# How to Set up Secure, Air-gapped Bitcoin Multisig with Bitcoin Core Read [START_HERE.md](START_HERE.md) first. Advisors: [CONTEXT_FOR_ADVISORS.md](CONTEXT_FOR_ADVISORS.md). Design: [FAQ.md](FAQ.md) and [THREAT_MODEL.md](THREAT_MODEL.md). ## Introduction The latest version of this guide lives at https://github.com/bowlarbear/yeti-2.0 Guide Version: 1.34 This guide was created using Bitcoin Core's [official multisig-tutorial](https://github.com/bitcoin/bitcoin/blob/master/doc/multisig-tutorial.md) and [offline signing tutorial](https://github.com/bitcoin/bitcoin/blob/master/doc/offline-signing-tutorial.md) as a reference. Users can verify the scripts found in Yeti-2.0 by comparing them to the scripts provided in the official Bitcoin Core multisig tutorial. We have intentionally avoided adding complexity to or deviating from the official scripts, so a reader can check our commands against Bitcoin Core's own tutorials. Our design goal is to turn Bitcoin Core’s official multisig and offline-signing docs into one start-to-finish procedure: a full archival node, a 3-of-7 multisig vault, full wallet and key backups, and an air-gapped signing workflow. This guide functions both as an educational tool and a successor to [YetiCold Level 3](https://github.com/jwweatherman/yeticold). See the [FAQ](FAQ.md) for answers to common questions about the design. This multisig vault is only appropriate for storing between $10k-$5M in Bitcoin. Note: This guide previously recommended Milenniata M-discs but due to user complaints of difficulty sourcing authentic milleniata M-Discs, we've decided to recommend Verbatim brand Ultralife Gold Archival grade DVDs instead. ## You will need: - 2 Dedicated Laptops (8GB RAM minimum) (try refurbished ThinkPads) (Chromebooks will not work) - 2 Fresh USB sticks (16GB minimum) (try Kingston DataTravelers 64GB) - 7 Verbatim brand Ultralife Gold Archival grade DVDs 4.7GB - 1 USB powered disc drive capable of writing DVDs (try ASUS ZenDrive) - 1 2TB SATA SSD 2.5 inch internal Hard Drive (will last you for approximately 10 years of full archival node storage as of Aug 2026 before requiring an upgrade) estimated total cost (using Amazon for reference as of 11 Aug 2026): ~$750 # A. Initial Setup These two laptops should be dedicated for use with Bitcoin Core ONLY. DO NOT use these two dedicated laptops for any other purpose or software than what is described in this guide. Pick one laptop to be the online computer, this will be the Bitcoin node. You will need to replace the internal SATA storage drive on this laptop with your 2TB SATA SSD. This process is not difficult, however it will usually require removing the screws on the bottom cover of the laptop. [The exact process will vary depending on the exact model of laptop you purchased](upgrade_node_storage.md). There should only be one internal storage drive inside of your online laptop. If the online laptop also contains an NVMe drive, you should remove it while you are replacing the SATA drive. You may use a 2TB NVMe drive if your laptop supports the form factor (these are more expensive than SATA drives), but in that case ensure you also remove the SATA drive if one is present. ## Step A1. [online computer] Install Ubuntu After upgrading the internal storage, we need to install Ubuntu on this computer. [Download the latest version of Ubuntu here](https://ubuntu.com/download/desktop) You will most likely need the Intel or AMD 64-bit architecture, download the latest version (26.04.1 as of the latest update to this guide). You should [verify the Ubuntu download](verify_ubuntu.md) before creating the installer. Grab one of the fresh USB sticks and mark it with a sticker or a piece of tape. This will be the Linux USB, and it needs to be flashed with the Ubuntu installer. If you are on Windows you can download an app called [Rufus](https://rufus.ie) and