{"id":2037,"date":"2026-10-01T12:43:35","date_gmt":"2026-10-01T12:43:35","guid":{"rendered":"https:\/\/neverlosebitcoin.com\/?p=2037"},"modified":"2026-10-01T12:44:44","modified_gmt":"2026-10-01T12:44:44","slug":"frostsnap-frost-threshold-signing-state","status":"publish","type":"post","link":"https:\/\/neverlosebitcoin.com\/fr\/frostsnap-frost-threshold-signing-state\/","title":{"rendered":"FrostSnap and FROST: A Reality Check on Threshold Signing"},"content":{"rendered":"<p>Every few years a wallet promises to break every rule. FrostSnap is the current candidate: a Bitcoin self-custody system built on FROST, a threshold Schnorr signing protocol, where your devices generate the wallet together and the full private key never exists anywhere, not even for an instant.<\/p>\n<p>In May 2026, a skeptical Stacker News post asked the uncomfortable questions: is FROST actually plug-and-play on Bitcoin yet, and how does FrostSnap handle distributed key generation without a trusted setup? Those questions are still worth asking. Here is what is verified and what is not.<\/p>\n<h2>What is verified: the product is real<\/h2>\n<p>FrostSnap is a real company with a real product line, and the receipts are public:<\/p>\n<ul>\n<li><strong>The site and docs are live.<\/strong> <a href=\"https:\/\/frostsnap.com\" target=\"_blank\" rel=\"noopener\">frostsnap.com<\/a> publishes a full security architecture document explaining the threshold t-of-n model. A 2-of-3 wallet needs any 2 of 3 devices to sign. Losing one device never puts funds at risk.<\/li>\n<li><strong>The code is open source.<\/strong> The entire stack is MIT licensed on <a href=\"https:\/\/github.com\/frostsnap\/frostsnap\" target=\"_blank\" rel=\"noopener\">GitHub<\/a>: ESP32 Rust firmware for the devices, a core Rust library for coordinator and signer state, the comms protocol, and a cross-platform Flutter wallet app that acts as the FROST coordinator.<\/li>\n<li><strong>The team is named.<\/strong> Lloyd Fournier (cryptographer and architect), Nick Farrow, Adam Mashrique, Evan Lin, and Alex Hanley. An Australian and Malaysian company, with hardware assembled and firmware flashed in-house in Malaysia.<\/li>\n<li><strong>The cryptography is documented.<\/strong> Their FROST implementation comes from secp256kfun, and their docs credit Bitcoin&#8217;s Taproot upgrade for making Schnorr threshold signatures practical: one public key on chain, single-sig fees, hidden multisig for privacy, straightforward recovery.<\/li>\n<\/ul>\n<p>One nice design detail from their docs: Frostsnap devices are not trusted to generate keys on their own. Your phone or laptop participates in key generation and verifiably contributes entropy. That is a direct answer to the class of RNG failure that burned Coldcard users in July 2026 (<a href=\"https:\/\/github.com\/nwfella\/coldcard-entropy-incident\" target=\"_blank\" rel=\"noopener\">public write-up<\/a>).<\/p>\n<h2>What is not settled: the open questions<\/h2>\n<p>The May 2026 skepticism raised two technical points, and I could not find public resolutions for either:<\/p>\n<ol>\n<li><strong>How mature is FROST on Bitcoin, really?<\/strong> The post claimed FROST still needs MuSig2 wrappers or pre-signed flows on current Bitcoin and that native threshold-signing support is not there yet. FrostSnap&#8217;s own docs describe a working FROST implementation over Taproot, which suggests the protocol side functions. Whether that counts as &#8220;plug-and-play&#8221; depends on your definition. Integrating with the existing wallet ecosystem is still early: a Sparrow feature request (issue #2039) asks for FrostSnap support as a hardware signing device, which tells you it is not yet a drop-in signer for the most popular coordinator.<\/li>\n<li><strong>The trusted-setup question.<\/strong> Distributed key generation without a trusted dealer is the hard part of any threshold scheme. The community asked how FrostSnap handles it. I found no public answer framed in those terms. Their docs describe the devices generating the wallet together, but the precise DKG ceremony and its trust assumptions deserve a direct answer from the team before you bet a treasury on it.<\/li>\n<\/ol>\n<p>Treat both as open community questions, not established facts in either direction.<\/p>\n<h2>How it compares to multisig<\/h2>\n<p>FROST threshold signing and <a href=\"https:\/\/neverlosebitcoin.com\/fr\/multisig\/\">multisig<\/a> solve the same problem, no single point of failure, with different tradeoffs. Multisig is battle-tested, coordinator-agnostic, and recoverable with a <a href=\"https:\/\/neverlosebitcoin.com\/fr\/seed-words-not-enough\/\">descriptor backup and standard tooling<\/a>. FROST gives you single-sig fees, on-chain privacy (the threshold setup is invisible), and no descriptor to back up, since there is no multisig script at all.