On this page
Back to: Security & Self-Custody Advanced
0
Objective: understand every non-seed recovery path honestly — what saves you, what exposes you, and what’s marketing.
Concept: the options, ranked by trust
- Multisig quorum (lose 1 of 3): no third party involved. Gold standard.
- Social recovery: guardians co-sign a reset. Trusts your circle’s honesty + availability.
- Custodial recovery: exchange/app resets your password. Full trust in the company (and its hackers, acquirers, regulators).
- Shamir shards: seed split into pieces needing a threshold. Elegant, operationally fiddly, shard-storage discipline required.
- “AI/encrypted cloud backup”: convenience products holding encrypted keys. Read who holds the decryption path — that’s your custodian with better branding.
Hands-on lab (free)
- Inventory *your* current recovery paths: list every way back into each wallet/exchange you use.
- Grade each: whom do you trust, what breaks if they’re evil/offline/hacked?
- Close the worst gap this week (e.g., add a second backup location, or migrate one custodial balance to multisig).
Safety checklist
- Every recovery path is also an attack path — count them like an adversary would.
- “Forgot password” flows on custodial apps are phishing’s favorite costume. Verify domains ruthlessly.
- Document the map for heirs without putting secrets in it.
Related glossary
Path complete. You now think in threat models, not tips. Teach one person the SIM-swap lockdown — that’s how the ecosystem hardens.
Course: Security & Self-Custody Advanced Lesson 5 of 5