Two keys sign.
One cannot.
In the 2-of-3 model, any two of the three keys can authorize a transaction. Coinhost's recovery key alone cannot spend. Two compromised keys can meet the same threshold.
2-of-3 / beta modelCustody starts with who can act, what can fail, and how you recover. Coinhost's 2-of-3 design distributes signing across your phone, your hardware device, and a separate recovery key.
A signing threshold is one part of security. Device protection, backups, verification, and recovery procedures matter too. These are the principles behind the wallet, and the limits to keep in view.
In the 2-of-3 model, any two of the three keys can authorize a transaction. Coinhost's recovery key alone cannot spend. Two compromised keys can meet the same threshold.
2-of-3 / beta modelYour phone and hardware device hold separate key roles. Keeping signers and backups in different failure domains reduces dependence on one device or location.
Devices / locations / backupsA descriptor records the public information needed to reconstruct the wallet. Keep a protected copy. It can reveal wallet activity, but it cannot authorize spending.
Descriptor + signing keysThe recovery key can work with your remaining key if one becomes unavailable. Recovery checks and delays govern Coinhost's participation; they do not freeze funds on-chain.
A service policy / not a timelockAn independent exit needs your saved wallet information, both of your usable keys, and compatible signing tools. Test that route while everything is available.
Export / reconstruct / testA model diagram is not an audit. This site does not publish an independent wallet audit report. The wallet remains in private testnet beta.
Test coins onlyRecovery combines your remaining key with Coinhost's key. Follow the procedure for your beta build. The sequence below explains the model; it does not promise a fixed completion time.
Identify the missing key and secure the remaining signer, backups, and account access.
Remaining key + wallet informationComplete the required checks and waiting period. Monitor the configured contact channels and report requests you did not make.
Requirements depend on the beta buildCheck the replacement setup and transaction. Your remaining key and the recovery key together satisfy the threshold.
One key alone is never sufficientA service pause cannot stop a transaction already authorized by two valid keys. Read the limits of a recovery delay.
A watch-only wallet can show a balance without being able to spend. Verify both halves of the recovery path. Prepare your independent recovery →
The current beta is for test coins. Features and device support may change. Mainnet availability will be announced separately.
This page describes the custody model. It does not certify the wallet implementation, infrastructure, or recovery operations.
Report a suspected vulnerability privately. The disclosure policy explains the scope, reporting channel, and research guidelines.