use that to create the live installer. MacOS users can download an app called [balenaEtcher](https://github.com/balena-io/etcher/releases). If you know how to use dd and you already have access to a terminal this is the best way because it does not rely on a third party dependency. Be careful that you flash the correct drive if you use dd, it's colloquially called "disk destroyer" for a reason. Once you have the Linux USB ready, the next step will be to install Linux on the online computer. Doing this requires turning off the computer, inserting the Linux USB (USB with tape) into the online computer and turning the power back on. If this doesn't work on the first try, you might need to change the boot order within the BIOS. After the Ubuntu splash screen select `Install Ubuntu`. During installation, simply proceed with all of the default settings, when you reach the "Disk Setup" screen select "Erase disk and install Ubuntu". When you reach the "Encryption and File System" screen select "Encrypt with a passphrase". Choose a password for the node, remember to write down this password (if you lose this password you will have to reinstall Ubuntu and resync the node, but the Bitcoin wallet will not be affected). ## Step A2. [online computer] Install Security Updates Once you've finished installing Linux, you need to install security updates. First connect to Wi-Fi or LAN. Open a terminal with `Ctrl + Alt + T`. Then type or copy and paste the following commands into the terminal. Note: To copy and paste within a terminal on Linux you must use `Ctrl + Shift + C` to copy and `Ctrl + Shift + V` to paste. ``` sudo apt update ``` Press enter, then press Y if prompted and press enter again, wait for it to finish. ``` sudo apt -y full-upgrade ``` press enter, then press Y if prompted and press enter again, wait for it to finish. ## Step A3. [online computer] Install the Latest Version of Bitcoin Core ## [online computer] Download Bitcoin Core Open a terminal, then copy and paste the following command into the terminal and press enter to download Bitcoin Core and its signed hash. ``` wget -P ~/Downloads https://bitcoincore.org/bin/bitcoin-core-31.1/bitcoin-31.1-x86_64-linux-gnu.tar.gz wget -P ~/Downloads https://bitcoincore.org/bin/bitcoin-core-31.1/SHA256SUMS wget -P ~/Downloads https://bitcoincore.org/bin/bitcoin-core-31.1/SHA256SUMS.asc ``` ### [online computer] Verify Bitcoin Core After you've finished downloading Bitcoin Core verify the hash by running this command in the terminal. ``` cd ~/Downloads && sha256sum --ignore-missing --check SHA256SUMS ``` Press Enter and ensure you get an "OK" result. If you do not see an "OK" message STOP AND DO NOT PROCEED. Again within the same terminal copy and paste the following command to verify the signatures on the Bitcoin Core Software. ``` cd ~/Downloads && wget -O guix.sigs.tar.gz https://github.com/bitcoin-core/guix.sigs/archive/refs/heads/main.tar.gz tar -xzf guix.sigs.tar.gz gpg --import guix.sigs-main/builder-keys/* gpg --verify SHA256SUMS.asc SHA256SUMS ``` Look for `gpg: Good signature from...` on at least a few Bitcoin Core contributors. If you do not see any good signatures STOP AND DO NOT PROCEED. If you see `WARNING: this key is not certified with a trusted signature! There is no indication that the signature belongs to the owner` [this can safely be ignored](gpg_warning.md). ### [online computer] Unpack Bitcoin Core from Tarball Again within the same terminal copy and paste the following command to unpack the Bitcoin Core tar.gz now that we have verified it is legitimate. ``` cd ~/Downloads && tar -xzf bitcoin-31.1-x86_64-linux-gnu.tar.gz -C ~ ``` Bitcoin Core now exists within the home directory inside of the `~/bitcoin-31.1` folder. ## Step A4. [online computer] Start Bitcoin Core ## Start Bitcoin Daemon Within your terminal, copy and paste the