Dark grey illustration of obscure multisig wallet experiments

The Multisig Underground: 10 Wallets You’ve Never Heard Of

Why this list exists

The multisig wallets everyone knows fit on one hand: Nunchuk, Sparrow, Specter, Electrum, the big custodial coordinators. But there is a stranger layer underneath. Solo developers and small teams are building multisig experiments on Stacker News: timelocked vaults, duress-resistant key sets, descriptor QR codes, threshold signing without hardware. Most will never reach a 1.0. Some are already dead. A few are genuinely clever. This is a tour of roughly a dozen of them, with honest labels on what is alive, what is dormant, and what was never more than a demo. If you are new here, read our multisig explainer first, then come back.

BitVault

BitVault is an open-source multisig system with customizable time delays (hours to days), hardware wallet integrations, and a secret notification system for unauthorized access attempts. It is alive: the site and blog are current, and a February 2026 press release announced a Wefunder “testing the waters” campaign. The honest framing: some of its claims have been contested on Stacker News (the discussion). Read the criticism before you trust it with real money. Interesting, but verify everything yourself.

Smart Vaults

Smart Vaults was a promising open-source multisig coordinator. It is now dormant. The documentation book has not been updated in roughly two and a half years, and the JavaScript client is even older. Nothing wrong with the code that exists, but an unmaintained coordinator is a coordinator you should not build a vault on. Treat this one as archaeology.

BitPac

super_testnet’s BitPac is a research demo, not a product. The idea: pre-signed, timelocked transaction “pacs” that enforce spending policy without a coordinator. Bitcoin Magazine covered the general BITPACS concept. As a demo it is fascinating. As a wallet you would use, it is not there. Keep it in the “clever ideas” bucket.

Multisig Backup

multisigbackup.com is alive and does one thing: it turns your multisig wallet descriptor into a compact backup you can store cheaply onchain. For a 2-of-3, the README puts the cost around 800 sats at 2 sats per vbyte. That is the whole pitch: your descriptor is the part of a multisig setup everyone forgets to back up, and losing it can make recovery painful. If you run any multisig, back up the descriptor, whether you use this tool or not. Our seed words piece explains why one backup is never enough.

PSBTHub

PSBTHub is alive and solves a narrow, real problem: getting a PSBT from one signer to another without trusting a server. Everything is encrypted client-side with AES-GCM. You share either a one-link URL (the key lives in the URL fragment, which never reaches the server) or a password (stretched with PBKDF2). No accounts. The server stores ciphertext only. It cannot read your transaction. For air-gapped multisig workflows where signers are in different places, that is exactly the tool you want. See the Stacker News thread for the design discussion.

DescriptorQR

DescriptorQR is real and verified: a site by joshdoman that encodes your multisig wallet descriptor as an animated QR code, 30 to 40 percent smaller than the standard encoding, using his descriptor-codec Rust library. It runs entirely in your browser, nothing leaves your machine, and it was discussed on Bitcoin Optech. Smaller QRs scan more reliably on hardware wallet cameras, which matters when you are registering a multisig wallet on a device with a tiny screen. Niche, but genuinely useful.

Boomerang

Boomerang is the most ambitious design on this list, and it is still a design. The current spec describes 5 custodians with an earliest spend path that is a 5-of-5 Boomerang branch after a milestone block, per-device secret “mystery” withdrawal thresholds, and per-custodian keys built with MuSig2 combining a mnemonic key with a Boomlet secure-element share. The standout idea is duress handling: distress signals are embedded in ordinary withdrawal traffic to a prearranged rescue service, with support for forced-withdrawal (SAR) and duress-withdrawal (WT) scenarios. If keys are lost, a deterministic fallback waterfall relaxes the quorum from 5-of-5 down to 1-of-5 at later milestones. The repository is actively developed, but it carries an explicit “not production-ready” warning. Respect that warning. This is the one to watch, not the one to use. Discussion: Stacker News.

The 2023 timelock proposal

In November 2023, Athena_Alpha proposed a multisig vault with a twist: a 2-of-3 where one key is timelocked, plus a 3-key override for emergencies. The timelock means a thief with two keys still has to wait. The override means you are not locked out forever if something goes wrong. It never became a product, but the pattern shows up in serious vault designs. Worth understanding as a concept: timelocks trade convenience for a guaranteed response window.

Satoshi Vault

In October 2024, pup published the Satoshi Vault white paper: an open-source, multi-platform application meant to simplify multisig wallet creation and operation without dedicated hardware. Four days later came Peritas, a vision piece for accessible multisig aimed at non-technical users. Both are design documents, not shipping software. The interesting question they pose: can multisig ever be normal-person easy? Nobody has answered it yet.

FrostSnap

FrostSnap is the most credible shipping FROST implementation in Bitcoin. It is alive and selling: 150,000 sats per device, delivery quoted around 10 days, and a v0.4.0 release in August 2026 that fixed two disclosed security issues. The pitch is threshold signing with cheap devices instead of a multisig quorum: your key is split across devices, and a threshold of them sign without ever reconstructing the key. That is a different trust model from multisig, with different tradeoffs. If you want the details, see frostsnap.com and the Stacker News discussion.

Safe₿its

Safe₿its is a Bitcoin.Design designathon concept: a learning hub and resource collection for multisig self-custody, aimed at everyone from security-conscious hodlers to nonprofit treasurers. See the project summary on Stacker News and safe.btc.pub. It is education, not software. But multisig’s biggest barrier is understanding, not code, so education counts.

Iceberg

Iceberg is real research, published August 2026 as arXiv:2608.20705 by Paul Gerhart (TU Wien), Nadav Kohen and Matias Furszyfer (Chaincode Labs), and Jesse Posner (Vora). The idea: nested threshold MuSig2. One side of a Lightning channel operates as a t-of-n threshold group while appearing to the counterparty as a standard MuSig2 participant. No changes to Bitcoin, no changes to Lightning, no changes required from counterparties. The prototype is integrated into a fork of eclair, and a group tolerating one corrupted member sustains over 93 percent of an unmodified endpoint’s payment throughput. Translation: multisig-grade security for a Lightning node that nobody on the network can tell apart from a normal one. Still research, but from a Tier 1 lab.

The verdict

Most of this list is not ready for your coins. That is fine. The value is in the ideas: timelocks buy response time, descriptors need backups too, PSBTs need a private transport, and threshold signing keeps nibbling at multisig’s edges. When you are ready to build something real, use boring, maintained tools. Check that your devices work together with our compatibility checker, design the quorum with the wizard, and compare hardware in our hardware wallet guide. The underground is for learning. Your savings belong aboveground.

Publications similaires

Laisser un commentaire

Votre adresse e-mail ne sera pas publiée. Les champs obligatoires sont indiqués avec *