xpub (extended public key)
An extended public key from which all the addresses of a wallet account can be calculated. Nobody can spend bitcoin with it – but anyone who knows it can see your entire account history.
Alsoextended public keyzpubypubmaster public keywatch-only key
Under the BIP 32 standard, a whole tree of keys grows from a single seed. The xpub (extended public key) is the public part of one branch, usually a wallet account. All the public keysGlossaryPublic keyCalculated from the private key and used to check your signatures. The calculation only works in one direction: the private key cannot be worked out from the public key.In the glossary → and addressesGlossaryBitcoin addressA string of characters like ‘bc1q…’ that someone can send bitcoin to. It is usually derived from a public key, can be shared without risk to your funds and should be generated afresh for every payment.On the learning path: Stage 5 · Step 4 – First withdrawal →In the glossary → of that account can be derived from it, but no private keys.[1] For Native SegWit accounts (addresses starting ‘bc1q…’), some wallets display it as a zpub.[2]
What it’s needed for
- Watch-only: an app with your xpub shows your balance and new receiving addresses, while the keys stay on your hardware walletGlossaryHardware walletA small dedicated device that keeps your private keys offline and signs transactions internally. The key never leaves the device, so malware on your computer can’t get at it.On the learning path: Stage 6 · Step 1 – Hardware wallets compared →In the glossary →.
- Multisig: the wallet needs the xpubs of all participants to calculate the shared addresses. That’s why they belong in the backup of every multisigGlossaryMultisig (multi-signature)A wallet in which several keys jointly control the bitcoin – for example 2 of 3. If one key is lost or stolen, the bitcoin stays safe. In return, setting it up and backing it up is considerably more demanding.On the learning path: Stage 6 · Step 4 – Inheritance & emergency plan →In the glossary → wallet.
- Merchants: a shop server generates a new address for every order without knowing any private keys.
Dive deeperWhy an xpub and a private key must never meet
Anyone who knows the xpub plus the private key of a single address derived from it can calculate all the private keys of the account.[1] That’s why the upper levels of the derivation pathGlossaryDerivation pathThe route a wallet follows to calculate individual keys from your seed phrase, for example m/84'/0'/0'. If another wallet uses a different path when you restore, it looks empty – even though nothing has been lost.In the glossary → are ‘hardened’ (marked with an apostrophe, as in 84'), so that such a leak stays confined to that one account. So never give out individual private keys.
Related terms
These terms are closely connected.
- This termxpub(extended public key)
- Public keyCalculated from the private key and used to check your signatures. The calculation only works in one direction: the private key cannot be worked out from the public key.
- Derivation pathThe route a wallet follows to calculate individual keys from your seed phrase, for example m/84'/0'/0'. If another wallet uses a different path when you restore, it looks empty – even though nothing has been lost.
- Multisig (multi-signature)A wallet in which several keys jointly control the bitcoin – for example 2 of 3. If one key is lost or stolen, the bitcoin stays safe. In return, setting it up and backing it up is considerably more demanding.
- Cold storageStoring bitcoin in a way that keeps the private keys from ever touching the internet – for example on a hardware wallet or an offline device. It protects against online attacks, but requires a carefully kept backup.
- Bitcoin addressA string of characters like ‘bc1q…’ that someone can send bitcoin to. It is usually derived from a public key, can be shared without risk to your funds and should be generated afresh for every payment.
Explained in depth
These articles go into more detail:
- Deep dive · Stage 5PrivacyBitcoin is pseudonymous, not anonymous. How chain analysis works, what your exchange and the tax office know about you and how to protect your privacy legally.
- Deep dive · Stage 6MultisigWhat a 2-of-3 multisig wallet is, who it’s worth it for, how to set it up and why you need to back up the descriptor as well as the seeds.
- Deep dive · Stage 5Testing recoveryHow to check that your wallet backup works when it matters, why a restored wallet can look empty and what you can do if you lose access.
More from „Wallets & security“
Sources2 sources · 1 publishers
The superscript numbers in the text refer to these sources.
- BIP 32: Hierarchical Deterministic Wallets – Bitcoin Improvement Proposals (Pieter Wuille), 11.02.2012 (accessed 28/09/2026)
- BIP 84: Derivation scheme for P2WPKH based accounts – Bitcoin Improvement Proposals (Pavol Rusnak), 28.12.2017 (accessed 28/09/2026)
This entry is for education only and is not investment, tax or legal advice.