Every Bitcoin transaction is broadcast from a device with internet access. The private key that signs the transaction does not need to be on that device — or ever connected to a network. PSBT (Partially Signed Bitcoin Transaction), defined in Bitcoin Improvement Proposal 174, creates a clean separation between the signing step and the broadcasting step. The private key signs the transaction on a device that has never been connected to the internet. The signed transaction is transferred to a networked device for broadcasting. The key is never online at any point in the process.
PSBT enables on-chain Bitcoin transactions with zero private key internet exposure — the signing device is offline, the broadcasting device never sees the key. For regular on-chain Bitcoin users who perform daily transactions, this means the attack surface on the private key does not grow with transaction frequency. Bitok Arena's read: the PSBT workflow with a hardware wallet is the maximum-security option for daily on-chain Bitcoin activity. Whether the security benefit justifies the workflow overhead depends on the BTC position size being protected. The workflow is compatible with any on-chain Bitcoin transaction, including daily competition round entries.
A standard Bitcoin transaction creates and signs in a single step on the same device — the wallet software constructs the transaction and signs it with the private key before broadcasting. PSBT splits this: the transaction is first constructed as an unsigned template with all the necessary data (inputs, outputs, amounts, destination address) but without the signature. This unsigned template is the PSBT. It contains no private key material and is safe to transfer to any device. The signing device adds the signature using the stored private key and returns a completed signed PSBT. The online device broadcasts the signed PSBT to the Bitcoin network.
The PSBT Workflow With a Hardware Wallet
The standard PSBT workflow for on-chain Bitcoin transactions pairs Sparrow Wallet on a connected computer with an air-gapped hardware wallet — ColdCard, Foundation Passport, or Keystone Pro. Sparrow manages the watch-only account, constructs unsigned PSBTs, and handles broadcasting. The hardware wallet handles signing with the private key that never leaves the device. The two devices communicate through QR codes (for Keystone Pro, Foundation Passport, and ColdCard Q) or microSD file transfer (for ColdCard Mk4).
Bitok Arena reviewed the PSBT signing workflow across compatible hardware wallet and companion software combinations for daily on-chain Bitcoin transaction use.
PSBT workflow (QR method — Keystone Pro, Passport, ColdCard Q) — Step 1 (Sparrow, online): create transaction with destination address and amount; export unsigned PSBT as animated QR displayed on computer screen. Step 2 (hardware wallet, offline): scan QR with built-in camera; display destination address and amount on device screen; user verifies address character by character; approve signing; device outputs signed PSBT as QR on its own display. Step 3 (Sparrow, online): computer camera scans signed PSBT QR; Sparrow broadcasts; TXID available for tracking.
PSBT workflow (microSD — ColdCard Mk4) — Same as QR method but with microSD file transfer at Steps 1 and 2 instead of QR scanning; adds physical card handling but eliminates camera requirement on the hardware device.
Time overhead vs hot wallet — QR PSBT workflow: approximately 60–90 seconds additional per transaction compared to direct hot wallet send; microSD: approximately 90–120 seconds additional. One-time setup cost: 30–45 minutes to pair hardware wallet with Sparrow in watch-only mode.
After setup, the daily on-chain transaction workflow is the same each round: open Sparrow, create transaction with the destination address (verified from the intended destination source), set fee rate, export unsigned PSBT, transfer to hardware wallet via QR or microSD, verify destination address on hardware device screen character by character, approve signing, transfer signed PSBT back to Sparrow, broadcast. The TXID appears in Sparrow's transaction history and can be tracked in mempool.space. The Bitcoin network records the transaction identically whether the private key was on an air-gapped hardware device or a connected software wallet — the signing method is not visible in the transaction data.
When the PSBT Workflow Matters
For occasional Bitcoin transactions — monthly or less — the security benefit of PSBT air-gap signing is present but the time overhead may not be worth it compared to a well-secured software wallet. For regular daily on-chain Bitcoin transactions where the private key is used hundreds of times per year, the PSBT workflow provides a meaningful security benefit: the private key's attack surface does not grow with transaction frequency because the key is never on a networked device regardless of how many transactions are signed.
Bitok Arena compared the security profile of PSBT air-gap signing against hot wallet signing for high-frequency on-chain Bitcoin use.
Hot wallet (software wallet on phone or desktop) — private key present on internet-connected device during signing; adequate security with strong passphrase and dedicated device; convenient (single-step sign and broadcast); security depends on device hygiene, software integrity, and passphrase strength. Appropriate for participants with small-to-moderate BTC positions prioritizing workflow convenience.
PSBT with hardware wallet — private key never on networked device at any point; signing device has zero internet exposure regardless of how many transactions are signed; 60–90 seconds additional per transaction over hot wallet; requires one-time setup (30–45 minutes); maximum available protection for key compromise via network-facing attack vectors. Appropriate for participants with significant BTC positions where daily key usage risk is a genuine concern.
The choice between hot wallet and PSBT is proportional to position size. A participant with 0.01 BTC who values convenience over maximum security is making a reasonable choice. A participant with 5 BTC performing daily on-chain transactions is making a different risk calculation.
The PSBT standard is supported by Sparrow Wallet, Electrum, Bitcoin Core, and all major Bitcoin wallet software. All major air-gapped hardware wallets support PSBT as their signing mechanism — it is the standard interface through which hardware wallets communicate with companion software. A participant who already uses a hardware wallet for Bitcoin storage is one Sparrow pairing session away from using PSBT for every subsequent on-chain transaction. The pairing is the one-time investment. Every daily transaction after that runs the same workflow.
Bitok Arena's review of PSBT signing for daily on-chain Bitcoin transactions: the workflow separates transaction signing from broadcasting — the private key signs offline, the signed transaction broadcasts from a connected device, and the key is never exposed to any network at any step. For daily on-chain Bitcoin participants who perform hundreds of signing operations per year, this means the key's network attack surface is permanently zero regardless of transaction frequency. Setup is 30–45 minutes; per-transaction overhead is 60–90 seconds. Whether that overhead is worth the security benefit scales directly with the BTC position being protected by the key.
Pair the hardware wallet with Sparrow, create the watch-only account, and test the PSBT round-trip with a small test transaction. After that setup, every on-chain Bitcoin transaction goes through the same air-gap workflow. The destination address verified on the hardware device screen before signing is the critical check — confirming the signed transaction sends to the intended recipient and not to a clipboard-hijacked substitute. That verification on the hardware device's own display is the final confirmation before the key is used. The transaction confirmed on the Bitcoin network is the result.
Bitok Arena's analysis of PSBT for on-chain Bitcoin transactions: the standard defined in BIP174 enables private key signing on an air-gapped device with the signed transaction broadcast from a networked companion device. The private key has zero internet exposure across every transaction signed this way, regardless of transaction frequency. Setup with Sparrow and a hardware wallet (ColdCard, Foundation Passport, or Keystone Pro): 30–45 minutes. Per-transaction overhead versus hot wallet: 60–90 seconds. The security benefit is constant across all transactions. The appropriate threshold for adopting PSBT over a hot wallet is proportional to the BTC position size and the daily transaction frequency that determines how often the key is used.