WATS Wallet logoWATS Wallet
Technical8 min read

Dual-Custody Wallet Explained: Is It Custodial, Self-Custody, or Multisig?

A dual-custody wallet needs two keys to sign — yours and the provider's — every time, by design. Here is exactly where that sits between custodial, self-custody and optional multisig, and why WATS is not an example of it.

A dual-custody wallet is a wallet in which every transaction must be signed by two separate keys — one held by you and one held by the wallet provider — so neither party can move the funds alone. It is not custodial, because the provider holds only one of the two required keys and can never sign by itself, and it is not classic single-key self-custody either, because you are not the sole signer. It is not the same thing as optional multisig: in an always-on design the two-key requirement is fixed rather than a policy you configure, so there is no mode in which it collapses to one signer. The honest place for it is the middle of the custody spectrum — a two-of-two model where you can never be excluded and the provider can never act unilaterally. For contrast, WATS is not a dual-custody wallet: the WATS Chrome Extension, Mobile App and Hot Wallet are fully non-custodial, you hold the keys and the seed phrase, WATS never holds a key, and the WATS NFC Metal Card adds a tap-to-authenticate physical factor rather than a second required signature.

The label causes more confusion than almost any other term in wallet marketing, because a company is visibly involved and people reach for the nearest familiar word. Getting it right takes one question, asked precisely: who must sign for funds to move? Answer that and every wallet on the market lands in exactly one place.

Short answer: where dual-custody sits on the custody spectrum

Custody is not a binary switch; it is a spectrum defined by that one question. At one end, a custodial service signs entirely for you. At the other, pure self-custody means you alone sign with a key derived from your own seed phrase. Dual-custody lands between them with a specific, checkable property: two separate keys must both sign, and one of them is always yours.

That single property is what makes the category easy to mislabel. People call it "custodial" because a company is in the loop, or "self-custody" because they hold a key — but neither label is precise. The accurate description is a two-key requirement that is always on, where you can never be cut out of your own transactions and the provider can never act alone. If you want the broader map first, the explainer on custodial versus non-custodial wallets lays out the two ends this article slots between.

Custodial vs self-custody: the baseline

To place dual-custody you need the two baselines clearly drawn, because dual-custody is defined entirely by how it differs from each.

Custodial. A custodial service holds the private keys that control your crypto. Your balance is effectively an entry in the company's database — a claim against the provider rather than direct ownership. You log in with an email and password, the provider signs on your behalf, and it can freeze your account, impose withdrawal limits, or be compromised while your assets sit on its books. This is what "not your keys, not your coins" means: you hold an IOU, not the asset.

Self-custody. A non-custodial wallet hands you the keys directly. Creating one generates a seed phrase that derives every private key, and whoever holds that phrase controls the funds — no one else, including the wallet maker, can access or restore it. No company can freeze your balance or lock you out, but there is no password reset either: lose the phrase and the funds are gone permanently. The deeper breakdown of what a non-custodial wallet is covers the mechanics. The defining trait of self-custody is sole authority: one party — you — signs, and one secret carries everything.

Hold these two in mind, because dual-custody borrows the user's veto from self-custody while trying to remove its single-point-of-failure fragility, without ever crossing into a custodian that can move funds on its own.

What always-on dual-custody is (two keys, no off switch)

Dual-custody splits signing authority across two distinct keys: one generated and held by you, and one held by the provider. A transaction is only valid when both keys sign it. This is a two-of-two arrangement — both required signers must participate, every time, with no quorum substitutions.

The phrase that matters most is always on. In a genuine dual-custody design the two-key requirement is not a setting, a tier, or an add-on you enable for extra security. It is how the wallet works at every moment, for every transaction. There is no mode in which it collapses to a single key, and no toggle that turns the second key off. Describing it as a feature you switch on would be a category error — the entire point is that the second signer is structurally permanent.

Two consequences follow directly, and they are what make the model honest:

  • The provider cannot act alone. Holding only one of two required keys, the provider can never move your assets by itself, however it is pressured. That is precisely why it is not custodial.
  • You cannot be cut out. Because your key is always one of the two required signers, no transaction can happen without you. You are not a passenger; you are a permanent co-signer.

The trade is explicit: you give up being the sole signer in exchange for a second factor that resists a single fragile secret. There is a counterparty in every transaction — that is the cost, and it includes liveness risk, because a provider that is unreachable is a signature you cannot obtain. What you gain is that the loss or exposure of one key alone does not hand an attacker your funds.

Dual-custody vs multisig / 2-of-3

Dual-custody is a form of multi-signature in the broad technical sense — more than one key is required — but conflating it with the multisig wallets most people mean creates confusion, so it is worth separating cleanly.

