If I decide to adopt multi-share backup, how should I set a reasonable threshold? What goes wrong if it's set too high or too low?
Setting the threshold too low (say, needing only 2 out of 10 to recover) is genuinely convenient for recovery, but the security advantage takes a real hit -- anyone motivated who obtains any 2 shares simultaneously can restore your wallet alone, which isn't all that different in risk from simply copying two complete recovery phrases. Setting the threshold too high (say, needing 9 out of 10) genuinely improves security, but it means you'll need to gather the vast majority of shares whenever you eventually need to restore the wallet -- if more than one share gets lost or damaged, the wallet becomes permanently unrecoverable. This "so secure you can't even get it back yourself" outcome is exactly the risk most people overlook when setting up their threshold.
A commonly reasonable range puts the threshold at roughly 60-70% of the total share count -- say, any 6 or 7 out of 10 (6-of-10 or 7-of-10). This ratio typically strikes a relatively balanced position between the two extremes of "a small number of stolen shares immediately breaks security" and "requiring you to gather nearly every share just to recover." But ultimately this still needs Fine-Tuning based on how many locations your shares are spread across and how reliable each custodian is -- there's no one-size-fits-all standard answer.
Who should you actually entrust with multi-share backup shares to keep them safe? Doesn't handing a share to someone you don't fully trust actually increase risk?
This is the aspect most easily underestimated when adopting this approach -- multi-share backup solves the mathematical problem of "a single share contains no information on its own," but it doesn't solve the trust problem of "you picked the wrong custodian." If you give a share to someone with bad intentions, that person genuinely can't restore your wallet with that single share alone -- but if they collude with other custodians to gather the threshold count, they can walk away with all your assets just the same. Multi-share backup defends against "a single point of failure," not "multi-point collusion."
A more robust practice is choosing custodians who are ideally unfamiliar with each other and have no shared incentive, avoiding a situation where your entire set of custodians happens to be members of the same family or the same friend group -- even if collusion genuinely occurs, this makes it considerably harder than a scenario where all your custodians already know each other and can easily coordinate. It's also worth considering entrusting some shares to a professional institution (like a trust company offering share-custody services) rather than handing all of them to individuals, replacing pure interpersonal trust with an institutional audit mechanism -- particularly worth considering for larger asset scales and more formal inheritance planning.
If I'm still on the fence about adopting multi-share backup, is there a simpler middle-ground option worth trying first?
The easiest and relatively low-complexity middle-ground option is adding an extra passphrase on top of your existing recovery phrase. This passphrase doesn't appear in any standard word list -- it's a string of text you set yourself, and only the recovery phrase combined with this passphrase reconstructs the wallet that actually holds your assets. Even if someone obtains your recovery phrase on paper, without knowing this additional passphrase, they still can't access your assets -- effectively adding a relatively simple layer of protection that requires obtaining two separate pieces of information simultaneously.
The advantage of this approach is that the operational logic is simple, and most major hardware wallets support it directly, with no need to learn concepts like shares and thresholds. The drawback is that the passphrase itself also needs to be properly memorized or backed up -- if you forget it yourself, the assets become just as permanently unrecoverable, sharing a similar "complexity risk" nature with multi-share backup, just at a much smaller scale. If, after evaluating your situation, you conclude you don't yet have a clear need for multi-party custody or geographic dispersion, this is a worthwhile entry-level option to try first -- and if circumstances change later, upgrading to a full multi-share plan is still an option down the road.
Besides Trezor, are there other Hardware Wallet manufacturers supporting similar multi-share backup technology? What should you watch for when choosing?
SLIP-39, the open standard behind Shamir Secret Sharing, is a specification any manufacturer can implement, and isn't theoretically limited to a single brand. In practice, though, Trezor (particularly the Model T and its subsequent Safe series) remains the most representative Hardware Wallet with clear, widely adopted support for this standard and a complete user interface for it. Some other manufacturers or software wallets (like Electrum) can support reading and restoring a backup created in SLIP-39 format, but may not necessarily be able to fully create a new multi-share backup or sign transactions on their own device.
