Recover a wallet from the plates
Read SeedHammer II plates back into a wallet, restore the signers, and rehearse it.
Rebuild a wallet from plates engraved on firmware v1.4.3 or older: the descriptor goes into a coordinator wallet as watch-only, and each seed plate into a signing device, checked by fingerprint. The machine is not needed; it keeps nothing and has no camera.
Seed words and a seed plate's QR code go only into a signing device, never through a phone, a computer, their cameras or a chat assistant.
What you need
- The descriptor, as text, QR code or both, often on the back of each seed plate: look at both faces. A descriptor is not a secret and cannot spend, but it reveals every address and balance of the wallet.
- The seed plates the quorum needs (two for a 2-of-3, one for single-sig) and one signing device per plate.
- A coordinator wallet that imports descriptors, for example Sparrow on a computer. Specter Add wallet > Import from wallet software and BlueWallet Add Wallet > Vault > Import wallet take one too (unverified).
- The owner's note of the wallet's first receive addresses, if there is one.
- For scanning: a soft pencil, a cloth, and a lamp you can move.
Read the plates
| Plate | What firmware v1.4.3 engraves |
|---|---|
| Seed | The master fingerprint of the seed without a passphrase, 8 capitals, above the words. Numbered words in capitals: 12 in one column; for 24, 1 to 16 on the left, 17 to 20 above the QR code, 21 to 24 below. A SeedQR, standard numeric form (unverified). Layout |
| Descriptor | Text: the full descriptor, each key with its origin in brackets ([73c5da0a/48h/0h/0h/2h]xpub...), its child path (/<0;1>/*), and an 8-character checksum after #. The line breaks are not part of it. QR code: the same descriptor without the checksum. Multisig is always sortedmulti, which Sparrow requires. Only a single-sig descriptor has text and QR code on one face; older plates may have both. |
| Wallet name | None. A title shows only on screen (titles). |
Screenshot pending: A seed plate and a descriptor plate from the demo wallet
Scan the QR code
- Clean and dry the plate. Light it softly from one side and tilt it until the reflections are gone.
- Rub a soft pencil over the code and wipe once, or fill it with black marker. Graphite has made one plate worse.
- Fixed-focus cameras, such as the stock SeedSigner's, struggle. A Coldcard Q reads plate codes (unverified).
- BlueWallet reads plate codes more easily on iOS than on Android, probably through another QR library. On Android, use another scanner.
- A phone's camera app reads codes well but is online. Use it for the descriptor only if you accept that privacy risk.
- If the code still does not read, type the text.
Import the descriptor into Sparrow
- Create a new wallet and open its Settings tab.
- At the Descriptor: field, click Edit....
- Paste or type the descriptor: one line, no spaces, every bracket, slash,
h,<0;1>,*and the#checksum. - To scan the plate instead, use the scan button beside the field.
- Click Apply. If it refuses the text, look for one misread character: the checksum catches typing mistakes (BIP380).
- For a multisig, Sparrow then shows "Backup Multisig Wallet?" with "Save PDF..." and "Close". Click Close.
- Compare the first receive addresses with the owner's note. Without one, the fingerprint check under Restore the signers is the test.
Screenshot pending: Sparrow Settings tab with the descriptor from the plate
Restore the signers
- Type the words of one seed plate into a signing device's restore function in the plate's numbered order, or scan its SeedQR with the signing device.
- Compare the signer's fingerprint with the seed plate and with one bracketed fingerprint in the descriptor.
- Repeat for each seed plate the quorum needs.
Plates from older firmware
Up to v1.4.2 the descriptor QR code left out the master fingerprints and the origin paths before each key; like v1.4.3, it carried no checksum. The addresses are the same.
- Scan the QR code into Sparrow as above. Apply stays disabled: the keys have no fingerprint or path.
- For each key, type
00000000as the fingerprint and the key's path, usuallym/48h/0h/0h/2hfor a native segwit multisig key (BIP48). That is enough to watch the wallet. - To sign, enter the real fingerprints. Passport Core and Keycard Shell refuse placeholders (unverified).
- Before engraving a new plate on v1.4.3, replace every
00000000with the real fingerprint, or that key loses its origin. Prepare the export as in Prepare the text.
Screenshot pending: Sparrow keystore with a typed fingerprint and path
Rehearse the restore
- On testnet, engrave a practice wallet, recover it from its plates and sign a test transaction. "Type" shows "(testnet)".
- With the real plates, restore the signers on spare devices, import the descriptor, compare fingerprints and first receive addresses, and sign a transaction without broadcasting it.
- Keep a note of the first addresses with the plates. Destroy any paper copy of the descriptor made for the drill; it risks only privacy.
- Once a year, check that every plate is readable and that each signer still shows the fingerprint on its seed plate.
- Keep copies of the wallet software you rely on, in the versions that worked in the drill.
If it does not work
| Symptom | Cause | Fix |
|---|---|---|
| The wallet cannot read the QR code. | Low contrast on steel. | See Scan the QR code, or type the text. |
| The import fails or the wallet stays empty. | The wallet is set to another script or quorum. | Match the plate: wsh( is native segwit, sh(wsh( nested, sh(sortedmulti( legacy; the number after sortedmulti( is the quorum. |
| The plate's text or checksum differs from the wallet's export. | v1.4.3 writes h for ' and leaves the checksum out of the QR code; some exports carry no child path (why); or the plate is older. |
Compare first receive addresses. |
| Restored signers refuse to sign, or Sparrow will not save a wallet from an old QR code. | Fingerprints and paths are missing or placeholders. | See Plates from older firmware. |
| The signer rejects the words, or its fingerprint does not match the seed plate or the descriptor. | A word misread or out of order (on 24-word plates, 17 to 20 sit above the QR); the plate is from another wallet; or the wallet used a passphrase kept elsewhere. | Read the words again in numbered order. If they are right, enter the wallet's passphrase, or use this wallet's seed plate. |
| Change or older payments are missing. | The plate holds /0/* only, or no child path. |
Type the descriptor with /<0;1>/* on every key and no checksum (unverified). |