South Africa's Bitcoin specialists. Compliant by design.
Custody & Security · By James Caw · Updated June 2026 · 9 min read

SimplB Vault: What Multi-Signature Custody Means for Your Bitcoin

A single hardware wallet is one key, one backup and one thing that can go wrong. SimplB Vault removes that single point of failure for larger holdings by splitting control across three keys, where you hold two and I hold one, and no party on earth can move the Bitcoin alone. It is the structure I reach for once a position is worth more than any one device should carry.

Key takeaway

SimplB Vault is a 2-of-3 multisig built on three hardware devices from three manufacturers, a Trezor, a Ledger and a Coldcard. You hold two keys and I hold the third for recovery and inheritance only. Any two signatures move the Bitcoin, so I can never act alone and you can always transact without me. Every key gets a steel backup and the keys live in separate places across South Africa, so no location can reach the threshold alone.

Below I walk through what multisig actually is, how the Vault is put together, why it earns its place above a certain value and where the honest trade-offs sit.

What multi-signature really means

Multisig means that spending Bitcoin needs more than one key to agree. In a 2-of-3 arrangement, three separate keys create the wallet and any two of them must sign before a single satoshi moves. One key on its own is powerless. That is the whole idea, and it is the same primitive that serious custodians have leaned on for years because it turns a lone secret into a quorum.

The difference this makes is not theoretical. A standard single-signature setup is one key with zero margin for error. Lose the seed and the Bitcoin is gone forever. Let a thief find it and the Bitcoin is gone that afternoon. Multisig takes that cliff edge and replaces it with a floor, because in a 2-of-3 wallet any single key can be lost, stolen or destroyed and the funds remain safe and reachable with the other two. You replace the missing key and rotate the vault at your own pace, which is a very different experience from staring at an empty wallet and a burnt piece of paper.

Losing one key is a Tuesday. In single-sig it is the end.

How the SimplB Vault is built

The Vault is a 2-of-3 multisig on three hardware devices from three manufacturers, a Trezor, a Ledger and a Coldcard. The vendors differ on purpose. If a firmware bug or supply chain compromise hits one manufacturer, it cannot touch all three keys at once. Because the three devices independently confirm the same receive address, a silent hardware fault gets caught before Bitcoin is sent to a dead address rather than after. You hold two of them on your own devices. I hold the third on an air-gapped Coldcard, purely for recovery and inheritance support under the regulated service.

You generate your own keys, with me guiding every step, and I never see or touch your seed words. Each key is written down, then stamped into a stainless steel plate that shrugs off fire and the kind of flood anyone in George will tell you about. The plates and devices then go to separate secure locations planned around your actual life, following a rule institutional custody has used for years: no two seed backups are ever stored together in one place. One key at home in Cape Town, one in an office safe in Sandton, the recovery key with me. Geography is not a nicety here. It is what stops a single burglary, a single fire or a single person with a demand from ever reaching a quorum.

When you want to move Bitcoin, you sign with your two keys and it goes. I am not in the loop for a normal withdrawal at all. My key exists for the day something breaks.

Why no single party can move your Bitcoin

This is the property the whole design turns on, so it is worth being blunt about it. Moving funds needs two of the three signatures. You control two keys. I control one. That arithmetic means I can never move your Bitcoin on my own, because one signature is not a quorum, and it also means you never need me to spend your own coins, because your two keys already clear the threshold. The regulated participation I provide sits alongside your control rather than on top of it.

Compare that to leaving Bitcoin on an exchange, where the exchange holds every key and your balance is an entry in their database that behaves like their asset the moment anything goes wrong. Multisig is verifiable in a way a database line never is. Because the wallet lives openly on the Bitcoin blockchain, you can see the address, confirm it genuinely requires two of three signatures and check the balance yourself, without taking my word for any of it. Auditors get the same transparency, which is precisely why regulated entities prefer on-chain multisig to solutions that hide the signing behind a private log. The proof is native to the chain.

Why it earns its place for larger holdings

For a modest position I do not push anyone toward a Vault. A single hardware wallet, bought directly from the manufacturer, backed up on steel and tested by restoring from the seed, is honest security and it is where I start most people. I lay that groundwork out fully in my guide to Bitcoin self-custody in South Africa, and the principle behind splitting keys in multi-signature Bitcoin custody.

Past a certain value the maths changes. When a holding is large enough that losing it would reorder your life, concentrating everything behind one key and one backup starts to feel thin, and that is the moment the structure itself should carry the discipline rather than your memory and your luck. A family office cannot run a serious Bitcoin position on a device in a drawer. A company holding Bitcoin on its balance sheet cannot answer its board with a single seed phrase. Multisig gives those holders something a single wallet cannot, which is redundancy against loss and a governance structure at the same time, so that no one person, whether a rogue employee, a compromised laptop or a founder under duress, can unilaterally move the treasury.

There is a South African wrinkle here that counts for more than most people realise. Because you physically hold the majority of the keys locally, the Bitcoin is treated as a locally domiciled asset held inside a regulated structure. For a company that has been a genuinely useful thing, because it is currently one of the cleaner ways to actually own your Bitcoin in self-custody rather than leaving it with a service provider, without first asking the Reserve Bank for permission to move wealth into an offshore arrangement. That is a structural advantage of holding your keys here at home, and it is one I did not fully appreciate until clients started asking exactly the right questions about domicile.

