Bitcoin Staking onboarding docs

Fireblocks enrollment guide

Enroll in Bitcoin Staking with Fireblocks

Open the Fireblocks x Stacks app, enroll your vault account in the approved bond, and confirm that registration succeeded.

Begin enrollment
Fireblocks x Stacks enrollment pre-flight showing the BTC amount and readiness checks
You check the Bitcoin amount, the allocation, and the readiness checks before you enroll.
Enroll in Bitcoin StakingEnroll your vault account in the bond.Exit a bond earlyUnlock your Bitcoin early and give up the remaining rewards.Enrollment RecordWhat the Endowment sends you.

01 / 06 · Prepare the vault

Get your vault account ready for enrollment.

Who: the operator with access to the Fireblocks workspace. Keep the approvers required by your Transaction Authorization Policy available for the signing steps later.

This step confirms your approved values and opens the correct vault account in the Fireblocks x Stacks app.

Before you begin

  • You have received your Enrollment Record from the Stacks Endowment. It shows the approved bond, amounts, reward asset, and signer-manager.
  • The Fireblocks x Stacks desktop app is installed and connected to your workspace. The app guides you through creating or importing Fireblocks API credentials. Your Fireblocks Customer Success Manager provides the app and setup instructions.
  • Raw Signing is enabled in your workspace. It is a premium Fireblocks feature. Request it from your Fireblocks Customer Success Manager well before the enrollment session.
  • A Transaction Authorization Policy rule allows Raw Signing for the vault account you are enrolling.
  • You submitted the vault account's Stacks and Bitcoin addresses at stacksendowment.co/bond-enroll and received written confirmation that they are whitelisted for this bond.
  • Your Stacks Endowment contact is available during the enrollment session.

Open the app and select your vault account

  1. Open the Fireblocks x Stacks app. Touch ID unlocks your stored credentials. It is not a transaction approval.
  2. On the dashboard, find the vault account approved for this bond. The dashboard lists each vault account with its Stacks balances.
  3. Select the vault account. Confirm that its complete Stacks address exactly matches the address you submitted for whitelisting. If it does not match, stop and select the correct vault account.
  4. Confirm the app shows Mainnet. The app must not say it is viewing a test network.
  5. Open Staking in the sidebar and select the same vault account in the account picker.

Make sure the vault account has enough funds

  1. The Bitcoin balance must cover the approved BTC amount shown in the Enrollment Record, plus the Bitcoin network fee.
  2. The STX balance must cover the STX requirement shown in the Enrollment Record, plus the Stacks transaction fee.
  3. If either balance is too low, deposit funds through Fireblocks and wait for the deposit to confirm before continuing.
Complete: the app shows Mainnet, the Staking page shows your approved vault account, and the bond card for the bond in your Enrollment Record says Enrollment open. If the card says access is required, the vault account is not whitelisted yet.

02 / 06 · Start enrollment

Start enrollment and set the Bitcoin amount.

Who: the operator. The pre-flight screen checks that your account is ready before anything is signed.

Nothing moves in this step. The app only checks balances, access, and the bond phase.

  1. On the bond card, select Enroll in bond.
  2. Enter the BTC amount approved in the Enrollment Record.
  3. Under Bitcoin funding, keep Fund from this Fireblocks vault selected. Fireblocks creates the Bitcoin lock transaction for you. There is no transaction ID to paste.
  4. Review the readiness checks. Every check must pass before you continue.
  5. Confirm that the displayed STX requirement matches the Enrollment Record.
  6. Select Continue.
Not approved for the bond? The bond card says access is required. Compare the vault account's complete Stacks address with the written whitelisting confirmation. Contact your Stacks Endowment contact if the addresses match but access is still missing.
Complete: all readiness checks pass and the BTC amount and STX requirement match the Enrollment Record.

03 / 06 · Reward asset

Choose how you will receive rewards.

Who: the operator. The reward asset is the asset in which this bond's rewards will be paid.

