Encyclopedia How the network works · Entry 88
Extended public keys: useful backups with privacy consequences
In this article
At a glance
Key facts
| Fact | Detail | Source |
|---|---|---|
| Contents | An extended public key carries a public key and chain code. | [1] |
| Boundary | Public derivation cannot cross a hardened child step. | [1] |
| Exposure | A parent extended public key plus a corresponding non-hardened child private key can compromise the parent private key. | [1] |
A branch of addresses, not one address
A shop can use an account’s public derivation information to generate fresh receiving destinations while its signing device retains private keys. The shop still needs the script type and derivation path to generate the intended addresses; a descriptor can express this context.
An extended key is not itself an ordinary payment destination. Software must derive the intended child key and construct the appropriate output script.
Read-only access still reveals information
Someone given a receive branch may recognize its past and future derived addresses. A broader account key may reveal more branches, depending on the hierarchy. This is why importing an extended public key into an external service creates a privacy decision even when that service cannot ordinarily sign payments.
BIP-32 also documents a particular combined-exposure risk: the parent extended public key and a non-hardened descendant private key can reveal more private-key material. Hardened derivation creates boundaries, but does not make casually sharing secret keys safe.
Check what the exported key covers
Record the network, script expression, account path and whether the export includes receiving and change branches. A watcher configured for one branch may miss funds on another.
Different wallet labels and serialization prefixes do not replace this context. Test a watch-only import against a known receiving address without disclosing private keys.
Direct answers
Questions people ask
Can an xpub alone spend my bitcoin?
An extended public key does not contain the private key needed to sign. It can nevertheless disclose wallet activity, and combined exposure with a related non-hardened private key is a separate serious risk.
Inspect the evidence
The answer and key facts have stable claim links. These records retain the scope and qualification when reused.
A BIP-32 extended public key combines a public key with a chain code. It can derive descendant public keys along non-hardened paths, supporting receive-address generation and monitoring without spending keys. Sharing it can expose a whole branch of wallet activity; it is more sensitive than sharing one receiving address.
Scope: Bitcoin · data through 2026-10-02. Verification: verified · 2026-10-02T18:15:23.891Z.
Link to this claimContents: An extended public key carries a public key and chain code.
Scope: Bitcoin · data through 2026-10-02. Verification: verified · 2026-10-02T18:15:23.891Z.
Link to this claimBoundary: Public derivation cannot cross a hardened child step.
Scope: Bitcoin · data through 2026-10-02. Verification: verified · 2026-10-02T18:15:23.891Z.
Link to this claimExposure: A parent extended public key plus a corresponding non-hardened child private key can compromise the parent private key.
Scope: Bitcoin · data through 2026-10-02. Verification: verified · 2026-10-02T18:15:23.891Z.
Link to this claimRevision history
- — Initial Bitcoin encyclopedia entry at this permanent URL.
- — Added reusable claims, explicit source locators, and matching Markdown and JSON. This publishing change does not itself establish factual verification.
Source register
Sources and references
Retrieval dates and locators are recorded individually.- Hierarchical Deterministic WalletsBitcoin BIPs contributors
Extended public keys, derivation and private-key exposure limitations.
Locator: Extended keys; Child key derivation; Security · Version / scope: BIP-32; immutable revision pinned in source URL · Retrieved: 2026-10-02T17:22:20.467ZOpen source - Output Script Descriptors General OperationBitcoin BIPs contributors
Descriptors describe output scripts, keys and derivation information.
Locator: Specification; Key expressions; Checksum · Version / scope: BIP-380; immutable revision pinned in source URL · Retrieved: 2026-10-02T17:22:20.620ZOpen source
Research and drafting use AI assistance. A separate automated review checks claims against primary sources; no external expert or named human review is implied. Publication, substantive editing, source retrieval and verification are recorded separately. This version was independently checked by an automated reviewer on 2 October 2026.
Editorial method and correctionsDegrees of Satoshi editorial project. “Extended public keys: useful backups with privacy consequences.” Published 2026-10-02; updated 2026-10-02. https://degreesofsatoshi.com/encyclopedia/bitcoin-extended-public-keys/