following command: ``` ~/bitcoin-31.1/bin/bitcoind -daemon ``` Press enter, you should see a message that says "Bitcoin Core Starting" This computer will now begin syncing the Bitcoin blockchain. This can take a while (multiple days). You will need this process to completely finish before you can perform any test transactions, but for now, continue with this guide. Note: It is important to always properly shut down Bitcoin Core before turning off this computer, this prevents wasted time spent resyncing in the future. To do this run this command: ``` ~/bitcoin-31.1/bin/bitcoin-cli stop ``` You should see a message that says "Bitcoin Core Stopping" ## Step A5: Switch to \*offline computer\* Now switch to the second computer, this will be the \*offline computer\*. Place a piece of tape on this computer to mark it. Insert the Linux USB (the one with tape) and turn the computer on. Remember if you are not greeted by the Ubuntu installer, you may need to adjust the boot order in the BIOS. From this point forward the Linux USB will remain plugged into the \*offline computer\* (remember both the \*offline computer\* and the Linux USB are marked with tape). Within the Ubuntu installer wizard, choose the option to connect to either Wi-Fi or LAN, this will be temporary. During Ubuntu installer wizard select `Try Ubuntu`. ## Step A6: [\*offline computer\*] Install Updates and Software ## [\*offline computer\*] Download this guide You can open this guide in your browser on the offline machine for now and leave it open, we will disable networking shortly and it will no longer be accessible if you accidentally close it. So we will download a copy just in case. Open a terminal and copy and paste the following command in the home directory and press enter. ``` wget -O README.md https://raw.githubusercontent.com/bowlarbear/yeti-2.0/main/README.md?$(date +%s) ``` You should now have this guide in the Home directory. You can run `less README.md` inside the home directory to open this guide in a terminal window on the offline machine. You can also copy and paste guide commands from nano, vim, firefox, or Ubuntu's text editor program. Do not try to download the guide as a pdf or to open it with document viewer. ### [\*offline computer\*] Install Bitcoin Core Repeat Step A3 on the \*offline computer\*. ### [\*offline computer\*] Install Brasero Open a terminal and run the following command ``` sudo apt update sudo apt -y install brasero ``` Press enter and wait for it to finish. You may see a dpkg error in the terminal after installing Brasero but this can safely be ignored. Note: The authenticity of the Brasero software is automatically checked by Ubuntu's apt package manager. Brasero is needed so we can make backups of our keys and burn them to DVDs. ## Step A7: [\*offline computer\*] Disable Networking Within the terminal copy and run the following command: ``` nmcli networking off rfkill block all ``` This command will disable all networking functionality (Wi-Fi, LAN, and Bluetooth) ### [\*offline computer\*] Disable any swap space Swap space is virtual RAM that is borrowed from the internal storage drive. Open a terminal and run this command to verify that there is no swap space enabled on the \*offline computer\*. ``` sudo swapoff -a ``` # B. Creating a Multi-Signature Cold Wallet on Bitcoin Core ## Step B1: [\*offline computer\*] Start Bitcoin Core Open a terminal and start the Bitcoin Daemon ``` ~/bitcoin-31.1/bin/bitcoind -daemon ``` You should see a message that says "Bitcoin Core Starting" ## Step B2: [\*offline computer\*] Create 7 Wallets Within the terminal copy and paste the following... ``` for ((n=1;n<=7;n++)) do ~/bitcoin-31.1/bin/bitcoin-cli createwallet "key_${n}" done ``` Press Enter. ## Step B3: [\*offline computer\*] Capture Extended Public Keys (XPUBs) ``` declare -A xpubs for ((n=1;n<=7;n++)) do xpubs["xpub_${n}"]=$(~/bitcoin-31.1/bin/bitcoin-cli -rpcwallet="key_${n}" listdescriptors | jq '.descriptors | [.