How a threshold works
Signers propose a transaction; other signers approve it; when the threshold is met, anyone can execute it. The contract enforces the count, so no signer can act alone and no off-chain agreement is needed.
Thresholds should tolerate loss as well as compromise. Two of three survives one lost key and one stolen key; two of two survives neither.
What it genuinely protects
Key theft, device loss, and insider risk in a team. It also creates a deliberate review step, which catches mistakes as often as attacks — a wrong address proposed by one person is usually spotted by the second.
For organisations holding funds, it is close to a baseline requirement rather than an enhancement.
Where multisigs fail
Signer fatigue, where approvals become rubber stamps and the review value disappears. Key concentration, where three signers keep their keys on the same laptop. And the oldest one: everyone approving a transaction nobody actually decoded.
There is also operational risk — losing enough keys to fall below the threshold makes funds permanently immovable, and that has happened to real treasuries.
Using one in practice
Distribute signers across people, devices and locations. Use hardware wallets as signers. Document a recovery plan for a lost key before you need it. Keep the threshold high enough to matter and low enough to survive attrition.
FBT Swap interacts with a multisig like any other wallet: the transaction is proposed to it, and execution happens when your signer set approves. The routing and quoting are unchanged.