BIP32 łączy klucz z 256-bitowym chain code. HMAC-SHA512 i numerowana ścieżka tworzą dzieci; xpub wyprowadza zwykłe publiczne potomki, a hardened wymaga sekretu. Granica umożliwia delegowanie i określa skutki wycieku.
Pieter Wuille napisał BIP32, przydzielony 11.02.2012. Hierarchia deleguje account lub receive branch bez reszty. To nie consensus; mnemonic, passphrase, script i discovery należą do BIP39, standardów ścieżek i descriptors. [BIP 32 — Hierarchical deterministic wallets] [BIP 39 — Mnemonic code for deterministic keys] [Bitcoin Developer Guide — Wallets]
Extended private key to scalar secp256k1 k i 32-byte chain code c; public ma K=point(k). HMAC-SHA512 z kluczem ‘Bitcoin seed’ daje IL jako master candidate i IR jako chain code. IL=0 lub IL≥n unieważnia seed. [BIP 32 — Hierarchical deterministic wallets]
CKDpriv dodaje parse256(IL) do parent scalar modulo n, IR staje się child code. Normal: serP(Kpar)||ser32(i); hardened: 0x00||ser256(kpar)||ser32(i), i≥2^31. CKDpub działa tylko dla normal public children. [BIP 32 — Hierarchical deterministic wallets]
xpub tworzy normal public descendants. Jednak parent xpub plus wyciek non-hardened child private key odzyskuje parent private key i siblings. Hardened blokuje ten rachunek, nie kradzież seed, słaby RNG ani źle zatwierdzoną transakcję. [BIP 32 — Hierarchical deterministic wallets]
78-byte serialization zawiera version, depth, 4-byte fingerprint, child number, chain code i key data, potem Base58Check. Mainnet xprv/xpub zwykle ma 111 znaków. Fingerprint nie uwierzytelnia; ypub/zpub SLIP132 ma nierówne wsparcie. [BIP 32 — Hierarchical deterministic wallets] [SLIP 132 — Registered HD version bytes]
BIP43 rezerwuje purpose'. BIP44 używa m/44'/coin_type'/account'/change/index, 0/1 i gap limit 20; BIP48 to multisig, BIP84 SegWit, BIP86 Taproot. To konwencje wallet, nie dane seed ani reguły nodes; ' oznacza +2^31. [BIP 43 — Purpose field for deterministic wallets] [BIP 44 — Multi-account hierarchy] [BIP 48 — Multi-script hierarchy for multisig wallets] [BIP 84 — Native SegWit derivation] [BIP 86 — Single-key Taproot derivation]
Scoped xpub pozwala watch-only bez podpisu, lecz wyciek łączy stare i przyszłe adresy, salda i czas. Zainfekowany host może podmienić adres; ważny receive sprawdzaj na ekranie trusted signer. [BIP 32 — Hierarchical deterministic wallets] [Bitcoin Developer Guide — Wallets] [Trezor Learn — Hierarchical deterministic wallets]
xpub nie określa script. Descriptor dodaje origin [fingerprint/path], wpkh(), multisig threshold/cosigners, wildcards i checksum. Jeden multisig seed nie odzyska innych xpub, kolejności ani progu; zachowaj przetestowany descriptor. [BIP 380 — Output script descriptors] [BIP 389 — Multipath descriptor key expressions] [Bitcoin Core — Output descriptors] [Bitcoin Optech — Output script descriptors]
Root seed eliminuje backup każdej nowej key, ale recovery wymaga passphrase, formatu, sieci, purpose/script, coin type, accounts, receive/change, gap policy i multisig descriptor. Zero często oznacza złe drzewo. Testuj UTXO i podpis. [BIP 44 — Multi-account hierarchy] [BIP 380 — Output script descriptors] [Bitcoin Core — Output descriptors] [BIP 39 — Mnemonic code for deterministic keys]
Rzadkie IL≥n, zero scalar lub infinity point przechodzą do kolejnego index. Częstsze są utracony origin, inne discovery, ypub/zpub, brak change, Taproot lub zła depth. xprv wydaje, xpub ujawnia finanse, descriptor mapuje policy. [BIP 32 — Hierarchical deterministic wallets] [BIP 380 — Output script descriptors] [SLIP 132 — Registered HD version bytes] [Bitcoin Core — Output descriptors]
Pełniejszy obraz uzyskasz, czytając to hasło razem z Portfel, Seed Phrase, Extended Public Key (xpub), Derivation Path, Gap Limit, Bitcoin. Do tego hasła prowadzą również odsyłacze z Adres Bitcoin, BIP 39, Cold Storage, Watch-only Wallet.