# What the SH II does and does not do


**Draft, not yet verified on hardware.**

Inputs, formats, scripts and limits of a SeedHammer II on stock firmware v1.4.3, for choosing a wallet export or buying plates.

<p class="alert alert-warning">Seed words are typed on the machine only and never pass through a phone, a computer or a chat assistant.</p>

A descriptor is not a secret, yet it reveals every address of the wallet.

## At a glance {#summary}

| Question | v1.4.3 |
| --- | --- |
| How does a seed get in? | Typed on the touchscreen: 12 or 24 BIP39 words. |
| How does a descriptor get in? | As text over NFC, written by a phone app such as NFC Tools while "Backup Wallet" is shown. |
| Camera, SD card, QR scanner, USB data cable, SeedSigner or another device? | None needed. No camera, no SD card. USB-C carries power; its only data is a firmware file in upgrade mode. |
| A descriptor or an xpub without a seed? | Yes (unverified). One job engraves one thing: a seed, a descriptor or a codex32 share. Send a descriptor with key origins, not a lone xpub. |
| Multisig? | Yes, without a multisig menu: each seed on its own plate, then the descriptor. |
| Largest multisig that fits? | Four keys (2-of-4, 3-of-4) with full key origins, as text or as QR, not both (unverified). Five keys or more: "Too Large". [What fits on a plate](/doc/manual/multisig-and-fit#fit). |
| Scripts? | Single-sig P2PKH, P2WPKH, P2SH-P2WPKH, single-key P2TR (unverified); multisig `sortedmulti` in P2WSH, P2SH, P2SH-P2WSH. |
| Taproot multisig, miniscript, unsorted `multi`? | No: "Unknown format". |
| codex32? | One share at a time, over NFC only, engraved as received; not in the menu (unverified). [Shares](#shares). |
| SLIP-39? | No. |
| Passphrase? | No entry screen; nothing engraves it. |
| Titles or custom text? | No custom text. A label in the export is shown on screen and not engraved (unverified). [Titles](/doc/manual/titles-and-plate-layout#titles). |
| Seed generation, dice entry, last-word calculation? | No. |
| Split a seed or a descriptor across plates? | No. A descriptor plate carries the whole descriptor. |
| Preview or dry run? | No. |
| Plates | One size, 85 x 85 mm, one face per job. |

## What you need {#requirements}

- The machine and a USB-C PD supply offering 20 V or 28 V at 5 A (100 W or 140 W); the firmware starts on 20 V to 28 V at 3 A or more ([power](/doc/manual/power-and-first-start#power)).
- Blank SH02 or SeedHammer II plates, 85 x 85 mm.
- For a descriptor: a phone with NFC and the NFC Tools app (iPhone or Android).

## The hardware {#hardware}

| Part | What it does |
| --- | --- |
| 3.5" touchscreen, 480 x 320 | All controls. Three touch slots on the right edge act as buttons (back, edit, checkmark, hold); no physical menu buttons. |
| NFC reader, right of the display (ST25R3916 chip) | Receives text from a phone or a tag, only while "Backup Wallet" is shown. |
| USB-C port | Power. In firmware upgrade mode it appears on a computer as a USB drive; release firmware reads no data over USB. |
| Engraver | One 85 x 85 mm plate per job, one face, 3 mm safety margin on every side. |

The start screen shows "Firmware: v1.4.3" at the bottom right; power faults: [Power supply and first start](/doc/manual/power-and-first-start#troubleshooting).

![SeedHammer II front with the NFC reader area right of the display](/static/img/capability-sheet-01.webp)
<!-- capture: photo, SH II front, start screen "Backup Wallet" lit, NFC reader area right of the display outlined; no lab shot yet -->

## How data gets in {#input}

| Route | How | Full steps |
| --- | --- | --- |
| Touchscreen | From "Backup Wallet": the checkmark (bottom of the right edge), "12 WORDS" or "24 WORDS" on "Input Seed", then each word on "Input Words". Letters that cannot continue a BIP39 word go dim. | [Enter a seed on the touchscreen](/doc/manual/seed-entry) |
| NFC | On "Backup Wallet" the machine acts as an empty NFC tag, and a phone writes text to it as to a sticker tag. The machine decodes the text and opens the matching screen itself. No descriptor menu. | [Send a descriptor with NFC Tools](/doc/manual/nfc-tools-transfer) |

