← All articles

Seed phrase vs private key, and xpub

Published: September 29, 2026

A private key spends the coins sitting at one address. A seed phrase is not a private key written in words — it is the number every one of your private keys is derived from, including the ones for addresses you have not used yet. Lose control of one private key and you lose one address. Lose control of the seed phrase and you lose everything the wallet will ever hold.

That is the answer to the question, and every page on the subject gives it. What none of them mentions is the third thing derived from the same seed: the extended public key. It cannot spend a single satoshi, which is why people hand it over without thinking — and it reads every address and every payment in the account. We run notrace.exchange, a mixing service, so the privacy half of this is the half we care about.

Three things a wallet holds: seed phrase and private key never to be shared, and the extended public key that spends nothing but reads your whole history

What each of the three is

The seed phrase is a set of words — usually 12 or 24 — drawn from a fixed list of 2,048. The standard that defines them, BIP-39, is blunt about why they exist at all: "A mnemonic code or sentence is superior for human interaction compared to the handling of raw binary or hexadecimal representations of a wallet seed."

That sentence is worth reading twice, because it says what the words are not. They are not a password you chose. They are a human-readable encoding of a number your wallet generated, and the spec turns them back into that number mechanically: "To create a binary seed from the mnemonic, we use the PBKDF2 function with a mnemonic sentence (in UTF-8 NFKD) used as the password and the string "mnemonic" + passphrase (again in UTF-8 NFKD) used as the salt."

The private key is what actually signs. One key authorises spending from one address, and the signature is the only thing the network checks. A wallet holds many of them.

The relationship between the two is one-way and mechanical. The seed produces a master key, the master key produces children, the children produce grandchildren, and every private key in the wallet hangs off that tree. This is why a wallet asks for the words and not for a list of keys when you restore it: from the words it can rebuild the whole tree, including branches that were empty when you wrote the words down.

The practical difference, which is about blast radius

Put plainly:

  • A private key that leaks costs you one address. The rest of the wallet is untouched, because nothing about that key reveals its siblings.
  • A seed phrase that leaks costs you the wallet. Every address, past, present and future, is derived from it.
  • Importing a single private key into a new wallet brings only that address. People discover this at the worst moment — they import one key, see one balance, and assume the rest is gone.
  • Writing down the words covers addresses that do not exist yet. This is the property that makes backups practical, and it is also what makes the words worth stealing.

Everything above is standard advice and you can find it on any of the pages Google ranks for this question. Here is where they stop.

The third thing: the extended public key

Every branch of that tree has a public counterpart. The extended public key — the string usually starting xpub — is the part of a branch that can generate public keys, and therefore addresses, without being able to sign anything.

BIP-32, the standard that defines it, states the consequence in one line: "knowing an extended public key allows reconstruction of all descendant non-hardened public keys." Then it says what to do about that, in a sentence almost nobody quotes: "extended public keys must be treated more carefully than regular public keys."

Translate that into what actually happens to a person. Give somebody your xpub — a portfolio tracker, a tax tool, a merchant plugin, a block explorer's "watch this wallet" box, a form that asks you to "verify wallet ownership" — and that party can generate every address in the account and look up all of them. Not the one address you meant to show them. All of them, including the ones your wallet has not handed out yet, and with them the balance, the whole payment history and the timing of it.

On the theft axis the xpub is harmless. On the privacy axis it is the most concentrated thing you own: one string, your entire financial history. It is the exact mirror of the situation with a single address, where the danger is also observation rather than theft — what a wallet address is and who sees it covers that one.

And it is not quite harmless on the theft axis either. BIP-32 flags a second weakness that is easy to miss: "One weakness that may not be immediately obvious, is that knowledge of a parent extended public key plus any non-hardened private key descending from it is equivalent to knowing the parent extended private key (and thus every private and public key descending from it)." An xpub you gave away plus one child key that leaked later is the whole branch.

I checked whether this is really missing from the answers people get, rather than assuming it. Of the pages ranking for "seed phrase vs private key" I could open — Ledger's academy article and Datarecovery's guide — neither mentions extended public keys, watch-only wallets or privacy at all. Ledger's distinction is scope of control: "Your seed phrase controls many accounts whereas each private key controls just one." Correct, and only half the picture.

Where the xpub already is, whether you thought about it or not

This is not an exotic risk you have to opt into. The standard recipe for cold storage puts a watch-only wallet on the online computer precisely so you can see incoming payments without the keys being there — and a watch-only wallet is an xpub. The private key never touches the internet, which is the whole point, and meanwhile the machine on the internet holds the one string that describes every address in the account.

That is not an argument against cold storage; it is the same two-axis problem as everywhere else in this subject, and hot wallet vs cold wallet goes through it properly. It is an argument for noticing which of the two axes you are protecting when you set something up.

Two habits follow, and they are cheap:

  • Treat the xpub like the history it is, not like an address. Pasting it into a website is publishing your account.
  • If a service needs to watch one payment, give it one address. The xpub is for tools you would trust with a bank statement.

What nobody legitimate will ever ask for

A note that belongs in an article about seed phrases, because this is where the money is actually lost.

No exchange, no wallet vendor, no support agent and no mixing service needs your seed phrase or your private key. There is no operation that requires them except spending your coins. A request for either — in a chat, in a form, in a "wallet validation" step, in a recovery tool that promises to find funds — is a theft in progress, and the theft is instant and final once the words are typed. This is also why the phrase is worth more to an attacker than any single key: one paste, and every address in the tree goes at once.

Where we stand

notrace.exchange never asks for a seed phrase, a private key or an extended public key, and nothing about the service could use them. What it asks for is two addresses to pay out to. Beyond that:

  • the payout leaves as two transfers to those two addresses, each with its own delay; on 29 September 2026 each delay could be set from zero to 6 hours, and a transfer leaves no earlier than the delay you chose;
  • the service is custodial for the length of that wait, and section 8 of the terms says so in those words: from the moment your deposit settles until the last transfer has left, the service is the custodian of those funds;
  • each order comes with a letter signed with our PGP key, naming what you send, the least you will receive, both addresses and both delays;
  • our fee on 29 September 2026 was 0.5% and it is the only thing added to the quote; the current figure is on the FAQ page.

The limit is the same one as always: nothing here removes what is already written in the chain, and no service can. What changes is whether coins leaving a known address can be followed forward.

Where to start

If you came for the difference, it is blast radius: one key, one address; the words, everything. If the part you had not met before is the xpub, the useful next step is to look at what a single address already gives away — what a wallet address is and who sees it — and then at how those observations get joined into a person in is Bitcoin traceable.

And if you are choosing where to send coins from an address that is already known, the bitcoin mixer page opens the form with its current minimum; the checks in how to choose a bitcoin mixer start with the one above — anything asking for keys is not a service.

Share: