# Extended public keys: useful backups with privacy consequences

A BIP-32 extended public key combines a public key with a chain code. It can derive descendant public keys along non-hardened paths, supporting receive-address generation and monitoring without spending keys. Sharing it can expose a whole branch of wallet activity; it is more sensitive than sharing one receiving address.

Evidence: [Hierarchical Deterministic Wallets](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0032.mediawiki)

Canonical: https://degreesofsatoshi.com/encyclopedia/bitcoin-extended-public-keys/
Published: 2026-10-02
Substantively modified: 2026-10-02
Independently verified by an automated reviewer: 2026-10-02T18:15:23.891Z
Data current through: 2026-10-02

AI-assisted research and drafting with a separate automated source-verification pass; no external expert or named human review is implied.

## Key facts

- **Contents:** An extended public key carries a public key and chain code. ([Hierarchical Deterministic Wallets](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0032.mediawiki))
- **Boundary:** Public derivation cannot cross a hardened child step. ([Hierarchical Deterministic Wallets](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0032.mediawiki))
- **Exposure:** A parent extended public key plus a corresponding non-hardened child private key can compromise the parent private key. ([Hierarchical Deterministic Wallets](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0032.mediawiki))

## A branch of addresses, not one address

A shop can use an account’s public derivation information to generate fresh receiving destinations while its signing device retains private keys. The shop still needs the script type and derivation path to generate the intended addresses; a descriptor can express this context.

An extended key is not itself an ordinary payment destination. Software must derive the intended child key and construct the appropriate output script.

Evidence: [Hierarchical Deterministic Wallets](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0032.mediawiki); [Output Script Descriptors General Operation](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0380.mediawiki)

## Read-only access still reveals information

Someone given a receive branch may recognize its past and future derived addresses. A broader account key may reveal more branches, depending on the hierarchy. This is why importing an extended public key into an external service creates a privacy decision even when that service cannot ordinarily sign payments.

BIP-32 also documents a particular combined-exposure risk: the parent extended public key and a non-hardened descendant private key can reveal more private-key material. Hardened derivation creates boundaries, but does not make casually sharing secret keys safe.

Evidence: [Hierarchical Deterministic Wallets](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0032.mediawiki)

## Check what the exported key covers

Record the network, script expression, account path and whether the export includes receiving and change branches. A watcher configured for one branch may miss funds on another.

Different wallet labels and serialization prefixes do not replace this context. Test a watch-only import against a known receiving address without disclosing private keys.

Evidence: [Hierarchical Deterministic Wallets](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0032.mediawiki); [Output Script Descriptors General Operation](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0380.mediawiki)

## Questions

### Can an xpub alone spend my bitcoin?

An extended public key does not contain the private key needed to sign. It can nevertheless disclose wallet activity, and combined exposure with a related non-hardened private key is a separate serious risk.

Evidence: [Hierarchical Deterministic Wallets](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0032.mediawiki)

## Claims and scope

### bitcoin-extended-public-keys-quick-answer

A BIP-32 extended public key combines a public key with a chain code. It can derive descendant public keys along non-hardened paths, supporting receive-address generation and monitoring without spending keys. Sharing it can expose a whole branch of wallet activity; it is more sensitive than sharing one receiving address.

Scope: {"collection":"bitcoin","dataAsOf":"2026-10-02","blockHeight":null}

### bitcoin-extended-public-keys-fact-contents

Contents: An extended public key carries a public key and chain code.

Scope: {"collection":"bitcoin","dataAsOf":"2026-10-02","blockHeight":null}

### bitcoin-extended-public-keys-fact-boundary

Boundary: Public derivation cannot cross a hardened child step.

Scope: {"collection":"bitcoin","dataAsOf":"2026-10-02","blockHeight":null}

### bitcoin-extended-public-keys-fact-exposure

Exposure: A parent extended public key plus a corresponding non-hardened child private key can compromise the parent private key.

Scope: {"collection":"bitcoin","dataAsOf":"2026-10-02","blockHeight":null}

## Sources

- [Hierarchical Deterministic Wallets](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0032.mediawiki) — Bitcoin BIPs contributors. Extended public keys, derivation and private-key exposure limitations. Locator: Extended keys; Child key derivation; Security. Retrieved: 2026-10-02T17:22:20.467Z.
- [Output Script Descriptors General Operation](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0380.mediawiki) — Bitcoin BIPs contributors. Descriptors describe output scripts, keys and derivation information. Locator: Specification; Key expressions; Checksum. Retrieved: 2026-10-02T17:22:20.620Z.

## Revision history

- 2026-10-02: Initial Bitcoin encyclopedia entry at this permanent URL.
- 2026-10-02: Added reusable claims, explicit source locators, and matching Markdown and JSON. This publishing change does not itself establish factual verification.

## Cite this entry

Degrees of Satoshi editorial project. “Extended public keys: useful backups with privacy consequences.” Published 2026-10-02; updated 2026-10-02. https://degreesofsatoshi.com/encyclopedia/bitcoin-extended-public-keys/