[] | select(.desc | startswith("wpkh") and contains("/0/*") )][0] | .desc' | grep -Po '(?<=\().*(?=\))' | sed 's /0/\* /<0;1>/* ') done ``` Press Enter. ## Step B4: [\*offline computer\*] Create the Multisig Wallet Descriptor ``` desc="wsh(sortedmulti(3,${xpubs["xpub_1"]},${xpubs["xpub_2"]},${xpubs["xpub_3"]},${xpubs["xpub_4"]},${xpubs["xpub_5"]},${xpubs["xpub_6"]},${xpubs["xpub_7"]}))" checksum=$(~/bitcoin-31.1/bin/bitcoin-cli getdescriptorinfo $desc | jq -r '.checksum') time=$(date +%s) multisig_desc="[{\"desc\": \"${desc}#${checksum}\", \"active\": true, \"timestamp\": ${time}}]" ~/bitcoin-31.1/bin/bitcoin-cli -named createwallet "multisig_watch_wallet" true true ~/bitcoin-31.1/bin/bitcoin-cli -rpcwallet="multisig_watch_wallet" importdescriptors "$multisig_desc" ~/bitcoin-31.1/bin/bitcoin-cli -rpcwallet="multisig_watch_wallet" getwalletinfo ``` Press Enter. ## Step B5: [\*offline computer\*] Export the Watch-Only Wallet Descriptor Grab the second USB stick (with no tape), this will be the transfer USB. Insert it into the \*offline computer\*. Copy `~/.bitcoin/wallets/multisig_watch_wallet` onto the transfer USB and then remove the transfer USB from the \*offline computer\*. Note: If you are using the file explorer to drag & drop to copy files you will need to click the drop down arrow in the top right corner of the window and click on "Show hidden files". The `~/.bitcoin` folder is hidden by default. Note: It is wise to always run the `sync` command in the terminal and wait for it to finish before removing a USB. Insert the transfer USB into the online computer. Copy the multisig_watch_wallet into the `~/.bitcoin/wallets` folder, then run the following terminal command. ``` ~/bitcoin-31.1/bin/bitcoin-cli loadwallet "multisig_watch_wallet" ``` You can use either bitcoin-cli or bitcoin-Qt (Bitcoin Core's graphical user interface) with the online computer to load this wallet, see the transaction history, check the balance of the wallet, and broadcast fully signed Bitcoin Transactions. It is not advised to use Bitcoin-Qt to create PSBTs as this can cause errors when signing with the steps in this guide. ## Step B6: [\*offline computer\*] Backup Keys Now back up each of the 7 keys and the wallet descriptor. Use Brasero to create 7 DVD backups. These files can be found in the `~/.bitcoin/wallets` folder. Take an DVD and write the number 1 on it with a permanent marker, insert disc 1 into the USB connected disc drive. Then use Brasero to create an ISO of key_1 & the multisig_watch_wallet from `~/.bitcoin/wallets` along with README.md which is a copy of this guide. Burn this ISO to disc 1. Repeat for all 7 keys. 1 = key_1 & multisig_watch_wallet & README.md 2 = key_2 & multisig_watch_wallet & README.md 3 = key_3 & multisig_watch_wallet & README.md 4 = key_4 & multisig_watch_wallet & README.md 5 = key_5 & multisig_watch_wallet & README.md 6 = key_6 & multisig_watch_wallet & README.md 7 = key_7 & multisig_watch_wallet & README.md Note: You will not be able to complete section C until your online computer has finished syncing the Bitcoin Blockchain. ### How to check sync status You can query the status of your node sync by running the following command in the terminal within your online computer. ``` ~/bitcoin-31.1/bin/bitcoin-cli -getinfo ``` Look for the line that says `verificationprogress`, when this value is at 100% your node is finished syncing. # C. Test Wallet Backups ## C1. [\*offline computer\*] Delete Wallets Folder Stop Bitcoin Core ``` ~/bitcoin-31.1/bin/bitcoin-cli stop ``` wait a moment for the daemon to finish shutting down Delete all of the keys from the `.bitcoin/wallets` folder ``` rm -rf ~/.bitcoin/wallets/key_* ``` start Bitcoin Core again ``` ~/bitcoin-31.1/bin/bitcoind -daemon ``` ## C2. [online computer] Create a Receive Address Next you will generate a receive address for your wallet on your online machine. Run this command to generate a new receive address: ``` ~/bitcoin-31.1/bin/bitcoin-cli -rpcwallet="multisig_watch_wallet" getnewaddress ``` Test the wallet by sending a very small amount of Bitcoin to this address (this should be less than $5). Note: You can also generate a receive address with Bitcoin-QT, which is Bitcoin Core's Graphical User Interface (GUI). To use the GUI, simply double click on "Bitcoin-Qt" inside of `~/bitcoin-31.1/bin` in the file explorer, if the Bitcoin daemon is already running you must stop it before starting Bitcoin-QT. Then load "multisig_watch_wallet" in the GUI if its not already loaded, and generate a receive address for a QR code. ## C3. [online computer] Check the Balance of the Wallet You can only check the balance of your wallet from the online computer, with the wallet properly loaded as shown in step B5. ``` ~/bitcoin-31.1/bin/bitcoin-cli -rpcwallet="multisig_watch_wallet" getbalances ``` Note: Fully settled, spendable funds will appear in the `trusted` field of the `getbalances` command. ## C4. [online computer] Create a Transaction Note: You can only create a transaction from the online computer with the wallet properly loaded as shown in step B5. ### Important: Replace $amount and $destination_address with the right values, make sure these are correct before running Note: The `amount` field is denominated in `0.00000000` BTC ``` funded_psbt=$(~/bitcoin-31.1/bin/bitcoin-cli -rpcwallet="multisig_watch_wallet" -named \ walletcreatefundedpsbt \ outputs="{\"$destination_address\": $amount}" \ options='{"subtractFeeFromOutputs":[0]}' | jq -r '.psbt') echo "$funded_psbt" > ~/Desktop/unsigned.psbt ``` Insert the transfer USB (no tape) into the online computer, copy the unsigned.psbt from the Desktop onto the transfer USB. Remove the transfer USB containing the PSBT from the online computer. ## C5. [\*offline computer\*] Sign the Transaction ### [\*offline computer\*] Transfer the Unsigned PSBT Insert the transfer USB (no tape) into the \*offline computer\*. Copy or drag and drop `unsigned.psbt` from the transfer USB onto the Desktop. ### [\*offline computer\*] Verify the PSBT [Verify the PSBT contents](verify_psbt.md). Note: Verifying the PSBT is not necessary for test transactions, but when moving larger amounts you should always verify the contents before and after signing. It is worth practicing the process on at least 1 test transaction. ### [\*offline computer\*] Load the Keys Choose 3 of the DVDs, insert them one at a time into the \*offline computer\*'s USB connected disc drive, and copy the key_# directory into `~/.bitcoin/wallets`. After copying a key run the following command, replace `key_#` with the name of the key you copied into `~/.bitcoin/wallets` ``` ~/bitcoin-31.1/bin/bitcoin-cli loadwallet "key_#" ``` ### [\*offline computer\*] Sign the PSBT After loading all 3 of the keys, sign the PSBT with this script in the terminal ``` psbt=$(cat ~/Desktop/unsigned.psbt) wallet1=$(~/bitcoin-31.1/bin/bitcoin-cli listwallets |jq -r '.[0]') wallet2=$(~/bitcoin-31.1/bin/bitcoin-cli listwallets |jq -r '.[1]') wallet3=$(~/bitcoin-31.1/bin/bitcoin-cli listwallets |jq -r '.[2]') psbt_1=$(~/bitcoin-31.1/bin/bitcoin-cli -rpcwallet="$wallet1" walletprocesspsbt "$psbt" | jq -r '.psbt') psbt_2=$(~/bitcoin-31.1/bin/bitcoin-cli -rpcwallet="$wallet2" walletprocesspsbt "$psbt_1" | jq -r '.psbt') psbt_3=$(~/bitcoin-31.1/bin/bitcoin-cli -rpcwallet="$wallet3" walletprocesspsbt "$psbt_2" | jq -r '.psbt') echo "$psbt_3" > ~/Desktop/signed.psbt ``` Note: There is a chance this process will fail if you attempt to run the signing script above with your "multisig_watch_wallet" loaded on the \*offline computer\*. To avoid this, only have 3 keys loaded when signing and