<\/p>\n<p>The cost is maturity and ecosystem. Multisig works today in Sparrow, Nunchuk, Electrum, and a dozen hardware wallets. FROST works in FrostSnap&#8217;s own stack, and the rest of the ecosystem is catching up.<\/p>\n<h2>The bottom line<\/h2>\n<p>FrostSnap is not vaporware. It is a serious, open-source attempt at threshold self-custody with real engineering behind it. It is also not yet the default choice. If you want threshold-style security today with maximum tooling support, a conventional 2-of-3 multisig remains the conservative pick. If you want to live on the frontier and you understand the open questions above, FrostSnap is the most credible way to do it.<\/p>\n<p>For a conventional multisig build, compare <a href=\"https:\/\/neverlosebitcoin.com\/fr\/best-bitcoin-wallet\/\">multisig-ready hardware wallets<\/a>, check device and coordinator compatibility <a href=\"https:\/\/neverlosebitcoin.com\/fr\/compatibility\/\">here<\/a>, or get a personalized recommendation from the <a href=\"https:\/\/neverlosebitcoin.com\/fr\/wizard\/\">multisig wizard<\/a>.<\/p>\n<p><em>Discussed on Stacker News: <a href=\"https:\/\/stacker.news\/items\/1489652\" target=\"_blank\" rel=\"noopener\">FrostSnap | The Bitcoin Wallet That Breaks Every Rule<\/a><\/em><\/p>\n<h2>Trouvez la configuration qui vous convient<\/h2>\n<p>Frontier cryptography or boring battle-tested multisig? Answer six questions and get a recommended setup for your situation: <a href=\"https:\/\/neverlosebitcoin.com\/fr\/wizard\/\">take the multisig wizard<\/a>.<\/p>","protected":false},"excerpt":{"rendered":"<p>Every few years a wallet promises to break every rule. FrostSnap is the current candidate: a Bitcoin self-custody system built on FROST, a threshold Schnorr signing protocol, where your devices generate the wallet together and the full private key never exists anywhere, not even for an instant. In May 2026, a skeptical Stacker News post&#8230;<\/p>","protected":false},"author":5,"featured_media":2038,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_kad_blocks_custom_css":"","_kad_blocks_head_custom_js":"","_kad_blocks_body_custom_js":"","_kad_blocks_footer_custom_js":"","_kadence_starter_templates_imported_post":false,"_kad_post_transparent":"","_kad_post_title":"","_kad_post_layout":"","_kad_post_sidebar_id":"","_kad_post_content_style":"","_kad_post_vertical_padding":"","_kad_post_feature":"","_kad_post_feature_position":"","_kad_post_header":false,"_kad_post_footer":false,"_kad_post_classname":"","footnotes":""},"categories":[11],"tags":[],"class_list":["post-2037","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-self-custody"],"taxonomy_info":{"category":[{"value":11,"label":"Self-Custody"}]},"featured_image_src_large":["https:\/\/neverlosebitcoin.com\/wp-content\/uploads\/2026\/10\/nlb-thumb-frostsnap-frost-threshold-signing-state-1024x576.webp",1024,576,true],"author_info":{"display_name":"WUMBOLOVER","author_link":"https:\/\/neverlosebitcoin.com\/fr\/author\/wumbolover\/"},"comment_info":0,"category_info":[{"term_id":11,"name":"Self-Custody","slug":"self-custody","term_group":0,"term_taxonomy_id":11,"taxonomy":"category","description":"","parent":0,"count":24,"filter":"raw","cat_ID":11,"category_count":24,"category_description":"","cat_name":"Self-Custody","category_nicename":"self-custody","category_parent":0}],"tag_info":false,"_links":{"self":[{"href":"https:\/\/neverlosebitcoin.com\/fr\/wp-json\/wp\/v2\/posts\/2037","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/neverlosebitcoin.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/neverlosebitcoin.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/neverlosebitcoin.com\/fr\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/neverlosebitcoin.com\/fr\/wp-json\/wp\/v2\/comments?post=2037"}],"version-history":[{"count":1,"href":"https:\/\/neverlosebitcoin.com\/fr\/wp-json\/wp\/v2\/posts\/2037\/revisions"}],"predecessor-version":[{"id":2039,"href":"https:\/\/neverlosebitcoin.com\/fr\/wp-json\/wp\/v2\/posts\/2037\/revisions\/2039"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/neverlosebitcoin.com\/fr\/wp-json\/wp\/v2\/media\/2038"}],"wp:attachment":[{"href":"https:\/\/neverlosebitcoin.com\/fr\/wp-json\/wp\/v2\/media?parent=2037"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/neverlosebitcoin.com\/fr\/wp-json\/wp\/v2\/categories?post=2037"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/neverlosebitcoin.com\/fr\/wp-json\/wp\/v2\/tags?post=2037"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}