On paper, Bitfinex in 2016 had the strongest custody in the industry: every customer wallet was 2-of-3 multisig, with one key held by the security firm BitGo as an independent co-signer. In August of that year, attackers took 119,756 BTC anyway — because the arrangement was a quorum in name only. The exchange's systems held its keys and the credentials that drove BitGo's automated co-signing, so compromising one organisation produced two signatures. The maths of M-of-N held perfectly; the independence the maths assumed did not exist. That is the whole syllabus of this module in one story: multisig is not a feature you switch on, it is independence you have to actually construct.
The mechanics first. A multisig wallet is controlled by N keys of which any M must sign to spend — "2-of-3" being the household workhorse. Each key lives in its own signing device with its own seed and its own steel backup; the wallet itself is defined by an output descriptor, the recipe naming every co-signer's public key. Any two keys spend. Any one key — lost, stolen, or born of a broken RNG — is worthless alone, and the compromised member is rotated out at leisure while the coins sit unmoved. Every confirmed victim of the 2026 Coldcard sweep was single-signature; the quorum holders watched it on the news.
What you are buying is the deletion of the single point of failure — and Bitfinex shows the purchase can silently fail. Independence has to hold along three axes at once. Vendors: three keys on three manufacturers' devices, so no one company's code, supply chain, or randomness is a shared fate. Places: three keys in three buildings, so no one fire, flood, or burglary meets the quorum. People and systems: no single person — and no single computer — able to produce M signatures. Two keys in one safe is a 2-of-3 in name; one laptop holding a key plus the credentials that drive a co-signing service is Bitfinex. Draw the failure that takes each key, and check no single event appears twice.
Cost it honestly, because the bill is real. Every spend is a small logistics exercise: a PSBT built by a coordinator, carried to M devices in M places, signed, reassembled, broadcast. The descriptor becomes a second class of backup — without it your heirs (or you, after a house move) cannot even see the wallet, so copies belong alongside every key backup; found by a stranger it reveals balances but spends nothing. Fees run slightly higher. And inheritance hardens: your estate must recover M keys, the descriptor, and the understanding, which is why Module 9's worksheet has a multisig section all to itself.
The failure statistics are humbling in the other direction: most real-world multisig losses are self-inflicted — lost descriptors, forgotten key locations, quorums designed by an enthusiast that no survivor can operate. Complexity you cannot confidently rehearse is not security, it is a slower accident. Hence the school's honest ladder: single-sig done well beats multisig done badly; single-sig with a separated passphrase (Module 4) carries most holders a long way; a 2-of-3 across vendors and buildings is the upgrade for life-changing size — if you will actually maintain it. Collaborative-custody services, where a company holds one key of your 2-of-3, soften the logistics in exchange for a standing business relationship and a data trail: read Bitfinex and Module 2's breach lesson before deciding what that trade is worth.
Getting it right is a procedure, not a purchase: start 2-of-3 across three vendors and three buildings; fund it small; rehearse a spend end to end; then rehearse the failure — recover with only two keys, as if one had burned. Write the design down in plain language, store it where your heirs will look, and put the annual review (Module 10) in the calendar. Only when the drill is boring does the quorum hold real size. The printable primer attached to this module carries the whole sequence in checklist form.
INTERACTIVE · THE QUORUM DESIGNER
Design the arrangement; read what it survives.
The maths of M-of-N only protects when independence actually holds — change one decision at a time and watch which failures come back.
The shape
Where keys live
Whose devices
THE SCENARIO BOARD
SURVIVES 0 OF 5One key spends alone, so the burglar who finds it has everything.
One fire meets every key and every backup that shares the building.
One vendor's RNG made the only seed — the 2026 Coldcard scenario, single-sig edition.
One person can be forced to hand over spendable access on the spot.
Losing the key (and its backups) is final.
The board scores structure, not competence — a 2-of-3 you cannot confidently rehearse loses to a single-sig you can. That trade is the module’s closing argument.
FIELD DOCUMENT · PRINTABLE · FREE ACCOUNT REQUIRED
Take this module off-screen.
An A4 handout to print, mark up, and keep with your custody records — seeds and worksheets belong on paper, not screens.
“Trusted third parties are security holes.”
“Security is a process, not a product.”
READING LADDER
Climb at your own pace.
FIELD TEST · SIGN-IN REQUIRED
Take the quiz. Track the curriculum.
The module text is open to everyone: no account required to read. The 3-question field test and the curriculum-wide graduation stamp need a free account so we can record your progress.
SIGN IN TO TAKE THE QUIZFREE · NEW ACCOUNT TAKES 30 SECONDS
