Bitcoin Multi Sig vs Secure Single Sig with Nick Neuman | SLP761 artwork

Bitcoin Multi Sig vs Secure Single Sig with Nick Neuman | SLP761

Stephan Livera Podcast

August 7, 2026

In this episode, Nick Neuman of Casa argues that it’s not the end of self-custody. Instead, it highlights why multisig with multiple vendors provides stronger protection without the hidden complexity of passphrases or dice rolling for single sig setups.
Speakers: Stephan Livera, Nick Neuman

Topics: Technology

**Stephan Livera** (0:00)
Hi, everyone, welcome back to Stephan Livera Podcast. Rejoining me on the show today is Nick Neuman, CEO and co-founder of CASA. Welcome back to the show, Nick.

**Nick Neuman** (0:07)
Hey, Stephan, glad to be back.

**Stephan Livera** (0:09)
So obviously, the cold card thing is the big topical thing that is on everyone's minds right now. Give us your kind of initial reaction to that. Obviously, I presume you must be really busy now having a lot of people migrating or onboarding to CASA.

**Nick Neuman** (0:24)
Yeah, I mean, it has been a really busy last week with helping people to get off of cold card single SIG and into some form of multi SIG to make sure that their assets are secure. And the team has been, I mean, really working around the clock, getting on calls with people, whether they're CASA clients or not, to try and help people. And it's been amazing to see. So that's like seeing our team come together, seeing the community come together to help people has been pretty amazing.
And then on the flip side, that this happened in the first place is really terrible. And so it's definitely a difficult moment, especially for the people that lost their assets, and we feel really sorry for them. But for the rest of the people, we're really trying to help them to get to a safe spot. And then for the people who lost their assets, hopefully they'll be able to, you know, I've seen a few people talking about, okay, I'm going to rebuild from here, and I think that's the right attitude.

**Stephan Livera** (1:31)
Yeah, in terms of, I guess, what you've seen from, let's say, existing CASA clients, I guess for some of them, they may have a Multiseq with you already, but Coldcard may be in their quorum. So then I guess for them, it's a matter of rotating that specific key out of the quorum to put another key in, right?

**Nick Neuman** (1:48)
Yeah, so we have very, we have different advice, depending on people's situations. Luckily, the CASA default security advice is you should not have a quorum of keys that are held by the same hardware manufacturer in your Multiseq. And so there were very, very few people, like you probably counted on one hand in our entire client base that had a quorum of cold cards.

**Stephan Livera** (2:18)
Like they were in a vulnerable position of like three of five or two or three or something, where a cold card's gone.

**Nick Neuman** (2:22)
Exactly, like they've got three cold cards and a three of five or something like that. But most people, maybe they had one, maybe they had two. And so in that scenario, our advice has been, hey, we're gonna help you rotate this cold card out, switch it for a different hardware wallet. You're not in danger right now.
But it's best practice. Like you're effectively one key down, so it's best practice to change that key over to something that's healthy.

**Stephan Livera** (2:51)
I see, yeah. And I guess the broader conversations are being had now. People are saying, on one hand, you're seeing people say, no, it's the end of self-custody. Other people are kind of going more to the, let's say the multi-sig pathway and saying, hey, the answer is multi-sig, multi-vendor.
How do you see that?

**Nick Neuman** (3:09)
It's definitely not the end of self-custody. I mean, that's going to be a sentiment for a while, right? And so I think we as an industry, and we're thinking about this a lot at CASA, really have to seize this moment to help shape that narrative going forward where it's like, this is not the end of self-custody. Because if you think about this, this was not really a vulnerability that was caused by self-custody.
This vulnerability came about because we, as a community, as people who bought cold cards, trusted that CoinKite, the security experts, had properly coded the firmware for cold card in order to make it secure. And if you think about what actually failed here, it was that. It was that the developers of this product did not properly develop it so that it was secure.
This same thing can unfortunately happen at exchanges or custodians just in a much bigger way. If they mess up, they have actually a larger honeypot sitting there that can be compromised. And so you have, it's more about who are the people, either one that you are putting your trust in to have developed this thing properly as security experts, or two, are you doing something that makes it so that you can reduce the amount of trust that you're having to put in any one party? And this is where I think we really need to help push our community towards this type of thinking, because this is the way that we help self custody continue to be a thing going forward, is you make sure that you don't have to trust any one party completely to have done a good job with developing their product in a secure way. You can actually distribute your trust across many different parties who have developed their own products and then use those products as checks on each other and as different layers of defense in your overall security set up.

27 more minutes of transcript below

Thousands of transcripts fetched by people building searchable podcast archives

Feed this to your agent

Try it now — copy, paste, done:

curl -H "x-api-key: pt_demo" \
  https://spoken.md/transcripts/1000651996090

Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.

From $0.10 per transcript. No subscription. Credits never expire. Prices exclude VAT, added at checkout for EU customers. Not what you expected? Email us within 14 days with 20 or fewer credits used and we refund the pack in full.

Using your own key:

curl -H "x-api-key: YOUR_KEY" \
  https://spoken.md/transcripts/YOUR_EPISODE_ID