Why we drilled at all
A recovery plan you have never rehearsed is a hope, not a plan. We hold a portion of treasury behind a 4-of-7 multi-sig, and the only honest way to know it works is to make seven people actually do it, on a weekend, with someone deliberately unreachable.
The goal was not to prove we are clever. It was to find the dumb thing that breaks under pressure, while the stakes were zero.
What surprised us
The cryptography was the easy part. The hard part was logistics: one signer's hardware wallet firmware was a version behind and needed an update mid-ceremony; another had moved and their backup was in a different city. Four of seven was reachable in an hour. Five would have been comfortable.

The checklist we wrote afterwards
We turned the drill into a standing checklist, and we run it quarterly now:
- Every signer verifies firmware and backups on the first of the quarter.
- At least 5 of 7 must be reachable within two hours, or we rotate a signer.
- The runbook lives somewhere you can reach without the wallet itself.
- One person is assigned to be deliberately offline each drill.


