In a multisig, only one xpub of a member is required to track *spends*. (Compared to all of them for unspent outputs, which is why you MUST back it up to restore your wallet) This is because the individual pubkeys derived from each member xpub are revealed on chain, and you could just check using one xpub. Someone can bruteforce all possible seeds’ multisig xpubs to track individual wallets.

Replies (1)

This is interesting. So my mk3 that got drained was 1 of 3 in a multi vendor multi Sig. utxo that got drained last night was from that multi sig. I was able to salvage remaining unrelated sats in the wallet..