Security alert · 30 Jul 2026: a seed-generation flaw in Coldcard devices was disclosed. What to do →

Articles

Short answers to the questions that come up before, during and after a multisig setup. Each article stands on its own; the setup guide ties them together.

Comparisons · When something goes wrong · Concepts · Hardware security · Doing it well

Comparisons

Devices, apps, backups and setups side by side.

  1. 01Trezor Safe 5 vs BitBox02 for a bitcoin multisigTrezor Safe 5 or BitBox02 as a key in a 2-of-3 multisig? Screen, firmware, backups and how each handles the multisig setup.
  2. 02Trezor Safe 5 vs Ledger Nano S Plus for a bitcoin multisigTrezor Safe 5 or Ledger Nano S Plus in a 2-of-3 multisig? Price, open source, screens and what the closed secure element means.
  3. 03BitBox02 vs Ledger Nano S Plus for a bitcoin multisigBitBox02 or Ledger Nano S Plus as a key in a 2-of-3 multisig? Open source, secure chips, backups and how each remembers your setup.
  4. 04BitBox02 vs BitBox02 Nova: which one for a multisig?The BitBox02 Nova adds a glass screen, an EAL6+ chip and iPhone support. Does that matter in a desktop multisig?
  5. 05Sparrow vs Nunchuk for a bitcoin multisigSparrow or Nunchuk to run a 2-of-3 multisig with hardware wallets? Desktop vs phone, paid extras and what each shows you.
  6. 06Sparrow vs Electrum for a bitcoin multisigElectrum has been around since 2011, Sparrow is newer. Which one to use as the coordinator for a hardware wallet multisig?
  7. 07Cryptosteel Capsule vs BillfodlTwo popular stainless steel seed backups with letter tiles. How they differ, and the one weakness they share.
  8. 08Metal seed backups: tiles, punched or engraved?Three ways to put a seed phrase on steel, compared on cost, speed, readability and how they fail.
  9. 09DIY multisig vs Unchained or CasaDo it yourself or pay a company that holds one of your three keys? What you gain and give up with collaborative custody.
  10. 102-of-3 vs 3-of-5 multisigIs a 3-of-5 multisig safer than 2-of-3? More keys protect against more failures, but also create more ways to make mistakes.

When something goes wrong

What to do, calmly and in order.

  1. 01Lost or broken hardware wallet in a 2-of-3 multisig: what now?One hardware wallet in your 2-of-3 multisig is broken, lost or stolen. Your bitcoin is safe; here’s how to restore your safety margin.
  2. 02Lost your multisig wallet descriptor? What still worksWithout the descriptor, two seeds may not be enough to recover a multisig. What you can still do, and how to prevent it.
  3. 03What if a hardware wallet company goes bust?Your bitcoin doesn’t depend on Trezor, BitBox or Ledger staying in business. How to recover if a maker disappears.
  4. 04A seed backup was seen or taken: moving to a new multisigSomeone saw, photographed or took one of your seed backups. What that means in a 2-of-3 multisig and how to move your coins to a fresh wallet.
  5. 05Signing laptop broken or infected: what to doYour signing computer died or might have malware. Your keys are safe on the hardware wallets; here’s how to rebuild and what to check.
  6. 06Forgot your Sparrow wallet password?Lost the password that encrypts your Sparrow wallet file? Your bitcoin is fine. How to rebuild the wallet from your descriptor.
  7. 07Bitcoin transaction stuck? Raising the fee with RBFYour multisig transaction is unconfirmed for hours. Why it happens and how to speed it up with Replace-by-Fee in Sparrow.
  8. 08Someone asks for your seed words? It’s a scamSupport staff, a recovery service, an app or a letter asking for your recovery phrase is always a scam. How these scams work and what to do.
  9. 09Receive address doesn’t match the device screenSparrow shows one address and your hardware wallet another. Don’t send anything. What it can mean and how to find out.

Concepts

The terms behind a multisig, in plain English.

  1. 01What is a wallet descriptor, and why back it up?A plain explanation of the output descriptor in a bitcoin multisig: what’s in it, why it’s not secret, and why you need it to recover.
  2. 02Multisig vs single-sig: which is safer for your bitcoin?Single hardware wallet or 2-of-3 multisig? The honest trade-offs: theft, loss, bugs, fees, privacy and effort.
  3. 03Should you add a passphrase to a bitcoin multisig?A BIP39 passphrase on top of a 2-of-3 multisig: what it protects against, what it doesn’t, and how to store it without creating a new way to lose everything.
  4. 04What is a PSBT?PSBT, the partially signed bitcoin transaction, explained: how Sparrow and your hardware wallets pass a multisig transaction back and forth until it’s signed.
  5. 05What is an xpub, and who can see it?The extended public key (xpub) explained: what it reveals, what it can’t do, and why one xpub from a multisig reveals less than you’d think.
  6. 06Why use three different hardware wallet brands?Why a 2-of-3 multisig should use hardware wallets from three different makers, with real examples of what can go wrong at one brand.
  7. 07BIP39 vs SLIP39 backupsTrezor offers 20-word SLIP39 backups; most wallets use 24-word BIP39. The difference, and why a mixed-brand multisig should use BIP39.
  8. 08How much more does a multisig transaction cost?Multisig transactions are larger than single-sig ones, so fees are higher. How much, and how to keep them down.
  9. 09Air-gapped vs USB hardware wallets in a multisigAir-gapped hardware wallets sign via QR codes or microSD instead of a cable. Does that matter in a 2-of-3 multisig?

