Tuga answers to approximately eleven names in this house. Her actual name, three diminutives, two sounds that aren't words, the formal version used when she is in trouble, and whatever the neighbours call her, which I suspect is something else entirely.
It is still one cat. The names are handles — different ways of reaching the same animal, each used in a different context, none of them her.
Your wallet works exactly this way, and understanding the layers resolves a lot of confusion: why a dozen words can restore thousands of addresses, why your wallet finds your money after a reinstall, and why one particular string is far more dangerous to share than people realise.
1. The Chain of Derivation
Four layers, each generated from the one above by mathematics, not by storage:
The recovery phrase. Twelve or twenty-four words encoding a single large random number. This is the cat. Everything below is derived from it, deterministically, forever.
The master private key. Computed from the phrase. Whoever has this controls everything the wallet can ever generate.
Derivation paths. A standardised structure — you may have seen something like m/84'/0'/0' in wallet settings — that splits the master key into separate branches: one per address type, per account, and separate chains for receiving addresses and for change. This is why a single phrase can hold several accounts that never mix.
The addresses. Each branch produces an effectively endless sequence: the first receiving address, the second, the thousandth. All of them derived from the same seed.
Nothing is stored anywhere. Your wallet doesn't keep a list of your addresses — it recomputes them, in order, every time. That's why "deterministic" matters: the same words always produce the same addresses, in the same order, in any compatible wallet, forever.
2. Why Restore Works
This explains the thing that feels like magic when you do the recovery drill.
You install a new wallet, enter your words, and within seconds it shows your balance. It didn't download your wallet from anywhere — there's nowhere to download it from. It regenerated the first batch of addresses from your phrase, asked the network which of them have unspent outputs, and added up the result.
If it looks empty after a restore, the usual cause is a mismatch rather than a loss: a different derivation path, or the wrong address type selected, or funds further down the sequence than the wallet's default scan distance (the "gap limit"). The coins are exactly where they were. The wallet is looking down the wrong branch.
Knowing that one fact will save somebody reading this an extremely unpleasant hour.
3. The Extended Public Key, and Why It Matters
Here's the layer most people have never heard of and really should.
Alongside the private keys, each branch has an extended public key — the xpub (or zpub/ypub, depending on the address type). It can generate every public address in that branch, but no private keys.
This is genuinely useful. It's how a watch-only wallet works: you can load an xpub onto a phone or a laptop, see your full balance and every incoming payment, and be completely unable to spend. Perfect for monitoring cold storage without ever exposing the hardware wallet, and for a business tracking receipts.
And it's a privacy hazard that catches people out. An xpub reveals every address you will ever use in that account, past and future. Anyone holding it can watch your entire financial life in that wallet in real time — not steal it, but see all of it, forever.
So: an xpub is not a secret in the way a seed is, and it is also not something to paste into a random website, a support chat, or a block explorer's "check my balance" box. Treat it as your bank statement rather than your bank card.
4. What to Share, and What Never To
Worth being very clear, in order of danger:
- Recovery phrase — never, to anyone, in any circumstance. This is total control.
- Private key for a single address — never. This is control of those coins.
- Extended public key (xpub) — only to software you'd trust with your full transaction history. Not a theft risk. A complete surveillance risk.
- An individual receiving address — freely. This is the thing you give people to pay you. It reveals that address's history, which is why you use a fresh one each time.
Most scams aimed at experienced users target the third line, not the first. People have learned not to give away their seed. Far fewer hesitate over an xpub, because it has "public" in the name.
5. Why It Was Designed This Way
Before this standard, wallets held a bag of unrelated keys and you had to back up the file again every time a new one was created. People lost money constantly to backups that were a week out of date.
Deterministic derivation fixed that permanently: back up once, at creation, and that backup covers everything the wallet will ever generate. Your metal plate from three years ago still protects coins received this morning.
It's the single biggest usability improvement in the history of self-custody, and almost nobody using it knows it's there.
The Point
Eleven names, one cat. The names are how different people reach her in different contexts; none of them is the animal, and knowing all eleven doesn't let you take her home.
Your seed is the cat. The addresses are the names. And the xpub is the list of every name she will ever answer to — harmless in the wrong sense, dangerous in the right one.
Back up the seed. Guard the xpub. Hand out addresses freely. 🐾⚡