# Recover a wallet from the plates


**Draft, not yet verified on hardware.**

Rebuild a wallet from plates engraved on firmware v1.4.3 or older: the descriptor goes into a coordinator wallet as watch-only, and each seed plate into a signing device, checked by fingerprint. The machine is not needed; it keeps nothing and has no camera.

<p class="alert alert-warning">Seed words and a seed plate's QR code go only into a signing device, never through a phone, a computer, their cameras or a chat assistant.</p>

## What you need {#requirements}

- The descriptor, as text, QR code or both, often on the back of each seed plate: look at both faces. A descriptor is not a secret and cannot spend, but it reveals every address and balance of the wallet.
- The seed plates the quorum needs (two for a 2-of-3, one for single-sig) and one signing device per plate.
- A coordinator wallet that imports descriptors, for example Sparrow on a computer. Specter **Add wallet** > **Import from wallet software** and BlueWallet **Add Wallet** > **Vault** > **Import wallet** take one too (unverified).
- The owner's note of the wallet's first receive addresses, if there is one.
- For scanning: a soft pencil, a cloth, and a lamp you can move.

## Read the plates {#read}

| Plate | What firmware v1.4.3 engraves |
| --- | --- |
| Seed | The master fingerprint of the seed without a passphrase, 8 capitals, above the words. Numbered words in capitals: 12 in one column; for 24, 1 to 16 on the left, 17 to 20 above the QR code, 21 to 24 below. A SeedQR, standard numeric form (unverified). [Layout](/doc/manual/titles-and-plate-layout#seed) |
| Descriptor | Text: the full descriptor, each key with its origin in brackets (`[73c5da0a/48h/0h/0h/2h]xpub...`), its child path (`/<0;1>/*`), and an 8-character checksum after `#`. The line breaks are not part of it. QR code: the same descriptor without the checksum. Multisig is always `sortedmulti`, which Sparrow requires. Only a single-sig descriptor has text and QR code on one face; older plates may have both. |
| Wallet name | None. A title shows only on screen ([titles](/doc/manual/titles-and-plate-layout#titles)). |

![A seed plate and a descriptor plate from the demo wallet](/static/img/recovery-from-plates-01.webp)
<!-- capture: photo, two plates engraved on v1.4.3 from lab/TESTWALLET.md: Demo A seed plate (12 words, fingerprint 73C5DA0A) and the Demo 2of3 descriptor plate from lab/fixtures/2of3-multipath.txt in "TEXT ONLY", flat on a table, diffuse light, callouts on the fingerprint, the word column, the SeedQR, the origin bracket [73c5da0a/48h/0h/0h/2h], one child path /<0;1>/* and the checksum #spmyt389 -->

## Scan the QR code {#scan}

- Clean and dry the plate. Light it softly from one side and tilt it until the reflections are gone.
- Rub a soft pencil over the code and wipe once, or fill it with black marker. Graphite has made one plate worse.
- Fixed-focus cameras, such as the stock SeedSigner's, struggle. A Coldcard Q reads plate codes (unverified).
- BlueWallet reads plate codes more easily on iOS than on Android, probably through another QR library. On Android, use another scanner.
- A phone's camera app reads codes well but is online. Use it for the descriptor only if you accept that privacy risk.
- If the code still does not read, type the text.

## Import the descriptor into Sparrow {#import}

- Create a new wallet and open its **Settings** tab.
- At the **Descriptor:** field, click **Edit...**.
- Paste or type the descriptor: one line, no spaces, every bracket, slash, `h`, `<0;1>`, `*` and the `#` checksum.
- To scan the plate instead, use the scan button beside the field.
- Click **Apply**. If it refuses the text, look for one misread character: the checksum catches typing mistakes (BIP380).
- For a multisig, Sparrow then shows "Backup Multisig Wallet?" with "Save PDF..." and "Close". Click **Close**.
- Compare the first receive addresses with the owner's note. Without one, the fingerprint check under [Restore the signers](#signers) is the test.

![Sparrow Settings tab with the descriptor from the plate](/static/img/recovery-from-plates-02.webp)
<!-- capture: desktop, Sparrow 2.5.5 in lab/sparrow, new wallet "Demo 2of3", Settings tab after Edit... with lab/fixtures/2of3-multipath.txt pasted, before Apply -->

## Restore the signers {#signers}

- Type the words of one seed plate into a signing device's restore function in the plate's numbered order, or scan its SeedQR with the signing device.
- Compare the signer's fingerprint with the seed plate and with one bracketed fingerprint in the descriptor.
- Repeat for each seed plate the quorum needs.

