Skip to content
COINHOST / INDEPENDENT BITCOIN CUSTODYYOUR KEYS. YOUR AUTHORITY.
coinhostGet in touch
coinhost / docs

Know your custody.

Understand the keys, the decisions, and the way back. These guides explain the Coinhost Wallet model and help you prepare for the private beta.

private beta · testnetupdated · 15 September 2026
Before you begin

The current beta uses a 2-of-3 model on testnet. Use test coins only. Models including 3-of-5 are planned; they are not available yet. Installation, supported devices, and exact recovery steps depend on your beta build and invitation.

Start here

Core concepts

1. A threshold, not a master key

In the 2-of-3 design, you control a mobile key and a hardware key. Coinhost holds a separate recovery key. Any two can authorize a transaction; one alone cannot. Coinhost's key is a recovery participant, not an override.

2. Keys and wallet information do different jobs

Signing keys authorize spending. A wallet descriptor records the public information needed to reconstruct the wallet. Keep a protected copy of your descriptor and follow the backup instructions for each signer. A descriptor cannot replace a lost private key.

3. Recovery should be rehearsed

A recovery plan depends on which keys remain accessible, which tools can use them, and any checks required by a recovery participant. Test the path before you need it. A service waiting period does not stop a transaction signed by two valid keys.

Reference

  • Security model — the design, its limits, and release status.
  • FAQ — consultancy, fees, the wallet, and self-custody.
  • About Coinhost — our practice and principles.