Skip to main content

Which Custody Model Fits My Threat Model?

There is no universal "best" way to hold bitcoin. The right custody model depends on your technical ability, value at stake, threat model, and need for recovery or inheritance. This page walks through the decision process.

Bottom line: Start simple. Upgrade custody as your balance and competence grow. A hardware wallet you use correctly beats a multisig you set up incorrectly.

Quick Decision Flow

How much bitcoin are you securing?
|
├── < $1,000 → Mobile hot wallet (Blockstream Green, Blue Wallet)
│ Acceptable risk for small amounts; focus on learning
|
├── $1,000 – $50,000 → Single-sig hardware wallet
│ ColdCard, Trezor, or Ledger + steel seed backup
|
├── $50,000 – $250,000 → Multisig (self-hosted or collaborative)
│ 2-of-3 with 2 hardware wallets + seed backup in separate location
|
└── > $250,000 → Collaborative custody or 3-of-5 multisig
Casa, Unchained Capital, or Specter + multiple hardware wallets

What Is Your Primary Threat?

ThreatBest ModelWhy
Theft / burglaryMultisig (2-of-3)Attacker needs 2 keys in different locations
Loss of seedCollaborative custodyProvider holds recovery key; you can reconstruct with their help
Self-error / deathCollaborative custody + inheritance planProvider + written instructions for heirs
Government seizureSelf-hosted multisigNo third party to subpoena or compel
Exchange failureSelf-custody any modelNot your keys, not your coins
Beginner mistakesSingle-sig hardwareLower complexity = fewer ways to fail

Self-Custody vs Collaborative Custody

Self-Custody (Sovereign)

You hold all keys. No one can help you recover, but no one can freeze or seize.

Best for: Privacy maximizers, technically proficient users, those in jurisdictions with custody risk.

Tools:

  • Single-sig: ColdCard, Trezor, Ledger + Sparrow/Electrum
  • Multisig: Specter Desktop + 2–3 hardware wallets

Trade-offs:

  • Full responsibility for backups and recovery
  • No inheritance safety net without additional planning
  • Multisig requires documenting derivation paths and script types

Collaborative Custody

You hold the majority of keys; a service holds one recovery key.

Best for: Users who want recovery guarantees without trusting a single custodian.

Tools:

  • Casa — Mobile-guided 2-of-3 or 3-of-5, subscription-based
  • Unchained Capital — 2-of-3 with financial services (loans, IRAs)

Trade-offs:

  • Subscription fees
  • Less privacy than fully self-hosted
  • Requires trust in provider's key recovery process (but not custody)

Inheritance Planning

If you die without a plan, your bitcoin dies with you.

Minimum viable inheritance plan:

  1. Write down key locations and recovery instructions
  2. Store a copy with a trusted attorney or family member (not the seed itself)
  3. Use a collaborative custody provider as a recovery key
  4. Revisit the plan yearly; test recovery on testnet

Advanced:

  • Nunchuk — Built-in inheritance workflows with time-locked releases
  • Casa — Legal documentation support for inheritance protocols

Common Mistakes

MistakeWhy It HurtsFix
2-of-2 multisigLose one key = funds unrecoverableUse 2-of-3 instead
Not backing up public keysLose one seed + one public key = no recovery in 2-of-3Export and backup all XPUBs
Storing seeds in cloud storageCloud accounts are hackable and subpoena-ableSteel backup in physical safe
Never testing recoveryYou discover a problem when it is too lateTest on testnet yearly
Using one manufacturer for all keysSupply-chain or firmware bug affects all keysDiversify hardware wallet brands

Decision Matrix

ProfileRecommended SetupEstimated Cost
Newcomer, < $5kBlockstream Green (2FA multisig) or ColdCard single-sig$0–$150
HODLer, $5k–$50kColdCard + Sparrow, steel backup, 2 locations$150–$300
Family, $50k–$250k2-of-3: ColdCard + Trezor + Casa recovery key$500–$1,000/yr
High net worth, > $250k3-of-5: 3 hardware wallets + Unchained + attorney-held key$1,000–$2,000/yr
Privacy maximalistSelf-hosted Specter 2-of-3, no third parties$300–$600
  • Custody Models — Full spectrum from self-custody to custodial
  • Multisig — Technical details of M-of-N threshold signatures
  • Casa — Managed collaborative custody with inheritance support
  • Unchained Capital — Collaborative custody with loans and IRAs
  • Specter Desktop — DIY multisig coordinator
  • Nunchuk — Mobile multisig with inheritance workflows
  • Caravan — Open-source web-based multisig coordinator
  • Bitcoin Address Types — P2SH, Segwit, Taproot multisig support