## Plates from older firmware {#old-plates}

Up to v1.4.2 the descriptor QR code left out the master fingerprints and the origin paths before each key; like v1.4.3, it carried no checksum. The addresses are the same.

- Scan the QR code into Sparrow as above. **Apply** stays disabled: the keys have no fingerprint or path.
- For each key, type `00000000` as the fingerprint and the key's path, usually `m/48h/0h/0h/2h` for a native segwit multisig key (BIP48). That is enough to watch the wallet.
- To sign, enter the real fingerprints. Passport Core and Keycard Shell refuse placeholders (unverified).
- Before engraving a new plate on v1.4.3, replace every `00000000` with the real fingerprint, or that key loses its origin. Prepare the export as in [Prepare the text](/doc/manual/nfc-tools-transfer#prepare).

![Sparrow keystore with a typed fingerprint and path](/static/img/recovery-from-plates-03.webp)
<!-- capture: desktop, Sparrow 2.5.5 in lab/sparrow, wallet imported from lab/fixtures/2of3-multipath.txt with every [..] origin and the #checksum removed (a v1.4.2-style QR payload), keystore of Demo A with fingerprint 73c5da0a and path m/48'/0'/0'/2' typed, Apply enabled -->

## Rehearse the restore {#rehearse}

- On testnet, engrave a practice wallet, recover it from its plates and sign a test transaction. "Type" shows "(testnet)".
- With the real plates, restore the signers on spare devices, import the descriptor, compare fingerprints and first receive addresses, and sign a transaction without broadcasting it.
- Keep a note of the first addresses with the plates. Destroy any paper copy of the descriptor made for the drill; it risks only privacy.
- Once a year, check that every plate is readable and that each signer still shows the fingerprint on its seed plate.
- Keep copies of the wallet software you rely on, in the versions that worked in the drill.

## If it does not work {#troubleshooting}

| Symptom | Cause | Fix |
| --- | --- | --- |
| The wallet cannot read the QR code. | Low contrast on steel. | See [Scan the QR code](#scan), or type the text. |
| The import fails or the wallet stays empty. | The wallet is set to another script or quorum. | Match the plate: `wsh(` is native segwit, `sh(wsh(` nested, `sh(sortedmulti(` legacy; the number after `sortedmulti(` is the quorum. |
| The plate's text or checksum differs from the wallet's export. | v1.4.3 writes `h` for `'` and leaves the checksum out of the QR code; some exports carry no child path ([why](/doc/manual/multisig-and-fit#differences)); or the plate is older. | Compare first receive addresses. |
| Restored signers refuse to sign, or Sparrow will not save a wallet from an old QR code. | Fingerprints and paths are missing or placeholders. | See [Plates from older firmware](#old-plates). |
| The signer rejects the words, or its fingerprint does not match the seed plate or the descriptor. | A word misread or out of order (on 24-word plates, 17 to 20 sit above the QR); the plate is from another wallet; or the wallet used a passphrase kept elsewhere. | Read the words again in numbered order. If they are right, enter the wallet's passphrase, or use this wallet's seed plate. |
| Change or older payments are missing. | The plate holds `/0/*` only, or no child path. | Type the descriptor with `/<0;1>/*` on every key and no checksum (unverified). |