Hardware security

Chips, certificates, firmware and what they really protect against.

  1. 01What is a secure element in a hardware wallet?A plain explanation of the secure element chip in hardware wallets: what it protects against, what it doesn’t, and how Trezor, BitBox and Ledger use it differently.
  2. 02What does CC EAL6+ certified mean?Hardware wallets advertise “CC EAL6+” secure elements. What Common Criteria and the EAL levels mean, and what the certificate doesn’t tell you.
  3. 03ST33K1M5: the secure element in the Ledger Nano S PlusWhat the ST33K1M5 chip in the Ledger Nano S Plus is, what its EAL6+ certification means, and why its closed code matters less in a multisig.
  4. 04Infineon OPTIGA Trust M in the Trezor Safe 5 and BitBox02 NovaThe OPTIGA Trust M V3 secure element in the Trezor Safe 5 and BitBox02 Nova: what it does, its EAL6+ certification and why makers chose it.
  5. 05ATECC608B: the secure chip in the BitBox02How the BitBox02 uses the Microchip ATECC608B secure chip: guarding an encryption secret and limiting password attempts, while the bitcoin code stays open source.
  6. 06Open vs closed source hardware walletsWhy some hardware wallets publish all their code and others can’t. What open source actually protects you from, and how multisig changes the question.
  7. 07Reproducible builds: checking your wallet runs the published codeOpen-source firmware only helps if the device runs that exact code. Reproducible builds let independent people confirm it.
  8. 08Bitcoin-only firmware: is it worth it?Several hardware wallets offer a Bitcoin-only edition or firmware. What it removes, why that helps, and which devices have one.
  9. 09Supply chain attacks on hardware walletsTampered devices, pre-filled recovery cards and fake replacement wallets: how supply chain attacks work and how to protect yourself.
  10. 1012 or 24 words: which seed length?Is a 24-word seed phrase safer than 12 words? What the difference means in practice, and why this guide uses 24.
  11. 11Derivation path explained: what m/48’/0’/0’/2′ meansA plain explanation of the derivation path used for bitcoin multisig, m/48’/0’/0’/2′, and why getting it right matters for recovery.
  12. 12Master fingerprint explainedWhat the 8-character master fingerprint in Sparrow means, why it isn’t secret, and how it tells you the right device and passphrase are connected.

Doing it well

Storage, upkeep and the habits that keep a multisig working for years.

  1. 01Bitcoin inheritance with a multisig: what to leave your familyA multisig with backups in three places is safe, and useless to your heirs if they don’t know about it. What to write down and where to keep it.
  2. 02Is Sparrow Wallet safe?Is Sparrow Wallet safe to use as a multisig coordinator? What it can and can’t do with your bitcoin, and the privacy trade-off.
  3. 03Where to store three seed backupsChoosing three places for the seed backups of a 2-of-3 multisig: the one-event rule, good and bad places, and what to tell whom.
  4. 04Your yearly multisig check-upWhat to check once a year so your multisig still works when you need it: about an hour’s work.
  5. 05Moving bitcoin from an exchange to your multisigWithdrawing from an exchange to a 2-of-3 multisig safely: verify the address, test with a small amount, and what exchanges may ask.
  6. 06Hardware wallet firmware updates: when and howShould you update your hardware wallet’s firmware? How to do it safely in a multisig, and what to check afterwards.
  7. 07Bitcoin multisig for a small businessHolding company bitcoin in a 2-of-3 multisig: separating it from personal coins, who holds the keys, watch-only access for your accountant, and continuity.
  8. 08Signing computer: Windows or Linux?Which operating system for a dedicated bitcoin signing laptop? The trade-offs between Windows and Linux for Sparrow and hardware wallets.
  9. 09Using Sparrow over TorHow to connect Sparrow Wallet through Tor to hide your IP address from the server, with the built-in Tor or the Tor Browser as a proxy.
  10. 10Running your own Bitcoin node for SparrowConnect Sparrow to your own Bitcoin Core node so no outside server learns your addresses. Pruned or full, and what it takes.