# What fits on a plate, and multisig without sharding


**Draft, not yet verified on hardware.**

Back up a multisig wallet on the SH II (stock firmware v1.4.3) as separate jobs: each cosigner seed on its own plate, then the whole descriptor, as text or QR code, on the plates you choose. The machine has no multisig menu and, unlike the original SeedHammer, never splits a descriptor across plates.

<p class="alert alert-warning">Type seed words on the machine only; they never pass through a phone, a computer or a chat assistant.</p>

## What you need {#requirements}

- One blank plate and the written seed words for each cosigner, and a free face for each copy of the descriptor.
- The descriptor as text on a phone with NFC Tools: [NFC Tools transfer](/doc/manual/nfc-tools-transfer), [desktop wallets](/doc/manual/descriptor-desktop-wallets), [phone wallets](/doc/manual/descriptor-mobile-wallets).
- A sorted multisig (`sortedmulti`): P2WSH, P2SH-P2WSH or P2SH. Others give "Unknown format".
- A descriptor string, never a bare key: a bare key loses its script and origin ([why](/doc/manual/capability-sheet#formats)). For P2SH-P2WSH or P2SH, no "Coldcard Export" either: the P2SH-P2WSH one gives "Unknown format", the P2SH one stops the firmware (unverified).

## Plan where the descriptor goes {#plan}

A descriptor is not a secret and cannot spend, but it reveals every address and balance of the wallet. Without it, spending can be blocked, so it goes on steel. Each descriptor job engraves the whole descriptor, unencrypted, on one face. No single plate can spend from a 2-of-3; you choose which plates carry the descriptor:

| Layout | You restore with | One plate found by someone else shows |
| --- | --- | --- |
| Descriptor on the back of every seed plate | any 2 of the 3 plates | one seed, plus every address and balance of the wallet |
| Descriptor on plates of its own, stored apart from the seeds | 2 seed plates and 1 descriptor plate | a seed plate: one seed only; a descriptor plate: every address, no seed |

## Engrave each seed {#seeds}

Engrave each seed as a normal seed job on its own plate: [Enter a seed on the touchscreen](/doc/manual/seed-entry). v1.4.3 has no passphrase screen. The fingerprint above the words is that of the seed without a passphrase, so a passphrase cosigner's plate will not match the descriptor. Store the passphrase some other way.

## Engrave the descriptor {#descriptor}

- Prepare the text: nothing from `?` on, no line break after it ([how](/doc/manual/nfc-tools-transfer#prepare)).
- Bring the machine to "Backup Wallet". It listens for NFC on this screen only.
- In NFC Tools, write the text as a **Text** record, never URL, with the phone flat on the panel right of the display.
- On "Engrave Descriptor", compare **Type** and **Script** with your wallet, such as "2-of-3 multisig".

![Engrave Descriptor for the demo 2-of-3 wallet](/static/img/multisig-and-fit-01.webp)
<!-- capture: II screen, flow "Engrave Descriptor", NFC text lab/fixtures/2of3-multipath.txt, Type "2-of-3 multisig", Script "Segwit (P2WSH)", no Title line (device-screen-map 4.2 row 28 with the 2-of-3 fixture) -->

- Tap the checkmark (bottom right).
- On "Engrave" ("Choose engraving"), tap **TEXT ONLY** or **QR ONLY**, then the checkmark.

![Choose engraving with TEXT ONLY and QR ONLY](/static/img/multisig-and-fit-02.webp)
<!-- capture: II screen, flow "Engrave" / "Choose engraving", same 2-of-3 fixture, TEXT ONLY pre-selected, QR ONLY below (device-screen-map 4.2 row 29) -->

- For the back of a seed plate, turn the plate over (seating face down and damage to the seed face unverified).
- On "Engrave Plate", insert the plate and engrave as in [Load a plate](/doc/manual/power-and-first-start#plate).
- For every further copy, write the descriptor again on "Backup Wallet".