The most important thing to check when choosing is whether the device and software you plan to use offer consistent support in both directions -- "creating shares" and "restoring from shares." Some tools only support one of these operations -- if you create shares on a device but later find your preferred software wallet can't use those shares to restore and sign a transaction, that backup approach effectively fails to work when it actually matters. Before formally relying on multi-share backup to protect significant assets, it's worth running a complete test with a small amount of test funds first -- create shares, deliberately damage or lose some of them, then restore using the remaining shares -- to confirm the entire toolchain genuinely works as expected, rather than trusting only what the manufacturer's official documentation claims.
Multi-share backup sounds like the ultimate solution in self-custody: split a recovery phrase into several pieces, where any combination below a set threshold is mathematically proven to reveal nothing about the original secret whatsoever -- even if a few shares are accidentally lost or stolen, as long as the threshold isn't simultaneously reached, assets stay safe. This technology is genuinely powerful, but powerful doesn't mean everyone needs it. The operational complexity of multi-share backup directly shows up the moment you eventually need to restore your wallet, and whether that cost is worth paying depends on your asset scale and actual circumstances -- it's not a default option everyone should blindly adopt.
A single recovery-phrase backup mainly faces two risks: loss (the one paper copy gets damaged or can't be found) and theft (someone gets hold of that copy). If your response is copying the same phrase multiple times and storing the copies in different locations, that can theoretically lower loss risk, but each additional copy adds one more point that can be stolen -- theft risk actually rises as the number of backups increases. This is the structural contradiction built into simply copying a recovery phrase: loss risk and theft risk trade off against each other, and no matter how you adjust the number of copies, you can't lower both simultaneously. Multi-share backup solves exactly this contradiction -- because a single share on its own contains no usable information, you can confidently increase both the number of shares and their storage locations, lowering both loss risk and theft risk at the same time. This is its core value over simply copying a phrase.
If your situation matches any of the following, multi-share backup's complexity is typically worth the cost: inheritance planning, where different shares go to a few family members or a designated attorney, with a threshold set so no single person can act alone, while family can still legally gather enough shares to restore your wallet together after you pass away; geographic disaster resilience, storing shares in different cities or even different countries, so a single earthquake, fire, or other disaster or accident can't destroy every backup location at once; shared family or partnership assets, where multiple parties each hold one share, ensuring no single party can unilaterally control all the funds -- particularly common in joint fund or family trust-style crypto asset management; and institutional or corporate-level asset custody, where multi-share naturally suits distribution across different departments or levels of management, aligning with typical internal-control requirements that no single individual should independently control critical assets.
For an average user without particularly large asset holdings and no need for multi-party custody or geographic distribution, a single recovery-phrase backup paired with proper physical safekeeping (like a fireproof, waterproof metal seed plate, avoiding paper damage from humidity or fire) is usually already an adequate level of protection. Forcing multi-share backup onto this situation doesn't just add operational complexity -- it genuinely raises the risk of an operational mistake. As the number of shares grows, forgetting to bring one during recovery, misremembering the threshold count, or confusing which share belongs to which threshold group all become more likely errors in a more complex process, potentially producing an outcome worse than the risk it was meant to prevent: an unrecoverable wallet. A more practical middle option is first evaluating a relatively simple measure that still substantially improves security, like adding an extra passphrase, rather than jumping straight to the approach with the highest operational bar.
The core principle in choosing a backup approach isn't "which is technically safest" -- it's "which approach will I still remember how to execute, and be able to gather everything needed for, at the exact moment I genuinely need to restore my wallet." Multi-share backup's security advantage is genuine, but that advantage only matters when your circumstances actually call for it. If your asset scale and custody needs are relatively simple, leaving that complexity to those who genuinely need it is actually the more responsible judgment for your own assets. The practical adjustment is honestly taking stock of your asset scale, whether you need multi-party custody, and whether inheritance planning is a real consideration -- then deciding whether to cross that complexity threshold, rather than adopting it simply because the technology sounds impressive.