[{"data":1,"prerenderedAt":25},["ShallowReactive",2],{"blog-content-en-always-on-dual-custody-wallet-explained":3},{"slug":4,"title":5,"excerpt":6,"description":7,"bodyHtml":8,"faqItems":9},"always-on-dual-custody-wallet-explained","Dual-Custody Wallet Explained: Is It Custodial, Self-Custody, or Multisig?","Dual-custody means signing needs two keys — yours and the provider's — always, by design. Here is exactly where it sits between custodial, self-custody, and optional multisig.","Dual-custody wallet explained: an always-on two-key model that is neither custodial nor classic self-custody, and how it differs from optional multisig.","\u003Cp>A dual-custody wallet is one where authorizing a transaction always requires two keys — one you hold and one the provider holds — so neither party can move funds alone. It is not custodial, because the provider cannot act without you and never holds your assets the way an exchange does. It is also not classic single-key self-custody, because you are not the sole signer. And it is not the same as optional multisig: in an always-on dual-custody model the two-key requirement is fixed and permanent, not a feature you switch on. The honest answer to \"is it self-custody or custodial?\" is that it sits deliberately in the middle — a two-of-two design where the user is always one of the two required signers.\u003C\u002Fp> \u003Ch2>Short answer: where dual-custody sits on the custody spectrum\u003C\u002Fh2> \u003Cp>Custody is not a binary switch; it is a spectrum defined by one question — who must sign for funds to move. At one end, a custodial service signs entirely for you. At the other, pure self-custody means you alone sign with a single key derived from your seed phrase. Dual-custody lands between them with a specific, checkable property: \u003Cstrong>two separate keys must both sign, and one of them is always yours\u003C\u002Fstrong>.\u003C\u002Fp> \u003Cp>That single property is what makes the category easy to mislabel. People call it \"custodial\" because a company is involved, or \"self-custody\" because they hold a key — but neither label is precise. The accurate description is a two-key requirement that is always on, where you can never be cut out of your own transactions and the provider can never act alone. If you want the broader map first, our explainer on \u003Ca href=\"\u002Fblog\u002Fcustodial-vs-non-custodial-wallet\">custodial versus non-custodial wallets\u003C\u002Fa> lays out the two ends this article slots between.\u003C\u002Fp> \u003Ch2>Custodial vs self-custody: the baseline\u003C\u002Fh2> \u003Cp>To place dual-custody, you need the two baselines clearly drawn, because dual-custody is defined by how it differs from each.\u003C\u002Fp> \u003Cp>\u003Cstrong>Custodial.\u003C\u002Fstrong> A custodial service holds the private keys that control your crypto. Your balance is effectively an entry in the company's database — a claim against the provider rather than direct ownership. You log in with email and password, the provider signs on your behalf, and it can freeze your account, impose withdrawal limits, or be compromised while your assets sit on its books. This is the meaning of \"not your keys, not your coins\": you hold an IOU, not the asset.\u003C\u002Fp> \u003Cp>\u003Cstrong>Self-custody.\u003C\u002Fstrong> A non-custodial wallet hands you the keys directly. Creating one generates a \u003Cstrong>seed phrase\u003C\u002Fstrong> that derives every private key, and whoever holds that phrase controls the funds — no one else, including the wallet maker, can access or restore it. No company can freeze your balance or lock you out, but there is no password reset either: lose the phrase and the funds are gone permanently. Our deeper breakdown of \u003Ca href=\"\u002Fblog\u002Fwhat-is-a-non-custodial-wallet\">what a non-custodial wallet is\u003C\u002Fa> covers the mechanics. The defining trait of self-custody is sole authority: one party — you — signs, and one secret carries everything.\u003C\u002Fp> \u003Cp>Hold these two in mind, because dual-custody borrows the user's control from self-custody while removing its single-point-of-failure fragility, without ever crossing into a custodian holding your funds.