Security model / private testnet beta

Separate keys.
Shared authority.

Custody starts with who can act, what can fail, and how you recover. Coinhost's 2-of-3 design distributes signing across your phone, your hardware device, and a separate recovery key.

The design principles

Control you can understand.

A signing threshold is one part of security. Device protection, backups, verification, and recovery procedures matter too. These are the principles behind the wallet, and the limits to keep in view.

01 / Signing authority

Two keys sign.
One cannot.

In the 2-of-3 model, any two of the three keys can authorize a transaction. Coinhost's recovery key alone cannot spend. Two compromised keys can meet the same threshold.

2-of-3 / beta model
02 / Separate signers

Distribute the points of control.

Your phone and hardware device hold separate key roles. Keeping signers and backups in different failure domains reduces dependence on one device or location.

Devices / locations / backups
03 / Open wallet information

Keep a map of your wallet.

A descriptor records the public information needed to reconstruct the wallet. Keep a protected copy. It can reveal wallet activity, but it cannot authorize spending.

Descriptor + signing keys
04 / Recovery

A second path. With clear limits.

The recovery key can work with your remaining key if one becomes unavailable. Recovery checks and delays govern Coinhost's participation; they do not freeze funds on-chain.

A service policy / not a timelock
05 / Independence

Rehearse your own way out.

An independent exit needs your saved wallet information, both of your usable keys, and compatible signing tools. Test that route while everything is available.

Export / reconstruct / test
06 / Evidence

Judge the implementation, too.

A model diagram is not an audit. This site does not publish an independent wallet audit report. The wallet remains in private testnet beta.

Test coins only
01 · The current model

Who can sign.

Everyday use
Your mobile key and hardware key meet the 2-of-3 threshold. Coinhost's signature is not required for this path.
One key unavailable
The other two keys can still meet the threshold. The path depends on access to those keys, wallet information, and any recovery process required by a signer.
Two keys lost
If two keys and their usable backups are permanently lost, the remaining key cannot spend. An account reset or descriptor cannot change that.
More models
3-of-5 is planned: any three of five keys would meet the threshold. Signer roles, recovery details, and availability are still to be defined.
02 · Before you rely on it

Check the whole path.

Mobile protection
Confirm how your beta build stores and backs up the mobile key. A phone backup or account login is not, by itself, evidence that signing access can be restored.
Hardware protection
Check your exact device and firmware against the beta's supported setup. Follow the manufacturer's backup procedure. Use the signer's display to review transactions where available.
Recovery requirements
Confirm the current identity checks, waiting period, notifications, and cancellation process. Keep those instructions accessible if your phone is lost.
Independent recovery
Save the complete descriptor and verify that a compatible tool can reconstruct the wallet and use your two keys. Rehearse with test coins before relying on this path.
03 · Assisted recovery

A process to rehearse.

Recovery combines your remaining key with Coinhost's key. Follow the procedure for your beta build. The sequence below explains the model; it does not promise a fixed completion time.

01 / Establish access

Know what remains.

Identify the missing key and secure the remaining signer, backups, and account access.

Remaining key + wallet information
02 / Review the request

Check the recovery path.

Complete the required checks and waiting period. Monitor the configured contact channels and report requests you did not make.

Requirements depend on the beta build
03 / Two signatures

Verify. Then authorize.

Check the replacement setup and transaction. Your remaining key and the recovery key together satisfy the threshold.

One key alone is never sufficient

A service pause cannot stop a transaction already authorized by two valid keys. Read the limits of a recovery delay.

04 · Your independent exit

Keep the map.
Keep the keys.

Wallet information

  • PolicyThreshold + signers
  • DescriptorsReceive + change
  • Key originsFingerprints + paths
  • NetworkTestnet during beta

Signing access

  • Your first keyMobile signer
  • Your second keyHardware signer
  • Compatible toolsImport + signing
  • RehearsalA completed test spend

A watch-only wallet can show a balance without being able to spend. Verify both halves of the recovery path. Prepare your independent recovery →

05 · Release status

Clear about where we are.

Private beta / testnet

2-of-3 wallet

The current beta is for test coins. Features and device support may change. Mainnet availability will be announced separately.

No report published here

Independent wallet review

This page describes the custody model. It does not certify the wallet implementation, infrastructure, or recovery operations.

Review evidence must identify its scope
Reports welcome

Responsible disclosure

Report a suspected vulnerability privately. The disclosure policy explains the scope, reporting channel, and research guidelines.

A custody plan you can understand.
A recovery path you can rehearse.