Most bitcoin custody arrangements that look distributed are not. A wallet holding several keys from one manufacturer has one firmware, one entropy path, and therefore one way to fail. The keys are separate objects. They are not separate risks.
The Custody Independence Standard is a published test for that distinction. It asks four questions of any arrangement, and it is written so that a reader can apply it to a setup we have never scored, including their own. An arrangement earns a pillar by meeting it, regardless of whether it is institutional, collaborative, or entirely self-managed.
The question this standard answers: how many independent parties or systems must fail before the bitcoin is at risk, and who is responsible for keeping them independent?
In July 2026, a firmware defect in a widely used hardware wallet caused the device to skip its hardware random number generator and fall back to a predictable software one. Keys generated on affected firmware could be reconstructed offline. The relevant detail for this standard is not the defect itself, it is what it did to multisig holders: wallets built from several units of the same device lost every key to a single root cause at the same moment.
Those holders had done what the industry told them to do. They had multiple keys, multiple devices, and a signing threshold. What they did not have was independence. Our incident status page tracks that event and the conflicting vendor guidance around it.
Can any single manufacturer or software vendor reach the spending threshold?
Keys must originate from separate vendors, so that one firmware defect, supply-chain compromise, or vendor insolvency cannot reach the threshold on its own. Counting devices is not the test. Counting distinct vendors is.
How it failsA 2-of-3 multisig using three hardware wallets from the same manufacturer has one vendor, one firmware, and one failure domain.
Were the keys generated by genuinely independent sources of randomness?
Each key must be generated by a separate entropy process under documented controls. Keys created on the same model, same firmware version, or the same ceremony share an entropy path even when the devices are physically distinct.
How it failsThree seeds generated on three devices running the same defective firmware are not three independent seeds. They are one seed generator used three times.
Can any single party move funds unilaterally?
The signing quorum must span separate legal entities or separately held keys, so that no one party, including the platform itself, can move assets alone. Compromise, coercion, insolvency, or insider action at any single party must be survivable.
How it failsA custodian that holds every key has full unilateral control regardless of how many internal approvals it documents.
Who sustains the separation over decades, and can you recover without the provider if it disappears?
Independence is not a setup state, it is a maintained condition. This pillar asks whether key holders are jurisdictionally and physically separated, whether recovery is documented and tested, and whether the burden falls on institutions or on one individual's memory. It also asks the exit question: if the provider shuts down, is acquired, or simply stops answering, can the holder reconstruct and spend the wallet using independent open-source tooling? An arrangement only one company's software can spend from concentrates vendor risk at the script layer no matter how many keys it holds.
How it failsThree vendor-diverse hardware wallets in one desk drawer are geographically concentrated. A vault whose spending policy is implemented in closed-source software that only its provider runs cannot be independently audited, and cannot be recovered if that provider is gone.
The matrix below assesses custody architectures rather than named products, so it stays accurate without asserting per-vendor claims we cannot substantiate. Individual platform assessments appear on each platform's review page.
| Custody architecture | Vendor | Entropy | Control | Operational | Must fail |
|---|---|---|---|---|---|
Single-signature hardware wallet One device, one firmware, one key. Whoever compromises the entropy path or the device holds the coins. | ○ | ○ | ○ | ○ | 1 |
Multisig, all keys from one vendor Looks distributed, is not. One firmware defect reaches every key at once. This is the configuration that made the Coldcard incident a systemic event rather than an individual loss. | ○ | ○ | ◐ | ○ | 1 |
Multisig, keys from different vendors, self-managed Technically the strongest self-managed answer. Every pillar of independence is achievable, and the entire burden of sustaining it over decades sits with one person. | ● | ● | ● | ○ | 2 to 3 |
Collaborative custody The provider cannot move funds alone, which is real sovereignty. Vendor and entropy independence still depend on which devices the holder chooses, and geographic separation remains the holder's job. | ◐ | ◐ | ● | ◐ | 2 |
Qualified single custodian Strong on segregation, legal title, and operational discipline. Unchanged on independence: one institution can move the assets. | ○ | – | ○ | ◐ | 1 |
Multi-institution custody Independence is structural rather than holder-maintained. Separate institutions generate and hold keys under their own ceremonies, in separate jurisdictions, and the burden of sustaining that sits with them. | ● | ● | ● | ● | 2 |
Two results in that matrix deserve emphasis, because they are the ones most often misread.
