
The recent Coldcard wallet vulnerability that lead to the loss of a massive amount of Bitcoin into the hands of hackers has left me thinking since that incident happened with and I have been asking myself this question below,
Is there any kind of wallet vulnerability that can allow hackers drain a wallet that has a 2 of 3 or 3 of 5 keys multi signature set up even though the hackers can't compromise the 2 and 3 keys but only able to compromise 1 key or 1 signing devices?
I did some research on my own to try answering the question myself and the things I learned are:
1. If a wallet has a multi signature set up, the rules of spending the Bitcoin in that wallet is ensured by Bitcoin script itself, not just the hardware wallet. That means that, if for example you have set up a 2 of 3 multi signature on your wallet, even if any vulnerability allow the hacker gain access to 1 key, they can't steal your coins unless they are able to compromise both keys.
2. Multi signature means that before the Bitcoin in your wallet can be spent, you have to request for consent and approval from all the devices holding the rest of the signature keys, it's not advisable to hold all keys in one device.
3. Firmware/software vulnerability can not drain a wallet with multisig except all the keys get compromised at once. If it's a 5 of 7 multisig, gaining access of 2 keys doesn't still means that the Bitcoin can be stolen, the hacker still needs to get the 3 remaining keys before stealing the Bitcoin.
4. A 2 of 3 or 3 of 5 multisig is good for individual holder and keys should be kept independently on different device because if due to a firmware vulnerability or a different kind of exoploit lead to compromising 1 signature device, it doesn't mean that the whole quorum will be affected.
If you are holding a large amount of Bitcoin or even if you are holding a small amount that you can not afford losing, adopt using multi signature configuration and also have designated signing device that is only to be used for signing, don't use a device that you are using to carry out different online activities or installation of unknown applications.
Keeping your Bitcoin in a hardware wallet without adding multisig is not just enough for security of your Bitcoin.
Correct me if there's any error in my findings, this is a research to educate myself and also post it here for others to benefit.
Reference.
https://bitcoin.org/en/secure-your-wallet?utm_source=chatgpt.com