![Start screen Backup Wallet with the firmware version](/static/img/capability-sheet-02.webp)
<!-- capture: II screen, start screen "Backup Wallet", "Firmware: v1.4.3" bottom right, no status line (device-screen-map 4.2 row 1); no lab shot yet -->

| NFC fact | v1.4.3 |
| --- | --- |
| When it listens | Only on "Backup Wallet". NFC is off on every other screen. |
| Records it reads | NDEF Text, UTF-8. URI records arrive with their prefix in front: a descriptor sent as a URL becomes `https://wsh(...)` and fails. |
| Records it ignores | UTF-16 Text, Data and MIME records, Smart Poster, external types. The phone still reports success; the machine shows nothing. |
| Size | Receive buffer 8192 bytes. A phone writes at most about 8180 characters, far more than any supported descriptor. |
| Read back | Always an empty tag. A phone cannot check what it sent by reading the machine. |
| Status line | "Scanning...", "Unknown format" or "Scan error", each for about one second. |
| Spaces and line breaks | Not trimmed. A trailing space or line break makes a plain descriptor, a key, seed words or a codex32 share fail; Coldcard-style text and JSON tolerate a final line break. |

![Status line Unknown format on the start screen](/static/img/capability-sheet-03.webp)
<!-- capture: II screen, start screen "Backup Wallet", status line "Unknown format" after NFC Text "hello world" (device-screen-map 4.2 row 25); no lab shot yet -->

## What it accepts over NFC {#formats}

The machine tries each reading in this order and takes the first one that works.

| # | Text received | Next screen | Title on screen |
| --- | --- | --- | --- |
| 1 | BIP39 seed words separated by single spaces | "Engrave Seed" | none |
| 2 | Coldcard or BlueWallet multisig text with a `Name:` line | "Engrave Descriptor" | the `Name:` value |
| 3 | A plain descriptor (BIP380), single path such as `/0/*` or multipath `/<0;1>/*` | "Engrave Descriptor" | none |
| 4 | JSON `{"label": ..., "descriptor": ...}`; other keys are ignored | "Engrave Descriptor" | the label |
| 5 | One extended public key for a single-sig wallet (see below) | "Engrave Descriptor" | none |
| 6 | A codex32 share | "Engrave Plate" at once | none (no confirmation screen) |
| | Anything else | stays on "Backup Wallet", "Unknown format" | |

A descriptor or a key needs no seed: from "Backup Wallet" the machine goes straight to "Engrave Descriptor" (unverified).

Never send a bare key, which is read by its prefix alone; send a descriptor with its key origin.

| Key sent | Read as | On the plate |
| --- | --- | --- |
| `xpub...` | "Legacy (P2PKH)", path m/44'/0'/0', even from a native segwit wallet or a multisig cosigner | `pkh(xpub...)`, the wrong script for a segwit wallet. The key is rebuilt for that path: an account-0 single-sig key keeps its string; a key at another depth (a multisig cosigner key) or from another account becomes a different string |
| `zpub...` | "Segwit (P2WPKH)", path m/84'/0'/0' | `wpkh(xpub...)`: the string never matches the `zpub` your wallet shows |
| `ypub...`, `Ypub...`, `Zpub...` | "Unknown format" | |
| `[fingerprint/84h/0h/0h]xpub...` (key with origin) | "Segwit (P2WPKH)", fingerprint kept; a cosigner key with a `48h` origin gives "Unknown format" | the key with its origin |

A bare key is engraved without fingerprint, path or child path such as `/0/*`.

Seed words over NFC are decoded up to 24 words, in multiples of 3, with a valid checksum; a wrong checksum shows "Unknown format" on this route, as does an Electrum seed in most cases.

Do not send seed words from a phone or a signer; type them as in [Enter a seed on the touchscreen](/doc/manual/seed-entry).

SeedQR digits are not decoded.

