What is a multisig wallet?
A multisig wallet needs approval from several separate keys before funds can move, so one stolen or lost key is not enough.
A multisig wallet, short for multi-signature, is a wallet that requires more than one key to approve a transaction. An ordinary wallet is controlled by a single private key, a secret number that authorizes spending. A multisig spreads that control across several keys, so no single one can move the funds alone.
How does a multisig wallet work?
A multisig is described by two numbers: how many keys exist and how many must sign. A "2-of-3" wallet has three keys and needs any two. A "3-of-5" has five and needs any three.
To make a payment, one key holder proposes a transaction and signs it. The others review it and add their signatures. Once the required number is reached, the network accepts the transaction.
Bitcoin supports this directly in its rules. On Ethereum and similar networks, a multisig is a smart contract, a program stored on the blockchain that holds the funds and releases them only when enough approved signers agree. Safe is a widely used example.
Who uses multisig wallets?
- Companies and funds use them so that no single employee can move the treasury, and so that one departure or compromised laptop is not a crisis.
- DAOs, which are organizations run by token holders, commonly keep shared funds in a multisig controlled by chosen signers.
- Exchanges and custodians use multisig or similar key-splitting methods for their reserves.
- Careful individuals use setups such as 2-of-3, with keys on separate hardware wallets kept in different places. One key can be lost or stolen without losing the funds.
What are the drawbacks?
Multisig is more work. Every key needs its own secure backup, usually a seed phrase, and the owner must also keep a record of how the wallet was set up. If too many keys are lost, the funds are locked for good. On smart contract chains, a multisig costs more in fees and adds the risk of a bug in the contract code.
Can a multisig still be hacked?
Yes. Requiring several signatures protects against one stolen key. It does not help if every signer is deceived at once.
On or about February 21, 2025, the exchange Bybit lost roughly $1.5 billion in crypto from a multisig wallet. According to published accounts of the investigation, attackers had tampered with the web interface the signers used. The signers believed they were approving a routine transfer and in fact approved a transaction that sent the funds to the attackers. The FBI attributed the theft to hackers working for North Korea. It ranks among the largest crypto hacks on record.
Security researchers drew a plain lesson from the episode. A multisig is only as strong as each signer's ability to check, independently, what they are actually signing.
This guide explains how things work. It is not financial, legal or tax advice. Last updated .