Why single-key wallets have a single point of failure
A standard Bitcoin wallet is controlled by one private key (or its seed phrase). That's elegant and simple — but it means anyone who gets that key gets everything. It also means if you lose the key with no backup, you lose everything.
For personal use with modest amounts, a single-key wallet with a well-protected seed phrase backup is often fine. For a business holding significant crypto — or a business with multiple owners who should all have oversight of funds — a single key is a liability.
How multi-sig works
A multi-signature wallet requires M-of-N keys to authorize a transaction — M signatures from a total of N key holders. Common configurations:
How it works technically (Bitcoin)
On Bitcoin, multi-sig is implemented using P2SH (Pay-to-Script-Hash) or P2WSH (Pay-to-Witness-Script-Hash) addresses. The address is derived from a script that specifies the M-of-N requirement. When spending, you provide M valid signatures matching M of the N public keys listed in the script.
The Bitcoin network validates that the signatures are correct and that the required threshold is met before confirming the transaction. No single key holder can bypass this check.
Ethereum uses smart contracts for multi-sig — the most popular being Gnosis Safe (now called Safe). This is a smart contract wallet deployed on-chain that enforces the M-of-N policy. It's widely used by DAOs, protocols, and businesses holding ETH or ERC-20 tokens.
Who should use multi-sig?
- Business with 2+ owners who share treasury
- Holding significant crypto long-term (>$10,000)
- Any wallet where a single compromise would be catastrophic
- Nonprofit boards approving crypto disbursements
- High-value merchant cold storage
- Hot wallet for everyday retail payments (use hardware wallet instead)
- Small amounts under $1,000
- Solo operator with good seed phrase backup practices
- USDC that gets auto-converted to dollars immediately
Multi-sig tools worth knowing
- Sparrow Wallet — excellent Bitcoin multi-sig coordinator. Open source, runs on desktop, integrates with hardware wallets (Ledger, Trezor, Coldcard). The most serious Bitcoin multi-sig setup for non-custodial control.
- Casa — managed multi-sig service for Bitcoin. They hold one key, you hold others. Good for people who want multi-sig security without the technical complexity of coordinating everything themselves.
- Safe (Gnosis Safe) — the standard for Ethereum/ERC-20 multi-sig. Web interface, hardware wallet integration, good tooling. Free to deploy, widely used by institutions and DAOs.
- Unchained Capital — collaborative custody for Bitcoin. You hold 2 of 3 keys; they hold 1. Professional key management service.
Multi-sig and your OrangeTill setup
OrangeTill sends payments directly to whatever wallet address you configure. If your business wallet is a multi-sig address, payments arrive there just like any other wallet — the receiving address looks normal to the network.
The multi-sig requirement only activates when you spend from that wallet — moving funds out requires the required number of signatures. For incoming merchant payments, multi-sig adds no friction whatsoever.
A common merchant setup: receive payments to a standard hot wallet for daily operations, then periodically sweep larger balances to a 2-of-3 multi-sig cold storage wallet. Fast for everyday use; secure for long-term holdings.
Build a business-grade crypto setup.
OrangeTill works with any wallet — including multi-sig cold storage. Accept payments to the address of your choice.
See pricing →