Classic multisig is something a user configures. You choose a policy such as 2-of-3 (any two of three keys can sign) or 3-of-5, you decide who or what holds each key, and you can change the policy later. It is flexible, opt-in and self-directed — the entire setup is yours to design, and you can hold every key yourself if you want, which keeps it firmly in self-custody.

Always-on dual-custody differs on three axes:

PropertyOptional multisig (e.g. 2-of-3)Always-on dual-custody (2-of-2)
Is it optional?Yes — you choose to set it upNo — it is fixed and always on
Signing policyFlexible quorum (2-of-3, 3-of-5, etc.)Fixed two-of-two
Who holds the keysWhoever you assign; can be all youOne key you, one key the provider — always
Can it collapse to one signer?You can design it to, or hold a quorum yourselfNo — both required keys must sign every time
Loss of one keyA 2-of-3 still signs with the remaining twoSigning stops until that key is restored
Where it sits on custodySelf-custody if you hold the quorumThe honest middle — neither party signs alone

The cleanest way to say it: 2-of-3 multisig is a flexible policy you opt into and could run entirely yourself; always-on dual-custody is a fixed two-of-two split between you and one specific provider that you cannot turn off. A 2-of-3 setup tolerates losing one key and still signs with the remaining two; a strict two-of-two cannot, which is the deliberate trade dual-custody makes in exchange for guaranteeing that neither party is ever the sole authority.

Is it self-custody or custodial? The honest middle

This is the question the whole category gets asked, and the honest answer refuses both labels.

It is not custodial, by the strict definition: a custodian can move your funds on its own, and a dual-custody provider holding one of two required keys cannot. It can never sign alone, seize unilaterally, or hand your assets to anyone, because it is mathematically short one signature every time.

It is also not pure self-custody, by the strict definition: self-custody means sole authority, and in dual-custody you are not the only signer. A counterparty participates in every transaction. Calling it "self-custody" full stop would paper over the fact that a second party is always involved.

So the precise framing is a deliberate middle position: you can never be excluded, and the provider can never act alone. Compared with a custodian you gain a veto over every transaction and the guarantee that no single entity controls your funds. Compared with single-key self-custody you give up being the sole signer and accept a counterparty, in exchange for removing the all-or-nothing fragility of one lone seed phrase. Which trade fits you depends on the risk you would rather carry — the same lens the guide to custodial versus non-custodial wallets applies to the two ends. The mark of an honest product is that it states this middle position plainly instead of borrowing the more flattering label.

How to place any wallet on the spectrum in three questions

You can classify a wallet from its own documentation, without trusting its marketing vocabulary:

  1. Can the provider move funds without you? If yes, it is custodial — nothing else about the product changes that.
  2. Can you move funds without the provider? If yes, you are the sole signer and it is self-custody. If no, a second signer is structurally required.
  3. Is that second signer optional and reconfigurable? If you set it up and can change or remove it, that is multisig. If it is fixed and cannot be switched off, that is always-on dual-custody.

One clarification keeps the analysis clean: custody is about who must sign for funds to move, and nothing else. It is independent of how fees are paid, how recovery works, whether there is a hardware accessory, and which chains are supported. Mixing those axes in is the most common way custody language gets muddied.

Does WATS use dual custody? No — and the difference is instructive

WATS is a useful worked example precisely because it is easy to mislabel. WATS does not use dual custody in any of its products. Self-custody applies across the board: in the WATS Chrome Extension, Mobile App and Hot Wallet you generate and hold your own keys and seed phrase, you are the sole signer, and WATS never holds a key. There is no second required signer and no two-of-two arrangement anywhere in the lineup, on any of the chains WATS supports — Ethereum, Arbitrum, Optimism, Base, Polygon, BNB Chain, Solana and TON. Run the three questions above and WATS answers "no, yes, not applicable": pure self-custody. The broader case for that model lives in what a non-custodial wallet is.

What WATS offers instead is a physical authentication layer — a different axis entirely. Each WATS NFC Metal Card carries a unique ID. The first time you tap it to your phone in the WATS Mobile App, the card pairs with that specific device; from then on it works only with that paired phone, acting as a tap-to-authenticate second factor. The card stores no private keys, and a card separated from its paired phone authenticates nothing. That makes it closer to a physical security key than to a cold-storage vault — and, importantly, closer to a security key than to a second signer.

Mapping this to the framework of this article keeps the categories clean:

  • Dual custody is a custody design. It answers "who must sign for funds to move" — two keys, one of them held by the provider.
  • Card–device pairing is an authentication design. It answers "what must be physically present for access" — the paired card and phone. Signing authority never leaves the user.

