@@ -200,9 +200,10 @@ worth the extra steps.
200200## More protection: watch-only wallet and offline signer
201201
202202On the offline signer, create an empty encrypted descriptor wallet with private
203- keys enabled and run ` ms32 wallet ` . Keep that computer permanently disconnected
204- from every network as soon as Bitcoin Core and codex32 are installed and
205- disconnect before recovery text or signing keys are present.
203+ keys enabled and run ` ms32 wallet ` . If this signer may need to rescan an
204+ existing wallet, synchronize Bitcoin Core or copy in the required chain history
205+ before making the signer permanently offline. Then disconnect every network
206+ path before entering recovery text or exposing signing keys.
206207
207208After the signer is restored, follow Bitcoin Core's maintained
208209[ offline-signing tutorial] ( https://github.com/bitcoin/bitcoin/blob/master/doc/offline-signing-tutorial.md ) .
@@ -224,12 +225,11 @@ its public wallet data with the separate wallet record.
2242251 . Collect the required cards with matching identifiers and text lengths.
2252262 . Find the separately stored wallet record and the original wallet
226227 instructions.
227- 3 . On Tails or another reviewed offline computer, check each card with
228- ` ms32 check ` . If validation fails, recheck what you typed before assuming
229- the paper is wrong.
230- 4 . Disable Ethernet, internet, Tor, Wi-Fi, Bluetooth, cellular, and every other
231- network path. Load a blank encrypted descriptor wallet with private keys
232- enabled in Bitcoin Core, and run:
228+ 3 . Before entering recovery text, ensure the offline signer already has the
229+ Bitcoin Core chain history needed for the requested rescan. Then disable
230+ Ethernet, internet, Tor, Wi-Fi, Bluetooth, cellular, and every other network
231+ path. Load a blank encrypted descriptor wallet with private keys enabled in
232+ Bitcoin Core, and run:
233233
234234 ``` bash
235235 ms32 wallet --timestamp 0
@@ -238,11 +238,11 @@ its public wallet data with the separate wallet record.
238238 If you know when the wallet was first used, an earlier Unix timestamp can
239239 shorten the rescan; ` 0 ` remains the safest choice when unsure.
240240
241- 5 . Select and confirm that wallet. If it is locked, follow the displayed
241+ 4 . Select and confirm that wallet. If it is locked, follow the displayed
242242 Bitcoin-Qt Console instructions; codex32 waits and continues automatically.
243243 It gives Core the master private key, asks Core to create the standard
244244 account-0 descriptors, scans history, and relocks an encrypted wallet.
245- 6 . If you need an online watch-only counterpart, keep the restored signer
245+ 5 . If you need an online watch-only counterpart, keep the restored signer
246246 offline and follow Bitcoin Core's
247247 [ offline-signing tutorial] ( https://github.com/bitcoin/bitcoin/blob/master/doc/offline-signing-tutorial.md )
248248 to export and restore the watch-only wallet. Let the online node synchronize,
0 commit comments