nothing else. You can unload the watch wallet with the following command: ``` ~/bitcoin-31.1/bin/bitcoin-cli unloadwallet multisig_watch_wallet ``` To check and see what wallets you currently have loaded run this command: ``` ~/bitcoin-31.1/bin/bitcoin-cli listwallets ``` ### [\*offline computer\*] Export Signed PSBT to Transfer USB Copy `signed.psbt` from the Desktop onto the transfer USB. Remove the transfer USB from the \*offline computer\* ### [online computer] Import Signed PSBT to Online Computer Insert the transfer USB into the online computer. Copy signed.psbt from the transfer USB onto the Desktop. ### [online computer] Verify the PSBT [Verify the PSBT contents](verify_psbt.md). Note: Verifying the PSBT is not necessary for test transactions, but when moving larger amounts you should always verify the contents before and after signing. It is worth practicing the process on at least 1 test transaction. ## C6. [online computer] Broadcast Transaction ``` psbt=$(cat ~/Desktop/signed.psbt) hex=$(~/bitcoin-31.1/bin/bitcoin-cli finalizepsbt "$psbt" | jq -r '.hex') ~/bitcoin-31.1/bin/bitcoin-cli sendrawtransaction "$hex" ``` Note: Delete old signed.psbt and unsigned.psbt files off of the transfer USB and offline and online desktops after finishing each transaction. Repeat this process (steps C1 through C6) until you've tested all 7 of the key backups. This will require 3 test transactions total 1st transaction: key1, key2, key3 2nd transaction: key4, key5, key6 3rd transaction: key7, + any 2 other keys Warning: If any of the test transactions fail during this process, the best thing to do is to go back to step C4 and try again. If it still doesn't work then something is wrong and you should stop. Delete all PSBTs on both computers' `~/Desktop`. Delete the multisig_watch_wallet on the transfer USB. Delete both of the `.bitcoin/wallets` folders on both computers, and start over at step A5 with fresh DVDs. Only after you have successfully completed all 3 test transactions, testing all 7 keys as described above, will you have confirmed that the wallet is working properly. ## C7. Geographically Distribute Backups The next step is to place each of the 7 backup discs into 7 different envelopes. Mark them with something non-descript like "Do not open. Last will and testament of . Hand deliver this only to next of kin or executor." What you write on these envelopes will ultimately be up to you, but it should be relatively non-descript. The 7 envelopes must be geographically distributed to 7 different locations. You now have a secure, Bitcoin multisig vault that can only be accessed by gathering 3 geographically distributed keys. # D. How to use the Wallet Normally ## D1. Receiving to the vault Receiving larger amounts to the vault requires more precaution than our test spends. To generate a receive address first load your `multisig_watch_wallet` in the online computer if it is not already loaded. Then generate a new address with the following command. ### [online computer] Create a New Address ``` ~/bitcoin-31.1/bin/bitcoin-cli -rpcwallet="multisig_watch_wallet" getnewaddress ``` Copy and paste this address into a text file and save the file on your transfer USB. Insert Linux USB into the powered off, \*offline computer\*, turn the computer on, after the Ubuntu splash screen select `Try Ubuntu` Temporarily connect to your home network, download and verify Bitcoin Core. Download this guide if needed (see steps A6 & A7). You do not need to install Brasero. ### IMPORTANT: [\*offline computer\*] Before Inserting any Key Material ### [\*offline computer\*] Disable Networking ``` nmcli networking off rfkill block all ``` ### [\*offline computer\*] Disable Swap Space ``` sudo swapoff -a ``` ### [\*offline computer\*] Load the `multisig_watch_wallet` ``` ~/bitcoin-31.1/bin/bitcoin-cli loadwallet "multisig_watch_wallet" ``` ### [\*offline