Setup an airgapped hardware wallet with QR codes
Prerequistes
This guide explains how to setup an airgapped hardware wallet with Sparrow using QR codes to create a secure Bitcoin storage solution. An airgapped hardware wallet is never connected to your computer - instead, data is exchanged by scanning QR codes. Because Sparrow will need to scan QR codes displayed on the device, your computer will need a webcam. If you would rather connect your hardware wallet with a USB cable, see the Setup a connected hardware wallet guide, and if your device signs transactions using an SD card, see the Setup an airgapped hardware wallet with SD cards guide.
We will be using a Passport in this guide, but the process is very similar for all hardware wallets that can sign transactions via QR codes - Sparrow supports the Coldcard, Keystone, Passport, Blockstream Jade, SeedSigner, Specter DIY, Krux, Keycard Shell and ERA Wallet. Note that only the Coldcard Q can communicate over QR codes, but if you are using this device, you MUST check and upgrade your firmware first.
Sparrow communicates with all of these devices using standard formats, so whichever device you have, you should be able to follow along. If you haven’t read the Quick Start guide yet, that’s a good place to learn how to install and get introduced to Sparrow.
Why use a hardware wallet?
If you’ve followed the Quick Start guide, you will already have Sparrow running with a software wallet. This is a good place to start getting familiar with sending and receiving Bitcoin transactions, and is a reasonable option to store small amounts. If your balance starts to grow however (to the point where you would care about losing it), then it’s time to consider purchasing a hardware wallet.
Hardware wallets offer something that software wallets cannot - they are simple devices that store your private keys and sign transactions, but otherwise have very limited connectivity and functionality. This is a good thing, because it means they are very difficult to hack! In a connected world of viruses and other malware, hardware wallets represent a major improvement in securing your Bitcoin.
Why QR codes?
There are two ways to use an airgapped hardware wallet with Sparrow - moving files back and forth on an SD card, or scanning QR codes. QR codes have a transparency advantage: the only data that can be transferred is what is displayed on the screens. This makes it very difficult for malware to smuggle any other data between the device and your computer, in either direction. They are also convenient - there are no cards to shuffle back and forth, and nothing is ever plugged into either the device or your computer.
Larger amounts of data (like a transaction) are displayed as an animated sequence of QR codes. This means both sides need to be able to scan - the device uses its built-in camera, and Sparrow uses the webcam on your computer.
Why Passport?
There are many hardware wallets available to purchase. The Passport is a good choice because it:
- Runs fully open source firmware that anyone can inspect
- Has a large colour screen and a good camera, which makes QR scanning quick and reliable
- Contains a good set of privacy and security related features
It is worth noting however that other choices are also reasonable, and in fact it is preferable when setting up a multisig wallet to use multiple vendors. As mentioned above, this guide applies generally to all QR-capable hardware wallets - the SeedSigner, Krux and Specter DIY in particular are popular low cost options that you can build yourself.
Ordering and receiving
The Passport should be ordered from the Foundation store only, and not third party resellers. The same advice applies to any hardware wallet vendor - buying direct removes the chance of receiving a device that has been tampered with along the way. Ideally, have it shipped to an address that is not your home - but don’t let this be a reason for not buying one!
Once you have received your Passport, examine the packaging for tampering before opening it. Check that the tamper-evident seals are intact and undamaged - your vendor’s site will describe what to look for on your particular model. If you’re confident the package has not been tampered with, you can open it and proceed to setting up the device.
Setting up your Passport
Before Sparrow can use your Passport, the device needs to be initialized - that is, create a new wallet seed and set a PIN. Unlike a connected hardware wallet, this is all done on the device itself - it never needs to be plugged into your computer. Passport models are battery powered - charge or insert batteries as described in the vendor’s instructions, and if charging over USB use a wall charger or battery pack rather than your computer for an airgapped setup. Other devices are powered differently, so follow the setup instructions for your particular device.
When you power on the Passport for the first time, it will guide you through Supply Chain Validation, which confirms the device is genuine and has not been tampered with. This is a challenge and response process between the secure element in the device and the Foundation website at validate.foundation.xyz. If validation fails, don’t use the device - contact Foundation support. Other vendors check authenticity in other ways, so follow the setup guidance for your particular device.
You will then be asked to select a PIN. Similar to a phone passcode, this PIN is an important defense against others using the device to sign transactions and steal your Bitcoin. Choose a PIN that others cannot easily guess, and that you can remember - if you forget your PIN, you cannot regain access to your Passport.
Next, select Create New Seed.
The device will generate a unique, long random number, which is the seed for your wallet.
The Passport will then prompt you to back up the seed.
Every vendor has a slightly different process to do this - some devices encode the seed into a set of words displayed on the device screen.
If your device asks you to write down these words, you should do so carefully on paper only (or even better, on a metal plate).
These words (or the backup you have created) are the key to your wallet - anyone who has them can steal your Bitcoin! Unless you know what you’re doing, you should NEVER enter these words anywhere but another hardware wallet. In particular, never type them into your computer - a legitimate application will never ask you to. Store the words in the most secure place you can think of, and consider making another copy for a second location in case of fire etc.
Congratulations! Your Passport is now ready.
Importing your Passport into Sparrow
Although your Passport is great at keeping your seed secure, it can’t create a transaction or display your balance. For that, you need Sparrow. Importing your Passport into Sparrow means importing the public key details into Sparrow so it can display your balance and addresses, and send and receive transactions to your wallet.
The difference between public and private keys is beyond the scope of this guide, but know that someone who has your public key can see your wallet transactions, but can’t steal your funds. The Passport will never export your private key.
Since we are doing an airgapped setup, we’re going to use QR codes to transfer the public key details from the Passport.
On the Passport, select the account, then Connect Wallet > Sparrow > Connect as Single Sig.
Other devices have a similar option to connect or pair with a software wallet.
The device will display an animated QR code containing the public key details for the wallet.
In Sparrow, from the menu select File > New Wallet and choose a name for your wallet. You will now see the Sparrow wallet Settings screen. You can leave all of the fields on the defaults and select ‘Airgapped Hardware Wallet’ from the four buttons below.

