TL;DR
An xpub (extended public key) lets software generate all the addresses of one key, but it can’t spend anything. In a single-sig wallet, a leaked xpub reveals your whole balance. In a multisig, one xpub alone reveals nothing about your multisig addresses.
What it is
Your seed produces a tree of key pairs. The xpub sits near the top of one branch: from it, software can calculate every public key and address below it. The matching private key (xprv) never leaves the hardware wallet.
What someone with your xpub can do
- Single-sig: see every address and the full balance and history of that wallet.
- Multisig: nothing useful with one xpub, because each address is built from all three. With all three (or your descriptor) they can see everything.
- In no case: spend, sign or change anything.
Who sees your xpubs in this setup
- Sparrow on your signing computer: all three, in the wallet file.
- Your descriptor backups: all three.
- The server Sparrow talks to: a public Electrum server sees the addresses Sparrow asks about (not the xpubs), which amounts to the same view of your wallet. Your own Bitcoin Core node gets the full descriptor, which is fine because the node is yours.
xpub, Zpub, and friends
You may see keys starting with Zpub or other prefixes. They’re the same kind of key with a label for the address type. Sparrow handles the conversion; the descriptor states the type explicitly.
Related: master fingerprint · derivation path