Multi-vendor 2-of-3 multisig
One key is a single point of failure — of theft, loss, fire and coercion. Multisig removes it: your bitcoin needs any 2 of 3 independent keys to move. No single device, location, vendor or person can lose or steal your funds.
Why multi-vendor matters
Using three different vendors (e.g. Trezor + Jade + Keystone) means a supply-chain attack, a firmware bug, a broken app or even a company collapse at any one vendor cannot touch your coins. Diversity is the defense: the odds that two independent stacks fail the same way at the same time are vanishingly small.
The setup, step by step
Acquire 3 devices from 3 vendors
Buy each directly from its manufacturer, ideally shipped to different addresses. Never accept pre-seeded devices. Trezor + Blockstream Jade + Keystone is a battle-tested open-source trio.
Generate each key independently
Initialize each device offline, on its own. Write each seed on paper/steel. Verify each device shows its own master fingerprint (e.g. A1B2C3D4) — you will need these to detect tampering.
Build the vault in Sparrow Wallet
In Sparrow (desktop, open-source): New Wallet → Multi Signature → 2 of 3. Import each cosigner via QR/airgap (Jade, Keystone) or USB (Trezor). Sparrow builds the wallet descriptor from the three xpubs.
Back up the wallet descriptor — critically
The descriptor (or an output-descriptor backup / BSMS file) records all three xpubs and the script. Without it, 2 seeds are NOT enough to recover. Store a copy of the descriptor with EVERY seed backup.
Verify receive addresses on the devices
Before depositing, display a receive address in Sparrow and confirm it on at least two hardware devices’ own screens. Only then is the address provably part of your 2-of-3 vault.
Rehearse spending & recovery
Send a small amount in. Spend it out with key 1+2, then test key 2+3. Then simulate disaster: restore the wallet in Sparrow from backups only, using two seeds + descriptor. If you can do that, you are truly sovereign.
Why Sparrow as the coordinator
Open-source & bitcoin-only
No tokens, no bloat, auditable code — a power tool built by and for bitcoiners.
Vendor-agnostic
Speaks to virtually every hardware wallet via USB, microSD, or fully air-gapped QR (Jade, Keystone, SeedSigner).
Standards-based
Uses output descriptors & BSMS — your vault is recoverable in other software (Electrum, Nunchuk, Bitcoin Core). You are never locked into Sparrow.
Full transparency
Shows scripts, fingerprints, fee rates, coin control, and connects to your own node — the coordinator that hides nothing.
Nunchuk: the pragmatic alternative
If Sparrow is the engineer’s cockpit, Nunchuk is the guided cockpit — multisig with a modern mobile/desktop UX, optional assisted key, and inheritance built in.
Multisig without the steep curve
Guided 2-of-3 creation across hardware wallets (Trezor, Ledger, Keystone, Jade, Coldcard…) from your phone or desktop — same math, friendlier UX.
Assisted & collaborative custody
Optionally let Nunchuk hold one key of the quorum: they co-sign within your limits, help with recovery — and can never move funds alone.
Inheritance, structurally solved
Time-locked inheritance key handover: your heirs receive a key only after a delay you set — while you can veto at any time while alive.
Trade-off
The smoothest paths involve trusting Nunchuk’s platform for orchestration/recovery metadata. Self-sovereign purists keep everything descriptor-based and platform-free — Nunchuk supports that too, it’s just less magical.
Multisig rules that are not optional
Back up the descriptor with every seed · geographically separate the keys · never store two keys in the same building · rehearse recovery yearly · tell your heirs the system exists (not where the keys are). Multisig done carelessly is just three ways to lose everything instead of one.