Skip to content
Satnam SatoshiIn service of humanityFind your place ↗
Menu
Lesson 05 / 21 · Expert

Multisig and independent control

Count independent failure domains, not just signatures.

14 MIN WITH PRACTICEREAD → TRY → REFLECTNO WALLET NEEDED

By the end, you’ll be able to…

  • Analyze availability and compromise in a threshold policy.
  • Identify shared recovery dependencies.
The idea, at a glance

Two signatures. Independent failure paths.

A + BCan meet a 2-of-3 threshold
A + CCan meet the same threshold
B + CCan meet the same threshold
Assumes valid signatures from distinct keys under the actual policy. A signing threshold is not proof of human authorization or recovery readiness.

A threshold changes who can spend

A multisignature policy can require a subset of several keys to satisfy spending conditions. In an illustrative two-of-three arrangement, two qualifying signers are needed. This can tolerate one unavailable signer, but compromise of a sufficient subset can still authorize spending. The policy needs exact implementation and recovery metadata.

Independence is operational

Three keys created on one compromised machine or stored in one location may share a failure. Three people relying on one account recovery route may also be less independent than the diagram suggests. Assess devices, locations, software, access procedures and social authority. Adding complexity without competent operators can introduce recovery mistakes.

Exercise both refusal and continuity

A healthy treasury workflow lets a signer refuse an unclear proposal and still recover from a missing coordinator. Practice reconstructing the policy with synthetic material and documenting who can act when a person becomes unavailable. Do not put real seeds in the exercise. A threshold is not an automatic substitute for governance: the people must still know what they are authorized to approve and how decisions are recorded.

Your turn / A paper experiment

Practice on paper

In a fictional two-of-three setup, one signer is unavailable and one refuses because the destination is unexplained. Is the correct response to bypass the refusal?

I’ve tried it — show the worked answer

No. The remaining technical threshold and the governance purpose are separate. Investigate the proposal and respect refusal; a recovery plan must not become a routine way to defeat an approval control.

Want to explore with buttons and instant feedback? Try the practice lab ↗

Think it through

Make a choice. Discover why.

Choose an answer and check the explanation. You can retry as often as you like. These are practice questions, not a test of mastery; answers are not saved or sent.

1. Do three keys necessarily mean three independent risks?
  • Yes
  • No
Read the explanation

No. Shared devices and recovery routes can correlate failures.

2. Can two compromised keys satisfy a two-of-three policy?
  • Yes
  • No
Read the explanation

Yes, assuming they meet the actual script’s conditions. Threshold design does not remove compromise risk.

One idea to take with you

Independent judgment and recovery matter alongside the threshold.

Your learning, at your pace

Read every lesson freely. Optional progress tracking needs JavaScript and browser storage; it does not require an account or wallet.