Ah, that's another arguments for never spending from a multisig so you don't give away the configuration. But still, if you're saying that an attacker will be willing to wait till they've broken the entropy from n different vendors before taking the easy money they have from the first one they broke until they've broken enough to spend the whole multisig, eh, maybe, but I think that's unlikely. If you're arguing that, say, they wait and break every seed they can from the weak ColdCard entropy and steal everything that's unlocked by that whole keyspace, including single-vendor multisigs, sure, but not attacking a singlesig ColdCard wallet because it's also part of a 2 of 3 multisig with say a Trezor and Ledger, that's more patience than I think they'll have.

Replies (2)

Can you give me a pointer on the "eventually" part of taproot fixing it? Is it just that most wallets don't support taproot multisig?
@Peter K Agreed that a patient attacker is the weak version of it. The stronger reason to mix vendors is that a same vendor quorum shares one failure mode, so a two of three stops being two independent checks and collapses into one. Nobody has to wait for anything, they get the whole quorum in a single break.