A DAO with $500,000 in treasury assets, 12 signers distributed across three continents, and a governance structure that requires 7-of-12 approval has a recurring problem: moving funds takes weeks. Signers miss notifications, lose access credentials, travel to regions with poor connectivity, or simply deprioritize the approval because it does not directly affect their individual incentives. When a time-sensitive opportunity arrives—a protocol upgrade requiring immediate token purchase, an emergency liquidity injection, or a strategic market position—the multisig wallet becomes a bottleneck rather than a security tool. The DAO governance forum fills with complaints, voting power concentrates among the fastest responders, and smaller governance participants wonder whether decentralization has simply replaced corporate bureaucracy with cryptographic friction.
This tension between security and operational speed is real, and it has led many DAO operators to assume that multisig wallets are the only defensible approach to collective fund management. That assumption deserves scrutiny. For smaller treasury operations, single-operator wallets using a modern non-custodial wallet application such as Bitget Wallet may offer a more practical balance. A single operator with full private key control, hardware wallet integration, biometric authentication, and encrypted key storage can execute transactions faster, reduce confirmation delays, and maintain stronger operational security than a multisig arrangement with chronic signing delays. The catch is clear: this model works only for specific governance structures and requires careful scoping of what treasury operations actually require collective approval.
The multisig bottleneck: Cost, delay, and false security
Multisig wallets are designed to prevent any single person from unilaterally moving funds. This is valuable when signers represent competing interests, when treasury assets are large enough to justify the overhead, or when the governance structure genuinely requires consensus. However, a 7-of-12 multisig arrangement often introduces problems that the original security model did not intend to solve. Each signer must maintain their own private key and confirmation workflow. A quorum requires coordination across time zones, authentication methods, and sometimes incompatible wallet software. If one signer loses access or becomes unreachable, the DAO governance process must execute a key rotation—itself a multisig transaction that may take weeks.
The security benefit of a multisig is also narrower than many assume. A 7-of-12 threshold prevents any single signer from stealing funds. It does not prevent a coordinated group of seven signers from acting against the DAO’s interest. It does not prevent a compromised signer’s device from approving fraudulent transactions to the DAO’s account. It does not prevent a social engineering attack that tricks multiple signers into approving a transfer to an attacker-controlled address. And critically, it does not prevent disagreement about whether a specific transaction actually reflects the DAO’s legitimate governance decision. If three signers believe a transaction contradicts recent governance votes and refuse to sign, the DAO’s operational capacity freezes regardless of what the other nine signers think.
The operational cost of multisig also compounds over time. Gas fees accumulate because multisig transactions are larger and more complex than standard transfers. Signer coordination overhead grows as the DAO scales, requiring formal communication channels, escalation procedures, and fallback signers to replace inactive participants. The cost is often invisible until a crisis occurs—a regulatory threat, a security incident, or a sudden market opportunity—and the DAO discovers that its security model has made it operationally paralyzed.
For a DAO with a clear operational hierarchy—say, a core team of 2–3 trusted individuals hired by governance to execute treasury strategy within predefined limits—a multisig structure is often unnecessary overhead. The governance check has already happened at the hiring stage and continues through ongoing performance evaluation and budget approval. Adding a multisig requirement on top of that governance layer duplicates the control without meaningfully strengthening it.
When a single operator with strong custody controls is more secure
A non-custodial wallet application places the operator in direct control of private keys while providing encryption, biometric authentication, and optional hardware wallet integration. Bitget Wallet supports this model across 90+ blockchains, including Ethereum, Binance Smart Chain, Polygon, Solana, and Tron, allowing a single operator to manage multi-chain treasury assets from one interface. The operator’s private key is encrypted and stored locally on the device, meaning neither Bitget nor any third party can sign transactions on the operator’s behalf.
A single operator using hardware wallet integration—plugging in a Ledger or Trezor device for each treasury transaction—creates a security model that is actually stronger than many multisigs in critical ways. The hardware device is isolated from internet-connected software. It requires physical interaction to sign, meaning malware on the operator’s computer cannot simply approve unauthorized transactions. The operator has control over timing: they can review each transaction on the hardware device’s screen, verify the destination address, confirm the amount, and then decide whether to physically confirm the signature. No remote attacker can make this decision for them.
Contrast this to a multisig signer who receives a notification to approve a transaction, clicks through a wallet interface on their phone, and signs without carefully reviewing the address. The multisig arrangement theoretically requires seven such approvals, but each individual signer’s review quality may be poor. The hardware wallet model concentrates the security responsibility on a single operator, but that operator is using a more robust tool than most multisig participants employ. The operator can also use Bitget Wallet’s encrypted private key storage and biometric authentication when they are not using a hardware device, adding a second layer of protection without slowing down legitimate operations.