**Important:** never send text that starts with `command: `, which is reserved for hidden debug commands: one changes the boot settings permanently, another starts the axes moving on a screen with no way out.

## Scripts {#scripts}

| Wallet type | Descriptor | "Script" on screen | v1.4.3 |
| --- | --- | --- | --- |
| Single-sig legacy | `pkh(...)` | "Legacy (P2PKH)" | yes |
| Single-sig native segwit | `wpkh(...)` | "Segwit (P2WPKH)" | yes |
| Single-sig nested segwit | `sh(wpkh(...))` | "Nested Segwit (P2SH-P2WPKH)" | yes |
| Single-sig taproot, one key | `tr(KEY)` | "Taproot (P2TR)" | yes (unverified) |
| Multisig native segwit | `wsh(sortedmulti(...))` | "Segwit (P2WSH)" | yes |
| Multisig nested segwit | `sh(wsh(sortedmulti(...)))` | "Nested Segwit (P2SH-P2WSH)" | yes |
| Multisig legacy | `sh(sortedmulti(...))` | "Legacy (P2SH)" | yes |
| Unsorted multisig | `wsh(multi(...))` | | no: "Unknown format" |
| Taproot with a script tree, taproot multisig, MuSig | `tr(KEY,{...})`, `multi_a` | | no: "Unknown format" |
| Miniscript (timelock and inheritance wallets) | `wsh(or_d(...))` and similar | | no: "Unknown format" |
| Any descriptor with a BIP393 annotation | `...)?bh=850000#...` | | no: "Unknown format" |

The "Type" line reads "Singlesig" or the policy, such as "2-of-3 multisig", with " (testnet)" added for testnet keys.

Multipath `/<0;1>/*` is fine; a path with three or more branches fails.

Sparrow 2.5.0 and later add `?bh=` once the wallet has a confirmed payment and `?gl=` after a gap-limit change; remove the suffix as in [Prepare the text](/doc/manual/nfc-tools-transfer#prepare).

## What it shows before engraving {#screens}

| Screen | Shows | Next |
| --- | --- | --- |
| "Engrave Descriptor" | "Title" (only when the export carried a label), "Type", "Script". No addresses, fingerprints, keys or derivation paths: check those in your wallet before you engrave. | The checkmark tries three layouts and offers only those that fit. If none fits, "Too Large" with "The descriptor cannot fit any plate size." appears instead; its checkmark returns to "Engrave Descriptor". |
| "Engrave" / "Choose engraving" | "TEXT + QR", "TEXT ONLY", "QR ONLY", whichever fit | The checkmark goes to "Engrave Plate". |
| "Engrave Seed" | The words | The checkmark tests the checksum. Failure: "Invalid Seed" with "The seed phrase is invalid." and "Check the words and try again.", or "Electrum seeds are not supported." for an Electrum seed. |
| "Engrave Plate" | "Insert a blank plate and close the lock." | A one-second hold on the hammer button starts the job. At the end: "Engraving completed successfully." |

![Engrave Descriptor for the demo 2-of-3 wallet with its title](/static/img/capability-sheet-04.webp)
<!-- capture: II screen, "Engrave Descriptor" after NFC Text of lab/fixtures/2of3-specter.json: Title "Demo 2of3", Type "2-of-3 multisig", Script "Segwit (P2WSH)" (device-screen-map 4.2 row 27); no lab shot yet -->

![Choose engraving for the demo 2-of-3 wallet](/static/img/capability-sheet-05.webp)
<!-- capture: II screen, title "Engrave", lead "Choose engraving", for lab/fixtures/2of3-specter.json: "TEXT ONLY" selected, "QR ONLY" below (device-screen-map 4.2 row 29); no lab shot yet -->

Single-sig gets all three layouts, multisig with up to four keys "TEXT ONLY" and "QR ONLY", five keys or more "Too Large" ([What fits on a plate](/doc/manual/multisig-and-fit#fit)).

