What is a Vault Descriptor?
Your vault descriptor is a small file that describes how your vault is built. Think of it as the blueprint for your vault: it lists the keys involved and the rules for how your bitcoin can be spent.
You download it during setup, and you keep it as part of your backup.
What it's for
If you ever need to rebuild or recover your vault, the descriptor is what tells your wallet software how to put it back together. Without it, recovery is far harder, even if you still have your keys.
That's why we ask you to save it: your device key and your descriptor work together. You need both to recover on your own.
Can someone steal my bitcoin with it?
No. The descriptor cannot move or spend your bitcoin. It has no private keys in it, so on its own it can't sign a transaction or send funds anywhere.
Then why keep it private?
Because while it can't spend your bitcoin, it can reveal it. The descriptor contains your extended public keys and spending policy, which means anyone who gets a copy can:
- see all your vault's addresses,
- watch your balance, and
- view your full transaction history.
So it's not a security risk in the "lose your funds" sense, it's a privacy risk. It won't cost you your bitcoin, but it can expose how much you hold and how you spend it.
Best practice
A few simple habits keep your descriptor safe and useful:
- Store it separately from your device key. Keep the two in different places so no single location holds everything needed to see or rebuild your vault. A copy alongside each device-key backup works well.
- Keep a copy, not just one. Store it in more than one secure place, so a single lost or damaged copy isn't a problem.
- Printing is fine. A printed copy kept private and out of sight is perfectly safe. Just don't leave it somewhere others can read it.
- Don't email it or put an unencrypted copy in cloud storage. These are the easiest ways for a copy to end up somewhere you didn't intend.
- If you encrypt a backup, record how to decrypt it. Make sure your recovery plan explains how, so a future you (or your heirs) can actually open it.
Why "separate" matters
Your device key and your descriptor each do a different job. Your device key can authorise spending. Your descriptor describes the vault. Kept apart:
- Anyone who finds your descriptor alone can see your vault, but can't touch your funds or rebuild access without your key.
- Anyone who finds a key backup alone doesn't have the full picture of your vault.
Keeping them in separate places means no single discovery, a misplaced file, a compromised cloud account, a lost drive, gives someone both your privacy and your recovery path at once.
Need a hand? If you're not sure where to store your backups, book a call and we'll talk it through.