The endgame of self-custody

Multi-vendor 2-of-3 multisig

One key is a single point of failure — of theft, loss, fire and coercion. Multisig removes it: your bitcoin needs any 2 of 3 independent keys to move. No single device, location, vendor or person can lose or steal your funds.

Why multi-vendor matters

Using three different vendors (e.g. Trezor + Jade + Keystone) means a supply-chain attack, a firmware bug, a broken app or even a company collapse at any one vendor cannot touch your coins. Diversity is the defense: the odds that two independent stacks fail the same way at the same time are vanishingly small.

Key 1 — e.g. Trezor (home safe)
Key 2 — e.g. Jade (bank vault)
Key 3 — e.g. Keystone (trusted family)
Any 2 of 3 signatures move the funds

The setup, step by step

01

Acquire 3 devices from 3 vendors

Buy each directly from its manufacturer, ideally shipped to different addresses. Never accept pre-seeded devices. Trezor + Blockstream Jade + Keystone is a battle-tested open-source trio.

02

Generate each key independently

Initialize each device offline, on its own. Write each seed on paper/steel. Verify each device shows its own master fingerprint (e.g. A1B2C3D4) — you will need these to detect tampering.

03

Build the vault in Sparrow Wallet

In Sparrow (desktop, open-source): New Wallet → Multi Signature → 2 of 3. Import each cosigner via QR/airgap (Jade, Keystone) or USB (Trezor). Sparrow builds the wallet descriptor from the three xpubs.

04

Back up the wallet descriptor — critically

The descriptor (or an output-descriptor backup / BSMS file) records all three xpubs and the script. Without it, 2 seeds are NOT enough to recover. Store a copy of the descriptor with EVERY seed backup.

05

Verify receive addresses on the devices

Before depositing, display a receive address in Sparrow and confirm it on at least two hardware devices’ own screens. Only then is the address provably part of your 2-of-3 vault.

06

Rehearse spending & recovery

Send a small amount in. Spend it out with key 1+2, then test key 2+3. Then simulate disaster: restore the wallet in Sparrow from backups only, using two seeds + descriptor. If you can do that, you are truly sovereign.

Why Sparrow as the coordinator

Open-source & bitcoin-only

No tokens, no bloat, auditable code — a power tool built by and for bitcoiners.

Vendor-agnostic

Speaks to virtually every hardware wallet via USB, microSD, or fully air-gapped QR (Jade, Keystone, SeedSigner).

Standards-based

Uses output descriptors & BSMS — your vault is recoverable in other software (Electrum, Nunchuk, Bitcoin Core). You are never locked into Sparrow.

Full transparency

Shows scripts, fingerprints, fee rates, coin control, and connects to your own node — the coordinator that hides nothing.

Nunchuk: the pragmatic alternative

If Sparrow is the engineer’s cockpit, Nunchuk is the guided cockpit — multisig with a modern mobile/desktop UX, optional assisted key, and inheritance built in.

Multisig without the steep curve

Guided 2-of-3 creation across hardware wallets (Trezor, Ledger, Keystone, Jade, Coldcard…) from your phone or desktop — same math, friendlier UX.

Assisted & collaborative custody

Optionally let Nunchuk hold one key of the quorum: they co-sign within your limits, help with recovery — and can never move funds alone.

Inheritance, structurally solved

Time-locked inheritance key handover: your heirs receive a key only after a delay you set — while you can veto at any time while alive.

Trade-off

The smoothest paths involve trusting Nunchuk’s platform for orchestration/recovery metadata. Self-sovereign purists keep everything descriptor-based and platform-free — Nunchuk supports that too, it’s just less magical.

Multisig rules that are not optional

Back up the descriptor with every seed · geographically separate the keys · never store two keys in the same building · rehearse recovery yearly · tell your heirs the system exists (not where the keys are). Multisig done carelessly is just three ways to lose everything instead of one.