How do multisig and inheritance planning change the key problem?
A single key is a single point of failure in both directions at once: lose it and the asset is gone, leak it and the asset is gone. Multi-signature arrangements are the first structural answer to that, and they work by refusing to let one event be decisive.
What m-of-n buys you
A multisig spending condition requires m valid signatures out of n keys. The common configuration is 2-of-3, and its properties are worth stating precisely:
- Any one key can be destroyed and the funds remain spendable with the other two.
- Any one key can be stolen and the thief can do nothing, because one signature is not enough.
For the first time, loss and theft stop trading off against each other. That is the entire point, and it is why institutional setups are quorum-based without exception.
Two implementations dominate. Script-level multisig puts the quorum in the chain's own spending rules — visible on chain, verifiable by anyone, and enforced by the network. Threshold signatures (MPC) split key material so that no whole key ever exists, and produce an ordinary single signature; cheaper and more private, but the quorum is enforced by a software protocol rather than by the chain, so you are trusting an implementation you usually cannot inspect.
Complexity is its own risk
A 2-of-3 has three key locations, three backup procedures, three ways to be wrong — and one artefact people routinely forget.
To rebuild a multisig you need more than the seeds. You need the wallet configuration: which public keys, which quorum, which derivation paths, which script type. Lose that description and you can hold every seed and still be unable to reconstruct the addresses. It is the most under-documented single point of failure in otherwise careful setups, and the fix is trivial: store the configuration wherever you store the seeds, and prove it works by restoring from it.
The general rule is uncomfortable: each layer of protection adds a procedure, and procedures fail. A quorum you cannot execute under stress, at 2am, without the person who designed it, is not a quorum.
The largest theft on record needed neither a lost key nor an insolvent venue. On 21 February 2025 Bybit moved about 401,000 ETH, roughly $1.5 billion, out of a cold multisig during a routine transfer. The signers used hardware devices and saw a correct-looking transfer in the wallet's web interface; the interface had been altered upstream, and what they signed replaced the wallet's logic. The FBI attributed the theft to North Korea's Lazarus group. Bybit stayed solvent and kept withdrawals open. For a quorum the lesson is exact: hardware protects the key, not the meaning of the payload, and a 3-of-5 whose signers all read one compromised screen is a 1-of-1. Verify the payload independently of the interface.
The problem nobody plans for
There is no registry, no probate hook, no bank to write to. If you die and nobody else can produce the signatures, the asset does not pass to your estate — it stops existing for all practical purposes, while remaining permanently visible on a public ledger.
The planning problem is a timing problem: the information must be unavailable now and available later, and every mechanism for that is a trade-off. Sealed instructions with an executor rely on the executor. Timelocked scripts that allow a backup key to spend after a delay rely on the delay being right. Splitting a quorum between a beneficiary and a professional adds a counterparty. Automated "dead man's switch" services add a company that must still exist when it is needed.
What every workable plan has in common is more boring than any of the mechanisms: someone must know the asset exists, and where the instructions are, without knowing the secret itself.
The case that is usually told wrong
QuadrigaCX, a Canadian exchange, told customers after its founder Gerald Cotten died in December 2018 that it could not access roughly C$190m held in cold storage, because he alone controlled the keys. The story circulated as the definitive lost-keys tragedy.
The Ontario Securities Commission's staff review, published in April 2020, found something different. Most of the shortfall owed to clients — approximately C$169m — arose from the founder's own trading with client assets and from balances credited in the platform's internal ledger that were never backed by real deposits. The keys were part of the story; the deficiency was not created by losing them.
Two lessons, both durable. Single-person key control is a genuine failure mode — no serious operation should have one. And "we lost the keys" is a claim, not a finding. An assertion about missing assets that cannot be independently verified against the chain and the books is exactly the situation the rest of this unit exists to detect.
Try it now
- Write your own quorum on one page: how many keys, held where, by whom, what quorum spends, and what happens if each single holder is unavailable. If a competent stranger could not follow it, it is not a plan.
- If you use a multisig, confirm you have stored the wallet configuration alongside the seeds — then prove it by restoring the wallet from the configuration plus m seeds on a spare device.
- Write the "if I am not here" note: what exists, where the instructions are, and the first thing one named person should do. The note must never contain the secret itself.