\u003C\u002Fp> \u003Ch2>What dual-custody is (user key + provider key, always on)\u003C\u002Fh2> \u003Cp>Dual-custody splits signing authority across two distinct keys: one generated and held by you, and one held by the provider. A transaction is only valid when \u003Cstrong>both\u003C\u002Fstrong> keys sign it. This is a two-of-two arrangement — both required signers must participate, every time, with no quorum substitutions.\u003C\u002Fp> \u003Cp>The phrase that matters most here is \u003Cstrong>always on\u003C\u002Fstrong>. In a genuine dual-custody design the two-key requirement is not a setting, a tier, or an add-on you enable for extra security. It is how the wallet works at every moment, for every transaction. There is no mode in which it collapses to a single key, and there is no toggle to turn the second key off. Describing it as a feature you switch on would be a category error — the entire point is that the second signer is structurally permanent.\u003C\u002Fp> \u003Cp>Two consequences follow directly, and they are what make the model honest:\u003C\u002Fp> \u003Cul> \u003Cli>\u003Cstrong>The provider cannot act alone.\u003C\u002Fstrong> Holding only one of two required keys, the provider can never move your assets by itself, however it is pressured. That is precisely why it is not custodial.\u003C\u002Fli> \u003Cli>\u003Cstrong>You cannot be cut out.\u003C\u002Fstrong> Because your key is always one of the two required signers, no transaction can happen without you. You are not a passenger; you are a permanent co-signer.\u003C\u002Fli> \u003C\u002Ful> \u003Cp>The trade is explicit: you give up being the \u003Cem>sole\u003C\u002Fem> signer in exchange for a second factor that resists a single fragile secret. There is a counterparty in every transaction — that is the cost. What you gain is that losing or exposing one key alone does not hand an attacker your funds.\u003C\u002Fp> \u003Ch2>Dual-custody vs multisig \u002F 2-of-3\u003C\u002Fh2> \u003Cp>Dual-custody is a form of multi-signature in the broad technical sense — more than one key is required — but conflating it with the multisig wallets most people mean creates confusion, so it is worth separating cleanly.\u003C\u002Fp> \u003Cp>Classic \u003Cstrong>multisig\u003C\u002Fstrong> is something a user configures. You choose a policy such as 2-of-3 (any two of three keys can sign) or 3-of-5, you decide who or what holds each key, and you can change the policy later. It is flexible, opt-in, and self-directed — the entire setup is yours to design, and you can hold every key yourself if you want, which keeps it firmly in self-custody.\u003C\u002Fp> \u003Cp>Always-on dual-custody differs on three axes:\u003C\u002Fp> \u003Ctable> \u003Cthead> \u003Ctr>\u003Cth>Property\u003C\u002Fth>\u003Cth>Optional multisig (e.g. 2-of-3)\u003C\u002Fth>\u003Cth>Always-on dual-custody (2-of-2)\u003C\u002Fth>\u003C\u002Ftr> \u003C\u002Fthead> \u003Ctbody> \u003Ctr>\u003Ctd>Is it optional?\u003C\u002Ftd>\u003Ctd>Yes — you choose to set it up\u003C\u002Ftd>\u003Ctd>No — it is fixed and always on\u003C\u002Ftd>\u003C\u002Ftr> \u003Ctr>\u003Ctd>Signing policy\u003C\u002Ftd>\u003Ctd>Flexible quorum (2-of-3, 3-of-5, etc.)\u003C\u002Ftd>\u003Ctd>Fixed two-of-two\u003C\u002Ftd>\u003C\u002Ftr> \u003Ctr>\u003Ctd>Who holds the keys\u003C\u002Ftd>\u003Ctd>Whoever you assign; can be all you\u003C\u002Ftd>\u003Ctd>One key you, one key the provider — always\u003C\u002Ftd>\u003C\u002Ftr> \u003Ctr>\u003Ctd>Can it collapse to one signer?\u003C\u002Ftd>\u003Ctd>You can design it to, or hold a quorum yourself\u003C\u002Ftd>\u003Ctd>No — both required keys must sign every time\u003C\u002Ftd>\u003C\u002Ftr> \u003Ctr>\u003Ctd>Where it sits on custody\u003C\u002Ftd>\u003Ctd>Self-custody if you hold the quorum\u003C\u002Ftd>\u003Ctd>The honest middle — neither party signs alone\u003C\u002Ftd>\u003C\u002Ftr> \u003C\u002Ftbody> \u003C\u002Ftable> \u003Cp>The cleanest way to say it: 2-of-3 multisig is a flexible policy \u003Cem>you\u003C\u002Fem> opt into and could run entirely yourself; always-on dual-custody is a fixed two-of-two split between you and one specific provider that you cannot turn off. A 2-of-3 setup can tolerate losing one key and still sign with the remaining two; a strict two-of-two cannot, which is the deliberate trade dual-custody makes in exchange for guaranteeing that neither party is ever the sole authority.