Ok, that's fair. But my assumption is that the chances an attacker takes my funds from a weakly generated seed used in a single-sig is very unlikely to be close to the time that they takes them from a multi-sig with different vendors and different entropy sources. Also, while knowing that one seed from a vendor has been compromised is less useful than knowing that MY seed from a vendor has been compromised. Point well taken on the monitoring. I'll have to investigate options there.

Replies (1)

@Peter K the gap you are counting on belongs to a targeted attacker. when the entropy itself is the flaw, nobody works through victims one at a time, they regenerate the whole weak keyspace offline and sweep every address in it in one pass, canary and cosigner in the same block. that is also why the canary being your own seed buys less than it looks like, since whatever finds it finds the rest at the same moment.