A multisig wallet won’t move a single coin until more than one key signs off. Setting one up comes down to a few decisions: how many keys you create, how many of them have to approve a payment, and which devices end up holding them.
Regular wallets live or die by one seed phrase. Multisig takes that single point of failure away, so anyone who pinches one device or stumbles on one backup still can’t touch your coins, and a lost gadget stops being a catastrophe.
Below, we cover how it works, where it breaks, and the actual setup in Sparrow, Electrum, COLDCARD, Safe{Wallet} and Casa.

Table of contents
So what is a multisig wallet?
Multi-signature, or multisig, describes a wallet that asks for several separate approvals before anything leaves it. Bitcoin.org puts it as a feature that lets a transaction “require multiple independent approvals to be spent.”
You’ll see every setup written as M-of-N, which people also call the quorum.
N counts the keys in total, and M is the number that has to sign. So a 2-of-3 wallet has three keys, and any pair of them can approve a payment.
Picture it in real life. One hardware wallet sits in your home, another at a relative’s place, and the third in a safe deposit box at the bank. Spending takes any two of them; if one goes missing or gets stolen, the coins don’t budge, and the remaining pair still lets you spend.
Setup screens throw a handful of terms at you:
- Each cosigner, sometimes just called a signer, is one key holder, and in most setups that’s a hardware wallet with a seed phrase of its own.
- An xpub, or extended public key, is the public side of a cosigner’s key. The wallet stitches all of them together to make addresses, and because an xpub can’t sign, it can’t spend anything.
- The app that joins those keys into a single wallet and puts transactions together is called the coordinator, a job Sparrow, Electrum and Safe{Wallet} each handle.
- Your output descriptor is a short piece of text recording the entire wallet (the keys, the script type and the derivation paths) in a format laid out in BIP-380.
- A PSBT, short for partially signed Bitcoin transaction, hops from one signer to the next until it’s collected enough signatures. BIP-174 is the spec.
- Safe calls M the threshold.
How does a multisig wallet actually work?
Bitcoin has multisig baked into its transaction rules. Gavin Andresen’s BIP-11 turned M-of-N transactions into a standard type back in 2011.
Ethereum does it differently. There, a multisig is a smart contract account (a Safe, for instance) that tallies approvals from its owners.
On the Bitcoin side, the sequence runs roughly like this:
- Every cosigner generates a seed phrase of its own, on its own device.
- The devices hand their xpubs over to the coordinator app.
- From those xpubs and the quorum you chose (2-of-3, say), the coordinator builds one wallet, and an output descriptor records it.
- Next, you register the wallet on every hardware device so each one can check addresses and change outputs for itself.
- When it’s time to spend, the coordinator drafts a PSBT, and signers add their signatures one after another until the quorum’s reached.
- Finally, the coordinator (or whichever device signs last) finalizes the transaction and broadcasts it.
If an analogy helps, think of a vault that won’t open until two managers turn their keys together. Nobody gets in alone, and one manager calling in sick doesn’t shut everybody out.
Safe follows the same logic on Ethereum, with owners confirming transactions inside the Safe{Wallet} app. Its documentation describes the threshold as “the number of required confirmations from the Safe owners a (Safe) transaction must have to be executable.”

Why bother with a multisig wallet?
With single-signature wallets, the seed phrase is everything: whoever has it has the coins.
Multisig splits that risk up. According to Bitcoin.org, it can stop “a thief from stealing funds by compromising a single device or location.”
Loss is covered too, since a 2-of-3 setup lets you lose a key and keep spending. That said, multisig has failure modes of its own, and we’d want to understand them before parking a big balance in one.
When the wallet configuration goes missing
This is the one we worry about most. Your seed phrases, on their own, won’t bring back a Bitcoin multisig; COLDCARD’s documentation says “the M-of-N policy, co-signer XFP/XPUBS, derivation path and address type must be known” to rebuild it.
Lose that record along with one seed and you’re in real trouble. The two seeds you still have can’t recreate the wallet, because nothing tells them the third xpub.
When the signing screen lies
No quorum helps if every signer is looking at the same poisoned screen.
The FBI says North Korea took “approximately $1.5 billion USD in virtual assets” from Bybit, a crypto exchange, on or about February 21, 2025. A week later, on February 28, 2025, the Safe Ecosystem Foundation traced the attack to “a compromised Safe{Wallet} developer machine resulting in the proposal of a disguised malicious transaction.”
Safe added that outside researchers didn’t find vulnerabilities in its smart contracts or source code. In other words, the multisig worked exactly as designed, and the signers approved a transaction dressed up as something else.
