
⏱ 2 min read
The draft creates an encrypted metadata backup to fix seed-only recovery gaps in complex wallets, while warning against xpub reuse that could expose wallet details.
Bitcoin’s BIP138 wallet-backup proposal was merged into the Bitcoin Improvement Proposals repository on Sept. 21 and remains marked Draft. The text outlines a standard for encrypting wallet metadata so complex setups can be recovered even when a seed phrase alone cannot.
Seed phrases regenerate private keys, but they don’t preserve descriptors, policies or other information that some multisignature and miniscript wallets require to reconstruct an account and find its coins. The draft also highlights a failure mode in shared setups: a wallet designed to survive the loss of one seed can still become unrecoverable if that signer’s public key is also lost, leaving the remaining signers without a complete script.
BIP138’s answer is an encrypted file that stores descriptors, wallet policies and other non-seed metadata. Private key material must be stripped before encryption. A holder of an eligible extended public key (xpub) from the backed-up wallet can decrypt a copy of this file without access to the seed. That reveals the public keys and script structure needed to reconstruct the wallet’s map, but the xpub alone does not grant spending authority.
Privacy and eligibility limits
The draft restricts who can decrypt by defining which keys are eligible. Public keys that appear directly in a spending script, and xpub roots that could be exposed by spending, are excluded as recovery keys. This aims to prevent an on-chain public key from doubling as a decryption key for the off-chain backup.
The privacy warning is specific: if a wallet-service server already knows an account xpub and that same xpub is reused as an eligible recovery key in a multisig, the server could decrypt the backup if it obtains a copy. That would reveal metadata inside—descriptors, policies, structure—but not the private keys required to spend.
▲ 0.36%
Why it matters
The proposal targets a practical recovery gap for complex wallets that depend on data beyond a seed. Standardizing an encrypted backup format, and gating decryption to eligible xpub holders, could lower the risk of stranded funds after descriptor or cosigner key loss—without expanding spending risk. The trade-off is a conditional privacy exposure if xpubs are reused across roles and already known to third parties.
What to watch next
Key signals will be whether wallet vendors adopt the draft, how they select eligible xpubs, and whether services change practices around xpub disclosure and reuse. Also watch for further revisions to the Draft in the BIPs repository clarifying encryption parameters and implementation guidance.
This content is for informational purposes only and does not constitute financial advice.
🧠 HafidWatch Take
BIP138 tackles a genuine recovery gap by enabling access to descriptors and policies that seed phrases alone miss in complex wallets. The draft’s encrypted backup, gated by xpubs, allows recovery without private keys but introduces a conditional privacy risk if xpubs are reused or publicly known. The critical questions moving forward involve which xpubs wallets designate as eligible, how they prevent reuse, and whether services adjust their xpub disclosure practices. Monitoring wallet vendor adoption and shifts in best practices around descriptor and xpub management will be important.
Daily crypto intelligence. Before the market opens.
Including the Divergence Index — the sentiment gap no other newsletter tracks. Free, every morning at 7:30am ET.
✓ Free forever · ✓ No spam · ✓ 50+ sources monitored



