The ever-present risk of relying on one key.

Most bitcoin holders know the compromise. One key is convenient, but it makes backup and signing hygiene do all the work. Cobault makes 2-of-3 multisig practical: chain-native, verifiable, no lock-in, and free during launch.

The situation

The compromise most holders make

Most self-custody starts with one device and one seed phrase. Everyone who has used that setup knows the bargain: it is simple, but the backup discipline matters, and the backup itself is sensitive.

That is the compromise most holders accept for convenience. If the seed and device are unavailable, no one can help. If someone gets the seed, or if the device signs the wrong transaction, the bitcoin can move.

Bitcoin ownership has still been worth that trade-off. The alternatives have often felt like overkill for an asset you mostly hold: expensive custody on one side, or a self-managed multisig setup that creates new ways to make a mistake.

Convenient multisig changes that. You can reduce single-key risk without giving a key to Cobault, wrapping the bitcoin, or building the setup yourself from scratch.

The usual answer

Why backups alone are not the same thing

More care around the same key still has a place: another seed backup, a metal plate, a second device.

That helps with loss. It also creates more places where the same key can leak. It is still single-key custody, just managed more carefully.

The mechanism

How multisig shared vaults help

A shared vault is a standard bitcoin multisignature address. Instead of one key, the vault has several. You choose how many must sign before bitcoin can move.

Cobault coordinates the setup and signing. It helps create the vault, connect the keyholders, collect signatures, and show the signing progress. The vault itself is standard bitcoin multisig.

In a 2-of-3 shared vault, there are three keys and any two are needed to spend. If one key is lost, the other two can move the bitcoin to a new vault. If one key is compromised, it still cannot spend alone.

The quorum matters. In a 3-of-3 vault, every key must sign. If one key is lost, the vault is frozen. Cobault tells you when you choose a quorum with no lost-key tolerance, but the choice is yours.

A setup that works

A common personal setup

For a personal vault, a practical 2-of-3 setup is:

  1. A low-friction key for everyday signing, such as a social-login key.
  2. A Ledger hardware-wallet key for deliberate approval.
  3. A Cobault browser-agent seed phrase kept offline as the backup key.

Use separate logins for the three keys, ideally across more than one email provider. Any two can sign. For a normal spend, that can be the low-friction key plus Ledger. If one key is lost, the other two can move the bitcoin to a new vault. If one key is compromised, it is not enough to spend.

Set up this way, the shared vault can become your main vault. For most spends, the added step is another approval you control, not a new custody process. The current flow takes about five minutes.

During launch, shared vaults are free to set up. Vaults created during the launch window stay free.

How it works

  1. Choose 2-of-3.
  2. Add your three keys: social login, Ledger, and browser-agent backup seed.
  3. Create the claim links and open each one from the right login or device.

When all keyholders have accepted, each participant checks the final roster, quorum, and address. Once everyone acknowledges the same vault, it becomes active and its address is fixed. To spend, one keyholder proposes a transaction. The others review it and sign. When enough signatures are collected, the transaction is broadcast to the bitcoin network.

Verify it yourself

P1The holder keeps a key

In a standard shared vault, Cobault holds no key. Each signing key stays with the login, device, or seed phrase that created it. Cobault does not receive a private key, cannot sign, and cannot move your bitcoin if we are breached, compelled, or unavailable.

How keys are generated
P2An ordinary bitcoin address

The vault is a bitcoin address. You can check its balance and transactions in a block explorer. The explorer-verification guide should show how to match that address to the vault details and how to read the transaction record.

Explorer-verification guide — publishing soon
P5Recover without Cobault

Your vault is recoverable without Cobault if enough keyholders have their seed phrases and recovery kits. The recovery kit is downloaded at activation. It contains the vault details needed to reconstruct the vault address and signing path, including the quorum, participant roster, network, and derivation information. It does not contain anyone's seed phrase and cannot sign by itself.

The shared-vault recovery guide
Limits

Limits to understand

  • It does not remove the need to back up your seed phrase or recovery kit. If you lose your seed, you lose your key. If you lose the recovery kit, a seed-only restore may not reconstruct this shared vault.
  • It does not protect a 3-of-3 vault from a lost key. A vault that needs every key has no lost-key tolerance.
  • It does not make the vault yours alone if other people hold keys. In a 2-of-3 vault, any two keyholders can spend. Choose keyholders accordingly.
  • It does not hide the vault. The address, balance, deposits, and spends are visible on the public bitcoin network.
  • It is not custody. Cobault is coordination software, not a bank, deposit-taker, or custodian. Bitcoin in a vault is not covered by a government guarantee or compensation scheme.
  • It does not enforce spending rules. Policy vaults are provided for by the standard Cobault implements, but they are not yet available.

Next step

Or read the walkthrough first: setting up a personal 2-of-3 vault. Publishing soon.

Real control isn't fragile.