## What gets engraved {#plates}

| Input | Text on the plate | QR | Title |
| --- | --- | --- | --- |
| Seed (typed or NFC) | Master fingerprint, 8 hex digits (3.0 mm), above numbered words (4.1 mm); layout in [Seed plate](/doc/manual/titles-and-plate-layout#seed) | SeedQR, standard numeric form (unverified) | none |
| Descriptor | The descriptor rebuilt as BIP380 text with key origins and checksum, hardened steps written as `h`, 3.8 mm, wrapped | The same descriptor with key origins, without checksum | none (unverified) |
| codex32 share | The share in capitals, groups of 10 characters in two columns | The share | the 4-character share identifier, under the columns |

The fingerprint on a seed plate is the one for an empty passphrase.

Why a descriptor plate can differ from the export (`h` for `'`, no child path from Coldcard-style text, old QR codes): [Why the plate differs](/doc/manual/multisig-and-fit#differences).

![Seed plate and descriptor plates engraved on v1.4.3](/static/img/capability-sheet-06.webp)
<!-- capture: photo, plates engraved on v1.4.3: Demo A 12-word seed plate (public test vector from lab/TESTWALLET.md), demo 2-of-3 descriptor as "TEXT ONLY" and as "QR ONLY"; no lab shot yet -->

## Shares: codex32 and SLIP-39 {#shares}

| Item | v1.4.3 |
| --- | --- |
| SLIP-39 | Not supported. The entry is switched off in the firmware. |
| codex32 entry | "Input Seed" offers only "12 WORDS" and "24 WORDS". No codex32 keyboard, so a share arrives only over NFC. |
| What it does with a share | Engraves one share as received. It does not create, split or combine shares. |
| After a share arrives over NFC | Straight to "Engrave Plate", no confirmation screen (unverified). |
| Back arrow on that "Engrave Plate" | Does not leave. The only ways out: finish the engraving or unplug the machine (unverified). |
| A share that cannot be laid out | Returns to "Backup Wallet" without a message (unverified). |

<p class="alert alert-warning">A codex32 share is secret like a seed: sent over NFC, it passes through the sending device (see <a href="/doc/manual/seed-entry">Enter a seed on the touchscreen</a>).</p>

## NFC tags, cards and desktop writers {#tags}

| Device | v1.4.3 |
| --- | --- |
| ISO 14443A Type 2 tag (NTAG21x), ISO 15693 Type 5 tag (ICODE SLIX, ST25TV) | Polled when no phone is in range (unverified). Write one Text record with NFC Tools, then hold the tag right of the display on "Backup Wallet". |
| NTAG21x capacity | 48 to 888 bytes, which can be too small for a multisig descriptor (unverified per tag). |
| Type 4 tag (DESFire, NTAG 424, ST25TA), Type 3 tag | Not read: the firmware has no reader for them (unverified). |
| Card that is not a Type 2 or Type 5 NDEF tag, such as MIFARE Classic | Not expected to work (unverified). |
| Desktop USB NFC writer aimed at the machine | The writer gets a scan error and beeps every second (unverified). Write the text to a tag and present the tag, or use a phone. |
| Coldcard Mk4 or Q | Presents a Type 5 tag, which the reader accepts (unverified). Exports: [Send a descriptor from Coldcard Mk4 or Q](/doc/manual/descriptor-coldcard). |

A tag keeps a readable copy of the keys; wipe or destroy it after use.

## Wallet exports at a glance {#wallets}

Step by step: [Sparrow and Specter](/doc/manual/descriptor-desktop-wallets), [phone wallets](/doc/manual/descriptor-mobile-wallets), [Coldcard](/doc/manual/descriptor-coldcard); the transfer: [NFC Tools](/doc/manual/nfc-tools-transfer).

