Articles on: Bitcoin Wallets
This article is also available in:

Set up a 2-of-3 Jade Plus multisig wallet

A 2-of-3 multisig wallet has three independent signing keys and requires any two to spend. One unavailable signer does not block recovery, and one stolen signer cannot spend alone. This guide uses three Jade Plus devices, each initialized separately, with Sparrow Wallet as the coordinator.


Three independent Jade Plus signers in a 2-of-3 wallet


Safety check: Complete the entire process with Jade Plus devices and a small mainnet balance before using it for meaningful funds. Confirm menu labels, registration, address display, every signing pair, and recovery.


Understand the components


Sparrow constructs the wallet, derives addresses, prepares PSBTs, combines signatures, and broadcasts. The Jade devices hold independent keys, display details, and sign after approval.


Each Jade recovery phrase restores only one signer. The wallet policy or output descriptor explains how all three public keys form the wallet. A 2-of-3 recovery needs the policy plus any two signer backups.


Three devices initialized with the same recovery phrase do not create three signers; they copy the same key three times. Never enter recovery phrases into Sparrow, another coordinator, a phone, computer, website, cloud form, chat, or support ticket. Enter each phrase only on trusted hardware in a documented flow.


One Jade Plus could theoretically be wiped and initialized three separate times to create three independent signer backups. You would then restore the required signer whenever you need to register the policy, verify an address, sign, or recover. We do not recommend this for normal use. It removes separation between physical devices, and repeated wiping and restoring makes setup, signing, and recovery more error-prone. Best practice is three separate Jade Plus devices. If you want to reduce dependence on one model or vendor, use a multi-vendor 2-of-3 setup only after physically testing the exact devices, firmware, transport methods, wallet policy, backups, address and change display, recovery, and all three signing pairs.


Prepare a test environment


You need three Jade Plus devices, three recovery cards, private storage locations, and a verified current Sparrow release on a trusted computer. Update each Jade through Blockstream's official method before setup. If privacy matters, connect Sparrow to your own Bitcoin node or private server; a public server can learn addresses and balances it checks.


Dice entropy is required for this A/B/C method. Jade A, Jade B, and Jade C must each use a different recovery phrase created from a separate sequence of physical dice rolls through Blockstream's documented dice recovery-phrase workflow. Work privately and never reuse a dice sequence, recovery phrase, parent seed, or BIP85 root between signers. If you cannot complete and recovery-test three independent dice-generated backups, do not use this setup.


Initialize Jade A, B, and C separately:


  1. Create a new wallet on each device.
  2. Record its recovery phrase on its assigned offline card.
  3. Set a unique PIN.
  4. Apply a neutral signer label.
  5. Record its master fingerprint.
  6. Verify that every fingerprint is different.


Do not derive the signers from one parent seed or BIP85 root. Independence is the security property multisig is meant to provide.


Build the 2-of-3 wallet policy


Follow Sparrow's current hardware-wallet and multisignature instructions. Read each label shown by Sparrow and the signing device before approving a key or wallet policy, and stop if either one shows something you do not expect.


  1. Create a new wallet with a 2-of-3 multisignature policy.
  2. For a new wallet, use Native Segwit P2WSH only if all tested devices and the current Sparrow version support it.
  3. Add Jade A, Jade B, and Jade C through the tested USB or QR workflow.
  4. Compare each fingerprint and derivation path with the recovery worksheet.
  5. Confirm all fingerprints differ.
  6. Record each xpub and its key order exactly as the policy uses it.
  7. Review the threshold, network, script type, key order, and complete descriptor before applying.


Sparrow settings for a 2-of-3 Native Segwit multisig policy with three independent signer slots


The screen uses empty keystore placeholders and contains no wallet keys. Add each physical signer through the workflow supported by that device.


Do not force derivation paths or xpub versions to make an import work. Resolve any mismatch before proceeding.


Back up and register the policy


Export Sparrow's policy or output descriptor before receiving. The complete backup requirements are in Back up and recover Jade Plus multisig. At minimum, record the 2-of-3 threshold, script/address type, all fingerprints, xpubs, derivation paths, key order, and coordinator configuration.


Jade can register a multisig configuration so it can verify receive addresses and validate change. Use Blockstream's multisig backup and registration guide and Sparrow workflow on each signer. Review the threshold and signer details on Jade before accepting. Keep independent descriptor copies even if a device stores the registration.


Jade confirms a test 2-of-3 multisig registration


Official reference: Blockstream's multisig configuration guide linked above.


Verify receiving and spending


Generate a fresh receive address in Sparrow. Display and compare the complete address independently on Jade A, Jade B, and Jade C. Use it only when the full address matches Sparrow on all three devices, then send a small mainnet amount.


Create a small spend. Review destination, amount, fee, and change on each signing Jade. Sign first with A+B, return each partial PSBT through the tested transport, and broadcast only after Sparrow shows enough valid signatures and the final transaction still matches your intent.


One successful pair is not enough. Repeat with A+C and B+C so the wallet can spend while each signer is unavailable in turn. Stop if a device warns that the policy is unknown or cannot verify an output.


Do not fund before recovery passes


Rebuild a clean watch-only wallet from the saved descriptor, confirm known addresses and history, restore two signer backups on spare or reset Jade Plus devices used only with the small-value test wallet, register the policy, and complete a small spend. Do not reset the only devices controlling meaningful funds.


Record tested versions, transports, all three signing pairs, and the recovery result. Only then design physical storage so no single event or unauthorized person can collect two usable signer credentials.



Updated on: 04/08/2026

Was this article helpful?

Share your feedback

Cancel

Thank you!