Community custody
Community custody

August 19, 2026

Community Custody: A Way to Hold Bitcoin Without Carrying All the Risk Yourself

Fedi

Fedi

For as long as many Bitcoiners can remember, self-custody has been held up as the ideal: hold your own keys, and no company or other person can freeze, lose, or misuse your money.

But holding your own keys means moving all of the risk onto yourself. One lost seed phrase (a 12-to-24-word randomised list used to create the private key for a Bitcoin wallet), one compromised device, one mistake, and you can lose access to your bitcoin forever.

In most people’s minds, the alternative to self-custody is leaving your bitcoin on an exchange. However, in doing so, you’re trusting that the exchange won’t freeze your account, get hacked, or fold with your money still in its custody. And because opening an exchange account means handing over your personal information, a breach of that data can put your funds and your privacy at risk, too.

In other words, trusting a third party with your bitcoin can leave you vulnerable as well.

Fedi wallets are built around a different way of holding your bitcoin: community custody.

Community custody consists of a small group of trusted people, whom we at Fedi call “Guardians,” who set up and look after a shared — or “multisig” — bitcoin wallet for their community.

While community custody comes with its own set of trade-offs, one major benefit of it is that no single person and no outside company can access or control the bitcoin in the community’s custody.

In this article, we provide an overview of how community custody works and compare it to other methods of managing the keys to your bitcoin. We also share information on how Fedi enables teams to collectively manage group or organisation funds via its Multispend feature. 


Your Options for Holding Bitcoin 

With bitcoin, whoever holds the keys controls the money.

The table below breaks down four different versions of what this looks like.  


How Community Custody Works 

Community custody is like a shared vault looked after by people you trust.

That group could be your family, a savings club, your community, or your church. A few trusted members become the Guardians, and together they make up what’s called a Federation, which we also refer to as a “wallet service,” “federated wallet,” or a “vault.”

A Federation is established when a minimum of four Guardians run a Fedimint node on a device such as a laptop or an Umbrel or Start9 server. When the Guardians do this, they set up a multisig bitcoin wallet, which is a wallet that requires multiple keys to sign transactions, and they also simultaneously enable an ecash mint. Ecash helps users maintain their transactional privacy.

The sats that you put into a Federation can be withdrawn at any time over either the Lightning Network or on the Bitcoin main chain. Put another way, you can withdraw your bitcoin from the Federation and move it to either your own Lightning or on-chain Bitcoin wallet when and if you so please.

The core rule of a federation is that no single Guardian alone can open the vault. Moving money requires more than two-thirds of the Guardians agreeing to move funds. There's no single device, single seed phrase, or single person whose failure, misstep, or misdeed can drain the funds in the wallet. That's why every Federation is run by at least four Guardians.

Splitting up Guardian responsibilities spreads out the risk and removes the single point of failure that comes with self-custody or leaving your bitcoin on an exchange. 

Another benefit of joining a Federation is that it doesn’t require handing over your name, address, or other identifying information. Since that information is never collected in the first place, there’s nothing to be leaked and later traced to you — a theft and security risk that has surfaced for both exchanges and hardware wallet providers in recent months. 


Self-Custody vs. Community Custody

Self-custody puts all responsibility in your hands — which is a responsibility that not everyone wants or can manage. The security of your bitcoin rests on one person never losing a seed phrase, never having a device compromised, and never making a mistake. That's a lot to ask, especially when there’s no safety net.

Plus, you give up some privacy when you use a hardware wallet: when you order one online, you have to provide some combination of your name, address, phone number, and email address, and this data can be leaked. 

Community custody keeps the core promise of self-custody — no company controls your money — but removes the single point of failure. Instead of one person guarding one secret, control is split across several Guardians who each hold a key. 

As with all discussions of custody, one needs to be fair about risks. With Federations, you are placing trust in the Guardians not to collude and take the funds in the Federation. You are also trusting the Guardians to:

  1. not lose their seed phrases, each of which comprises one of the keys in the Federation’s multisig wallet, and 

  2. not to issue more ecash than bitcoin held by the Federation, and keep their nodes online. If a certain number of nodes in a Federation go offline (this number differs depending on the number of Guardians in the Federation), then funds within the Federation are frozen until the nodes are back online.

Then there's the risk that extends to all types of wallet software and hardware. Whether you self-custody your bitcoin, keep it on an exchange, or use a Federation, you're relying on the underlying software being sound. The recent Coldcard issue in which the device’s firmware generated insufficient private-key entropy is one example of this. BitBox’s recent urgent update is another. 


When is Community Better than Self-Custody?

Think about the people in your life who are never going to write down twelve secret words (the seed phrase) and keep them safe for the rest of their lives. Also think about the people who would not know what to do in an emergency, and would panic and potentially lose their money through a misstep. 

Those people tend to either keep their bitcoin on an exchange or never touch bitcoin at all.

Community custody meets them halfway. The technical part of self-custody sits with the Guardians, while the other users of the Federation benefit from the Guardians’ effort without having to develop particular technical skills. In time, they will hopefully gain the assets and confidence needed to self-custody safely, but community custody enables them to hold their assets in a privacy-preserving multi-sig manner from day one. 


Multispend: Shared Control Over Shared Money

Community custody removes the single point of failure at the level of a whole Federation. It also enables one of Fedi’s most unique and notable features: Multispend.˚

Multispend enables a group to manage shared funds. Think of it as a group wallet that members can deposit into, request withdrawals, and see every transaction. 

With Multispend, no one person controls the money. Spending requires a set number of members to vote in favour of a withdrawal request, based on a threshold the group agrees on when it’s set up. 

Because control is shared, Multispend makes most sense in a community-custody model, while adding features a lone seed phrase never could. 

Multispend also works with a group’s Stable Balance (a bitcoin balance pegged to a fixed fiat value). 


The Bottom Line on Bitcoin Custody

When it comes to holding bitcoin, one major question must be asked: Who holds the keys?

Hold them on your own, and you carry all the risk yourself.

Hand them to a company, and you inherit its risks instead.

Hold them in community custody, and control is split across people you trust, so no single failure and no single person or company can take your money.

Community custody won’t replace self-custody for everyone, but for many people, it offers the same security with far less risk of a single, fatal mistake.