Security alert · 30 Jul 2026: a seed-generation flaw in Coldcard devices was disclosed. What to do →

What is a wallet descriptor, and why back it up?

TL;DR

The descriptor is a short line of text that describes your wallet: the three public keys, the 2-of-3 rule and the address type. It contains no secrets, but without it you may not be able to find your coins after losing a seed.

What’s in it

Output descriptor · example, shortened

wsh(sortedmulti(2,
  [a1b2c3d4/48h/0h/0h/2h]xpub6E…Q3x,
  [e5f6a7b8/48h/0h/0h/2h]xpub6F…k9L,
  [c9d0e1f2/48h/0h/0h/2h]xpub6D…m2P))

Shortened for readability. A real export from Sparrow also ends each key with /<0;1>/* and has a checksum after a #.

  • wsh: the address type, Native SegWit script (P2WSH).
  • sortedmulti(2, …): the rule, two signatures from these keys.
  • [a1b2c3d4/48h/0h/0h/2h]: each device’s fingerprint and the path to its key.
  • xpub…: each device’s extended public key.

Why it isn’t secret

Everything in it is public. An xpub lets software calculate addresses but can’t sign anything. Someone with your descriptor can see your addresses and balance, which is a privacy loss, but they can’t spend any of it.

Why you need it

Each seed gives you one key. Your addresses need all three public keys at once. As long as you have all three seeds you can rebuild everything. Lose one seed and the descriptor is the only place the third public key still exists. A 2-of-3 is supposed to survive losing a seed, but it only does if a copy of the descriptor survives as well.

How to store it

  • A printout (with QR code) in every seed box.
  • A text file on a USB stick in every box.
  • Extra digital copies are fine: password manager, encrypted cloud.

In Sparrow you find it under the wallet’s Settings tab. Step 7 of the guide shows how to export it.