Multisig with keys from one vendor scores worse than most people expect. It provides real protection against theft of a single device and against some categories of operator error. It provides no protection at all against a defect in the thing every key has in common.
Self-managed multi-vendor multisig scores better than most institutions will admit. A holder who genuinely uses different manufacturers, verifies each entropy source, separates the keys geographically, and documents recovery has built something with excellent independence. The pillar it cannot satisfy is the fourth one, and the reason is not technical.
How many separate parties or systems must fail before the bitcoin is at risk. Devices are not domains. Keys that share a manufacturer, a firmware build, or an entropy path all fail together.
The first three pillars are properties of a setup. The fourth is a property of a decade. Independence is not a state you reach at setup, it is a condition somebody has to maintain: firmware tracked across several vendors, keys kept in genuinely separate places, recovery tested rather than assumed, and a handoff that works when the person who built it is not available to explain it.
Self-managed arrangements put that entire burden on one person. That is a legitimate choice, and for holders with the discipline to sustain it, it produces excellent independence. It also carries a failure mode with a completion rate of one hundred percent over a long enough horizon, which is the holder's own death or incapacity. Institutional arrangements move that burden to entities whose job it is to carry it, and pay for that with fees and counterparty relationships.
Neither answer is universally correct. The standard exists so the trade is visible instead of implied.
Each platform is evaluated from published architecture: how many distinct parties generate and hold keys, whether any single one can reach the spending threshold, what is documented about key generation and recovery, and where the operational burden sits. Where a platform's outcome depends on choices the holder makes, the pillar is marked depends on configuration rather than met, because the platform cannot guarantee it. Where architecture is not publicly documented, the pillar is marked not publicly documented rather than assumed either way.
A platform earns the Independence Verified badge only by meeting all four pillars. Any provider that believes an assessment is wrong can send documentation to hello@proofofcustody.io. Corrections are published in our corrections log and changes to this standard in our changelog.
Take the four questions in order and answer them about the wallet holding most of your bitcoin. Count vendors rather than devices. Count entropy sources rather than seed phrases. Ask who could move the coins acting alone, then ask who is responsible for keeping the rest of it true in five years. Our walkthrough of what those answers mean in practice is in Is your custody setup actually safe?
Proof of Custody, Custody Independence Standard v1.0, proofofcustody.io/standards/custody-independenceIt is a published four-pillar test of whether a bitcoin custody arrangement has genuine independence: vendor independence, entropy independence, control independence, and operational independence. An arrangement meets a pillar on its merits regardless of whether it is institutional, collaborative, or self-managed.
Not on its own. Multisig distributes keys, but if those keys come from the same manufacturer they share one firmware and one entropy path, so a single defect can reach all of them at once. Independence depends on how many distinct vendors, entropy sources, and parties are genuinely involved, not on how many devices you own.
No. A self-managed multisig using devices from different manufacturers, with verified entropy, genuine geographic separation, and documented tested recovery can meet the first three pillars fully. The fourth pillar, operational independence, is the difficult one for self-managed setups because it asks who sustains the separation over decades and what happens on death or incapacity.
The count is the wrong question. Three devices from one vendor is one failure domain. Three devices from three vendors is closer to three, but only if they are separated geographically and their recovery is documented. Ask how many independent things must fail before you lose access, not how many devices you own.
Dice can address the quality of entropy for one key, which is a real improvement when a device's own randomness is not trustworthy. They do nothing for vendor independence, control independence, or operational independence. A perfectly generated key held in a single-signature wallet is still a single point of failure.