The crucial requirement is that the single operator must be genuinely trustworthy and must have a strong incentive to act in the DAO’s interest. This is typically the case for a core team member or a hired treasurer whose compensation and reputation depend on executing treasury strategy correctly. If the DAO governance structure selects this person through a transparent hiring process and can remove them through governance votes, the single-operator model has more legitimacy and stronger incentive alignment than a multisig arrangement where signers are passive participants in a bureaucratic approval process.
Scoping treasury operations: What requires approval versus what does not
The transition from multisig to single-operator custody only works when the DAO clearly separates strategic decisions from execution decisions. Strategic decisions—what assets to buy, what protocols to yield farm in, what treasury diversification targets to maintain—require governance votes. These decisions should produce explicit, documented directives that specify the asset type, amount, time window, and acceptable price range or yield parameters. Once governance has made a strategic decision, the operator executes it within those constraints without requiring additional approval.
For example, a DAO governance vote might specify: “Allocate $100,000 to provide liquidity in the USDC/ETH pool on Uniswap v3, using the operator’s judgment on price range and tier, provided the APY is above 8%.” The governance decision is the policy. The operator’s execution is tactical—selecting the exact price range, timing the deposit, monitoring the position. If the operator deposits $100,000 into a different pool or without documenting the decision, that is a breach of the governance mandate. If the operator waits three days to execute because market conditions were unfavorable and then deposits at a better price, that is prudent execution.
This boundary also means that certain transactions should remain multisig even if most treasury operations move to single-operator control. Treasury transfers to externally owned accounts, distributions to token holders, and payments to contractors should generally require multisig approval because they cross the boundary from internal management to external obligation. The operator can prepare the transaction, but a second party—perhaps the DAO treasurer or a governance delegate—should approve it before broadcast. This hybrid model maintains security for high-risk operations while improving speed for tactical execution.
Operational workflow with Bitget Wallet and governance checkpoints
A practical workflow begins with the operator creating a governance proposal describing the treasury action: “Buy 10 ETH on the open market, targeting $1,800–$1,900 per coin, within 14 days, to rebalance treasury allocation.” After governance votes and the proposal passes, the operator can begin execution. Using Bitget Wallet’s multi-chain support and DEX integration, the operator can execute token swaps directly within the application, track portfolio performance through the built-in portfolio tracking tools, and confirm floor prices for NFT treasury assets if the DAO holds digital collectibles.
Each operation is documented in a treasury log that the DAO community can review. The operator records the block number or transaction hash, the exact price paid, slippage if applicable, and any market conditions that affected execution. This creates an audit trail that allows governance to evaluate the operator’s performance and hold them accountable. If the operator systematically executes transactions at unfavorable prices or fails to follow governance directives, the DAO can present evidence and vote to replace the operator through a standard governance process.
For yield farming or protocol participation, the operator uses Bitget Wallet’s DeFi protocol integration to manage positions directly. The wallet displays the estimated returns, current position size, and unclaimed rewards across multiple chains and protocols. This visibility allows the operator to monitor whether a position is still meeting its governance-approved yield target and to exit if conditions change. Governance can require monthly or quarterly reporting on treasury performance, with specific metrics tied to the original allocation decisions.
If a governance decision requires multisig approval—such as a large payout to a contractor—the operator can prepare the transaction within Bitget Wallet, generate the unsigned transaction data, and share it with a second approver who reviews the details before signing. To get started with this hybrid model, the DAO first establishes which operations are single-operator and which require multisig approval, then the operator creates governance-approved directives for each category of operation.
When multisig remains necessary despite the overhead
Multisig wallets are still the correct choice in several scenarios. If the DAO has no clear operational hierarchy—if treasury decisions are meant to be genuinely distributed and no single person should have unilateral control—then multisig is the appropriate governance structure regardless of the operational friction it creates. The DAO should accept the delays and complexities as the cost of true distributed decision-making. If the treasury is large enough that the security benefit of multisig justifies its overhead cost, then maintaining the arrangement makes sense. A DAO with $50 million in treasury assets should tolerate longer transaction confirmation times in exchange for the protection that multisig provides.
Multisig is also necessary when the DAO’s signers represent fundamentally competing interests or when no single person can be trusted to act in the collective interest. In such cases, the multisig structure ensures that no majority of signers can unilaterally harm the minority. The bottleneck is a feature, not a bug; it forces slower, more deliberate decision-making. However, most DAOs have not actually reached this state. They have adopted multisig as a default, without examining whether their actual governance structure and signer relationships justify the cost.
For DAOs that have invested heavily in multisig infrastructure and have signers distributed across multiple regions and time zones, switching to a single-operator model requires genuine change management. Signers who have been part of the approval process will resist a shift that removes their input. Governance may need to create a transition period, maintain an advisory multisig that reviews the operator’s performance, or gradually shift operational categories to single-operator control while keeping some functions in multisig. This transition should be gradual and documented, allowing the community to evaluate whether the new model is working before committing fully.
