Wallets

Nunchuk: first wallet and shared access

A phone app that coordinates multisig, including wallets shared with another person. What to build first, what to back up beyond the keys, and which features quietly add a dependency.

Beginner About 30 minutes Updated Aug 17, 2026
MobileMultisigShared access

Most mobile wallets are a wallet. Nunchuk is closer to a coordinator that happens to live on your phone: it can run an ordinary single-signature wallet, but its reason to exist is multisig — including wallets shared between two or more people, each holding their own key.

That makes it one of the few practical routes to a household wallet where a partner genuinely co-signs rather than being told the password. It also means the setup involves choices that other wallet apps do not ask you to make, and one backup obligation that is easy to miss.

A phone showing a multisig wallet with two of three keys marked as signed, held above a desk where a hardware wallet and an NFC card are sitting.

Image to come

The phone coordinates. The keys stay on the hardware.

Before you start

  • The Nunchuk app, installed from the official app store listing linked at nunchuk.io rather than found by search.
  • At least one hardware signing device if you are building anything beyond a small spending wallet.
  • Backup material for every key you are about to create, plus somewhere to record the wallet configuration.
  • For a shared wallet, the other person present, with their own device.
  • No bitcoin. Move none until the checks at the end pass.

1Decide what you are actually building

Nunchuk will happily build any of these, and they are not interchangeable. Pick before you start.

Phone key

Software wallet

Small spending amounts. The key lives on the internet-connected phone itself.

One device

Single-sig with hardware

Savings without multisig. The phone is only the interface; the signer holds the key.

Your devices

Personal multisig

Larger savings. No single key or device can lose the bitcoin.

Split ownership

Shared multisig

Households, partners, businesses, and deliberate inheritance arrangements.

If this is your first wallet of any kind, build the first or second row, use it, and prove you can recover it before attempting either multisig option. Multisig multiplies every backup mistake by the number of keys.

2Add your hardware keys

Nunchuk supports an unusually broad range of signers — COLDCARD, TAPSIGNER, Jade, SeedSigner, Trezor, Ledger, BitBox, Passport, and Keystone among them — and several ways to talk to them.

  • NFC for card-format signers such as TAPSIGNER: tap the card to the phone to sign.
  • QR for air-gapped devices: the phone displays a code, the device reads it, and the signature comes back the same way. Nothing is ever connected.
  • USB where the device and phone support it.
  • Set up each device independently, generating its own seed on that device. Never create several keys from one seed — that is one key wearing several hats, and it defeats the entire point of multisig.

Prefer the QR path where your device offers it. An air gap that exists by default is worth more than one you have to remember to use.

3Back up the configuration, not just the keys

This is the obligation people miss, and it is the one that turns a working multisig into an unrecoverable one.

Your seed phrases alone cannot rebuild a multisig wallet. Software also needs the policy, the script type, the derivation paths, and the public keys of every key in the wallet — the bundle called the wallet configuration or descriptor. Nunchuk can export it. Do that during setup, while you are already thinking about backups, rather than intending to later.

  • Export the wallet configuration from Nunchuk and store a copy alongside every seed backup.
  • Write a plain-language note with it: how many keys exist, how many are needed, and which is which.
  • For a shared wallet, make sure every participant holds the configuration, not just the person who set it up.
  • Record the master fingerprints so a future restore can be checked against something.

It is not a secret that can spend your coins

The configuration contains public keys only. Someone who finds it learns your balance and history, which is a privacy problem, but they cannot move anything. Losing it is far worse than leaking it — so store it widely rather than cleverly.

4How a shared wallet actually works

In a shared wallet each person holds their own key and can see the wallet, but a spend needs the threshold to be met. A 2-of-2 between partners means neither can move funds alone. A 2-of-3 with a third key held elsewhere means either person can spend with that third key's help, and either can be replaced.

  • Agree the threshold deliberately. 2-of-2 is genuine joint control and also means one lost key locks you both out. 2-of-3 is more forgiving and slightly less strict.
  • Every participant needs their own backup of their own key, stored where the other person cannot reach it, or you have re-created a single point of failure.
  • Every participant needs the wallet configuration. If only one person has it, that person is a dependency.
  • Decide in advance what happens if someone becomes unavailable — through illness, a falling-out, or death. That is the scenario a shared wallet exists for, and it should not be improvised.

Rehearse a spend with each valid combination of keys before the wallet holds anything meaningful. An untested pair is a pair you are assuming works.

5Assisted services: know which side of the line you are on

Nunchuk offers optional paid services alongside the self-serve app — assisted recovery, inheritance arrangements, and wallets where the platform holds a key or provides support. These are legitimate products and solve real problems, particularly for people who want multisig without becoming its sole operator.

They also change what you depend on, so establish which features you are using and answer one question before committing anything serious:

If this company disappeared overnight, could I still spend my bitcoin — and do I already hold everything I would need to do it?

  • Confirm you can export the full wallet configuration yourself, and that you have it stored.
  • Confirm your own keys meet the spending threshold without any platform key.
  • Confirm you can recover using other software — Sparrow and Specter both open standard multisig wallets — rather than only the Nunchuk app.
  • Understand what lapses if a subscription lapses. A stopped payment should never be able to strand your funds.
  • Rehearse a recovery in other software once, so the answer is something you have seen rather than something you were told.

6Verify and test before funding

  • Generate a receive address and verify it on a hardware device screen, not only in the app.
  • Send a small test amount and confirm it arrives.
  • Spend from it using each valid combination of keys.
  • Rebuild the wallet in different software from your configuration file and the required seeds. That proves your backup package is complete.
  • Only then move an amount you would miss.

The rebuild is the real test

Everything else confirms the wallet works today, on this phone, with this app installed. Rebuilding it elsewhere confirms it will work in five years on hardware you have not bought yet — which is the situation your backups actually exist for. Test your recovery covers the drill in full.

Feature tiers, service names, and which capabilities are free change over time. Confirm what is self-serve and what depends on a subscription or a platform key against Nunchuk's own documentation before relying on any of it.

Do not guess

Stuck on a step?

If the screen in front of you does not match the guide, stop. Review the related walkthroughs or get a second set of eyes before exposing recovery words or approving a transaction.