Run a Recovery Drill
A recovery drill is a rehearsal you run while nothing is wrong. It answers one question — if Keystody vanished tonight, could you actually get your Bitcoin? — at a moment when a wrong answer costs you an afternoon rather than everything.
Last updated: 20 August 2026
1. Why rehearse at all
Recovery is not difficult. It is just unfamiliar, and unfamiliar procedures fail under stress in ways they never fail on a quiet Sunday. Almost every real recovery failure is the same handful of causes, and every one of them is discoverable in advance:
- The descriptor was never exported, or the only copy is somewhere unreachable.
- The descriptor was copied by hand and a character is wrong. A descriptor carries a checksum precisely so this is caught, but only if you try it.
- A seed phrase was written down incorrectly, or the passphrase that goes with it was never recorded.
- Two of the three keys turn out to be in the same place, or in the same person's hands.
A drill surfaces all four while they are still fixable. That is the entire point — not to prove the software works, but to prove your setup does.
2. Level 1 — the watch-only drill
Start here. It requires no keys, touches nothing, and cannot put a single satoshi at risk. Most of the value of a drill is in this level, and it takes about fifteen minutes.
- Find your Recovery Document without looking it up in Keystody. This is part of the test. If the only way you can find your descriptor is by logging in to us, you do not yet have a recovery plan — you have a dependency.
- Install Sparrow from sparrowwallet.com and verify the download signature against the maintainer's key. A drill that skips signature verification rehearses a bad habit.
- Create a new watch-only wallet and import the descriptor exactly as printed, on one line. If Sparrow rejects it, the descriptor was transcribed wrongly — that is a finding, not a failure of the drill.
- Compare the first receive address against the one Keystody shows for the same vault. They must match character for character. This is the assertion that matters: two independent implementations agreeing that this descriptor describes this vault.
- Let it scan, and check the balance. Sparrow gets history from the Bitcoin network, not from us. A matching balance means the vault is fully discoverable without Keystody.
If all five steps pass, you have proved the part people most often get wrong. Record the date and move on with your life.
3. Level 2 — the full drill
Level 1 proves you can see your Bitcoin without us. Level 2 proves you can move it. It requires two of your three keys physically in front of you, and it is worth doing at least once — ideally when you first fund the vault, while the balance is still small.
Do this with a small amount, sending back to an address of your own. You are testing the procedure, not moving money.
- Start from the Level 1 wallet — the one built from the descriptor, not from Keystody.
- Construct a transaction back to another address you control. Any amount that is comfortably above the dust threshold will do.
- Sign with your first device. Read the destination and amount on the device screen and confirm they are what you intended. The device should show exactly the payments you meant to make and nothing else.
- Sign with your second device — a genuinely different device, ideally fetched from wherever it normally lives. Retrieving it is part of the test: a key you cannot get to in an hour is a key you may not have.
- Broadcast, and confirm it settles. Only a confirmed transaction proves the whole chain worked.
Having done this once, you know the answer to the question that actually matters, and you know it from experience rather than from our assurance.
4. What to write down
Keep a short record. Not for us — we neither need nor want it — but because a drill you cannot date is a drill you will re-run from scratch or, worse, assume you already did.
Four lines are enough: the date, the wallet software and version you used, which level you completed, and anything that did not go as expected. That last line is the valuable one; it is the only part that ever changes what you do next.
5. How often
Once a year is a reasonable rhythm for the watch-only drill, and Keystody will remind you as part of your vault's Recovery Readiness. Re-run it sooner if anything material changed: a key rotated, a device replaced, a cosigner moved house, a new person added to the vault.
The full drill is worth repeating after any change to the key set, because that is precisely when an assumption you have been carrying quietly for a year stops being true.
6. If a drill fails
A failed drill is the drill doing its job, on the best possible day for it to happen. Nothing is lost while the vault is still operating normally and every key still exists.
If the descriptor will not import, or the addresses do not match, or a device will not produce a signature, write down exactly what you saw and contact support@keystody.com. If you believe the mismatch indicates an attack rather than a mistake, report it privately instead.
Related reading: Recover Your Bitcoin Without Keystody for the procedure itself, and Verify Your Addresses on Your Hardware Wallet for the check that belongs in every drill.