Feature 1: Duress PIN โ Protection Under Physical Coercion
A duress PIN is a secondary PIN code that appears to unlock your wallet normally but instead opens a pre-funded decoy wallet containing a small balance. From the attacker's perspective, the login succeeds and they see funds โ but they are seeing a completely separate wallet, not your real holdings.
The Coldcard Mk4 goes further with a third option: the brick-me PIN, which immediately and permanently wipes the device when entered. Under extreme coercion where maintaining the deception isn't feasible, this eliminates the attack vector entirely.
Feature 2: Shamir Secret Sharing โ Eliminate Every Single Point of Failure
Standard seed phrase backup has a structural weakness: a single copy lost or stolen means total loss or total compromise respectively. Shamir Secret Sharing (SLIP39) solves this mathematically โ your seed phrase is split into shares where only a threshold number (e.g., any 2 of 3) can reconstruct it. Each share alone is cryptographically useless.
Feature 3: 2-of-3 Multisig Vault โ No Single Device Controls Your Funds
A multisig wallet requires multiple devices to authorize each transaction. In a 2-of-3 setup, any 2 of your 3 hardware wallets must sign before funds move. No single device โ and no single geographic location โ has spending authority alone. This architecture is used by institutional Bitcoin custodians and is fully available to individual Canadians through Sparrow Wallet.
Total cost: ~$342 CAD (3 ร Ledger Nano S+ at $114 each). This is the minimum-cost enterprise-grade custody setup available to Canadian retail holders.
Feature 4: Passphrase (25th Word) โ Hidden Wallets
A BIP39 passphrase (sometimes called the "25th word") appended to your seed phrase generates a completely different wallet. The same 24-word seed with different passphrases produces completely independent wallets with different addresses. No one who finds your seed phrase and doesn't know your passphrase can access the passphrase-protected wallet.
(blank passphrase)
Feature 5: Dead Man's Switch โ Automatic Inheritance
A dead man's switch for crypto uses time-locked multisig: your heir holds Device 3 in your 2-of-3 setup, but it cannot spend alone. After a pre-agreed period of wallet inactivity (e.g., 5 years), a time-lock script activates the heir's key to operate with a different threshold โ enabling them to recover funds without court involvement.
Geographic Distribution Matrix
| Security Layer | Location | Access | Value If Compromised Alone |
|---|---|---|---|
| Device 1 (Multisig) | Home safe, Vancouver | Daily | $0 โ needs 2nd device to spend |
| Device 2 (Multisig) | RBC Box #456, Vancouver | Emergency | $0 โ needs another device |
| Device 3 (Heir key) | Lawyer safe, Toronto | Inheritance | $0 โ needs Device 1 or 2 |
| Shamir Share A | Home safe, Vancouver | Recovery | $0 โ needs 1 more share |
| Shamir Share B | TD Box, Vancouver | Recovery | $0 โ needs 1 more share |
To defeat this setup, an attacker must simultaneously compromise 2 of 5 geographically separated locations โ requiring cross-city coordination against at least 2 of: your home, 2 different bank vaults, and a lawyer's office. This is nation-state level effort for a retail portfolio.
Pro Feature Implementation Priority by Portfolio Size
Your Pro Security Roadmap
Your Next Steps
Get the Full 105-Page Guide
Includes all 15 chapters + setup checklist