Duress PINs, Shamir 2-of-3 shares, multisig vaults, passphrase hidden wallets, and dead man's switches for $25K+ Canadian portfolios.
๐ก๏ธ
Fact Checked By: ColdWallets.ca Research Team
Last updated for 2026 โข Hardware wallet auditing & security analysis
11/15
Who This Chapter Is For: Experienced cold wallet users with $25,000+ CAD portfolios who have mastered Chapters 1โ10 and are ready to implement enterprise-grade security features beyond basic cold storage.
๐ Prerequisites
This chapter assumes you already have a working hardware wallet set up with a properly backed-up seed phrase (Chapter 10). Pro features are layered on top of โ not instead of โ the fundamentals. Do not attempt multisig or Shamir setups until your basic cold storage is verified and tested.
Feature 1: Duress PIN โ Protection Under Physical Coercion
๐ญ
Physical Threat Protection
Duress PIN + Brick-Me PIN
Coldcard Mk4Trezor Safe 3/5/7
A duress PIN is a secondary PIN code that appears to unlock your wallet normally but instead opens a pre-funded decoy wallet containing a small balance. From the attacker's perspective, the login succeeds and they see funds โ but they are seeing a completely separate wallet, not your real holdings.
The Coldcard Mk4 goes further with a third option: the brick-me PIN, which immediately and permanently wipes the device when entered. Under extreme coercion where maintaining the deception isn't feasible, this eliminates the attack vector entirely.
๐
Normal PIN
1 3 5 7 9
Opens real wallet โ $50,000 CAD
๐ญ
Duress PIN
2 4 6 8
Opens decoy โ $100 CAD visible
๐ฅ
Brick-Me PIN
0 0 0 0
Instant device wipe โ total destruction
๐ด Real Coercion Scenario
1.Attacker demands your PIN under threat
2.You enter the duress PIN โ device unlocks normally
5.Test: enter duress PIN โ verify decoy appears โ
Feature 2: Shamir Secret Sharing โ Eliminate Every Single Point of Failure
๐
Mathematical Backup Splitting
Shamir Backup (SLIP39) โ 2-of-3 Threshold
Trezor Safe 3/5/7Keystone 3 Pro
Standard seed phrase backup has a structural weakness: a single copy lost or stolen means total loss or total compromise respectively. Shamir Secret Sharing (SLIP39) solves this mathematically โ your seed phrase is split into shares where only a threshold number (e.g., any 2 of 3) can reconstruct it. Each share alone is cryptographically useless.
๐ก Shamir 2-of-3 Split โ Canadian Geographic Distribution
Share A
Home Safe
Vancouver home ยท Daily access
Share B
RBC Safety Deposit
Vancouver bank ยท Emergency
Share C
Lawyer's Office
Toronto ยท Inheritance
Any 2 of 3 shares reconstruct the full seed ยท Any 1 share alone = useless
โ House fire destroys Share A โ Lawyer (C) + Bank (B) recovers
โ Lawyer dies, Share C lost โ Home (A) + Bank (B) recovers
โ Bank robbed, Share B stolen โ Useless alone โ 1 share is cryptographically worthless
๐ต Setup with Trezor Suite
1.Create new wallet โ select Shamir Backup option
โNation-state level coordination needed to breach
Feature 3: 2-of-3 Multisig Vault โ No Single Device Controls Your Funds
๐๏ธ
Multi-Signature Architecture
2-of-3 Multisig with Sparrow Wallet
3ร Ledger Nano S+Sparrow Wallet
A multisig wallet requires multiple devices to authorize each transaction. In a 2-of-3 setup, any 2 of your 3 hardware wallets must sign before funds move. No single device โ and no single geographic location โ has spending authority alone. This architecture is used by institutional Bitcoin custodians and is fully available to individual Canadians through Sparrow Wallet.
๐ผ
Device 1 โ Daily
Home Safe
Vancouver ยท Daily access
๐ฆ
Device 2 โ Emergency
RBC Box #456
Vancouver bank ยท Emergency
โ๏ธ
Device 3 โ Inheritance
Lawyer Safe
Toronto ยท Heir key
Total cost: ~$342 CAD (3 ร Ledger Nano S+ at $114 each). This is the minimum-cost enterprise-grade custody setup available to Canadian retail holders.
๐ต Sparrow Wallet Setup
1.Sparrow Wallet โ File โ New Wallet โ Multisig
2.Set 2-of-3 threshold โ connect each Ledger in turn
3.Each Ledger exports its xpub key โ Sparrow combines
4.Test: send $5 CAD โ Device 1 signs โ QR to Device 2
BIP39 Passphrase โ Multiple Wallets from One Seed
All LedgerAll TrezorColdcard
A BIP39 passphrase (sometimes called the "25th word") appended to your seed phrase generates a completely different wallet. The same 24-word seed with different passphrases produces completely independent wallets with different addresses. No one who finds your seed phrase and doesn't know your passphrase can access the passphrase-protected wallet.