The machine asks for no seed before "Engrave Descriptor" and never compares the descriptor with seeds engraved before (unverified).

## What fits on a plate {#fit}

After the checkmark on "Engrave Descriptor", the machine tries three layouts on one face and offers those that fit: **TEXT + QR**, **TEXT ONLY**, **QR ONLY**. If none fits: "Too Large" and "The descriptor cannot fit any plate size." No title is engraved ([Titles](/doc/manual/titles-and-plate-layout#titles)).

- Text: the rebuilt descriptor with each key's fingerprint and path, and the checksum (`#` and 8 characters).
- QR code: the same descriptor without the checksum, at error correction level L (the lowest).
- Fit is decided on the rebuilt descriptor: removing spaces, line breaks, JSON keys or the checksum changes nothing.
- Fit counts keys and ignores the threshold: a 2-of-5 is as long as a 3-of-5.
- Fit on older firmware does not carry over: the v1.4.3 QR code keeps fingerprints and paths and is larger.

| Wallet, every key with fingerprint and path | Layouts offered (unverified) |
| --- | --- |
| Single-sig (`wpkh`, `pkh`, `tr` with one key) | **TEXT + QR**, **TEXT ONLY**, **QR ONLY** |
| Multisig with 2 to 4 keys (1-of-2, 2-of-3, 2-of-4, 3-of-4) | **TEXT ONLY**, **QR ONLY** |
| Multisig with 5 or more keys (2-of-5, 3-of-5, 3-of-6) | "Too Large" |

Use two faces for both forms of a multisig descriptor. Text is read by eye and its checksum catches a typing mistake; a QR code needs a camera that reads steel ([recovery](/doc/manual/recovery-from-plates)). Demo 2-of-3, before homing: about 11 minutes as **TEXT ONLY**, 39 as **QR ONLY** (unverified).

## Why the plate differs from what you sent {#differences}

- **`h` instead of `'`.** The machine writes hardened steps as `h` (`48h`). Same keys and addresses, but the checksum covers every character, so a descriptor sent with apostrophes (`48'`, as Nunchuk writes) comes back with another checksum (unverified). Descriptor strings from Sparrow, Specter and Coldcard use `h` and come back unchanged (unverified).
- **No `/<0;1>/*` or `/0/*`.** Coldcard-style setup text (Coldcard, BlueWallet vault, Sparrow's Coldcard, Keystone and Passport Multisig exports) and Sparrow's Specter Desktop export carry no child path, so the plate has none. A Coldcard refuses it on import ("Invalid subderivation path - only 0/* or <0;1>/* allowed"); Nunchuk too (unverified). For a Coldcard restore, send a descriptor with `/<0;1>/*` on every key.
- **Plates from v1.4.1 and v1.4.2.** Their QR code left out the master fingerprints and the origin paths before each key; like v1.4.3, it carried no checksum. The addresses are the same. Some hardware signers need the full key origins to sign: [Plates from older firmware](/doc/manual/recovery-from-plates#old-plates).

To check any plate, let your wallet derive the first receive address from the engraved text and compare it.

## If it does not work {#troubleshooting}

| Symptom | Cause | Fix |
| --- | --- | --- |
| "Too Large" / "The descriptor cannot fit any plate size." | Five or more keys with full origins on v1.4.3 ([table](#fit)). Dropping key origins leaves a descriptor some signers refuse. | Engrave the seeds. Keep the descriptor in another durable form. |
| Only **TEXT ONLY** and **QR ONLY** offered | Normal for multisig on v1.4.3. | Use two faces for both. |
| "Unknown format" with a multisig descriptor | Unsorted `multi`, taproot multisig or miniscript; Coldcard-style text with a second `Derivation:` line; `Format: P2SH-P2WSH` (a P2SH-P2WSH "Coldcard Export" or a wrapped BlueWallet vault). | Export a plain descriptor with every key's origin. Every cause: [Troubleshooting](/doc/manual/troubleshooting#nfc). |
| NFC Tools shows an error after the write | The phone moved, or the machine answered late (after more than about 77 ms, while the screen redraws). | Harmless if the machine shows "Engrave Descriptor" ([NFC Tools](/doc/manual/nfc-tools-transfer#troubleshooting)). |
| Fingerprint on a seed plate differs from the descriptor | The cosigner uses a passphrase (the plate carries the fingerprint without it), or the seed belongs to another wallet. | See [Engrave each seed](#seeds). |
| Engraved checksum differs from your wallet's | Your wallet wrote apostrophes ([why](#differences)). | Compare first receive addresses. |

