Skip to content
Satnam SatoshiIn service of humanityFind your place ↗
Menu
Lesson 13 / 21 · Advanced

HD wallets and derivation paths

Understand reproducible keys without mistaking xpubs for harmless data.

14 MIN WITH PRACTICEREAD → TRY → REFLECTNO WALLET NEEDED

By the end, you’ll be able to…

  • Explain a hierarchy of derived keys.
  • Identify why derivation metadata and xpub privacy matter.
Your learning map

Three questions to carry into this lesson.

01Explain a hierarchy of derived keys.
02Identify why derivation metadata and xpub privacy matter.
Use these goals to guide your reading. Try the paper exercise, then explain the result in your own words.

A tree replaces isolated key records

BIP 32 defines hierarchical deterministic wallets: a seed can derive a tree of keys through indexed paths. Extended keys include information needed for child derivation. This helps wallets create many receiving addresses without requiring a separately improvised backup for every new address. A path identifies a position in the hierarchy, not a separate blockchain account.

Public derivation is useful and sensitive

An extended public key can derive corresponding non-hardened public descendants without spending authority. That makes watch-only receiving and monitoring possible. It can also reveal a broad set of addresses and their activity. Some combinations of exposed extended public information and private descendants have serious security consequences, which is one reason hardened derivation exists.

Recovery needs context

A seed alone does not always tell replacement software which script type, account or path the original wallet used. Store the required policy metadata securely according to the wallet’s recovery design. Never post a real xpub in a public support issue merely because it cannot independently sign. For a learning diagram, label a root, account branch, receiving branch and change branch without including actual key material.

Your turn / A paper experiment

Practice on paper

A shop wants an online server to generate receiving addresses without holding spending keys. What concept helps, and what privacy tradeoff remains?

I’ve tried it — show the worked answer

A suitable extended public key or watch-only descriptor can support receiving-address generation. The server can still learn and expose the associated address history, so its scope and access should be limited.

Want to explore with buttons and instant feedback? Try the practice lab ↗

Think it through

Make a choice. Discover why.

Choose an answer and check the explanation. You can retry as often as you like. These are practice questions, not a test of mastery; answers are not saved or sent.

1. Is an xpub equivalent to one ordinary receiving address?
  • Yes
  • No
Read the explanation

No. It can reveal a family of derived addresses.

2. Can every wallet infer all derivation choices from a seed alone?
  • Yes
  • No
Read the explanation

No. Recovery may require additional metadata.

One idea to take with you

Back up the policy context as well as the secret.

Your learning, at your pace

Read every lesson freely. Optional progress tracking needs JavaScript and browser storage; it does not require an account or wallet.