<!--
bench-checks:
  - [ ] Scan a v1.4.3 descriptor QR (Demo 2of3, "QR ONLY") with Sparrow webcam, BlueWallet on iOS and Android, SeedSigner and Coldcard Q: plain, with side light and tilt, with graphite, with marker fill; rank the remedies and rewrite the scan list (SYNTHESIS F row 5). The #scan list is unranked, from mixed harvest results: graphite helped some plates and made one worse; Coldcard Q reading plate codes and BlueWallet iOS reading more easily than Android are owner reports
  - [ ] Restore a 2-of-3 in Sparrow by typing the text plate and sign a testnet PSBT with restored signers; Sparrow imports the v1.4.3 QR payload (no checksum) and derives the same first addresses as the text plate; text typed with one wrong character is refused (record the message). Which common signers need the multisig registered before signing for a restored wallet (no body step until settled). Sparrow 2.5.5 restore path: new-wallet menu label, "Settings" tab, "Descriptor:" field, "Edit...", label of the scan button, "Apply"; "Backup Multisig Wallet?" after Apply for an imported descriptor; label of the addresses tab; keystore fingerprint and derivation field labels; message when Apply stays disabled
  - [ ] Restore from a v1.4.2 stripped QR, enter real fingerprints, and sign; also 00000000 with a path other than the key's real one: are the addresses still right? (Q50 says an explicit path per key is needed); re-engrave on v1.4.3 a descriptor holding a 00000000 fingerprint: that key's origin is left out (bip380/bip380.go:226). Passport Core and Keycard Shell refuse to sign with 00000000 placeholders (SYNTHESIS D, signers refuse placeholders; body says "(unverified)"). Pre-v1.4.3 text plates: origins kept or stripped, not settled (diff v1.4.2 against v1.4.3 text layout, SYNTHESIS F row 9); which quorums fit text and QR code on one face on v1.4.2 (SYNTHESIS F row 7)
  - [ ] Plate from a Coldcard-format setup file (no child path) and from Specter Desktop JSON (/0/*) imported into Sparrow: which receive and change addresses appear; does the change-row fix (`/<0;1>/*` typed on every key, no checksum) bring back change and older payments (fix from research/desktop-wallets.md row "Output Descriptor, Export File..." and research/mobile-wallets.md DESCRIPTOR_EXTERNAL_INTERNAL: `/<0;1>/*` is receive and change). Specter Desktop "Add wallet" > "Import from wallet software" (labels seen in lab/specter/shots/specter-13-add-wallet-type.png) and BlueWallet "Add Wallet" > "Vault" > "Import wallet" with the plate descriptor, typed and scanned. Descriptor sent with ' engraves with h and a different checksum (source: bip32/bip32.go Path.Encode); same first addresses in Sparrow (SYNTHESIS D says fixed in v1.4.3; source says not). Any titled export (v1.4.3, Demo 2of3 Coldcard text or Specter JSON): does the plate carry the title, or only the screen? (SYNTHESIS F row 11)
  - [ ] Seed plate SeedQR from v1.4.3 read by signers that read SeedQR (list which); decode the Demo A plate QR (public test vector): 48 digits, standard SeedQR, not CompactSeedQR bytes (SYNTHESIS F row 18; the #read table says "(unverified)", from the source; harmonized 2026-10-10); plate fingerprint equals the restored signer's fingerprint and the descriptor origin for Demo A, B and C
sources: manuals/REVIEW-wave1.md sections 2 to 4 (harmonized: old-QR wording from the v1.4.3 release note "The checksum is still stripped", research/hardware-signers.md section 4; see manuals/HARMONIZE-wave1.md); research/device-screen-map.md (1.5 incl. Title line and "(testnet)", 3), research/BRIEF.md (corrections; TEXT ONLY/QR ONLY settled by code; ?bh= annotations), research/desktop-wallets.md (1.1 incl. row E "Backup Multisig Wallet?", 1.2, 1.3, 1.4, 2.2, bench checks), research/mobile-wallets.md (1), lab/TESTWALLET.md, lab/specter/shots/specter-13-add-wallet-type.png ("Add wallet", "Select the type of wallet", "Import from wallet software"), lab/check shcheck run on lab/fixtures (plate text, "TEXT ONLY"/"QR ONLY" for 2-of-3, "TEXT + QR" for single-sig), firmware ea4b65b bip32/bip32.go Path.Encode, bip380/bip380.go:69-88 Script.String and :226 (origin dropped when mfp is 0), backup/backup.go wordColumn and frontSideSeed, gui/gui.go validateDescriptor and :2131-2146, BIP380, BIP48, harvest Q51 Q50 Q52 Q26 (answers) and Q21 Q23 Q27 Q33 Q44 Q47, harvest/HARVEST.md (scanning items: lead wiped out, Coldcard Q reads plate codes, marker and isopropyl, TEAM pencil trick 2025-05-14 and 2025-10-04; wallet-bluewallet TEAM item: zbar vs zxing, phone camera app), SYNTHESIS C 2026-08-03 (no durable writes), SYNTHESIS D (stripped QR, Sparrow stripped import, signers refuse placeholders, SeedSigner steel QR, BlueWallet Android), SYNTHESIS F rows 5, 7, 9, 11 and 18. Edit pass 2026-10-10 (manuals/EDIT_BRIEF.md): #differences, #type and #sparrow headings folded into #read, #import and #troubleshooting (no inbound links; #scan kept, plates.md links it); BlueWallet troubleshooting row folded into #scan; the #signers Important callout folded into its troubleshooting row; body Check: lines folded into the bench items above. Verification fixes 2026-10-10: paste restored in #import (capture 02 pastes); "use another scanner" kept in #scan; missing child path attributed to the export, not v1.4.3
-->
