Multisig, in practice
Requiring two or three signatures instead of one removes the single point of failure that ends most thefts.
At a glance
- A multisig wallet requires a set number of independent signatures, e.g. two of three, before any transaction executes.
- Compromising one signer's key is no longer enough — an attacker needs to compromise the threshold, not one device.
- The trade-off is speed and coordination: every transaction now needs multiple people or devices to act.
A standard wallet has one private key, and whoever holds it can move every asset the wallet controls. A multisig wallet replaces that single key with several, and requires a set threshold of them — commonly two of three, or three of five — to sign before any transaction is valid.
The practical effect is that compromising one signer no longer ends the story. An attacker who steals one of three keys still cannot move anything; they need to compromise the threshold, which is a materially harder and slower operation than phishing a single device.
This is why multisig is the default for anything shared — a company treasury, a DAO's funds, a fund's cold reserves. The keys are typically distributed across different people, different devices, and sometimes different physical locations, so that no single point of failure, human or technical, can authorise a transfer alone.
The cost is coordination. Every transaction needs multiple people to be available and to actually verify what they are signing, which is slower than a single signer clicking approve — and that slowness is, by design, the entire security benefit.
| Single key | Multisig | MPC | |
|---|---|---|---|
| Single point of failure? | Yes | No | No |
| Signers required | One | A threshold, e.g. 2 of 3 | A threshold, computed jointly |
| If one key is lost | Funds are gone | Remaining signers can act | Remaining shares can act |
Key terms
- Multisig
- A wallet requiring a threshold of independent signatures before a transaction executes.
- Threshold
- The number of signatures required out of the total set of keys, e.g. two of three.
- MPC
- Multi-party computation — an alternative to multisig that splits one key mathematically rather than using several.
Frequently asked
Is multisig only for companies and DAOs?
No — individuals use two-of-three setups for personal holdings too, often splitting keys across different devices or trusted parties.
What happens if too many signers lose their keys?
If the number of remaining accessible keys falls below the threshold, the funds become permanently inaccessible — the same trade-off that provides security also creates this risk.
Is MPC better than traditional multisig?
They solve the same problem differently — MPC can be cheaper and more private on some chains, while multisig is more transparent and battle-tested on others.