Skip to content

[Feature] Encryption scheme for watch only wallets #1938

Description

@semillabitcoin

I've seen some requests to add YubiKeys as 2FA alongside passwords to encrypt the Sparrow wallet file. However, I believe this adds unnecessary complexity. Instead of using a YubiKey or another external key, why not leverage the hardware wallet itself to access the watch-only wallet file? Password encryption would remain available but this feature could be a plan B.

Most users already store their 12/24-word mnemonic plus their passphrase, adding redundancy to prevent loss of funds. Adding passwords to the Sparrow file is yet another element to manage and back up. What if we could avoid relying exclusively on this password and have the option to decrypt the file directly with the descriptor when connecting our hardware wallet?

This solution would allow storing wallet files more securely in the cloud and other locations without the risk of them being decrypted with weak passwords. Additionally, it would be an effective way to protect transaction labels and metadata against accidental loss, since you could maintain multiple encrypted copies without compromising privacy.

This approach is already implemented in Liana through a specific BIP they developed to make it possible:

https://github.com/pythcoiner/bips/blob/encrypted_descriptor/bip-encrypted-backup.md

Activity

  1. craigraw commented on Jan 27, 2026

    @craigraw
    Collaborator

    Thanks, I'm aware of this BIP proposal - in fact I've commented on the PR. Let's see how it evolves.

  2. semillabitcoin commented on Sep 23, 2026

    @semillabitcoin
    Author
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions