Nunchuk 3-of-4 shared custody multisig setup guide illustration

Nunchuk 3-of-4 Shared Custody Guide

Why 3-of-4, and why Nunchuk

Most shared custody setups are 2-of-3: two keys can move the money, one can be lost. A 3-of-4 raises the bar on both sides. You can lose one key and still spend. An attacker needs three. For a small team or a family treasury, that tradeoff is often worth it. Nunchuk is one of the few coordinators that makes a 3-of-4 painless: it creates the group wallet, handles PSBT sharing between signers, and even includes an in-app chat so cosigners can coordinate. If you have never run multisig before, read our multisig explainer first.

Rehearse on Testnet4 first

The original walkthrough this guide is based on used Testnet4 coins, two phones (iPhone and Android), two hot keys, and two Blockstream Jades. That is the right approach. Never build your first multisig with real money. Get Testnet4 coins from a faucet, run the entire setup below, fund the wallet, spend from it, and only then repeat with mainnet. Everything that can go wrong will go wrong on testnet, where it costs you nothing. Our self-custody guide covers the basics if any step below assumes too much.

Step 1: Put the Jades on testnet

On each Jade: Device, then Settings, then Network, then Testnet. Both Jades must be on the same network, or nothing downstream will work. This is the step people skip and then debug for an hour. Check it twice.

Step 2: Export the xpubs

On each Jade: Options, then Wallet, then Export Xpub, then Multisig. The xpub is the extended public key: it lets the coordinator build the wallet and generate addresses without ever seeing your private key. Export from both Jades and both hot keys. Four xpubs total. Verify each one matches what the device shows, on the device screen, not just in the app.

Step 3: Create the Group Wallet

In Nunchuk, create a Group Wallet and add the four xpubs. Nunchuk defaults to 2-of-3. Change it to 3-of-4. Name each key clearly: “Jade 1”, “Jade 2”, “Phone hot key”, “Spare hot key”, or whatever matches your actual setup. Six months from now, “Key 3” will mean nothing to you. Names are part of the backup.

Step 4: Fund it and spend from it

Send a small Testnet4 amount to the group wallet’s address. Then spend it. A 3-of-4 spend needs three signatures: coordinate through Nunchuk’s built-in PSBT sharing and the in-app chat. The first spend will feel slow. That is normal. You are rehearsing the ceremony you will perform under stress someday, so make it boring and repeatable. Before you buy anything, compare your devices in our hardware wallet guide and check they work together with the compatibility checker.

The backup lesson everyone learns too late

Here is the part that kills multisig setups: the backup. Each cosigner backs up their own seed phrase, obviously. But the wallet also needs its descriptor backed up: the file that records all four xpubs and the 3-of-4 quorum. Lose the descriptor and recovery becomes a painful reconstruction project. Nunchuk pushes BSMS, the Bitcoin Secure Multisig Setup format, as the standard backup for exactly this reason: one file, all the xpubs, the quorum, verifiable on any device. Export the BSMS file at setup, store copies with at least two cosigners in separate locations, and test a full restore on testnet before you fund the mainnet wallet. The four classic seed storage mistakes apply to every cosigner, and seed words alone are not enough when a descriptor is involved.

Who 3-of-4 is for

Two founders and a lawyer. A couple plus two trusted relatives. A small company treasury. Anywhere you want redundancy against one lost key and resistance against two compromised ones. It is overkill for a personal stack, where a 2-of-3 is simpler and easier to rehearse. Match the quorum to the threat model. When you are ready to design yours, the multisig wizard walks through the tradeoffs.

Publicaciones Similares

Deja una respuesta

Tu dirección de correo electrónico no será publicada. Los campos obligatorios están marcados con *