Nostr'a Katılın
2026-07-31 21:42:07 UTC

Decentralized on Nostr: An unpopular opinion, offered as exactly that, a personal one. A lot of people are ...

An unpopular opinion, offered as exactly that, a personal one.
A lot of people are saying this week that multisig is the answer.

Let me concede the strongest version of that argument up front: multisig across different manufacturers would have protected every single person affected by this. That's true, and it matters.

But here's what I keep coming back to.
Multisig doesn't remove a single point of failure. It trades one for another.
Lose your descriptor, the file holding every participant's xpub, the script type, the derivation paths, and your funds are gone even if all three seeds are sitting safely in your hands.
Two of three seeds without a descriptor is not a recoverable wallet.
Most people who set up multisig back up their keys religiously and their descriptor nowhere.
So the honest question isn't "is multisig more secure?"
It's "more secure for whom, set up by whom, recoverable by whom in five years?"
For someone who has never done a full recovery, a well-generated seed with a strong passphrase, backed up in metal, split across locations, beats a multisig they don't fully understand.
Not because multisig is worse, because a setup you can't operate isn't a setup, it's a liability with extra steps.
And if you're going to use a passphrase: back it up physically, separately from the seed. Never rely on memory.
A typo produces a valid, empty wallet, not an error message.

The real lesson from this week isn't multisig. It's independent failure domains. Don't let one manufacturer's mistake reach all your keys. Dice-generated entropy does that.
A passphrase does that. Multisig across vendors does that. Pick the one you can actually execute.

Start at kilometre zero. Nobody walked a thousand in a second.