Multisig, explained

A vault that needs M of N keys to spend — offline calculator, not a wallet

Offline crypto Checking…
Address calculator only — this pane is a coordinator. It cannot spend. You can receive / watch the vault address without the keys present. This page builds a multisig address/script from public keys. It does not create a spendable wallet, hold keys, or sign spends. To actually spend later you need a real wallet that imports the same policy plus each cosigner’s private material. Device PIN ≠ coordinator file password (hides balance only) ≠ BIP-39 passphrase (changes the seed).

What is multisig?

A vault that needs M of N keys to spend — offline calculator, not a wallet.

Safe-deposit box metaphor

Think of a bank safe-deposit box that needs more than one key. A normal Bitcoin address is 1-of-1. Multisig means M of N keys must agree before coins move.

  • N — total cosigners.
  • M — how many must sign (e.g. 2-of-3).
  • Public key — safe to share to build the address.
  • Private key — never paste here; WIF / xprv refused.

Policy readout

Set M and N (or generate demo cosigners) — policy text updates after build.

Cosigner checklist
  • ☐ Each cosigner generated their own seed offline / on hardware
  • ☐ Independent vendor / firmware class as well as independent entropy (same-vendor boxes can share a bug)
  • ☐ Only public keys (or account xpubs/zpubs) are shared to build the vault
  • ☐ M and N written down for recovery (e.g. 2-of-3)
  • ☐ BIP67 sort agreed (recommended) so everyone builds the same address
  • ☐ Before funding: every cosigner independently verifies the multisig vault address on their own device That means the shared vault from Build (P2SH / P2WSH) — not each person’s solo phone address.
  • ☐ Backup plan: who holds which key; how to replace a lost cosigner
  • ☐ No private keys or seeds pasted into this page
  • ☐ This tool does not sign or spend — real wallet software is required later
What if a cosigner is lost? (short answer)

You cannot keep the same vault address and “swap one key.” The address is locked to the exact set of public keys + M.

  1. Remaining signers (still M-of-N) spend coins out of the old vault.
  2. Build a new multisig with a replacement public key (new cosigner or your new seed).
  3. Everyone re-verifies the new vault address, then move funds there.

If you no longer have M keys, coins on the old vault are not recoverable with this design. Use the ⓘ on the checklist for the full story.

Where do the public keys come from?

Paste compressed pubkeys (02/03…) or generate throwaway demo cosigners offline — never seeds here.

Real life vs this lab
  • Real life: each person exports a public key from hardware / Sparrow; private keys never leave their device.
  • In this lab: Generate demo cosigners creates N throwaway seeds offline and fills pubkeys.
  • Demo seeds are for education only — do not fund them.

Generate demo cosigners (optional)

Creates N throwaway BIP-39 seeds. Each cosigner card shows two different public things: an account zpub (watch-only export) and one compressed pubkey that this page puts into Build for the M-of-N vault.

Why both a zpub and a compressed pubkey? (read this)

1. BIP-84 zpub — account watch-only at m/84'/0'/0' (SLIP-132 prefix zpub…). Real wallets export this so you can monitor all addresses under that account. Not an “xpub” string: do not paste a zpub into a tool that only accepts BIP-44 xpub (or the reverse). Wrong prefix is a classic import error.

2. Compressed pubkey at path m/84'/0'/0'/0/0 (first receive address under that account). This lab’s Build uses only these hex keys to form one multisig vault script. The zpub is shown so you learn what hardware/Sparrow export looks like — it is not pasted into the M-of-N script on this page.

So what? Zpub = “watch this whole account.” Compressed pubkey = “this one key participates in the vault.” Confusing them is how people fund the wrong wallet or fail imports.

N people in the vault. Example only: N=3 often uses M=2 (2-of-3) for convenience — not a universal best practice. Higher M means more security but more coordination; higher N means more redundancy but more key-management burden. Custody setups sometimes use 3-of-5 or stricter.

BIP39 word count for every demo cosigner

Pick strength first (12–24 words), then generate. All N cosigners use the same word count for this batch.

Like the 25th word — changes seed and BIP84 zpub. If you forget it, that cosigner key is permanently different / inaccessible (same words alone will not recover it). Leave empty unless you are teaching passphrases.

Build an address (public keys only)

Compressed pubkeys hex, one per line — or use the generator above. Private keys / WIF / xprv rejected.

Format: compressed secp256k1 — hex starting with 02 or 03, 66 hex characters (33 bytes). Uncompressed keys start with 04 and are longer; this page rejects them. Example (first line of placeholder): 66 chars, prefix 02.

Active source: paste compressed pubkeys below, or use Generate demo cosigners (warns before overwrite).

M must be ≤ N (number of pubkeys). More M → harder to spend without collusion; more N → more keys to back up.

Recommended on. Deterministic sort so the same key set always yields the same address regardless of paste order. Unchecking can produce a different address for the same keys — usually a recovery foot-gun.

Ready. Generate demo cosigners, or paste compressed public keys (hex), set M, then Build.

Compared to Ian Coleman’s multisig tool

iancoleman.io/multisig is also usable offline if you disable explorer calls. This page defaults to safer teaching settings: public keys only, no private-key fields, and CSP that blocks network from this page. Different defaults, not “his tool is unsafe by nature.”