| App and version | Export | Result on v1.4.3 (unverified) | Title |
| --- | --- | --- | --- |
| Sparrow 2.5.5 | Settings, "Descriptor:" field, right-click, "Copy Output Descriptor" | accepted; fails with `?bh=` or `?gl=` | none |
| Sparrow 2.5.5, multisig | "Export...", then "Keystone Multisig", "Passport Multisig", "Coldcard Multisig" or "BlueWallet Vault Multisig", "Export File..." | accepted when all cosigners share one derivation path | wallet name, shortened to 20 characters |
| Sparrow 2.5.5 | "Export...", "Specter Desktop" | accepted; fails with `?bh=` or `?gl=` | wallet name |
| Sparrow 2.5.5 | "Export...", "Output Descriptor", "Export File..." | whole file fails; the first descriptor line alone is accepted | none |
| Sparrow 2.5.5 | "Descriptor:" field, right-click, "Copy Value" | fails (keystore names, not keys) | |
| Specter Desktop v2.1.11 | "Settings", "Export", "Go to export details", "Copy Wallet Data" | accepted, receive branch only | wallet name |
| Nunchuk Android 2.9.0 | "Export wallet configuration", "Descriptor" | accepted, receive branch only | none |
| Nunchuk Android 2.9.0, "Do it now" after wallet creation | "Save BSMS file", then "Export configuration as a file" | BSMS fails; the configuration file (`/<0;1>/*`) is accepted | none |
| Nunchuk | "BSMS" | fails | |
| BlueWallet 8.0.2, vault | "Export Coordination Setup" | accepted for P2WSH and P2SH vaults; fails for a wrapped (P2SH-P2WSH) vault; a cosigner on its own path silently gets the common path, so its engraved origin is wrong | vault name |
| BlueWallet 8.0.3, single-sig | "Show Wallet XPUB" | bare key, do not use: `zpub` accepted without origin and engraved as `xpub`; `ypub` fails; `xpub` read as Legacy (P2PKH) | none |
| Cove 1.3.0 | "Export Xpub", "QR Code", copy icon | accepted | none |
| Bitcoin Keeper 2.6.3, vault | "Wallet configuration file", "Show QR" | accepted; miniscript vaults fail | none |
| Bitcoin Keeper 2.5.13, hot wallet | "Show xPub" | read as Legacy (P2PKH): wrong script | none |
| Envoy 2.3.5 | "Show Descriptor", "Segwit", "Copy" | accepted, receive branch only | none |
| Blockstream app 5.7.0 | "Watch-only", "Output Descriptors" | fails as copied (two lines); accepted after deleting the second line | none |

## If it does not work {#troubleshooting}

| Symptom | Cause | Fix |
| --- | --- | --- |
| "Unknown format", "Scan error", or nothing after an NFC write | The text matches no reading above, or the transfer failed | [Troubleshooting: NFC](/doc/manual/troubleshooting#nfc) |
| "Too Large" with "The descriptor cannot fit any plate size." | The descriptor fits no layout | [What fits on a plate](/doc/manual/multisig-and-fit#fit) |
| Any other message or fault | Varies | [Troubleshooting](/doc/manual/troubleshooting); power: [Power supply and first start](/doc/manual/power-and-first-start#troubleshooting) |

