The Privacy Price of Assisted Multisig
Assisted multisig sells you convenience: a company holds one key in your quorum, handles coordination, and helps you recover if things go wrong. The price is usually quoted in dollars per year. In August 2026, a Stacker News poster added up the other price, denominated in privacy, and found it steep.
What the co-signer sees
The post, by @anon, walks through Nunchuk’s assisted model with a platform key as co-signer. Two costs stand out:
- Identity linkage. Using the platform key requires email signup, which indirectly ties an identity to the wallet, and likely to the user’s phone through delay notifications. Your multisig wallet, designed to have no single point of failure, now has a single point of identification sitting in a company’s user database.
- Full balance visibility. As a co-signer, Nunchuk can see the user’s entire wallet balance. The poster’s phrasing is vivid: it paints a target on your back. Anyone who can see the balance, the company itself, a hacker who breaches the company, a government with a subpoena, knows exactly what you hold.
The poster is not anti-assisted-multisig. They like the extra-key-as-backup concept. The argument is that the privacy costs are under-discussed relative to the convenience benefits, and buyers should see the full invoice before signing up.
This is structural, not a Nunchuk-specific bug
Any assisted model where a company co-signs has some version of this. Casa, Nunchuk, and every collaborative custodian needs your xpubs to coordinate signing, which means they can derive your addresses and watch your balance. That is not malice, it is how the coordinator role works. But “how it works” and “acceptable” are different questions, and the market has mostly not been asked to answer the second one.
This is also why the “can’t see vs won’t look” distinction matters. A provider that promises not to look at your balance still can. Architecture that makes balance visibility impossible is a stronger guarantee than a privacy policy.
The proposed fix: chain code delegation
The poster’s suggestion is specific: Nunchuk, Casa, and others should adopt Bitkey’s chain code delegation approach. The idea is to withhold the full BIP-32 chain code from the cosigner and hand over only transaction-specific derivation info with each signing request. Without the chain code, the cosigner cannot derive your unrelated addresses or reconstruct your transaction history. It sees only what it needs to co-sign the transaction in front of it.
This is especially relevant if you run your own node, since you have already done the work to keep your transaction data private and then hand the view back to a cosigner at the last step. Chain code delegation would close that loop.
Whether Nunchuk or Casa adopt it is unverified and, as of this writing, unknown. The August 2026 thread shows users actively asking for it, which is how protocol improvements usually start: not with a roadmap announcement, but with customers naming the gap.
The tradeoff, stated plainly
Assisted multisig: recovery help and convenience, bought with subscription fees, identity linkage, and balance visibility. DIY multisig: full privacy and no fees, bought with operational responsibility and no one to call.
There is no universally right answer, only the right answer for your situation. If you go assisted, go in with eyes open about what the cosigner sees, and ask them directly: what exactly can you see, what do you store, and what happens to that data if you are breached or compelled? If the answers are vague, that is your answer.
To work through which model fits you, try the multisig wizard. For the hardware side of a DIY build, see the best bitcoin wallet comparison and the compatibility checker.
Discussed on Stacker News: Safety/Privacy of Nunchuck (Assisted multisig wallet)
Finde deine Konfiguration
Assisted or DIY, the right custody starts with an honest assessment. Answer six questions and get a recommended multisig setup: take the multisig wizard.




