Plan a multi-vendor 2-of-3 Bitcoin wallet
Before using a 2-of-3 wallet with Blockstream Jade Plus, Trezor Safe 5, Foundation Passport Prime, and Sparrow Wallet, test the exact combination yourself. Any two independent keys should authorize a spend, but documentation alone does not prove that these models, firmware versions, transports, and wallet policy work together from setup through recovery.

Test this setup before using it: Do not secure meaningful funds with this combination until physical tests pass for address verification, all three signing pairs, every native backup route, and clean recovery.
Current Foundation device: Passport Prime is Foundation's current device. Foundation documents Prime as usable with multisig-capable wallet coordinators, but that does not validate this exact three-device combination. Test Passport Prime's current firmware, backup format, Sparrow transport, address display, signing behaviour, and recovery path on physical hardware before using meaningful funds.
Define what vendor diversity should improve
Different manufacturers can reduce the chance that one vendor-specific hardware, firmware, or companion-app failure removes a signing quorum. It does not eliminate shared risks:
- Sparrow still assembles the policy and transactions;
- every device must interpret the same script and PSBT correctly;
- operators must verify addresses and change accurately;
- poor storage can place two keys under one failure or person;
- all signers can be affected by one mistaken setup or update process.
Vendor diversity does nothing if two signers share a recovery phrase, derive from one parent seed, or are stored together.
Record the exact setup
Record the exact combination before testing:
- Signer A: Blockstream Jade Plus;
- Signer B: Trezor Safe 5;
- Signer C: Foundation Passport Prime;
- coordinator: a verified current Sparrow release in a dedicated profile;
- Bitcoin network, 2-of-3 threshold, selected script/address type, and server connection;
- model and firmware version for every signer;
- transport and import method proposed for each signer.
Do not substitute another model midway and assume prior results still apply.
Keep native backups independent
Initialize each device separately in a private room, using its manufacturer's documented setup. Give each a unique PIN, neutral label, and independently generated key. Record its master fingerprint and test its native backup using a documented non-destructive check or compatible spare hardware.
Backup formats are not interchangeable by assumption. A Trezor backup, a Jade BIP39 phrase, and a Passport backup may require different restoration procedures. Physically validate a replacement route for each exact format.
Never load one signer's recovery backup into another during setup or type it into Sparrow, a phone, computer, website, cloud form, chat, or support ticket. Private recovery input belongs only on trusted hardware in documented flows.
Build and document the wallet policy
Use a new wallet with no meaningful balance. Through each vendor's current official Sparrow flow, attempt to add the three keystores. Do not claim compatibility until this succeeds on physical devices.
Record the exact:
- 2-of-3 threshold and Bitcoin network;
- script/address type;
- sorted or unsorted key policy and key order;
- signer labels, fingerprints, xpubs, and derivation paths;
- complete output descriptor;
- model, firmware, Sparrow version, and transport for each signer;
- coordinator wallet-file and server configuration.
Do not force a derivation path or xpub version to make an import succeed. Stop and document the incompatibility.
Test the full hardware combination
Testnet can help operators practise, but the final validation must use a small mainnet amount to test the actual network, account, paths, addresses, and policy.
Receive test: Generate an address in Sparrow and verify the complete address independently on every device that supports address display for the tested policy. Record any field or address a device cannot display; missing verification is a security finding. Send a small amount and confirm discovery through the intended server.
Signing-pair tests: Create separate small transactions and test:
- Jade Plus + Trezor Safe 5;
- Jade Plus + Foundation Passport Prime;
- Trezor Safe 5 + Foundation Passport Prime.
For each pair, compare destination, amount, fee, and change on both signers. Transfer each partial PSBT through the recorded transport, confirm Sparrow accepts both signatures, and ensure the final transaction still matches before broadcast. The setup has not passed until it spends while each signer is unavailable in turn.
Run clean recovery tests
In a separate Sparrow profile, rebuild the watch-only wallet from the saved descriptor and confirm known addresses and history. Restore two signers through their own tested native backup routes on spare or reset hardware. Re-establish or review the multisig policy using each vendor's tested procedure, verify a known address on hardware, and complete a small mainnet spend. Repeat until A+B, A+C, and B+C have each passed.
Keep every pair of usable signing credentials under separate physical and administrative control. Update one signer at a time and rerun its signature test before changing another.
Official planning sources: Blockstream with Sparrow, Trezor multisig, Passport Prime Bitcoin wallet documentation, Foundation Passport Prime, and Sparrow documentation.
Related security steps
- Back up and recover a multisig policy.
- Test Bitcoin wallet recovery.
- Verify Jade Plus and avoid wallet scams.
Updated on: 04/08/2026
Thank you!
