIL)$2.927.72%
  • CelestiaCelestia(TIA)$3.181.75%
  • Black AgnusBlack Agnus(FTW)$0.000183423.46%
  • Lombard Staked BTCLombard Staked BTC(LBTC)$84,465.004.02%
  • POL (ex-MATIC)POL (ex-MATIC)(POL)$0.2063993.13%
  • KaspaKaspa(KAS)$0.0682239.38%
  • STAUSTAU(STAU)$0.17397910.95%
  • FasttokenFasttoken(FTN)$4.020.01%
  • Sonic (prev. FTM)Sonic (prev. FTM)(S)$0.5212.98%
  • algorandAlgorand(ALGO)$0.1896979.65%
  • ORA CoinORA Coin(ORA)$4.885.92%
  • ArbitrumArbitrum(ARB)$0.3397526.22%
  • Arbitrum Bridged USDT (Arbitrum)Arbitrum Bridged USDT (Arbitrum)(USDT)$1.000.07%
  • GGTKNGGTKN(GGTKN)$0.1121180.75%
  • kucoin-sharesKuCoin(KCS)$11.231.19%
  • Solv Protocol SolvBTCSolv Protocol SolvBTC(SOLVBTC)$84,076.003.32%
  • fetch-aiArtificial Superintelligence Alliance(FET)$0.4856098.68%
  • optimismOptimism(OP)$0.776.43%
  • StoryStory(IP)$4.75-2.68%