Multisig Threshold Planner
Work out an M-of-N multisig threshold from how many signers you have and how many you can afford to lose, showing the loss and compromise tolerance of every combination.
Last reviewed by the Radiatus Cloud team
Need this done properly for your business?
Radiatus delivers secure cloud, DevOps & compliance engineering.
Every threshold trades two failure modes against each other
An M-of-N multisig fails in two opposite ways. It can be compromised, when an attacker obtains M keys, and it can be bricked, when more than N minus M keys are lost and no valid quorum remains. Raising M protects against the first and worsens the second, and there is no value that eliminates both. Choosing a threshold is choosing which failure you would rather have, and the answer depends on whether keys are more likely to be stolen or lost in your situation, which for most individuals is loss.
Two of three is popular for a reason and is not always right
Two of three tolerates one loss and one compromise, which is the smallest configuration that tolerates anything at all. It fails when two keys are stored in ways that share a risk: two devices in one house, or two seed backups in one safe, make it effectively one-of-one against fire and two-of-two against nothing. The number is only as good as the independence of the keys behind it, and that independence is the part nobody audits.
The recovery path is the part that is never tested
A multisig that has never had a signer replaced has an untested recovery procedure, and the moment it is needed is the moment a key has been lost, which is when the remaining quorum is at its smallest. Rehearsing a signer rotation while everything works costs an afternoon; discovering that the procedure does not work while one key is already gone costs the funds. This is the single most common way a well-designed multisig fails in practice.
Related tools
- Ethereum Unit Converter — Convert between Wei, Gwei, and Ether units.
- Gas Fee Calculator — Calculate transaction costs based on gas price and limit.
- IPFS CID Generator — Generate IPFS Content Identifiers (CID) from text or files.
- Wallet Address Validator — Validate Ethereum and Bitcoin wallet addresses.
Frequently Asked Questions
What does M of N mean?
M signatures out of N total signers are needed to move funds. Raising M makes compromise harder and loss more dangerous, and lowering it does the reverse.
How many keys can I lose?
N minus M. At two of three you can lose one; at three of five you can lose two. Beyond that no valid quorum remains and the funds are permanently inaccessible.
How many keys can be stolen?
M minus one without any loss of funds. At two of three, one stolen key is survivable and two is not.
Is two of three always right?
It is the smallest useful configuration. It fails when two keys share a risk, such as two devices in one house, because the number is only as good as the independence of the keys behind it.
Why rehearse a signer replacement?
Because it is needed exactly when a key has already been lost and the quorum is at its smallest. Discovering the procedure does not work at that moment is the most common way a well-designed multisig fails.
Privacy & Security
Everything runs in your browser; nothing is uploaded.
How to Use
Enter your signer count and threshold to see the trade-off.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.