Blockstream Green: Self-Custody Wallet That Plays Well With On-Chain Transactions
Most mobile Bitcoin wallets store one key on the device — and a compromised device means a drained wallet. Blockstream Green breaks that pattern by default: two keys are required to authorize any transaction, one on the device and one on Blockstream's signing server. A stolen or malware-infected phone has only one of those keys. Without the second, it cannot move the Bitcoin. This 2-of-2 multisig default is structurally unusual for a consumer mobile wallet, and it changes the risk profile of daily mobile Bitcoin activity substantially for holders who use their phone as their primary on-chain interface. Bitok Arena's review of Green maps each configuration against what it actually provides.
Green's 2-of-2 multisig requires both the device and Blockstream's server to sign every transaction. For a holder whose phone is their primary Bitcoin interface, this means: stolen phone, lost phone, or compromised phone cannot drain the wallet — the attacker has one key and needs two. The tradeoff is that Blockstream's server must be reachable to sign. Green includes a timelocked recovery path for server unavailability, but that path requires a 12-month wait.
Green supports three configurations: the 2-of-2 multisig default (device key + Blockstream server key), a single-signature mode (one key on device, standard architecture), and a 2-of-3 multisig for advanced users (two of three keys required, with the user controlling all three key locations). Blockstream also produces the Jade hardware wallet, which integrates directly with Green for hardware-signed transactions. The choice between configurations depends on security priority, wallet value, and daily transaction frequency.