When you withdraw bitcoin on-chain to a new address, Bitaroo asks you to prove that the address belongs to a wallet you control.
Signing a message is the quickest way to do this, and it is the recommended method.
You use your wallet to sign a short piece of text that Bitaroo provides, then paste the result back. No funds move, and Bitaroo never gains access to your wallet.
Message signing is supported by most popular wallets, including Electrum, Sparrow and BlueWallet.
Before you start
- Use the same wallet that owns the address you are withdrawing to. Only that wallet can sign for that address.
- Have your wallet open on your computer or phone.
- Keep the Bitaroo verification screen open so that you can copy across the message and the address.
The steps at a glance
On the Bitaroo "Sign a Message" screen you will see four steps:
- Open your wallet and find "Sign Message" (it is sometimes under Tools or Advanced).
- Copy the message (the challenge text) from Bitaroo and paste it into your wallet.
- Select or paste the address shown by Bitaroo. This must be the address you are withdrawing to.
-
Sign the message, copy the signature your wallet produces, paste it back into Bitaroo, then select "Verify Signature".
If the signature is valid, the address is marked as verified and you can continue your withdrawal. A verified address is remembered, so you will not need to repeat this for future withdrawals to the same address.
Below are step-by-step instructions for common desktop and mobile wallets: Electrum, Sparrow, and BlueWallet. Follow the one that matches your wallet, the process is much the same in others.
Wallets known to work
Message signing is available in most wallets that hold your own keys. The wallets and devices below have been confirmed to produce a signature that Bitaroo accepts. Your keys never leave your wallet or device, and no bitcoin moves.
| Wallet | Where to sign | Notes |
|---|---|---|
| BitBox02 | The BitBoxApp | Native SegWit addresses, beginning with bc1q |
|
Blockstream app formerly Green |
Transact → Receive → List of Addresses → the signature icon on the address | Singlesig accounts. A 2FA or multisig account has no signing option, so use the satoshi test for those |
|
Blockstream Jade Classic, Core, Plus |
The Blockstream app, or Sparrow with the device connected | Sign from a singlesig account, as above |
| BlueWallet | Wallet menu → Sign/Verify message | Steps below |
|
Coldcard Mk4, Q |
On the device through Address Explorer, or through Sparrow | Signs while air-gapped. If you generated your seed on a Coldcard, please read our Coldcard security advisory first |
| Electrum | Tools → Sign/Verify message | Works for legacy, nested SegWit and native SegWit addresses. Steps below |
| Foundation Passport | On the device: Account Tools → Sign a Message | Passport reads the message as a QR code, so allow an extra step to move the text across |
|
Ledger Nano S, S Plus, X |
Electrum or Sparrow, with the device connected | Ledger publishes its own guide for this. Message signing is done through Electrum or Sparrow rather than Ledger Live |
| Sparrow | Tools → Sign/Verify Message | Also covers Taproot addresses. Steps below |
|
Trezor Model One, Model T, Safe |
Trezor Suite → Sign and Verify | Available on Legacy, Legacy SegWit and SegWit accounts. Taproot accounts sign a different way, so use another method for those |
If your wallet is not listed, it may still work. Look for "Sign message", often under Tools or Advanced, and follow the steps below.
Desktop wallets
Electrum
|
Sparrow
|
Mobile wallets
BlueWallet
If you hold several wallets in BlueWallet, make sure you open the one that the address belongs to, otherwise the signing option will not produce a valid result.
|
Note: message signing on mobile works for standard single-key (hot) wallets. If your address is held on a hardware wallet, use the Electrum or Sparrow desktop steps above.
Finishing in BitarooWhichever wallet you used, the last step happens back in Bitaroo. Once your wallet has produced the signature, return to the Bitaroo "Sign a Message" screen, paste the signature into step 4, and select Verify Signature. If the signature is valid, the address is confirmed and your withdrawal continues. A verified address is remembered, so you will not need to repeat this for future withdrawals to the same address. |
Why did my message signing fail?
- The address and the wallet do not match. Sign with the wallet that actually owns the address shown by Bitaroo.
- The message was changed. Copy the message exactly, with no extra spaces or line breaks. Using the copy button avoids this.
- You signed with a different address. Confirm the address in your wallet matches the address on the Bitaroo screen, character for character.
- The challenge expired. If too much time passes, start the verification again to get a fresh message.
-
Your wallet cannot sign for that address type. A small number of wallets cannot sign messages for some address types, especially Taproot addresses (those that begin with
bc1p). If so, try another supported wallet, or use a different verification method such as your extended public key, a multisig output descriptor, or a satoshi test. - The signature was not copied in full. A complete signature is roughly 88 characters long and usually ends with an equals sign. Check that nothing was cut off at either end.
- The address belongs to a multisig wallet. A single signature cannot prove an address that needs several keys. Use a wallet descriptor or a satoshi test instead.
- Your wallet signs from singlesig accounts only. The Blockstream app is one example: a 2FA or multisig account there has no signing option at all, so use the satoshi test for those.
- Your wallet offered a choice of signature format. Choose the standard or simple message signature.
If an attempt fails, start again from the verification screen and copy the message afresh before signing, because the message may have changed.
Is this safe? Does signing a message move my bitcoin?
Yes, it is safe. Signing a message is a read-only proof. It uses your private key to produce a signature, but it does not create a transaction, reveal your private key, or move any funds. It simply demonstrates that you control the address. Bitaroo never gains the ability to access or move your bitcoin.
Privacy Matters
Bitaroo built this verification model to protect your privacy, as well as the privacy of all our other users.
The Travel Rule, introduced on 1 July 2026, forces exchanges to routinely share customers’ personally identifiable information and, in many cases, engage with globally centralised third parties (“Travel Rule Providers”) whenever bitcoin moves to or from a custodial service. Those arrangements often expose the exchange’s hot wallet to chain surveillance corporations, giving them visibility into the activity of all users transacting through it.
Bitaroo remains compliant by removing the need for these “information-sharing” arrangements altogether.
By verifying that you control your own wallet, we can keep your personal information out of unnecessary hands.
Message signing is the most privacy-preserving verification method. It proves you control the address without revealing any of your other addresses, balances or transactions, which is why we recommend it.
Still need help?
If you have tried the steps above and verification still fails, please contact our support team and we will help.