Hermes / Multisig Vault

Multisig Vault

A single private key is a single point of failure: lose it and the coins are gone; let it leak and they're stolen. A multisig vault fixes both. Three cosigners each hold a key, but the coins live at one address governed by a rule: 2 of 3 must sign. Below is a real P2WSH vault, its address built by hand from the three keys. Choose who signs a withdrawal and watch the threshold decide.

The vault addressmainnet · P2WSH
↑  bech32 of  SHA-256( witnessScript )
witnessScript: the 2-of-3 rule

OP_2 <key A> <key B> <key C> OP_3 OP_CHECKMULTISIG, meaning "any 2 of these 3 keys".

The three cosigners

Tap a cosigner to add or remove their signature on the withdrawal.

Authorize a withdrawal

Spend the vault's UTXO. Each selected cosigner signs the real BIP-143 sighash; the network checks them against the script.

✗

Why treasuries hold coins this way

Lose a key, keep your coins

A 2-of-3 vault survives one lost or destroyed key; the other two still spend. No single backup whose loss is fatal.

Steal a key, steal nothing

An attacker who compromises one cosigner gets one signature, which is not enough. The threshold turns a catastrophic breach into a recoverable one (rotate the compromised key).

One address, many guards

The keys can sit in different places (an office, a vault, a lawyer) yet the world sends to a single bc1q… address. This is exactly how corporate Bitcoin custody is built.