05 · Plebum Dominium
Multi-tool verification
Official downloads. Hash + signature. Sparrow vs Electrum vs Ian Coleman.
Download official releases at home, check them, then take only verified files across the airgap. One program can lie. Two independent implementations should not agree by accident.
Get files from the official project
Tails, Sparrow Wallet, Electrum, Ian Coleman BIP39 (official GitHub repo, saved as local HTML). Bookmark those yourself. Do not follow a random video’s shortened link.
A. Run the audit before the data USB
- Put the downloads next to verify_kit.sh.
- Open a terminal in that folder.
- Run chmod +x verify_kit.sh
- Run ./verify_kit.sh or double-click it.
- It checks pinned SHA-256 hashes. Not signatures.
- One failure means format the drive and stop.
- Only then copy files to the data USB.
$ chmod +x verify_kit.sh$ ./verify_kit.sh
B–D. Cross-check keys, wallet, and every spend
- Dice bits → same 24 words in the converter and in offline Ian Coleman.
- Same seed + path in Sparrow and Electrum → same first receive addresses.
- Output descriptor reconstructs the same addresses when imported in the second tool. Path m/48'/0'/0'/2', P2WSH, 2-of-3.
- Watch-only online Sparrow matches the offline receive addresses. Dust in, two explorers agree.
- Unsigned PSBT: both tools show the same destination, amount, change, and fee before you sign.
- After signature 1, session 2 sees it as valid. After signature 2, online Sparrow reports fully signed and unchanged.
The rule of two at home. Two downloads (hash + signature). Two wallets (Sparrow + Electrum). Two humans if someone you trust can read a plate against a screen. Two rehearsals — dust in, dust out — before savings move.