What is multisig?
A vault that needs M of N keys to spend — offline calculator, not a wallet.
Safe-deposit box metaphor
Think of a bank safe-deposit box that needs more than one key. A normal Bitcoin address is 1-of-1. Multisig means M of N keys must agree before coins move.
- N — total cosigners.
- M — how many must sign (e.g. 2-of-3).
- Public key — safe to share to build the address.
- Private key — never paste here; WIF / xprv refused.
Policy readout
Set M and N (or generate demo cosigners) — policy text updates after build.
Cosigner checklist
- ☐ Each cosigner generated their own seed offline / on hardware
- ☐ Independent vendor / firmware class as well as independent entropy (same-vendor boxes can share a bug)
- ☐ Only public keys (or account xpubs/zpubs) are shared to build the vault
- ☐ M and N written down for recovery (e.g. 2-of-3)
- ☐ BIP67 sort agreed (recommended) so everyone builds the same address
- ☐ Before funding: every cosigner independently verifies the multisig vault address on their own device That means the shared vault from Build (P2SH / P2WSH) — not each person’s solo phone address.
- ☐ Backup plan: who holds which key; how to replace a lost cosigner
- ☐ No private keys or seeds pasted into this page
- ☐ This tool does not sign or spend — real wallet software is required later
What if a cosigner is lost? (short answer)
You cannot keep the same vault address and “swap one key.” The address is locked to the exact set of public keys + M.
- Remaining signers (still M-of-N) spend coins out of the old vault.
- Build a new multisig with a replacement public key (new cosigner or your new seed).
- Everyone re-verifies the new vault address, then move funds there.
If you no longer have M keys, coins on the old vault are not recoverable with this design. Use the ⓘ on the checklist for the full story.
Where do the public keys come from?
Paste compressed pubkeys (02/03…) or generate throwaway demo cosigners offline — never seeds here.
Real life vs this lab
- Real life: each person exports a public key from hardware / Sparrow; private keys never leave their device.
- In this lab: Generate demo cosigners creates N throwaway seeds offline and fills pubkeys.
- Demo seeds are for education only — do not fund them.
Generate demo cosigners (optional)
Creates N throwaway BIP-39 seeds. Each cosigner card shows two different public things: an account zpub (watch-only export) and one compressed pubkey that this page puts into Build for the M-of-N vault.
Why both a zpub and a compressed pubkey? (read this)
1. BIP-84 zpub
— account watch-only at m/84'/0'/0' (SLIP-132 prefix zpub…).
Real wallets export this so you can monitor all addresses under that account.
Not an “xpub” string: do not paste a zpub into a tool that only accepts BIP-44 xpub
(or the reverse). Wrong prefix is a classic import error.
2. Compressed pubkey
at path m/84'/0'/0'/0/0 (first receive address under that account).
This lab’s Build uses only these hex keys to form one multisig vault script.
The zpub is shown so you learn what hardware/Sparrow export looks like — it is
not pasted into the M-of-N script on this page.
So what? Zpub = “watch this whole account.” Compressed pubkey = “this one key participates in the vault.” Confusing them is how people fund the wrong wallet or fail imports.
N people in the vault. Example only: N=3 often uses M=2 (2-of-3) for convenience — not a universal best practice. Higher M means more security but more coordination; higher N means more redundancy but more key-management burden. Custody setups sometimes use 3-of-5 or stricter.
Pick strength first (12–24 words), then generate. All N cosigners use the same word count for this batch.
Like the 25th word — changes seed and BIP84 zpub. If you forget it, that cosigner key is permanently different / inaccessible (same words alone will not recover it). Leave empty unless you are teaching passphrases.
Build an address (public keys only)
Compressed pubkeys hex, one per line — or use the generator above. Private keys / WIF / xprv rejected.
Format: compressed secp256k1 — hex starting with 02 or 03,
66 hex characters (33 bytes). Uncompressed keys start with 04 and are longer; this page rejects them.
Example (first line of placeholder): 66 chars, prefix 02.
Active source: paste compressed pubkeys below, or use Generate demo cosigners (warns before overwrite).
M must be ≤ N (number of pubkeys). More M → harder to spend without collusion; more N → more keys to back up.
Recommended on. Deterministic sort so the same key set always yields the same address regardless of paste order. Unchecking can produce a different address for the same keys — usually a recovery foot-gun.
BIP67 sort is off: key order now affects the address. Only disable if you intentionally match a non-BIP67 setup.
Ready. Generate demo cosigners, or paste compressed public keys (hex), set M, then Build.
Before funding: each cosigner must independently verify this same address on their own device / wallet. One mismatched key or M value funds an unspendable vault. This page only computed the address — it cannot sign or spend.
P2SH (starts with 3) — legacy-wrapped multisig (script hash in a P2SH output).
Wider compatibility with older software; slightly larger on-chain footprint than native segwit.
P2WSH (starts with bc1q, longer) — native segwit multisig.
Same M-of-N policy; usually lower fees and modern wallet defaults. Prefer when all cosigners support it.
Redeem / witness script (hex)
Keys in final order
Vault map
This string is the map to the vault (public policy). It is not a seed. Store a copy with each key. If you lose the map and one key, you may not rebuild the address.
Compared to Ian Coleman’s multisig tool
iancoleman.io/multisig is also usable offline if you disable explorer calls. This page defaults to safer teaching settings: public keys only, no private-key fields, and CSP that blocks network from this page. Different defaults, not “his tool is unsafe by nature.”