Multisig is a wallet that needs more than one private key to spend. Take 2 of 3 as the example: any two of the three private keys can sign. Lose one and nothing is lost, as long as you keep three backups and the descriptor.
One private key is one point of failure
Holding bitcoin is holding the key to that bitcoin. That key is a private key. A signer, such as a hardware wallet, signs payments with it. Its backup is 12 or 24 words.
Lose the private key, or have it stolen, and the coins are gone. One private key is one point of failure.
What multisig changes
A multisig wallet uses several private keys, each with its own backup. The policy says how many of the private keys must sign. With a 2 of 3 policy, any two of the three private keys can sign.
Lose one signer and nothing is lost. The other two still sign, and you restore the third from its backup.
The three signers can come from different makers. Then a flaw in one maker’s device cannot empty the wallet alone. Multisig is one way to protect bitcoin, not the only way.
The descriptor
The wallet also needs a descriptor: the public keys and some more technical info. That info includes the policy, here 2 of 3, and the script type. Without the descriptor, a new wallet cannot tell which addresses are yours.
Public keys cannot spend. If a descriptor leaks, you lose privacy, not coins: others can see your addresses and balance. Back it up anyway.
Keep four things
Three backups and the descriptor. Lose any one and you can still rebuild the wallet. Lose two and you cannot.
One condition: rebuilding from the three backups only works if you know the wallet settings, meaning the script type and the derivation paths. Write them down next to the descriptor.
Keep them in different places
Spread the four things across different places: home, a bank box, an office. Each signer signs from where it is. A fire or a burglary in one place then cannot take two of the three private keys.
Recreate the wallet using the descriptor
Do it as a test, before you need it. Import the descriptor into a new wallet. Check that its first address matches the original. Then sign a small test payment with two signers.
Importing the descriptor tests only that copy of the descriptor. Also restore each signer from its backup once, and check that its public key matches the one in the descriptor.
What it costs
Multisig removes a single point of failure. Multisig adds complexity: more devices, more backups, more places, more steps to get wrong. It is not for everyone. It is worth it for larger holdings.
Words used here
- Private key: the secret that signs.
- Public key: the partner of a private key. It can receive, but it cannot spend.
- Backup: 12 or 24 words that restore a private key.
- Signer: a device that signs with a private key. It may store the private key or load it from the backup.
- Signature: proof that a private key approved a payment.
- Wallet: the software that tracks your coins and builds payments for your signers to sign.
- Policy: how many of the private keys must sign, such as 2 of 3.
- Descriptor: the public keys plus some more technical info, such as the policy and the script type.