The choice was made before this session and appears in the Enrollment Record.

  1. Select the reward asset listed in the Enrollment Record.
  2. If the Record lists sBTC, rewards arrive at your vault account's Stacks address. No other setting is needed.
  3. If the Record lists native BTC, select the reward destination vault account your organization approved in writing.
  4. Confirm the verified destination address against that written approval.
  5. Enter the per-cycle withdrawal fee budget your organization approved, in satoshis.
  6. Read the payout explanation shown for your selection. Stop if it differs from the Enrollment Record.
  7. Select Continue.
The Bitcoin fee budget is fixed for the life of the bond. It is reserved from each cycle's reward to pay the Bitcoin withdrawal fee. Any part of the budget that is not spent is kept by the signer-manager operator. The app warns if the budget is more than a cycle is expected to earn. A cycle that earns less than the budget cannot be claimed.
Changing the reward asset later re-routes unclaimed rewards. Switching to sBTC after enrollment removes the saved Bitcoin destination. Rewards already earned but not yet claimed are then paid as sBTC to your Stacks address.
Complete: the selected reward asset and destination match the Enrollment Record.

04 / 06 · Signer-manager

Confirm the signer-manager.

Who: the operator. A signer-manager is a smart contract that validates your bond and distributes your rewards.

The Stacks Labs signer-manager is selected by default. It is the only one offered unless you add your own. Most partners keep the default. Confirm it matches the Enrollment Record.

  1. Confirm the Stacks Labs signer-manager is selected. Compare its full contract address with the Enrollment Record character by character, including the name after the dot.
  2. Wait for the app's signer-manager checks to pass. Both checks must pass.
  3. Only if your Enrollment Record names a custom signer-manager: select Enter a different manager…, paste the full contract address from the Record, and select Add manager. Do not type it by hand. The app validates it for this enrollment only and does not save it.
  4. If anything is different or unclear, stop and contact your Stacks Endowment contact before continuing.
  5. Select Continue.
A custom signer-manager has full control over how your rewards are distributed. Do not enter one unless it is named in your Enrollment Record and your organization understands the risks. If you are unsure, keep the default.
Complete: the signer-manager's contract address matches the Enrollment Record and both signer-manager checks pass. The signer-manager is fixed for the life of the bond.

05 / 06 · Authorize

Review the summary and authorize the enrollment.

Who: the operator, plus every approver required by your Transaction Authorization Policy.

This step contains two transactions. The first locks BTC on Bitcoin. After it confirms, the second registers the bond on Stacks. The app runs both and shows progress.

The irreversible momentYour BTC becomes locked when the Bitcoin transaction is broadcast. Stop before authorizing if any value differs from the Enrollment Record.

Review the enrollment summary

  • Bond number and BTC amount match.
  • STX requirement matches.
  • Reward asset matches the Record. The reward destination matches your written approval.
  • Signer-manager contract address matches.
  • Maturity matches your approved terms.
  • The enrolling vault account is correct.
  1. Compare every row of the summary with the Enrollment Record.
  2. Select Authorize enrollment and authenticate with Touch ID.
  3. Approve the signing request in the Fireblocks mobile app or through your workspace's automatic approver, per your Transaction Authorization Policy. Approvers must stay available until enrollment completes.

What the app does after you authorize

  1. Keep the app open and your computer awake. The app sends the Bitcoin transaction and waits for it to confirm. This can take a while.
  2. After the Bitcoin transaction confirms, the app registers the bond on Stacks.
  3. Wait for the app to report that you enrolled. It shows both transaction IDs. Save them with your records. The screen says the position is Upcoming until the bond activates. That is normal.
Do not close the app or start a second enrollment. If the app closes after the Bitcoin transaction was sent, reopen it and run enrollment for the same bond again. It resumes the existing enrollment rather than sending a second Bitcoin transaction.
Complete: the app reports the enrollment succeeded and shows both transactions.

06 / 06 · Verify enrollment

Confirm that the bond registration succeeded.

