07 · Plebum Dominium
Build the 2-of-3
Sparrow 2.5.5. One seed per boot. Then the wallet, with no seed loaded.
Offline signing on your Tails USB. Networking stays disabled the entire session. The file on the clean data USB must be Sparrow 2.5.5, named sparrowwallet-2.5.5-x86_64.tar.gz. That is the Linux file. The Windows installer and the Mac installer do not belong on that USB. Verify the hash and the signature on the online computer first. Do not download Sparrow from inside Tails.
The terminal is not a test
You will type a few lines that are printed here. In Tails: top-left Applications menu → Terminal. You will see something like amnesia@amnesia:~$. The computer printed that. You type after it. Press Enter. Wait for that prompt to come back before the next line.
- Type the line exactly. Spaces count.
- Do not skip the ./ in front of Sparrow.
- Zero and the letter O are not the same. Lowercase L and the number 1 are not the same.
- If the next line is red or says “No such file”, stop. Do not invent a fix.
- Backspace is allowed. These lines cannot break Tails.
Launch Sparrow offline
- 01 · Boot Tails offline. Networking to Disabled. Start Tails.
- 02 · Copy the archive from the data USB to the Desktop.
- 03 · Open Terminal. Type these four lines, one at a time, Enter after each:
$ cd ~/Desktop$ tar -xvf sparrowwallet-2.5.5-x86_64.tar.gz$ cd Sparrow$ ./bin/Sparrow
Wait 15–30 seconds. A Sparrow window should open. If it does, you are done with the terminal for this session.
One seed per boot, then the public key
You are not building the vault yet. You are copying one public key per boot. A public key is not the 24 words. It still shows the money later, so it goes on the data USB, not in a photo.
- 01 · Boot with networking off. Launch Sparrow. File → New Wallet.
- 02 · Multi Signature. Native Segwit. 2 of 3. This sets the path. It must read m/48'/0'/0'/2'. If it shows anything else, stop. Do not type a different path.
- 03 · Keystore 1 → New or Imported Software Wallet. Enter the 24 words for this seed only. Confirm the path again.
- 04 · On that keystore, export the xpub. Save it on the data USB as s1-xpub.txt, then s2, then s3. Do not Apply a finished wallet. Close Sparrow. Shut down. Wait for a dark screen.
- 05 · Repeat for Seed 2. Then for Seed 3. Three boots. One seed each. Never continue from the previous boot.
Build the 2-of-3 with no seed loaded
- 01 · Fresh Tails boot. Networking off. Launch Sparrow. Do not type a seed.
- 02 · File → New Wallet. Multi-signature. Native Segwit. 2 of 3.
- 03 · Import the three public keys from the data USB. Confirm the path still reads m/48'/0'/0'/2'.
- 04 · Export the output descriptor to the data USB. This is the wallet map. It watches. It cannot spend. Shut down.
- 05 · On the everyday computer, import that map into Sparrow as watch-only. This computer never holds a seed.
- 06 · Still offline, on a later boot, open the same map in Electrum with one seed. The first addresses must match Sparrow. If they differ, stop.
Sign in the airgap session
- 01 · Import the 2-of-3 wallet from the output descriptor, or restore one software keystore from one seed.
- 02 · File → Open Transaction → From File → select the .psbt.
- 03 · Read destination, amount, change, and fee against your written notes. Then Sign.
- 04 · Export with a new filename such as tx-partial-s1.psbt. Close Sparrow. Shut Tails down fully.
Safety at home
- Keep networking disabled. If it is on, shut down and treat the session as burned.
- Load only one seed at a time. Seed 3 stays boxed unless Seed 1 or 2 is gone.
- Full shutdown before you carry the data USB back to the online computer.
- Do not unlock Persistent Storage on a spend. Restore the one seed into RAM, sign, and shut down. Do not let Electrum keep the wallet on the USB.
- Test the whole path with a small amount before savings touch this wallet.
Next. Practice spend. Dust only. Savings stay where they are until dust has moved both ways.