<!--
bench-checks:
  - [ ] layouts offered and where "Too Large" starts on v1.4.3, sortedmulti with full origins (lab/fixtures singlesig-wpkh (wpkh), 2of3-multipath, 2of4-descriptor, 3of5-descriptor, 3of6-descriptor). Body table = v1.4.3 layout code run on the demo wallet's keys (P2WSH, P2SH and P2SH-P2WSH, every key with fingerprint and path), marked unverified. Expected from lab/check/RESULTS.md: single-sig all three; 2-of-3 and 2-of-4 TEXT ONLY and QR ONLY; 3-of-5 and 3-of-6 Too Large. Fix-stage `go run . check` in lab/check (ea4b65b) on descriptors built from the 2of3-descriptor and 3of6-descriptor fixture keys, rows still to be added to RESULTS.md: TEXT ONLY and QR ONLY for 1-of-2 and 2-of-2 P2WSH, 1-of-2 P2SH and P2SH-P2WSH, 2-of-3 P2SH and P2SH-P2WSH, 3-of-4 (`/0/*` QR v16 72.9 mm, `/<0;1>/*` QR v17 76.5 mm), 2-of-4 P2SH and P2SH-P2WSH multipath (QR v17); Too Large for 2-of-5, 3-of-5, 4-of-5 P2WSH (723 bytes each) and 3-of-5 P2SH (722). Without origins: 1-of-2 P2WSH gets TEXT + QR (QR v10, 51.3 mm), 2-of-3 and 3-of-5 get TEXT ONLY and QR ONLY (the page does not advise dropping origins). This page owns the fit table (capability-sheet keeps only its At-a-glance row; harmonized 2026-10-10)
  - [ ] descriptor-only flow on v1.4.3: no seed requested before "Engrave Descriptor" (SYNTHESIS F16; v1.4.3 source goes straight from "Backup Wallet" to "Engrave Descriptor")
  - [ ] engraved text versus sent text, checksum included, for the apostrophe and h spellings. Fix-stage `go run . check -v` in lab/check: an apostrophe copy of lab/fixtures/2of3-multipath.txt carries BIP380 checksum #77c3yrpe and is engraved with `h` and #spmyt389; the fixture itself (h) goes in and comes out unchanged as #spmyt389
  - [ ] text layout of v1.4.1 and v1.4.2 (SYNTHESIS F9), moved off the page: was the text shortened too? `git grep EncodeCompact v1.4.1 v1.4.2 -- gui/gui.go` shows `qr.Encode(desc.EncodeCompact(), qr.L)` at both tags, with text `desc.Encode()`; `git diff v1.4.2 v1.4.3 -- bip380/bip380.go` shows v1.4.2 `Encode()` already kept origins and the checksum. ea4b65b changed the QR only. Confirm on a v1.4.2 plate. Old-QR wording harmonized 2026-10-10 from the v1.4.3 release note ("The checksum is still stripped"): fingerprints and origin paths left out, no checksum in any version's QR
  - [ ] no seed-to-descriptor match check on v1.4.3 (SYNTHESIS F1, F2): engrave a seed, then a descriptor that does not contain it
  - [ ] descriptor on the back of an engraved seed plate: plate seats flat in the lock face down, seed face unharmed, which face to engrave first
  - [ ] QR ONLY on one face and TEXT ONLY on the other of a descriptor-only plate
  - [ ] "Type" reads "2-of-3 multisig" and "Script" "Segwit (P2WSH)" for the demo wallet; no Title line for the plain descriptor
  - [ ] engraving time of TEXT ONLY and QR ONLY for the demo 2-of-3: `shcheck check -v` plans 10m58s and 39m27s without homing; page says about 11 and 39 minutes, marked unverified