Device security and key management in single-operator custody
The security of a single-operator model depends entirely on the security of the operator’s private key. Bitget Wallet provides encrypted local key storage, meaning the private key is encrypted on the device and never transmitted to Bitget’s servers. However, the operator must ensure that the device itself is secure. A compromised phone or computer can be exploited to steal the private key, regardless of how well it is encrypted by the wallet software.
The operator should use a hardware wallet integration for transactions above a certain threshold—say, any transaction larger than $10,000. This requires the operator to physically connect a Ledger or Trezor device and confirm the transaction on the device’s screen. For smaller, routine operations, the operator can use Bitget Wallet’s biometric authentication (Face ID or Touch ID) combined with a strong PIN. The device itself should use full-disk encryption and should not be shared with other people.
The recovery phrase must be treated as the most critical secret. It should be written down or otherwise stored offline, never stored in cloud notes or password managers, and never transmitted electronically. A copy should be kept in a physical safe or with a trusted custodian, separated from the device in case the device is stolen or damaged. The operator should test the recovery process without exposing the secret—by restoring the wallet on a separate device and verifying that it produces the same addresses—to ensure that the backup actually works before a crisis occurs.
Transparency and governance accountability in execution
A single-operator model requires more transparency, not less, because there is no longer a multisig quorum to distribute the oversight burden. The operator should publish a monthly treasury report documenting all transactions, asset allocations, performance against governance-approved targets, and any deviations from the original plan. The report should include transaction hashes, prices paid, fees incurred, and the operator’s justification for any decisions that fell outside standard parameters.
The governance community should establish clear metrics for evaluating the operator’s performance. If a governance-approved yield farming strategy is supposed to generate 10% APY and the operator achieves 6%, the community should understand why. If market conditions changed, the operator should explain which factors were unfavorable and what adjustments were made. If the operator made a tactical error, that should be documented and discussed as a learning opportunity. This ongoing transparency allows governance to make an informed decision about whether the operator should continue in the role.
The DAO should also establish clear procedures for removing the operator if performance deteriorates or if trust is broken. This might include a simple governance vote requiring a majority to remove the operator, or it might require a supermajority if the DAO wants to make removal more difficult. The removal process should be tested and documented before it is needed, so that if a crisis occurs, everyone understands how the transition will happen.
The future of DAO treasury management: Hybrid models and automation
The tension between security and operational speed is not unique to DAOs. Corporate treasuries face similar challenges, and many solve it through a combination of delegation, clear policies, and monitoring rather than pure multisig governance. As decentralized finance matures, DAO treasury management will likely converge on hybrid models: single operators executing day-to-day operations within governance-approved constraints, multisig or governance voting for strategic decisions and high-risk transactions, and transparent monitoring to keep the operator accountable.
Automation will also become more common. Bitget Wallet’s support for multiple blockchains and protocols makes it possible to automate routine operations such as rebalancing, harvesting yield, and moving funds between strategies. A DAO could use smart contracts to automatically execute governance-approved treasury policies without requiring an operator to manually approve each action. This removes the single-operator risk while maintaining operational speed. However, automation introduces its own complexities: the smart contract must be correctly programmed, must be properly audited, and must handle edge cases and market disruptions without making catastrophic errors.
The key insight is that the multisig-versus-single-operator decision should be made deliberately, based on the DAO’s specific governance structure and risk tolerance, rather than adopted as a default. A DAO with a clear operational hierarchy, a transparent hiring process for treasury operators, and a strong governance culture of accountability may get better results from a single operator using a modern non-custodial wallet than from a multisig arrangement that creates coordination delays without meaningfully improving security. The operators of smaller DAOs should evaluate this model seriously before accepting the operational bottleneck that multisig entails.
Frequently asked questions
Is a single-operator wallet actually more secure than a multisig for DAO treasury management?
It depends on implementation. A single operator using hardware wallet integration (Ledger, Trezor) with strong device security practices can achieve stronger security than a multisig arrangement where individual signers use poor authentication or do not carefully review transactions. However, the operator must be genuinely trustworthy and must have secure key management practices. A multisig remains more secure against operator theft or fraud for large treasuries where the governance benefit justifies the operational overhead.
What treasury operations should remain multisig if we switch to single-operator control?
External payments—contractor payouts, token distributions, and fund transfers to outside wallets—should generally remain multisig or require governance voting because they create obligations beyond the DAO’s internal fund management. Strategic decisions on asset allocation should also require governance approval. Tactical execution within governance-approved directives (such as executing a yearn strategy approval or selling tokens at an approved price) can be single-operator without additional approval.
How does a DAO hold a single operator accountable without multisig oversight?
Through transparency and governance: the operator publishes monthly reports documenting all transactions, performance metrics, and deviations from approved strategy; the governance community reviews these reports and can remove the operator through a voting process if performance is poor or trust is broken. This creates stronger accountability than a passive multisig signer, because the community is actively monitoring and can act on documented evidence rather than simply approving or rejecting individual transactions.
