So I got this 1-of-2 multi-sig setup. Seed A is in location A, Seed B in location B, and public keys are in location C. If seed A gets leaked, can the attacker still access my funds since they don’t have the public key for seed B?
Exploring a 1-of-2 Multi-Sig Setup with Hidden Keys
24 replies 172 views
Dude, if it's 1-of-2, then one key is enough to move the funds. Not sure what the point of a 1-of-x wallet is.
Wait, you can move funds with just one private key and not even both public keys? How's that work?
fork_vaultMember
Posts: 27 · Reputation: 223
#4Feb 4, 2021, 11:24 PM
When I set up a multi-sig wallet in Electrum, it warns me that I need the master public key for each cosigner in all backups. So, you can't send funds with just one private key, right?
You got it right. But remember, it's like having just one cosigner. Either you or the other person can handle transactions.
To restore the wallet, yeah, you need one key and both public keys. But to actually move funds, you only need one key.
I still don’t get it. If the other guy doesn’t have both public keys, can he transfer funds or not? I thought you needed both.
chrisomegaFull Member
Posts: 158 · Reputation: 631
#8Feb 6, 2021, 03:42 PM
From what I know, yes, you need both public keys if the address has been used before, else the keys can be found on the blockchain.
fork_vaultMember
Posts: 27 · Reputation: 223
#9Feb 6, 2021, 06:19 PM
It really comes down to your threat model. You might be safer from attackers, but you also risk losing access yourself.
swiftdiamondMember
Posts: 224 · Reputation: 87
#10Feb 6, 2021, 10:56 PM
I get that. But the point of a 1-of-2 multi-sig wallet is to allow transactions with one of the backups. Isn't it similar to 2-of-3?
fork_vaultMember
Posts: 27 · Reputation: 223
#11Feb 7, 2021, 04:38 AM
Those public keys relate to the redeem script, which you won't manage with Electrum anyway. Someone with the private key and wallet address can still create and broadcast transactions.
Sure, but if they know your setup, they might preemptively compromise your wallets. Just saying, it’s risky.
fork_vaultMember
Posts: 27 · Reputation: 223
#13Feb 7, 2021, 11:56 AM
If they know you have a lot of cash, they’ve already got a plan. You need to be prepared for anything.
The redeem script isn’t shown in Electrum, but it’s saved in the wallet file. To sign a transaction, you need both the redeem script and the cosigner's public key.
Nope, that’s not how it works. Think about it. You’ll figure it out from the replies.
That link doesn’t even back your claim. It’s about using a redeem script, which is essential for creating a transaction.
Thanks for your input! So regarding Q1, the public key is on the blockchain if there’s been a transaction, but how does the attacker know which one? The public key for a seed differs in multi-sig and single-sig wallets, right?
Totally. Safer from attackers is one thing.
For Q4, yeah, that’s an option, but passphrases can be forgotten. Just trying to explore my options.
I’ll check out that link you shared. Appreciate it.
Related topics
- Is Mempool.space Accurate for Fee Estimates? 19
- HD Wallet vs Descriptor Wallet: What's the Deal? 3
- New Wallet Regulations for Crypto Purchases Over $10K in the US 15
- Advice on Channel Size for Lightning Network 5
- Creating a Brain Wallet Generator with Bash 15
- Do derivative traders move funds to wallets after closing positions? 19