\u003C\u002Fp> \u003Ch2>Is it self-custody or custodial? (the honest middle)\u003C\u002Fh2> \u003Cp>This is the question the whole category gets asked, and the honest answer refuses both labels.\u003C\u002Fp> \u003Cp>It is \u003Cstrong>not custodial\u003C\u002Fstrong>, by the strict definition: a custodian can move your funds on its own, and a dual-custody provider holding one of two required keys cannot. It can never sign alone, freeze-and-seize unilaterally, or hand your assets to anyone, because it is mathematically short one signature every time.\u003C\u002Fp> \u003Cp>It is also \u003Cstrong>not pure self-custody\u003C\u002Fstrong>, by the strict definition: self-custody means sole authority, and in dual-custody you are not the only signer. A counterparty participates in every transaction. Calling it \"self-custody\" full stop would paper over that a second party is always involved.\u003C\u002Fp> \u003Cp>So the precise framing is a deliberate middle position: \u003Cstrong>you can never be excluded, and the provider can never act alone\u003C\u002Fstrong>. Compared with a custodian you gain veto power over every transaction and the guarantee that no single entity controls your funds. Compared with single-key self-custody you give up being the sole signer and accept a counterparty, in exchange for removing the all-or-nothing fragility of one lone seed phrase. Whether that trade fits you depends on which risk you would rather carry — the same lens our guide to \u003Ca href=\"\u002Fblog\u002Fcustodial-vs-non-custodial-wallet\">custodial versus non-custodial wallets\u003C\u002Fa> applies to the two ends. The mark of an honest product is that it states this middle position plainly rather than borrowing the more flattering label.\u003C\u002Fp> \u003Cp>One clarification keeps the analysis clean: custody is about \u003Cem>who must sign for funds to move\u003C\u002Fem>, and nothing else. It is independent of how fees are paid, how recovery is handled, or which chains are supported. Mixing those in is the most common way custody language gets muddied.\u003C\u002Fp> \u003Ch2>Does WATS use dual custody? No — and the difference is instructive\u003C\u002Fh2> \u003Cp>It is worth using \u003Ca href=\"\u002Fhot-wallet\">WATS\u003C\u002Fa> as a concrete example precisely because it is easy to mislabel. WATS does not use dual custody in any of its products. Self-custody applies across the board: in the WATS Chrome extension, mobile app and Hot Wallet you generate and hold your own keys and seed phrase, you are the sole signer, and WATS never holds a key. There is no second required signer and no two-of-two arrangement anywhere in the lineup. The broader case for that model lives in \u003Ca href=\"\u002Fblog\u002Fwhat-is-a-non-custodial-wallet\">what a non-custodial wallet is\u003C\u002Fa>.\u003C\u002Fp> \u003Cp>What WATS offers instead is a \u003Cem>physical authentication layer\u003C\u002Fem> — a different axis entirely. Each WATS NFC Metal Card carries a unique ID. The first time you tap it to your phone in the WATS mobile app, the card pairs with that specific device; from then on it works only with that paired phone, acting as a tap-to-authenticate second factor. The card stores no private keys, and a card separated from its paired phone authenticates nothing.\u003C\u002Fp> \u003Cp>Mapping this to the framework of this article keeps the categories clean:\u003C\u002Fp> \u003Cul> \u003Cli>\u003Cstrong>Dual custody is a custody design.\u003C\u002Fstrong> It answers \"who must sign for funds to move\" — two keys, one of them held by the provider.\u003C\u002Fli> \u003Cli>\u003Cstrong>Card–device pairing is an authentication design.\u003C\u002Fstrong> It answers \"what must be physically present for access\" — the paired card and phone. Signing authority never leaves the user.