Seed + Passphrase
Wallet
Balance
seed words + "" (blank passphrase)
Decoy Wallet C
$100 CAD
seed words + "Family2026!"
Secondary Wallet B
$25,000 CAD
seed words + "MyDog2026!"
Main Vault Wallet A
$50,000 CAD
โ ๏ธ Critical Warning
Your passphrase must be memorized or separately backed up โ it is not stored on your device and is not recoverable from your seed phrase. If you forget your passphrase, your wallet is permanently inaccessible. Use a phrase you can reliably remember under stress (date + name, not random characters).
Feature 5: Dead Man's Switch โ Automatic Inheritance
โณ
Time-Locked Inheritance
Time-Locked 2-of-3 โ Heir Key Activation
Casa / UnchainedCustom Multisig
A dead man's switch for crypto uses time-locked multisig: your heir holds Device 3 in your 2-of-3 setup, but it cannot spend alone. After a pre-agreed period of wallet inactivity (e.g., 5 years), a time-lock script activates the heir's key to operate with a different threshold โ enabling them to recover funds without court involvement.
๐ต How It Works
1.You control Devices 1 + 2 โ normal daily use
2.Heir holds Device 3 pre-funded with $10 CAD to confirm it works
3.5-year inactivity trigger โ heir's key unlocks at lower threshold
To defeat this setup, an attacker must simultaneously compromise 2 of 5 geographically separated locations โ requiring cross-city coordination against at least 2 of: your home, 2 different bank vaults, and a lawyer's office. This is nation-state level effort for a retail portfolio.
Pro Feature Implementation Priority by Portfolio Size
$25,000 โ $100,000 CAD
Start Here: Duress PIN + Passphrase
โ Duress PIN on Coldcard Mk4 (~$200)
โ Passphrase hidden wallet on existing device
โ Fund $100โ$200 CAD decoy wallet
$100,000 โ $500,000 CAD
Level Up: Multisig + Shamir
โ 2-of-3 multisig (3ร Ledger Nano S+ ~$342)
โ Shamir 2-of-3 shares (3ร metal plates ~$90)
โ Geographic distribution (home + 2 bank vaults)
$500,000+ CAD
Full Stack: All Five Features + Dead Man's Switch
โ 3-city geographic distribution
โ Dead man's switch + heir key ready
โ Annual security audit (March 1)
โ Legal will integration with crypto counsel
Your Pro Security Roadmap
Phase 1 ยท 30 Days
Duress + Passphrase
โ Set up duress PIN
โ Fund $100 decoy
โ Create passphrase wallet
Phase 2 ยท 90 Days
2-of-3 Multisig
โ 3 Ledger devices
โ Sparrow Wallet setup
โ Geographic placement
Phase 3 ยท 6 Months
Shamir + Geo Split
โ Shamir backup created
โ 3 metal plates distributed
โ Recovery tested
Phase 4 ยท 1 Year
Heir + Audit
โ Dead man's switch
โ Heir key ready
โ Annual March audit
Your Next Steps
โ $25K+ โ Start Here
Coldcard Mk4 โ Duress PIN
~$200 CAD ยท Ships from Toronto ยท 1โ3 days. The only consumer hardware wallet with a true duress PIN + brick-me PIN. First pro feature for most serious holders.
~$342 CAD total for all three devices. Sparrow Wallet is free, open-source, and the gold standard for personal multisig setup. Full tutorial on ColdWallets.ca.
Before committing large amounts to any pro setup, run the full workflow โ duress PIN test, multisig send, Shamir recovery โ with a $100 CAD test balance to verify every step.
๐ Next Chapter
Daily Usage: Transaction Approval
Chapter 12 covers the 30-second screen verification checklist for daily cold wallet use โ address verification, red flags, Canadian exchange workflows, and the malware stress test.
๐ Chapter Summary
Five pro features for $25K+ Canadian portfolios: Duress PIN (Coldcard/Trezor) opens a decoy wallet under coercion; Brick-me PIN instantly wipes the device; Shamir 2-of-3 (Trezor) splits the seed so any 2 of 3 shares recover it; 2-of-3 Multisig (3ร Ledger + Sparrow) requires 2 devices to sign every transaction; Passphrase creates hidden wallets from one seed; Dead man's switch enables time-locked heir inheritance without probate. Implementation priority: duress PIN at $25K, multisig at $100K, full geographic stack at $500K+.
Disclaimer: Educational content only. Not financial or legal advice. Advanced security features involve complexity โ test thoroughly with small amounts before committing large portfolios. ColdWallets.ca may use affiliate links.