Plan the way back.
Recovery starts with knowing what remains accessible. This guide covers the 2-of-3 design; rehearse the exact process supplied with your testnet beta build.
When a key goes missing
A lost phone or failed hardware device does not necessarily mean the key is permanently lost: a usable backup may still restore it. First establish which keys and backups remain accessible. Avoid resetting a surviving device before understanding your recovery path.
- Phone unavailable: the hardware key and Coinhost recovery key can meet the threshold, subject to the recovery process.
- Hardware key unavailable: the mobile key and Coinhost recovery key can meet the threshold, subject to the recovery process.
- Coinhost unavailable: your mobile and hardware keys can meet the threshold, provided you can use them with your saved wallet information and compatible signing tools.
If two of the three keys and their usable backups are permanently lost, the remaining key cannot authorize a transaction. A descriptor reconstructs the wallet; it cannot replace a private key.
The recovery process
The Coinhost-assisted path combines your remaining key with the recovery key. Before using it, confirm the identity checks, waiting period, notifications, and cancellation steps documented for your beta build. This guide does not establish a fixed recovery time.
- Identify the missing signer. Keep the remaining signer and account access secure.
- Start through the verified recovery channel. Review the request and any checks required by the current process.
- Review the waiting period. Monitor the configured contact channels and report requests you did not make.
- Verify before signing. Check the replacement setup and transaction using your remaining signer before approval.
Replacing a key
Changing a key in a conventional multisig policy requires a new wallet policy and a transaction moving funds to its addresses. It does not change the keys controlling existing outputs. Verify the replacement signers and backups before the move, and account for network fees.
Keep the old wallet information until you have checked for remaining outputs and updated any saved receiving instructions. Do not continue receiving to a wallet whose security has been compromised.
What a service pause cannot do
A recovery delay or service pause can limit when Coinhost participates in signing. It cannot freeze the Bitcoin network or invalidate a transaction authorized by two valid keys. It is not an on-chain timelock.
If two keys are compromised, an attacker may already be able to spend. Do not rely on an account lock or a recovery email to stop that transaction.
Prepare an independent exit
Before you need it, save the complete wallet descriptor and the instructions required to use your two keys outside Coinhost. The receiving wallet must support the descriptor format, network, and signing devices.
- Keep a protected copy of all wallet descriptors and key-origin information.
- Confirm access to both of your signing keys, including any required backups or adapters.
- Reconstruct the wallet in a compatible tool and compare its receive and change information.
- Rehearse signing on testnet. A watch-only import is not proof that spending works.
Do this while your setup is available. An outage is too late to discover that the only export or signer connection depended on a service you can no longer reach. Treat descriptors as private information because they can reveal wallet activity.
Getting help
For beta support, email support@coinhost.com. For a suspected security issue, use security@coinhost.com and the disclosure policy. Do not send seed phrases, private keys, or passwords. Ask for a secure channel before sharing sensitive evidence.