Security alert · 30 Jul 2026: a seed-generation flaw in Coldcard devices was disclosed. What to do →

Signing laptop broken or infected: what to do

TL;DR

Your bitcoin isn’t on the laptop. If the laptop is broken, you lose an afternoon reinstalling and importing your descriptor. A possibly infected one needs a clean reinstall before you sign anything or hand out a new address.

If it’s broken

  1. Set up a replacement as in step 2.
  2. Install and verify Sparrow (step 3).
  3. Use File → Import Wallet and load your descriptor from a backup USB stick or the printed QR code.
  4. Register the Ledger again when Sparrow asks; the BitBox02 still has its registration.
  5. Check the first receive address against an address you used before.

If it might be infected

Signs: your antivirus reports something, the laptop behaves oddly, or you opened something on it that doesn’t belong there. The keys are still safe inside the hardware wallets, but malware could show you false addresses or change transactions before you sign.

  1. Stop: don’t sign anything and don’t generate new receive addresses on it.
  2. Reinstall the operating system from scratch using official media, then follow the broken-laptop steps above.
  3. Check your exchange withdrawal address again on a device that has your multisig registered.
  4. If you signed anything during the suspicious period, look up where the coins went on a block explorer (a website that shows public blockchain data). If the coins went where you meant them to, nothing was stolen.

Why this isn’t worse

Everything that controls your coins lives in the hardware wallets and your backups. The laptop only holds public information and a wallet file you can rebuild. That’s why the keys live on hardware wallets and only unsigned transactions (PSBTs) pass through the laptop.