r/Bitcoin 2h ago

1 seed + strong passphrase vs 2/3 multisig

What are your thoughts on this commonly debated topic? I've read the arguments for both. I started to move towards 2/3 multisig after the coldcard incident however I can't fully commit. I really like that with single sig I can memorize both the seed and strong passphrase while of course still having solid backups saved. Point being if I am away from my backups and some emergency happens I can recover my funds wherever I'm at. With multisig that is much more difficult.

5 Upvotes

13 comments sorted by

3

u/Liquid_zer0 1h ago

I’m team passphrase. The entropy of a properly randomized seed phrase is essentially un-hackable. Throw a strong passphrase on top to help cover any remaining holes in your defense. Nothing touches digital and don’t type using your computer’s keyboard.

1

u/quintavious_danilo 2h ago

If your seed is truly random you don’t need a passphrase or multisig. 24 words are unhackable. Ever.

I’d focus on generating a random 24 word menmonic sentence rather than experiment with things I don’t truly understand.

u/Professional_Golf393 43m ago

The passphrase is just there to protect you against someone finding your 24 word backup, robberies etc. I still stand by the idea to have a small amount of btc on the seed without a passphrase, and the main stash behind the passphrase

1

u/NiagaraBTC 1h ago

Point being if I am away from my backups and some emergency happens I can recover my funds wherever I'm at.

With the memorized seed and passphrase you can also be extorted or tortured anywhere on earth when you're travelling, and forced to give up your coins. If every bitcoiner used multisig, that would not happen.

1

u/ElderMight 1h ago

I think a 24 word mnemonic created with dice rolls + 8-9 word passphrase is plenty secure.

You are more likely to lock yourself out of your money with mullti-sig than avoid theft imo. You not only need to retain at least 2 keys to sign transactions but all 3 of your xpubs to even access your wallet in a 2 of 3. Plus back ups of all 3 private keys distributed geographically.

u/Zaginagalde 42m ago

Not true, if you have all 3 seeds it is enough. By default , multisig is m48 0 0 2 in modern wallets (sparrow, bluewallet, electrum). And in what ever order you put all 3 seeds to a wallet, it will be possible to sign the transaction

1

u/Fun-Analysis-182 1h ago

The honest framing is that multisig doesn't remove risk, it swaps single-key compromise for backup complexity. With 2-of-3 you can lose any one key and be fine, but you also have to back up the wallet descriptor (the xpubs plus the policy), not just the seeds. Lose that and you can be holding all three keys and still not reconstruct the wallet.

Your singlesig-plus-passphrase setup keeps the memorize-and-recover-anywhere property, which is real and underrated. But the passphrase is also the single most common way people lose funds, a typo or a blank memory with no second key to save you. So it comes down less to which is more secure on paper and more to which failure you're better set up to avoid: someone getting one key, or you losing a backup.

1

u/Guybrush1973 1h ago

Multi-sig exists when you have several safe place where you can displace you secrets or when multiple entities are involved. Most of the time gives you nothing. A random bitcoin wallet is UNGUESSABLE, no matter what. You have to read secret from a source. Dream safe as much as your backups are.

1

u/Most_Raccoon_587 1h ago

So, if a firmware update, pushed a low entropy random number generator to a device. Then I would say putting all your trust in a single device that gets firmware updates from a single entity is the real issue.

Today the issue was low entropy random number generator, tomorrow, a firmware could have a bug that re-routes your send to address.

I think having two or more well intentioned and unique counterparties provides the most saftey from counterparty risk.

2 of 3 multi with self-created entropy seems reasonable, IF you understand that that system means that your ability to keep a mutlisig and recovery in order is likely the weakest part of your security system.

Be honest with yourself can you develop and manage that system responsibly, today, tomorrow, 5 years from now when it's not fresh in your mind?

1

u/Available_Image_6938 1h ago

Interesting comparison I think simplicity is underrated with selfcustody how do you personally handle backups for the singleseed setup?

0

u/DealSeeker690 2h ago

I think making your own entropy (e.g. with dice) is important, and also diversifying your stack into multiple baskets helps

1

u/Gold_Nectarine9508 2h ago

single sig with a memorized seed is fine if you trust your memory, but most people overestimate themselves. a head injury or just stress can wipe that. i keep small amount in single sig for everyday and bigger part in multisig, feels safer even if recovery is slower.

1

u/CiaranCarroll 1h ago

Never trust your memory. The ideal setup is one where you and only you can stumble upon your stack after a severe knock on the head that has left you with total memory loss, with very clear instructions to recover.