computer\*] Verify the Address Copy the address from the address text file on your transfer USB into the following command, replacing `$address` with your actual address, and run it in the terminal. ``` ~/bitcoin-31.1/bin/bitcoin-cli -rpcwallet="multisig_watch_wallet" getaddressinfo "$address" ``` In the result of this command you need to look for "ismine": true, this second check confirms that the address belongs to your wallet. You can now send funds to the vault with this address. See the [Verifying Outputs section](https://github.com/bowlarbear/yeti-2.0/blob/main/verify_psbt.md#verifying-outputs) of the verify PSBT subguide for a visual example of how this looks. Warning: You should never re-use a Bitcoin address. ## D2. Spending from the vault You should already have a good understanding of how this works from the test spends. The \*offline computer\* does not have any persistence. This is for your security, so no keys are ever written to the computer's storage, they can never be recovered without the backup discs. Each time you wish to sign a PSBT with the \*offline computer\* follow these steps carefully... Insert Linux USB into the powered off, \*offline computer\*, turn the computer on, after the Ubuntu splash screen select `Try Ubuntu` Temporarily connect to your home network, download and verify Bitcoin Core. Download this guide if needed (see steps A6 & A7). You do not need to install Brasero. ### IMPORTANT: [\*offline computer\*] Before Inserting any Key Material ### [\*offline computer\*] Disable Networking ``` nmcli networking off rfkill block all ``` ### [\*offline computer\*] Disable Swap Space ``` sudo swapoff -a ``` From here the process for spending from the multisig is the same as the test spends. Next time you want to spend Bitcoin from the multisig: 1. [online computer] Create the unsigned PSBT on the online computer, drag the unsigned PSBT into the transfer USB (step C4) 2. [\*offline computer\*] insert transfer USB into the \*offline computer\*, drag the unsigned PSBT onto the desktop (step C4) 3. [\*offline computer\*] [verify the PSBT contents](verify_psbt.md) (step C5) 4. [\*offline computer\*] collect any 3 of the key discs, insert them 1 at a time and drag the key folders into the `~/.bitcoin/wallets` folder (step C5) 5. [\*offline computer\*] load the keys from the terminal (step C5) 6. [\*offline computer\*] sign the PSBT (step C5) 7. [\*offline computer\*] drag the signed PSBT from the desktop onto the transfer USB, remove the transfer USB and insert it into the online computer (step C5) 8. [online computer] drag the signed PSBT from the transfer USB onto the desktop (step C5) 9. [online computer] [verify the PSBT contents](verify_psbt.md) (step C5) 10. [online computer] broadcast the signed PSBT (step C6) For security you should always turn off the \*offline computer\* after you finish signing and exporting a PSBT. This ensures the deletion of any key material from the computer. # Vault maintenance Remember: These two laptops should be dedicated for use with Bitcoin Core ONLY. DO NOT use these two dedicated laptops for any other purpose or software. Remember: [Keep your software up to date](update_software.md). Remember: You should check your key backups periodically and refresh the backups approximately once every 7 years. Archival grade DVDs are rated to last for 100 years, but this refresh routine is a good practice to ensure that none of the keys in your vault have been lost. This would mean copying the contents of a backup disc onto a fresh archival grade DVD, then adding it to the envelope to be stored beside the original. This should only be done on the *\offline computer\* and requires reinstalling Brasero. If at any point one of your keys becomes lost or unusable, best practice would be to move all of your funds into a fresh multisig vault.