<!--
bench-checks:
  - [ ] Regenerate the format and limit tables from firmware source on every release, not by hand: lab/check `go run . facts` and lab/check/RESULTS.md at ea4b65b match this page; re-run `./upstream.sh <tag>` and `go test ./...` on the next tag and diff (scan.go, parse.go, backup.go)
  - [ ] Physical tags: one Text record with lab/fixtures/singlesig-wpkh.txt, then lab/fixtures/2of3-descriptor.txt, on NTAG213, NTAG215, NTAG216 and ICODE SLIX2, held to "Backup Wallet": read or not, and which tag holds the 2-of-3
  - [ ] Cards that should not work: DESFire or NTAG 424, MIFARE Classic 1K: expect nothing
  - [ ] Desktop USB NFC writer (ACR1552U class, NFC Tools desktop and nfcpy) straight to the machine: what the screen shows, whether the writer beeps every second, and whether the machine's tag ID changes every second (the owner-reported cause, SYNTHESIS D row "Desktop NFC writer", status open; this page owns the statement, gives the symptom as unverified and, since the edit pass of 2026-10-10, keeps the unconfirmed cause in this block only)
  - [ ] codex32 share over NFC on v1.4.3 (lab/check/testdata/codex32.txt, BIP93 vector also in gui/scan_test.go): goes straight to "Engrave Plate"; back arrow keeps the same screen; a share that cannot be planned returns to "Backup Wallet" with no message; engraved share id; whether it fits one face. This page owns the codex32 statement (source reading, shown as "unverified" in #shares); seed-entry, troubleshooting, titles and security-faq link here
  - [ ] Seed words over NFC (lab/check/testdata/mnemonic-12.txt, public vector, from a test tag, never a personal seed): "Engrave Seed"
  - [ ] Descriptor alone over NFC (lab/fixtures/2of3-specter.json): "Engrave Descriptor" with no seed asked first; a bare xpub alone likewise (At a glance row, shown as unverified)
  - [ ] Titled export: Title "Demo 2of3" shown; plate carries no title
  - [ ] Layouts offered (lab/fixtures): singlesig-wpkh all three; 2of3 and 2of4 "TEXT ONLY" and "QR ONLY"; 3of5 and 3of6 "Too Large" / "The descriptor cannot fit any plate size."
  - [ ] Layouts by key count, payloads built from the 2of4/3of5 fixture keys (not yet saved in lab/fixtures; lab/check run 2026-10-10): 3-of-4 single path and multipath, 2-of-4 multipath, sh(wsh()) 2-of-4 multipath: "TEXT ONLY" and "QR ONLY"; 2-of-5 single path: "Too Large"
  - [ ] Bare xpub of a multisig cosigner (lab/fixtures/cosigner-a-ms-xpub.txt): engraved key string differs from the one sent; lab/check predicts pkh(xpub6Bs7JjzNpKcx...)#ut3ln8pa
  - [ ] Bare single-sig account xpub (lab/fixtures/cosigner-a-xpub.txt): same key string engraved, inside pkh(); lab/check predicts #pgykunhp
  - [ ] Bare zpub of Demo A m/84'/0'/0' (zpub6rFR7y4Q2AijBEqTUquhVz398htDFrtymD9xYYfG1m4wAcvPhXNfE3EfH1r1ADqtfSdVCToUG868RvUUkgDKf31mGDtKsAYz2oz2AGutZYs): "Segwit (P2WPKH)"; plate text wpkh(xpub6CatWdiZ...)#fnl05fl6 as lab/check predicts
  - [ ] Bare xpub with account number 1 (depth 3, child 1h): engraved key string differs from the one sent, as lab/check predicts
  - [ ] Apostrophe spelling: lab/fixtures/singlesig-wpkh.txt with 84'/0'/0' and checksum #wc3n3van: plate text uses h and checksum #afwvtk2s, as lab/check predicts (SYNTHESIS D apostrophe row, F row 9)
  - [ ] Coldcard import of a plate made from Coldcard-style text (no child path): "Invalid subderivation path - only 0/* or <0;1>/* allowed" (hardware-signers key finding 7)
  - [ ] BlueWallet vault with one custom-path cosigner: wrong origin on the plate (mobile-wallets BlueWallet bench check 3)
  - [ ] Links to descriptor-coldcard, descriptor-desktop-wallets and descriptor-mobile-wallets added to #tags and #wallets 2026-10-10 while those pages are wave-2 drafts; recheck the titles and anchors when wave 2 is final (descriptor-mobile-wallets links back to #wallets, so keep that anchor)
  - [ ] Typing X as the first letter on "Input Words": freeze or restart (once, off camera)
  - [ ] Single-key tr() descriptor (lab/check/testdata/tr-singlekey.txt): "Taproot (P2TR)", engraved plate, read back by a wallet
  - [ ] Seed plate: SeedQR is the standard numeric form; 24-word layout as on titles-and-plate-layout#seed (no longer restated here)