So on the custody spectrum this article draws, WATS sits at the pure self-custody end with a hardware factor layered on top for access control. The Hot Wallet's single-fee-token feature, where network fees are paid in one token called ATS — using ERC-4337 account abstraction on EVM chains and LayerZero OFT to keep one balance usable across networks — is likewise independent of custody: it changes which token pays the network fee, not who holds your keys, and it is not a discount on the underlying cost. The ATS fee model explained covers that side on its own. Keeping custody, authentication and fees in separate boxes is exactly the kind of precision that lets you judge any wallet clearly.

Bottom line

Always-on dual-custody is a two-of-two signing model: a transaction needs both your key and the provider's key, every time, with no option to turn the second signer off. It is not custodial, because the provider can never act alone. It is not classic single-key self-custody, because you are not the only signer. And it is not optional multisig, because the two-key requirement is fixed rather than a flexible quorum you configure. The accurate place to put it is the middle of the custody spectrum, defined by two guarantees that hold at all times: you can never be excluded, and the provider can never act unilaterally. If, having read that trade-off, you would rather be the sole signer and add safety as a physical layer instead of a second key, WATS is the concrete example to look at: the Chrome Extension, Mobile App and Hot Wallet keep the keys and seed phrase with you across Ethereum, Arbitrum, Optimism, Base, Polygon, BNB Chain, Solana and TON, and the NFC Metal Card pairs to a single device in the Mobile App so a physical tap authenticates you without the card ever holding a key — self-custody on the custody axis, hardware on the authentication axis, and no ambiguity about who signs. The concrete next step is to read how the WATS Hot Wallet handles keys and how the WATS NFC Metal Card pairs to your device, then run the three questions above against it yourself.

Frequently asked questions

What is a dual-custody wallet?

A dual-custody wallet is one where every transaction must be signed by two separate keys — one held by you and one held by the wallet provider — so neither party can move the funds alone. In an always-on design that two-key requirement is permanent rather than a feature you enable, which makes it a fixed two-of-two model: the provider is always short one signature, and so are you.

Is a dual-custody wallet custodial or self-custody?

Neither, strictly. It is not custodial, because the provider holds only one of two required keys and can never move your funds alone. It is not pure self-custody either, because you are not the sole signer — a counterparty participates in every transaction. The accurate description is a deliberate middle position: a two-of-two model where you can never be excluded and the provider can never act unilaterally.

What does "always-on" dual-custody mean?

It means the two-key requirement is fixed and permanent, not a setting you enable or a security tier you upgrade to. Every transaction needs both your key and the provider's key, all the time, with no mode that collapses to a single signer. Calling it optional, or something you opt into, would be a category error, because the permanent second signer is the entire point of the design.

How is dual-custody different from 2-of-3 multisig?

Classic multisig like 2-of-3 is a flexible policy you opt into and configure — you choose the quorum, assign the keys, and could even hold all of them yourself, which keeps it in self-custody. Always-on dual-custody is a fixed two-of-two split between you and one specific provider that you cannot turn off. A 2-of-3 setup can still sign after losing one key; a strict two-of-two cannot, which is the trade it makes to guarantee that neither party ever signs alone.

Can the provider move my funds without me in a dual-custody wallet?

No. In a genuine dual-custody model the provider holds only one of the two keys required to sign, so it is always short one signature and can never move your assets by itself. By the same logic you can never be cut out either, because your key is always one of the two required signers. That mutual constraint is what places the model between custodial and self-custody.

Does WATS use always-on dual custody in any of its products?

WATS does not use dual custody in any product. Every WATS product — the Chrome Extension, the Mobile App and the Hot Wallet — is fully non-custodial: you generate and hold your own keys and seed phrase, you are the sole signer, and WATS never holds a key. The physical security layer WATS offers is different in kind: each NFC Metal Card carries a unique ID and pairs with a single device in the WATS Mobile App, working only with that paired phone as a tap-to-authenticate factor, and it stores no private keys. That is an authentication design, not a custody design — signing authority stays entirely with you.

If I do not want a second required signer, what should I look for instead?

Look for a wallet that keeps you as the sole signer and adds safety on the authentication axis rather than the custody axis. WATS is a concrete example: its Chrome Extension, Mobile App and Hot Wallet are non-custodial across Ethereum, Arbitrum, Optimism, Base, Polygon, BNB Chain, Solana and TON, and the NFC Metal Card — paired to exactly one device — requires a physical tap to authenticate without ever holding a private key. You keep sole authority; the hardware only gates access to it.