About 14 minutes with practice. You only need something to take notes with. No real wallet details or payments are part of this lesson.
Course contents · Lesson 13 of 21
- Read the whitepaper as an argument · Marked complete
- Hashes and Merkle commitments · Marked complete
- UTXOs, change and accounting · Marked complete
- Scripts describe spending conditions · Marked complete
- Signatures and what they authorize · Marked complete
- Block headers and the chain of work · Marked complete
- Difficulty, hashrate and noisy observations · Marked complete
- Issuance, fees and incentives · Marked complete
- Mempools and policy are not consensus · Marked complete
- Fee changes: RBF and CPFP · Marked complete
- SegWit and transaction weight · Marked complete
- Taproot and Schnorr: useful, not magical · Marked complete
- HD wallets and derivation paths · Marked complete
- PSBT: separate construction from signing · Marked complete
- Descriptors make a wallet policy portable · Marked complete
- Full nodes, pruning and verification · Marked complete
- Reorganizations and lightweight evidence · Marked complete
- Lightning channels and HTLCs · Marked complete
- Lightning liquidity has direction · Marked complete
- Soft forks, proposals and human coordination · Marked complete
- Capstone: trace a payment end to end · Marked complete
What you will learn
- Explain a hierarchy of derived keys.
- Identify why derivation metadata and xpub privacy matter.
A tree replaces isolated key records
BIP 32 defines hierarchical deterministic wallets: a seed can derive a tree of keys through indexed paths. Extended keys include information needed for child derivation. This helps wallets create many receiving addresses without requiring a separately improvised backup for every new address. A path identifies a position in the hierarchy, not a separate blockchain account.
Public derivation is useful and sensitive
An extended public key can derive corresponding non-hardened public descendants without spending authority. That makes watch-only receiving and monitoring possible. It can also reveal a broad set of addresses and their activity. Some combinations of exposed extended public information and private descendants have serious security consequences, which is one reason hardened derivation exists.
Recovery needs context
A seed alone does not always tell replacement software which script type, account or path the original wallet used. Store the required policy metadata securely according to the wallet’s recovery design. Never post a real xpub in a public support issue merely because it cannot independently sign. For a learning diagram, label a root, account branch, receiving branch and change branch without including actual key material.
Practice on paper
A shop wants an online server to generate receiving addresses without holding spending keys. What concept helps, and what privacy tradeoff remains?
Reveal the worked answer
A suitable extended public key or watch-only descriptor can support receiving-address generation. The server can still learn and expose the associated address history, so its scope and access should be limited.
Check your understanding
Choose an answer in your head or on paper, then reveal the explanation. Retry whenever you like. Answers are not submitted or scored; completion marks are your own learning notes.
1. Is an xpub equivalent to one ordinary receiving address?
- Yes
- No
Reveal answer 1
No. It can reveal a family of derived addresses.
2. Can every wallet infer all derivation choices from a seed alone?
- Yes
- No
Reveal answer 2
No. Recovery may require additional metadata.
Take this with you
Back up the policy context as well as the secret.
Your learning, at your pace
Read every lesson freely. Optional progress tracking needs JavaScript and browser storage; it does not require an account or wallet.
Remove the saved completion marks for this course on this browser? Other courses will stay unchanged.
Saved only in this browser for this website address. Clearing storage, changing device or using a different gateway may lose these marks. No sync, grading or credential; nothing is sent to us. The export is a record for you, not a file this site can import.