{
  "$schema": "https://degreesofsatoshi.com/encyclopedia/schemas/article-v1.json",
  "schemaVersion": "1.0.0",
  "id": "bitcoin-extended-public-keys",
  "canonical": "https://degreesofsatoshi.com/encyclopedia/bitcoin-extended-public-keys/",
  "collection": "bitcoin",
  "title": "Extended public keys: useful backups with privacy consequences",
  "description": "Learn what an extended public key can derive, what it reveals about a wallet and why hardened derivation boundaries matter.",
  "aliases": [
    "xpub",
    "extended public key"
  ],
  "dates": {
    "published": "2026-10-02",
    "modified": "2026-10-02",
    "verified": "2026-10-02T18:15:23.891Z",
    "dataAsOf": "2026-10-02"
  },
  "authorship": {
    "publisher": "Degrees of Satoshi editorial project",
    "process": "AI-assisted research and drafting with a separate automated source-verification pass; no external expert or named human review is implied."
  },
  "quickAnswer": {
    "text": "A BIP-32 extended public key combines a public key with a chain code. It can derive descendant public keys along non-hardened paths, supporting receive-address generation and monitoring without spending keys. Sharing it can expose a whole branch of wallet activity; it is more sensitive than sharing one receiving address.",
    "claimId": "bitcoin-extended-public-keys-quick-answer",
    "sourceIds": [
      "bip32"
    ]
  },
  "keyFacts": [
    {
      "label": "Contents",
      "value": "An extended public key carries a public key and chain code.",
      "sourceIds": [
        "bip32"
      ],
      "id": "contents",
      "claimId": "bitcoin-extended-public-keys-fact-contents"
    },
    {
      "label": "Boundary",
      "value": "Public derivation cannot cross a hardened child step.",
      "sourceIds": [
        "bip32"
      ],
      "id": "boundary",
      "claimId": "bitcoin-extended-public-keys-fact-boundary"
    },
    {
      "label": "Exposure",
      "value": "A parent extended public key plus a corresponding non-hardened child private key can compromise the parent private key.",
      "sourceIds": [
        "bip32"
      ],
      "id": "exposure",
      "claimId": "bitcoin-extended-public-keys-fact-exposure"
    }
  ],
  "prerequisites": [
    "private-keys-and-seed-phrases"
  ],
  "sections": [
    {
      "id": "derive",
      "heading": "A branch of addresses, not one address",
      "sourceIds": [
        "bip32",
        "bip380"
      ],
      "paragraphs": [
        "A shop can use an account’s public derivation information to generate fresh receiving destinations while its signing device retains private keys. The shop still needs the script type and derivation path to generate the intended addresses; a descriptor can express this context.",
        "An extended key is not itself an ordinary payment destination. Software must derive the intended child key and construct the appropriate output script."
      ]
    },
    {
      "id": "privacy",
      "heading": "Read-only access still reveals information",
      "sourceIds": [
        "bip32"
      ],
      "paragraphs": [
        "Someone given a receive branch may recognize its past and future derived addresses. A broader account key may reveal more branches, depending on the hierarchy. This is why importing an extended public key into an external service creates a privacy decision even when that service cannot ordinarily sign payments.",
        "BIP-32 also documents a particular combined-exposure risk: the parent extended public key and a non-hardened descendant private key can reveal more private-key material. Hardened derivation creates boundaries, but does not make casually sharing secret keys safe."
      ]
    },
    {
      "id": "scope",
      "heading": "Check what the exported key covers",
      "sourceIds": [
        "bip32",
        "bip380"
      ],
      "paragraphs": [
        "Record the network, script expression, account path and whether the export includes receiving and change branches. A watcher configured for one branch may miss funds on another.",
        "Different wallet labels and serialization prefixes do not replace this context. Test a watch-only import against a known receiving address without disclosing private keys."
      ]
    }
  ],
  "faq": [
    {
      "question": "Can an xpub alone spend my bitcoin?",
      "answer": "An extended public key does not contain the private key needed to sign. It can nevertheless disclose wallet activity, and combined exposure with a related non-hardened private key is a separate serious risk.",
      "sourceIds": [
        "bip32"
      ]
    }
  ],
  "claims": [
    {
      "id": "bitcoin-extended-public-keys-quick-answer",
      "articleSlug": "bitcoin-extended-public-keys",
      "statement": "A BIP-32 extended public key combines a public key with a chain code. It can derive descendant public keys along non-hardened paths, supporting receive-address generation and monitoring without spending keys. Sharing it can expose a whole branch of wallet activity; it is more sensitive than sharing one receiving address.",
      "sourceIds": [
        "source-225ce32b9f96878c"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-225ce32b9f96878c",
          "locator": "Extended keys; Child key derivation; Security"
        }
      ],
      "scope": {
        "collection": "bitcoin",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T18:15:23.891Z",
        "reviewer": "Independent automated verification agent verify_bitcoin_stablecoins_100",
        "notes": [
          "Read BIP-32 Extended keys, CKDpub and Security. Public derivation is limited to non-hardened paths; parent xpub plus a descendant private key along a non-hardened path can compromise the parent secret.",
          "Checked BIP-380 script-context and key-origin requirements. Monitoring privacy and spending capability are distinguished."