\u003C\u002Fli> \u003C\u002Ful> \u003Cp>So on the custody spectrum this article draws, WATS sits at the pure self-custody end, with a hardware factor layered on top for access control. The Hot Wallet's single-fee-token feature, where every action is paid in one token called ATS, is likewise independent of custody: it is about \u003Cem>which token pays the network fee\u003C\u002Fem>, not about who holds your keys, and it changes the paying token rather than making gas cheaper. \u003Ca href=\"\u002Fblog\u002Fats-fee-model-explained\">The ATS fee model explained\u003C\u002Fa> covers that side on its own. Keeping custody, authentication and fees in separate boxes is exactly the kind of precision that lets you judge any wallet clearly.\u003C\u002Fp> \u003Ch2>Bottom line\u003C\u002Fh2> \u003Cp>Always-on dual-custody is a two-of-two signing model: a transaction needs both your key and the provider's key, every time, with no option to turn the second signer off. It is not custodial, because the provider can never act alone. It is not classic single-key self-custody, because you are not the only signer. And it is not optional multisig, because the two-key requirement is fixed rather than a flexible quorum you configure. The accurate, honest place to put it is the middle of the custody spectrum — defined by two guarantees that hold at all times: you can never be excluded, and the provider can never act unilaterally. WATS, for its part, is not an instance of that design: every WATS product is self-custody, and the NFC Metal Card's one-device pairing adds a physical authentication factor rather than a second key. Knowing exactly where a wallet sits on this spectrum — and choosing the trade-off on purpose — is the whole point.\u003C\u002Fp>",[10,13,16,19,22],{"q":11,"a":12},"Is a dual-custody wallet custodial or self-custody?","Neither, strictly. It is not custodial, because the provider holds only one of two required keys and can never move your funds alone. It is not pure self-custody either, because you are not the sole signer — a counterparty participates in every transaction. The accurate description is a deliberate middle position: a two-of-two model where you can never be excluded and the provider can never act unilaterally.",{"q":14,"a":15},"What does \"always-on\" dual-custody mean?","It means the two-key requirement is fixed and permanent, not a setting you enable or a security tier you upgrade to. Every transaction needs both your key and the provider's key, all the time, with no mode that collapses to a single signer. Calling it optional, or something you opt into, would be a category error, because the permanent second signer is the entire point of the design.",{"q":17,"a":18},"How is dual-custody different from 2-of-3 multisig?","Classic multisig like 2-of-3 is a flexible policy you opt into and configure — you choose the quorum, assign the keys, and could even hold all of them yourself, which keeps it in self-custody. Always-on dual-custody is a fixed two-of-two split between you and one specific provider that you cannot turn off. A 2-of-3 setup can still sign after losing one key; a strict two-of-two cannot, which is the trade it makes to guarantee neither party ever signs alone.",{"q":20,"a":21},"Can the provider move my funds without me in a dual-custody wallet?","No. In a genuine dual-custody model the provider holds only one of the two keys required to sign, so it is always short one signature and can never move your assets by itself. By the same logic, you can never be cut out either, because your key is always one of the two required signers. That mutual constraint is what places the model between custodial and self-custody.",{"q":23,"a":24},"Does WATS use always-on dual-custody in any of its products?","No. Every WATS product — the Chrome extension, the mobile app and the Hot Wallet — is self-custody: you hold your own keys and seed phrase, and WATS never holds a key. The physical security layer WATS offers is different in kind: each NFC Metal Card carries a unique ID and pairs with a single device in the WATS mobile app, working only with that paired phone as a tap-to-authenticate second factor. That is an authentication design, not a custody design — signing authority stays entirely with you. It is also separate from the Hot Wallet's single-fee-token ATS model, which concerns which token pays fees, not who holds your keys.",1784634270064]