After the recent Coldcard incident, I've seen a lot of people suddenly rushing into multisig. A word of caution.
Multisig is not automatically the right answer.
The UX has improved dramatically over the past few years, but building a robust multisig setup still takes careful planning. I regularly see people locking themselves into configurations that are painful, and sometimes impossible, to recover from safely. Adding keys buys you resilience against a single point of failure. It also adds complexity, and complexity is where people lose funds. Both of these are true at once.
An alternative worth considering: Miniscript.
Ledger has (one of) the most complete implementations of Bitcoin Miniscript, with clear signing on every spending path. You can express sophisticated policies, inheritance, 2-of-3 multisig, recovery keys with timelocks, and much more, while keeping the security of a hardware wallet and seeing exactly what you sign, every time. (More here ➤
ledger.com/blog/how-ledgers-… )
The other half of the puzzle is the frontend. Ledger Live doesn't ship a multisig option today, but good options exist. Liana (
@lianabitcoin) for instance, does a good job of hiding the underlying complexity, making advanced policies accessible without forcing users to think in terms of scripts or descriptors.
For developers, it gets more interesting. A few months ago I built a custom wallet UX around Miniscript. With Claude, I had a fully functional Bitcoin wallet supporting advanced spending policies in a few hours. I was comfortable testing it directly on mainnet, because every policy and every signature is displayed on the device itself. That is the whole point of clear signing: it is very hard to accidentally sign something different from what your application intends. What You See Is What You Sign.
If you care about the future of trustless Bitcoin wallets, read
@salvatoshi 's post on why Miniscript is such a powerful building block ➤
ledger.com/blog/towards-a-tr…
And if you want the cryptographic version of multisig rather than the script version, Ledger devices are, to my knowledge, the only hardware wallets that support MuSig2 today. Several signers aggregate their keys into a single Schnorr key and produce a single signature, so on-chain it is indistinguishable from a normal spend. Smaller, more private, and still clear signed on the device ➤
ledger.com/blog-musig2-ledge…
Multisig can absolutely be the right tool. So can Miniscript. Just choose it because your threat model demands it, not because a headline scared you into it.
But, for most people, single-sig is still the right answer: a certified hardware wallet, built on a certified secure element, with real backup options and clear signing on every flow.
Stay safe. Stay honest about your trust assumptions.