What happens when a key is lost

The redundancy is not a marketing line. It is the day-to-day reason the Vault exists.

Say a device dies, a plate goes missing in a house move or one location is simply no longer safe. In a single-sig setup any one of those events is a catastrophe. In the Vault it is an inconvenience you handle at leisure. You still hold a controlling pair of keys, or you and I together still clear the threshold, so the assets can be migrated to a freshly generated vault with new keys while nothing is ever exposed. The Bitcoin moves to safety first and the panic never arrives.

There is one piece of a multisig that people setting it up on their own almost always forget and it quietly ruins recoveries. Alongside the seed words you also need the wallet configuration file, the descriptor that tells recovery software which three keys make up the wallet. Lose that file in a do-it-yourself setup and a full set of seed words, correctly written and safely stored, can still leave you locked out. In the managed Vault I hold that configuration file alongside my recovery key, so the map and a signature are already in safe hands the day you need them.

Estate access built in from day one

Courts can confirm who your heirs are. No court on earth can decrypt a private key. That gap is where most Bitcoin inheritance plans quietly fail, and it is the gap the Vault is built to close.

Every Vault comes with a documented recovery plan, a letter of instruction telling your executor what exists, where the keys live and who to contact, without a single seed word ever being written into a will that becomes a public document during estate administration. The inheritance path is deliberately simple for the person who has to walk it. Your executor does not need to be technical and does not need to hunt down every device you ever owned. Retrieving any one of your seed backups is enough, because my Coldcard recovery key co-signs alongside it to reach the threshold and release the Bitcoin on the estate's instruction. I set out what executors actually face in what happens to your Bitcoin when you die in South Africa.

Millions of coins are already lost to the grave forever. A Vault is how you make sure yours is not one of them.

The honest trade-offs

A Vault asks more of you than an app on a phone. There are three keys to keep track of, several locations to maintain and a setup that is deliberately slow because rushing it is how mistakes get baked in. I do five Vault setups a month, by consultation, precisely because doing one properly takes real time and includes the estate work that makes it worth having. For a small holding that overhead is not justified, and I will say so.

The complexity is the point rather than a flaw. Institutions and family offices administer serious assets with exactly this kind of active care, and once the setup is done the discipline becomes boring, which in custody is the highest compliment I can pay a structure. What you are buying is not convenience. It is the removal of the single point of failure that has quietly taken more Bitcoin than every exchange hack combined, a pattern I track in what has and has not been hacked in Bitcoin's history.

Who the Vault is for

The Vault suits holders whose position has outgrown a single device. Family offices treating Bitcoin as a core asset get a structure that matches their fiduciary standards. Trusts holding coins across generations get an inheritance path that survives the founder. Companies carrying Bitcoin on the balance sheet get withdrawals that need two parties by design rather than by policy, view-only access for auditors and an asset that stays locally domiciled and off any custodian's books.

If your holding is smaller, start with guided self-custody and grow into a Vault when the value asks for it. If you already run pure self-custody with full confidence, you may not need my third key at all. There is no shame in either answer, and I would rather point you to the right level than sell you a structure you do not yet need. When you are weighing it up, book a Vault setup consultation and I will map the key geography, the estate plan and the whole arrangement to your situation before anything is built.

Frequently asked questions

What is SimplB Vault and how does it work?

SimplB Vault is a 2-of-3 multisig Bitcoin custody structure built on three hardware devices from three manufacturers, a Trezor, a Ledger and a Coldcard. You hold two keys and I hold the third on an air-gapped Coldcard for recovery and inheritance only. Any two signatures move the Bitcoin, so I can never act alone and your own two keys already let you transact without me. Every key gets a steel backup and the keys are stored in separate locations.

What is 2-of-3 multisig custody and why does it matter?

It means three private keys create the wallet and any two of them must sign before Bitcoin can move. No single key can move funds on its own. This removes the single point of failure that a lone hardware wallet carries, where losing one seed phrase means total loss, while still leaving you fully in control. If one key is ever lost, stolen or destroyed, the other two keep the Bitcoin safe and reachable.

Who holds the keys in a SimplB Vault arrangement?

You do, for two of the three. You generate your own keys with me guiding every step and I never see or touch your seed words. I hold the third key on an air-gapped Coldcard purely for recovery and inheritance support under the regulated service. In normal use your two keys sign on their own. If a key is ever lost, my recovery key co-signs with your remaining one to reach the threshold.

What happens to my Bitcoin if SimplB stops operating?

Nothing that locks you out. You hold two of the three keys, which is enough to move funds on your own without any input from me. You can transfer your Bitcoin to any address you control at any time. The structure is designed so that my continued existence is never a dependency on your access, and you keep the wallet configuration you need for a standard multisig recovery.

What is the minimum holding size for SimplB Vault?

There is no hard rand line, but the Vault earns its place once a position has outgrown a single hardware wallet, which for most people is well above the R10,000 where I start guided self-custody. Below that the overhead of three keys and several locations is not justified, and a single hardware wallet backed up on steel and tested by restoring from the seed does the job well. I do five Vault setups a month by consultation.

Split the keys before you need to.

SimplB helps South Africans buy, secure and structure Bitcoin compliantly, as a Juristic Representative of CAEP Asset Managers (FSP 33933).

Book a Vault setup consultation