  - [ ] Seed plate sizes: #plates gives fingerprint 3.0 mm and words 4.1 mm (research/device-screen-map.md section 3, backup/backup.go:89-91); titles-and-plate-layout#seed gives fingerprint 2.0 mm and words 2.7 mm on a 4.1 mm line; measure an engraved plate with a ruler and correct the page that is wrong
  - [ ] Sparrow descriptor with ?bh= : "Unknown format"; same text trimmed at "?" with no line break: accepted
  - [ ] URI record with https prefix carrying a descriptor: "Unknown format"
  - [ ] Payload of 8192 bytes or more (lab/check/testdata/9k.txt via a tag or test rig; a phone cannot send it), then a valid descriptor on the same start screen: "Scan error" sticks until checkmark then back
  - [ ] Electrum seed (lab/check/testdata/electrum-seed.txt) typed: "Invalid Seed" / "Electrum seeds are not supported."
  - [ ] Bare xpub of a native segwit account: "Legacy (P2PKH)"; zpub: "Segwit (P2WPKH)"; ypub: "Unknown format"
  - [ ] 20 V 3 A (60 W) PD supply: boots and engraves, or "engraver: not enough power available" (requirements now give the 5 A buying advice and the 3 A gate as on power-and-first-start#power)
  - [ ] Coldcard Q or Mk4 NFC push of a descriptor to stock v1.4.3 (bench list owned by descriptor-coldcard; #tags says the reader accepts its Type 5 tag, shown as unverified)
  - [ ] Every wallet row in #wallets on a machine (parser-run results only so far)
  - [ ] Confirm v1.4.3 does not relate a seed to a descriptor (harvest F1, F2) if the page ever states it
notes: edit pass 2026-10-10 (manuals/EDIT_BRIEF.md). Every body "Check:" became "(unverified)" in a cell or in parentheses; each one already had its bullet above. Provenance moved here from the body: the page was written from the v1.4.3 firmware source; the no-seed descriptor and xpub flow, single-key tr(), the codex32 handling, the title not engraved and the Coldcard Type 5 tap rest on source readings; the four-key fit limit was measured with the firmware's layout code (lab/check); each #wallets row was rebuilt as the app's source writes it and fed to the v1.4.3 parser on a computer, with labels quoted from the app source at the version named; the desktop writer symptom is owner-reported, and owners attribute it to the machine changing its tag ID every second (cause not confirmed). Deleted as a repeat: the #plates titles bullet (At a glance links Titles). Seed plate: fingerprint (8 hex digits, 3.0 mm) and word size (4.1 mm) stay in #plates; the 24-word layout (words 17 to 20 above the QR, 21 to 24 below) is a link, owned by titles-and-plate-layout#seed, which gives the fingerprint as 2.0 mm (bench check above). Verification fixes 2026-10-10: restored the signer line in #formats (the top alert names no signer) and the seed plate sizes; the desktop writer row again says the writer beeps; "Too Large" moved to the "Engrave Descriptor" row, since it replaces "Choose engraving" (device-screen-map 1.5); the Type 4 and Type 3 row is "(unverified)" like its bench check; seed-entry steps in #input shortened, owned by seed-entry. Anchors kept: summary, requirements, hardware, input, formats, scripts, screens, plates, shares, tags, wallets, troubleshooting (other pages link formats, scripts, shares, tags, wallets).
sources: manuals/REVIEW-wave1.md sections 2 to 4 (harmonized: fit table, troubleshooting and plate bullets replaced by links, bare keys as a table, status line position dropped; see manuals/HARMONIZE-wave1.md); research/BRIEF.md (incl. "SETTLED BY CODE" fit and bare xpub hazard; its "string is NOT the string the wallet exported" holds only for keys at another depth or account and for zpubs, per lab/check RESULTS notes 4 to 6), research/device-screen-map.md (sections 0 to 3, 5, 6), research/desktop-wallets.md (key finding 1, 1.2), research/mobile-wallets.md (sections 1 to 4, 7), research/hardware-signers.md (key finding 7), research/nfc-tools-transfer.md (sections 0, 5, 6, 7), lab/check (README.md, RESULTS.md, facts at ea4b65b; check -v runs 2026-10-10 on cosigner-a-xpub.txt, cosigner-a-ms-xpub.txt and on zpub, account-1, apostrophe, 3-of-4, 2-of-4 multipath, sh(wsh()) 2-of-4 and 2-of-5 payloads built from TESTWALLET keys), lab/fixtures, lab/TESTWALLET.md, harvest Q11 Q15 Q16 Q20 Q32 (also Q13 Q21 Q22 Q24 Q27 Q31 Q40), SYNTHESIS D rows on unknown format, freeze, desktop writer, card not read, phone write error, engraved checksum differs; SYNTHESIS F rows 4, 7, 9, 11, 12, 16, 17, 18, 19
-->