Who: the operator. Enrollment is complete only after the Stacks registration transaction is confirmed and successful.

The position card is your ongoing view of the bond.

  1. On the Staking page, confirm that Your position now shows the bond.
  2. Compare the bond number, BTC amount, STX amount, reward asset, and signer-manager with the Enrollment Record. Compare the maturity with the Authorize summary you reviewed.
  3. Open the Stacks transaction from the success screen or the position card. Confirm the explorer reports Success. Confirmed alone is not enough.
  4. Confirm the locked amount on a Bitcoin block explorer using the Bitcoin transaction ID. The explorer shows the amount that actually funded the lock.
  5. Save both transaction IDs with your records.
  6. Tell your Stacks Endowment contact that enrollment is complete.
Enrollment complete: the position card shows the bond, the Stacks registration reports Confirmed and Success, and all values match the Enrollment Record.
Reward claiming is not available in the app yet. Your position earns rewards from enrollment. The claim feature arrives in a later app release. Your Stacks Endowment contact will tell you when it is available.

If something goes wrong

The bond card says access is required

Your vault account has not been approved for that bond. Compare the complete Stacks address with the written whitelisting confirmation. Contact your Stacks Endowment contact if they match but access is still missing.

A readiness check does not pass

Read the message under the failed check. Most failures are a balance that is too low or a bond that is not open yet. Fix the cause and select Refresh.

The signer-manager checks do not pass

Confirm the selected signer-manager matches the Enrollment Record. If you entered a custom one, confirm you pasted the full contract address exactly as shown in the Record. If it is correct and a check still fails, the signer-manager may not be accepting enrollments. Contact your Stacks Endowment contact before continuing.

The reward destination address was rejected

Re-select the destination vault account in the app instead of typing an address. If it is still refused, contact your Stacks Endowment contact.

The signature request fails or never reaches an approver

Raw Signing may be disabled or your Transaction Authorization Policy may not allow it for this vault account. Contact your Fireblocks Customer Success Manager.

A cycle paid out as sBTC instead of Bitcoin

This is expected when the cycle's reward is at or below the threshold shown at enrollment. The rewards are not lost. They arrive at your Stacks address.

The app closed during enrollment

Reopen the app and run enrollment for the same bond again. The app resumes the existing enrollment. Do not send Bitcoin manually.

The signing request was not approved

Check the Fireblocks mobile app or your cosigner. The request must be approved per your Transaction Authorization Policy before the app can continue. If the Touch ID prompt was missed or cancelled, nothing was sent. Select Authorize enrollment again.

Bitcoin confirmed but Stacks registration is pending or failed

Do not repeat the Bitcoin step. Save both transaction IDs, the bond number, and the error message, then contact your Stacks Endowment contact immediately.

After enrollment

Keep the Enrollment Record with your custody records.

Retain both transaction IDs, the vault account's addresses, the bond number, signer-manager, amounts, and maturity block. At maturity your BTC unlocks without any announcement and without giving up rewards. If you must unlock sooner, follow the early-exit guide.

Signer-manager

What does the signer-manager do?

The signer-manager is a smart contract used by Bitcoin Staking when your bond is registered. The protocol calls it to validate your participation. It also receives rewards for the people using it and defines how those rewards are calculated, claimed, and paid.

Why the choice matters

The contract's deployer can customize its logic. Signer-managers may have different participation rules, commissions, payout methods, claim processes, administrators, and controls for changing those settings. A poorly designed or adversarial contract could reject a registration or mishandle rewards.

The Fireblocks x Stacks app offers the Stacks Labs signer-manager by default. You can add a custom one, but it then controls how your rewards are distributed. Only do so when your Enrollment Record names it.

The signer-manager does not hold your locked BTC. Your Bitcoin remains controlled by the lock and the keys used to create it.

What the reference implementation does

This is an example, not necessarily the signer-manager approved for your bond. View the PoX-5 reference implementation