        ]
      }
    },
    {
      "id": "bitcoin-extended-public-keys-fact-contents",
      "articleSlug": "bitcoin-extended-public-keys",
      "statement": "Contents: An extended public key carries a public key and chain code.",
      "sourceIds": [
        "source-225ce32b9f96878c"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-225ce32b9f96878c",
          "locator": "Extended keys; Child key derivation; Security"
        }
      ],
      "scope": {
        "collection": "bitcoin",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T18:15:23.891Z",
        "reviewer": "Independent automated verification agent verify_bitcoin_stablecoins_100",
        "notes": [
          "Read BIP-32 Extended keys, CKDpub and Security. Public derivation is limited to non-hardened paths; parent xpub plus a descendant private key along a non-hardened path can compromise the parent secret.",
          "Checked BIP-380 script-context and key-origin requirements. Monitoring privacy and spending capability are distinguished."
        ]
      }
    },
    {
      "id": "bitcoin-extended-public-keys-fact-boundary",
      "articleSlug": "bitcoin-extended-public-keys",
      "statement": "Boundary: Public derivation cannot cross a hardened child step.",
      "sourceIds": [
        "source-225ce32b9f96878c"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-225ce32b9f96878c",
          "locator": "Extended keys; Child key derivation; Security"
        }
      ],
      "scope": {
        "collection": "bitcoin",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T18:15:23.891Z",
        "reviewer": "Independent automated verification agent verify_bitcoin_stablecoins_100",
        "notes": [
          "Read BIP-32 Extended keys, CKDpub and Security. Public derivation is limited to non-hardened paths; parent xpub plus a descendant private key along a non-hardened path can compromise the parent secret.",
          "Checked BIP-380 script-context and key-origin requirements. Monitoring privacy and spending capability are distinguished."
        ]
      }
    },
    {
      "id": "bitcoin-extended-public-keys-fact-exposure",
      "articleSlug": "bitcoin-extended-public-keys",
      "statement": "Exposure: A parent extended public key plus a corresponding non-hardened child private key can compromise the parent private key.",
      "sourceIds": [
        "source-225ce32b9f96878c"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-225ce32b9f96878c",
          "locator": "Extended keys; Child key derivation; Security"
        }
      ],
      "scope": {
        "collection": "bitcoin",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T18:15:23.891Z",
        "reviewer": "Independent automated verification agent verify_bitcoin_stablecoins_100",
        "notes": [
          "Read BIP-32 Extended keys, CKDpub and Security. Public derivation is limited to non-hardened paths; parent xpub plus a descendant private key along a non-hardened path can compromise the parent secret.",
          "Checked BIP-380 script-context and key-origin requirements. Monitoring privacy and spending capability are distinguished."
        ]
      }
    }
  ],
  "sources": [
    {
      "id": "bip32",
      "label": "Hierarchical Deterministic Wallets",
      "publisher": "Bitcoin BIPs contributors",
      "url": "https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0032.mediawiki",
      "locator": "Extended keys; Child key derivation; Security",
      "note": "Extended public keys, derivation and private-key exposure limitations.",
      "version": "BIP-32; immutable revision pinned in source URL",
      "checkedAt": "2026-10-02T17:22:20.467Z",
      "contentSha256": "e5e00a8289db2f681052cf24a745320afc225e66b25d1e489a7c884d2fc7f11f",
      "recordId": "source-225ce32b9f96878c"
    },
    {
      "id": "bip380",
      "label": "Output Script Descriptors General Operation",
      "publisher": "Bitcoin BIPs contributors",
      "url": "https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0380.mediawiki",
      "locator": "Specification; Key expressions; Checksum",
      "note": "Descriptors describe output scripts, keys and derivation information.",
      "version": "BIP-380; immutable revision pinned in source URL",
      "checkedAt": "2026-10-02T17:22:20.620Z",
      "contentSha256": "34e6510bb2eba9445a68eacf3d24d5a4e5f24481477488d5552f674ac81dd5fe",
      "recordId": "source-36e62aca6baaa2f2"
    }
  ],
  "related": {
    "articles": [
      "watch-only-wallets",
      "bitcoin-output-descriptors",
      "bitcoin-address-reuse"
    ],
    "dossiers": [],
    "wallets": []
  },
  "revisionHistory": [
    {
      "date": "2026-10-02",
      "kind": "published",
      "summary": "Initial Bitcoin encyclopedia entry at this permanent URL."
    },
    {
      "date": "2026-10-02",
      "kind": "publishing-format",
      "summary": "Added reusable claims, explicit source locators, and matching Markdown and JSON. This publishing change does not itself establish factual verification."
    }
  ],
  "citation": "Degrees of Satoshi editorial project. “Extended public keys: useful backups with privacy consequences.” Published 2026-10-02; updated 2026-10-02. https://degreesofsatoshi.com/encyclopedia/bitcoin-extended-public-keys/"
}
