Articles on: Bitcoin Wallets
This article is also available in:

Back up and recover a Jade Plus multisig wallet

A Jade Plus recovery phrase restores one signer, not a complete multisig wallet. Recovering a 2-of-3 wallet requires enough independent signer backups to meet the threshold and a policy or output descriptor that describes how the public keys form addresses.


Keep private inputs on hardware. Never enter recovery phrases or passphrases into Sparrow, another coordinator, a phone, computer, website, cloud form, chat, or support ticket. Enter them only directly on trusted hardware in a documented recovery flow.


Back up every part of the policy


Export the policy or output descriptor from the coordinator before receiving bitcoin. Create durable offline copies that preserve:


  • wallet identifier and Bitcoin network;
  • signing threshold (for example, 2 of 3);
  • script/address type;
  • all signer master fingerprints;
  • every signer xpub;
  • every signer derivation path;
  • exact key order, including whether the policy uses sorted or unsorted keys;
  • complete output descriptor or equivalent policy export;
  • coordinator configuration, wallet-file export, software version, server connection choice, and import method;
  • hardware models and firmware versions used in the last successful test;
  • date, signer pairs, and outcome of the last recovery drill.


The policy backup must not contain recovery words, device PINs, or BIP39 passphrases. An xpub or descriptor cannot sign, but the complete set can derive addresses and reveal balances and transaction history. Treat it as sensitive recovery metadata.


A Sparrow wallet file is useful coordinator configuration, but it cannot be the only recovery path. Prove that the descriptor or policy export rebuilds the wallet independently.


Store policy copies for availability


Keep more than one policy copy. A copy may be stored with each signer backup because it cannot sign alone; this improves recoverability but increases privacy exposure. Use sealed or encrypted storage when appropriate.


Separate signer devices from their own recovery phrases. Do not place any two usable signer credentials where one fire, flood, theft, or unauthorized person can collect them. A usable credential can be a device, recovery phrase, recovery share, or other backup that restores a key.


Use neutral location labels on the worksheet rather than exact addresses beside the descriptor. Ensure the authorized recovery person can locate a policy copy and two independent signer backups.


Register and export the policy on Jade Plus


Jade can register a multisig configuration to verify receive addresses and validate change during signing. Follow Blockstream's current registration and export steps for each signer. Review the threshold and signer details on Jade before accepting.


Jade registered multisig wallet list showing the generic test label Jade_Multisig


Official reference: Back up a multisig configuration on Jade.


A policy stored on a device is helpful but not sufficient. The device can be lost or reset; retain independent descriptor copies.


Rebuild the watch-only wallet


Use a clean coordinator profile and the saved descriptor or policy—not the original wallet file—to prove the recovery packet is complete.


  1. Import the policy into the tested Sparrow version.
  2. Confirm the network, threshold, script type, fingerprints, derivation paths, xpubs, and key order.
  3. Compare the first known receive addresses with addresses previously verified on hardware.
  4. Confirm the coordinator discovers the small test transaction through the intended server connection.


A matching balance alone is not enough. The descriptor and known addresses must match.


Restore and test a signer quorum


On spare or reset test Jade devices, restore two independent signer phrases directly on the hardware. Add any signer-specific passphrase directly on that Jade. Record and compare each restored fingerprint.


Register or review the recovered multisig policy on each device using the tested flow. Verify a known receive address on at least two hardware screens. Then create a small transaction, review the complete destination, amount, fee, and change on both devices, sign, combine the PSBTs, and broadcast.


Do not reset the only signers protecting a meaningful balance. Recovery tests belong on spare devices or a small-value test wallet.


Test more than one recovery path


A 2-of-3 design promises recovery when any one signer is unavailable. Test all three signing pairs before meaningful funding:


  • A+B;
  • A+C;
  • B+C.


Record the versions, connection method, policy-registration result, and transaction ID for the test without recording balances or secrets. After major firmware or coordinator updates, change one signer at a time and retest before changing another.


Respond to a lost, suspected-exposed, or confirmed-exposed signer


One unavailable signer does not block a healthy 2-of-3 wallet. One copied signer recovery phrase cannot spend alone, but that signer must no longer be treated as independent. A multisig signer cannot be rotated in place while keeping the same policy and addresses.


If one signer is lost or may be exposed, stop using it as trusted and prepare a new multisig wallet with fresh independent keys and a new policy; urgency increases if an attacker may obtain a second usable signer credential. If enough signer credentials to meet the threshold are confirmed exposed, move urgently and do not delay solely for a small test when delay materially increases theft risk. Back up the new policy, verify its addresses, and move funds. Start with Set up a 2-of-3 Jade Plus multisig wallet.



Updated on: 04/08/2026

Was this article helpful?

Share your feedback

Cancel

Thank you!