Security alert · 30 Jul 2026: a seed-generation flaw in Coldcard devices was disclosed. What to do →

Is Sparrow Wallet safe?

TL;DR

Yes, if you download it from the official site and verify it. In a multisig with hardware wallets, Sparrow never holds a private key, so it can’t spend your bitcoin. The main thing to think about is privacy: which server it talks to.

What Sparrow can and can’t do

  • It holds only public keys (xpubs), so it can show addresses and balances but can’t sign.
  • It builds transactions; your hardware wallets check them on their own screens and sign.
  • If you set a password when saving, Sparrow encrypts the wallet file with it. Lose that password and you only lose your labels: you rebuild the wallet from the descriptor and register the Ledger again.

Why it’s trusted

  • Open source, so anyone can read the code.
  • Every release is signed by its developer, Craig Raw. You check that signature before installing, as in step 3.
  • It sticks to open standards, such as descriptors and PSBT (the format for passing an unsigned transaction to your devices), so your wallet isn’t locked into Sparrow.

What can actually go wrong

  • A fake copy. Scam sites get pushed through search ads. Type sparrowwallet.com into your browser yourself and verify the signature.
  • A compromised computer. Malware can show you a wrong address. Check every receiving address on the screen of a hardware wallet that has your multisig registered, as in step 8.
  • Privacy. The server Sparrow connects to can see your addresses and balance. Pick a server with a no-logs policy, or run your own node (see advanced topics).

Alternatives

Nunchuk and Electrum can coordinate the same multisig. The wallet software page compares them. Sparrow is the one this site uses.