Skip to content
Satnam SatoshiIn service of humanityFind your place ↗
Menu

Sikh Bitcoin · Expert · Lesson 5 of 21

Multisig and independent control

Count independent failure domains, not just signatures.

About 14 minutes with practice. You only need something to take notes with. No real wallet details or payments are part of this lesson.

Course contents · Lesson 5 of 21
  1. Threat model before tools
  2. Design a custody architecture
  3. Entropy, mnemonics and passphrase tradeoffs
  4. Hardware signing and trusted displays
  5. Multisig and independent control
  6. Recovery and continuity across people
  7. Coin control and privacy tradeoffs
  8. Lightning operations and recovery
  9. Payment operations and reconciliation
  10. Native bitcoin and wrapped claims
  11. USDC, reserves and redemption
  12. Identify a Morpho market precisely
  13. Oracles, prices and measurement risk
  14. LTV, liquidation and nonlinear losses
  15. Variable rates and growing debt
  16. Vaults, allocation and exit liquidity
  17. Arc, Base and cross-chain dependencies
  18. Allowances, signing and simulation
  19. Treasury accounting and restricted funds
  20. Incident response with clear human authority
  21. Capstone: a defensible treasury design

What you will learn

  • Analyze availability and compromise in a threshold policy.
  • Identify shared recovery dependencies.

A threshold changes who can spend

A multisignature policy can require a subset of several keys to satisfy spending conditions. In an illustrative two-of-three arrangement, two qualifying signers are needed. This can tolerate one unavailable signer, but compromise of a sufficient subset can still authorize spending. The policy needs exact implementation and recovery metadata.

Independence is operational

Three keys created on one compromised machine or stored in one location may share a failure. Three people relying on one account recovery route may also be less independent than the diagram suggests. Assess devices, locations, software, access procedures and social authority. Adding complexity without competent operators can introduce recovery mistakes.

Exercise both refusal and continuity

A healthy treasury workflow lets a signer refuse an unclear proposal and still recover from a missing coordinator. Practice reconstructing the policy with synthetic material and documenting who can act when a person becomes unavailable. Do not put real seeds in the exercise. A threshold is not an automatic substitute for governance: the people must still know what they are authorized to approve and how decisions are recorded.

Practice on paper

In a fictional two-of-three setup, one signer is unavailable and one refuses because the destination is unexplained. Is the correct response to bypass the refusal?

Reveal the worked answer

No. The remaining technical threshold and the governance purpose are separate. Investigate the proposal and respect refusal; a recovery plan must not become a routine way to defeat an approval control.

Check your understanding

Choose an answer in your head or on paper, then reveal the explanation. Retry whenever you like. Answers are not submitted or scored; completion marks are your own learning notes.

1. Do three keys necessarily mean three independent risks?

  • Yes
  • No
Reveal answer 1

No. Shared devices and recovery routes can correlate failures.

2. Can two compromised keys satisfy a two-of-three policy?

  • Yes
  • No
Reveal answer 2

Yes, assuming they meet the actual script’s conditions. Threshold design does not remove compromise risk.

Take this with you

Independent judgment and recovery matter alongside the threshold.

Your learning, at your pace

Read every lesson freely. Optional progress tracking needs JavaScript and browser storage; it does not require an account or wallet.