  - [ ] plate without child path: Sparrow and the reader's other wallets restore the same first receive address; Coldcard import refuses it ("Invalid subderivation path - only 0/* or <0;1>/* allowed", hardware-signers key finding 7); Nunchuk "Recover via QR code" refuses it (hardware-signers section 4, libnunchuk, "likely refused"; page says "Nunchuk too (unverified)")
  - [ ] P2SH (BIP-45) "Coldcard Export" with no `Format:` line: source predicts a panic in Encode (hardware-signers key finding 6, case M3); page says "stops the firmware (unverified)"; bench with care
  - [ ] P2SH-P2WSH "Coldcard Export" and wrapped BlueWallet vault (`Format: P2SH-P2WSH`): "Unknown format" (hardware-signers key finding 3, case M2; mobile-wallets BlueWallet table)
  - [ ] bare `xpub` over NFC: "Engrave Descriptor" shows "Singlesig" and "Legacy (P2PKH)", plate string differs from the export (lab/check/RESULTS.md notes 2 to 6; owner capability-sheet#formats)
  - [ ] passphrase cosigner: seed plate fingerprint is the no-passphrase one and differs from the descriptor
  - [ ] NFC Tools end-of-write error with the 2-of-4 fixture from iPhone and Android (statement owned by nfc-tools-transfer#troubleshooting; here one troubleshooting row)
  - [ ] X as first letter on "Input Words": freeze or restart (shared with seed-entry)
  - [ ] unsourced, kept off the page: what recovering a multisig without its descriptor takes (every cosigner key, threshold, script, paths, sorted or not); needs a note before the page says more than SYNTHESIS Q47
notes: the seedhammer.com partitioning articles describe the original SeedHammer, not the SH II (removed from #plan in the 2026-10-10 condensing pass; the lead keeps "unlike the original SeedHammer"). HARMONIZE-wave1 row 14 points to #descriptor for the seed-to-descriptor statement.
sources: research/BRIEF.md (device facts, corrections, SETTLED BY CODE, bare xpub hazard, write-error bench fact), research/device-screen-map.md (1.2, 1.3, 1.4, 1.5, 1.7, 2, 3, 4.2, 5.6), research/desktop-wallets.md (key findings, 1.2, 1.3, 1.4 X2, 2.2), research/mobile-wallets.md (parser notes, BlueWallet vault formats, Nunchuk apostrophe origins), research/hardware-signers.md (key findings 3, 5, 6, 7; 1.5 export map; section 4 recovery table and v1.4.3 release-note quote "The checksum is still stripped"), research/nfc-tools-transfer.md (section 6 "Too Large" row, v1.4.3 release note quote), lab/TESTWALLET.md, lab/fixtures, lab/check/RESULTS.md, firmware gui/gui.go DescriptorScreen.Draw ("%d-of-%d multisig") and validateDescriptor at v1.4.1, v1.4.2, v1.4.3, bip380/bip380.go Derivation.Encode and Encode at v1.4.2 and v1.4.3, harvest Q16 Q21 Q22 Q23 Q24 Q25 Q26 Q28 (also Q27 Q47 Q50), SYNTHESIS D (Too Large 3-of-5, stripped QR, checksum differs, phone write error, Unknown format), SYNTHESIS F 1 2 3 7 9 15 16 17 20, manuals/REVIEW-wave1.md sections 2 to 4 (harmonized, see manuals/HARMONIZE-wave1.md)
-->