You will see a list of different import options for various hardware wallets. Look for the Passport option and select ‘Scan…’. (Note clicking on the ‘Details’ link will display the instructions for showing the QR code on the device, which we did earlier.)

Sparrow will open a dialog showing the view from your webcam. Hold the Passport up to the webcam so that the QR code on its screen is visible - you will see the progress indicator fill as Sparrow reads the animated QR code. Sparrow will read the QR code and import the Passport’s public key details:

You can now click ‘Apply’ at the bottom. You should choose a good password to protect the wallet file - even though the Passport is protecting your funds from being stolen, a password on the Sparrow wallet protects your privacy. If Sparrow is connected it will look for any transactions, but since this is a new wallet there won’t be any.
Congratulations! Setup is complete and your wallet is ready to receive bitcoin.
Receiving Bitcoin
In Sparrow, using the blue menu on the left select ‘Receive’. The address field will display the first receive address in your wallet:

This is where a QR-capable hardware wallet shines - you can verify the address on the device itself.
On the Passport, select your account and choose Verify Address, then scan the QR code Sparrow is displaying with the device camera.
The device will search its addresses and confirm the address belongs to your wallet.
This confirms the address really belongs to your hardware wallet, and protects you against malware that could alter the address shown on your computer screen.
You can now receive to this address, for example from an exchange. Once the exchange has sent the funds, you will see a new transaction in the Transactions screen (top button on blue menu) in Sparrow. Generally you should wait for at least one confirmation of this transaction (about 10-30 minutes) before you can send bitcoin from this wallet. However, if you are sending to yourself, you can send a transaction immediately.
Sending Bitcoin
Once your wallet has funds, you can send from it. To do this, go to the Send screen and enter the destination address, the label and the amount. Note that you can use an address from this wallet (send to yourself) using the drop-down arrow on the right in the address field. You can then click ‘Create Transaction’. This will open up the transaction editor with your new transaction, where you can inspect the inputs and outputs. For now though, we are going to practice signing with the Passport.
Click the large blue ‘Finalize Transaction for Signing’ button. You will now see the Signatures area, which shows the progress of signing the transaction. Because we are using the Passport in an airgapped manner, we will be doing the signing via QR codes. Click the ‘Show QR’ button, and Sparrow will display the transaction as an animated sequence of QR codes:

On the Passport, select the QR code button (or Sign with QR Code on other devices) and scan the animated QR code on your computer screen with the device camera.
The device will read the transaction and present the details to you on its screen.
It’s important to verify these details are correct on the device screen, not just in Sparrow. Check that the address and amount matches. You can select from the Outputs tree on the left in the Sparrow transaction editor to view these details. This check is the whole reason your hardware wallet has a screen - even if your computer were compromised, the device shows you what you are really signing.
Once you’re satisfied, confirm the transaction on the device. The Passport will sign the transaction and display the signed transaction as another animated QR code. In Sparrow, click the ‘Scan QR’ button and hold the device up to your webcam, just as you did when importing the wallet. Sparrow will read the signature, and the signatures progress bar will fill to indicate the transaction is now signed!
To send the transaction, click ‘Broadcast Transaction’. Your transaction will be broadcast to the Bitcoin network, and hopefully be confirmed into the blockchain shortly.
Congratulations! You now have a secure Bitcoin storage solution, and can send and receive from it. Keep your device firmware up to date to take advantage of all its features, and keep your seed backup in a safe place - it will make sure you don’t need to worry about loss of funds!
Bonus: Adding an account
You can now add an account to your wallet, which is in effect creating a second Bitcoin wallet based on the same seed but a different derivation path. A second account allows you to segregate funds (for example KYC and non-KYC funds) which ensures that differently sourced UTXOs are not linked when spending. You can also use accounts to segregate funds intended for different purposes.
To add an Account, go to the Settings tab in Sparrow and click Add Account… at the bottom. You will be able to select from multiple different accounts - for now, select Account #1.

Sparrow will then add a row of tabs on the left. The wallet account you have recently configured will be labelled Deposit, and the new wallet account is Account #1.
You need to import the public key details for the new account from the device.
On the Passport, first create the account by selecting Create Account from the Accounts menu and choosing 1 under Advanced Options.
Then navigate to the new account and select Connect Wallet > Sparrow > Connect as Single Sig as before.
Click ‘Airgapped Hardware Wallet’ from the four buttons in Sparrow and scan the QR code again.
You can then click Apply, and your second account is ready for use!