When the contract itself breaks
Multisigs built on smart contracts are only as sound as their code. Back on November 6, 2017, someone opened a GitHub issue in Parity’s repository that read simply “I accidentally killed it,” after destroying the library contract Parity’s multisig wallets were built on.
Mistakes no quorum can fix
Keep in mind that multisig guards your keys; it doesn’t guard your transfers. Send to the wrong address or over the wrong network and the money’s gone for good, with nobody able to reverse it.
We’d only ever send to an address the coordinator produced and you’ve confirmed on the device screens.
Setting up a multisig wallet, step by step
Which route you take depends on the chain. Bitcoin users pair hardware wallets with a coordinator app, while Ethereum and other EVM chains mean deploying a Safe.
For more options side by side, see our roundup of the best multisig wallets.
| Tool | Chain | Where the keys live | What setup looks like |
|---|---|---|---|
| Sparrow Wallet | Bitcoin | On your hardware wallets, or as software keys | You switch Policy Type to Multi Signature, then import a keystore per cosigner |
| Electrum | Bitcoin | In software seeds, or on hardware wallets via add-ons | Each cosigner hands over a master public key |
| COLDCARD | Bitcoin | Across as many as 15 cosigners | Wallets get registered in Settings > Multisig Wallets |
| Safe{Wallet} | Ethereum plus other EVM chains | Owners can be any Ethereum address or ENS name | You pay gas to deploy, and a multisig Safe can’t skip it |
| Casa | BTC, ETH, USDT, USDC | With you, as Casa says it doesn’t hold customer funds | A 3-key vault starts at $250/year (September 2026), and a 5-key vault runs $2,100/year |
First, choose a quorum and your devices
Sparrow’s best-practice guide suggests “at least a 2-of-3 multisig setup” for cold storage, and it wants those hardware wallets to come from different vendors so that one company’s bug can’t expose every key at once.
Spread the devices, and their seed backups, across separate locations.
On a budget? You could combine a Trezor Safe 3 with a Ledger Nano S Plus, both $59 at the time of writing (September 2026), and add a third device from some other maker. Our Ledger vs Trezor head-to-head and our best Bitcoin hardware wallet list should help narrow it down.
Building a Bitcoin multisig in Sparrow
Over USB, Sparrow talks to “Trezor, Ledger, Coldcard, BitBox02, Blockstream Jade, KeepKey and OneKey.” Airgapped devices work as well, through SD cards and QR codes.
- Go to File > New Wallet and give it a name, then switch Policy Type to Multi Signature and choose a Script Type (Native Segwit is a sensible default).
- Use the Cosigners and M of N settings to get a 2-of-3 quorum.
- For every cosigner, pick Connected Hardware Wallet, hit Scan… and then Import Keystore. SD card and QR devices go through Airgapped Hardware Wallet instead.
- Hit Apply and the wallet’s created. Give it a strong password you don’t use anywhere else, which is what Sparrow’s guide recommends.
- In the wallet settings, find the Descriptor field and use Export… to save it, then tuck a copy in with each seed backup.
- Register the wallet on each hardware device too (on a COLDCARD that’s Settings > Multisig Wallets > Import).
- Press Get Next Address and confirm it on every device’s screen before you deposit anything.
Start with a small test amount. Then send it back out using two devices, which proves the signing flow works before any serious money lands there.

Building a Bitcoin multisig in Electrum
Electrum lists multisig among its headline features, and its documentation takes you through a 2-of-2.
- Go to File > New and pick “Multi-signature wallet.”
- Choose your quorum, such as “2 of 2.”
- Create your seed and put it somewhere safe.
- Swap master public keys with your cosigner, pasting theirs into the lower box.
From there, both wallets produce identical addresses.
Spending starts with one cosigner, who builds and signs the transaction on the “send” tab. That half-signed file then travels to the other cosigner on a USB stick, as a QR code or through the Cosigner Pool plugin, and they press “sign” and broadcast it.
There’s no spare key in a 2-of-2, which bothers us. If either seed is lost the coins are stuck, so we’d go with 2-of-3 for savings.
Creating an Ethereum multisig with Safe{Wallet}
According to Safe’s help center, the whole thing “takes just 60 seconds.” You’ll want some ETH (or whichever native coin the chain uses) in the wallet you connect, since deploying costs transaction fees.
- Head to app.safe.global; Safe suggests using Google Chrome.
- Connect a signer wallet. We’d use a hardware wallet address here rather than a key that only lives in the browser.
- Give the Safe a name, which stays on your own computer.
- Add the other signers, either by pasting an Ethereum address or typing an ENS name.
- Pick the threshold, meaning how many confirmations every transaction or settings change will need.
- Look everything over and choose “Pay now” to deploy.
There’s a “Pay later” option that avoids gas up front, which sounds nice until you read the fine print: “Multisignature Safes can’t be created gaslessly for now.”
Before you approve anything, Safe{Wallet} can run the transaction through a Tenderly simulation and a Blockaid scan. Blockaid flags potential risks in yellow and known threats in red.
Prefer a hand? Casa’s managed multisig
Casa sells guided multisig for people who’d rather not do it all themselves. The Standard plan runs $21/month or $250/year at the time of writing and includes “3-key vaults to secure BTC, ETH, USDT, and USDC.”
Step up to Premium and you’re paying $175/month or $2,100/year for 5-key vaults, plus a box with “3 hardware devices, Faraday bags, and more.” At the top, Private Client costs $9,100/year.
Casa states that it “does not hold, control, or transmit customer funds,” so this remains a non-custodial arrangement.
Habits that keep a multisig wallet safe
- Go with 2-of-3 at minimum, since it survives a single lost or stolen key.
- Buy each cosigner device from a different company, which is Sparrow’s advice too.
- Keep every device, and its seed backup, somewhere different from the others.
- Save the output descriptor or wallet file alongside each seed backup. It can’t spend anything, but recovery isn’t possible without it.
- Register the wallet on all your hardware devices, because a registered COLDCARD will check change outputs against that setup.
- Confirm each receive address on the device screens and not only on your computer.
- Do a small test deposit, a test spend and a dry-run recovery before your savings go in.
- With Safe, read every transaction on the hardware wallet itself and take Tenderly and Blockaid warnings seriously.
Multisig wallet mistakes worth avoiding
- Only backing up the seed phrases is the classic one. Without the descriptor or the xpubs, losing one key can make the others useless, so store the configuration with every seed.
- Putting all the keys in the same drawer means a single fire or break-in beats the whole setup. Spread them out.
- Three devices of one model share one firmware, and a bug there could hit every key. Mixing vendors avoids that.
- A 2-of-2 for long-term savings locks you out the moment either key disappears. A third key fixes it.
- People skip the recovery test and discover the gaps when it’s already too late. Restore the wallet on a spare setup before you fund it.
- Trusting what the computer shows is how Bybit’s signers ended up approving a disguised transaction. Read the details on each device instead.
Multisig wallet FAQ
What’s the best multisig setup if it’s just me?
Usually 2-of-3, with hardware wallets from different vendors kept in different places. That’s also the minimum Sparrow recommends for cold storage.
Do I need hardware wallets for multisig?
No. Sparrow and Electrum will both take software keys, but hardware signers keep every private key off your computer, which is why we’d use them.
What does it take to recover a multisig wallet?
You need enough seed phrases to meet the quorum and the wallet configuration as well. COLDCARD lists the M-of-N policy, the cosigner fingerprints and xpubs, the derivation path and the address type as things that must be known.
What does a Safe multisig cost to create?
Just the network gas fee for deployment. Safe says multisignature Safes can’t be created gaslessly for now, so leave some native coin, such as ETH, in the wallet you connect.
Can I swap signers out later?
Yes on Safe, where settings changes need the same threshold of confirmations as a transaction. A Bitcoin multisig is different: replacing a key usually means building a new wallet and moving the coins over, and Casa offers guided replacement if a key is lost or stolen.
Will multisig protect me from phishing or fake transactions?
Not by itself. During the February 2025 Bybit attack, signers approved a disguised transaction, so read the details on every hardware wallet screen before you sign.
How many cosigners will a COLDCARD take?
15 at most, in any M-of-N combination.
Wrapping up your multisig wallet setup
Most of the work in setting up a multisig wallet is four decisions: quorum, devices, coordinator app and backups.
On Bitcoin, Sparrow’s suggested starting point is a 2-of-3, and you can build it in Sparrow or Electrum with devices from mixed vendors. Ethereum users get the same result from Safe{Wallet}, which does the job with a smart contract.
Whichever way you go, back up the wallet configuration, check addresses on the devices themselves, and rehearse a recovery before real money goes in. Skipping that last step means trusting a setup you’ve never tested, and we wouldn’t.
This article is for general information only and is not financial, legal, or investment advice. Prices and features change; check the vendor’s official page before buying.



