BIP85 — Deterministic Entropy
BIP85 lets a single BIP32 master key generate deterministic
entropy at child paths. Each child can become:
- A separate BIP39 mnemonic.
- A WIF private key.
- A separate xprv.
- HEX bytes for any other use.
The parent seed still backs everything; only one paper backup needed.
Path structure
m/83696968'/<app_id>'/<index>'
83696968' = ASCII for BIP85 (0x4F 0x4E 0x53 0x4F...
actually it's the ASCII codes). Hardened.
app_id = which sub-application (BIP39 mnemonic, WIF, xprv, etc.).
index = nth child for this app.
App IDs (selected)
| App ID |
Output |
Path suffix |
| 39 |
BIP39 mnemonic |
<app_id=39>'/<lang>'/<words>'/<index>' |
| 2 |
HD-Seed WIF |
<app_id=2>'/<index>' |
| 32 |
XPRV |
<app_id=32>'/<index>' |
| 128169 |
HEX bytes |
<app_id=128169>'/<num_bytes>'/<index>' |
| 707764 |
PWD-base85 |
password generator |
BIP39 example
parent: m/83696968'/39'/0'/12'/0' (English, 12 words, index 0)
HMAC-SHA512(key="bip-entropy-from-k", msg=childkey) → 64 bytes
take first 16 bytes → 128 bits of entropy
add BIP39 checksum → 12-word mnemonic
The result is a deterministic 12-word mnemonic. Any future derivation
from the parent at the same path always returns the same 12 words.
Why BIP85
Use cases:
- Multi-account separation — one master, many independent BIP39
wallets for different purposes (savings, payments, hot wallet).
- Children's wallets — give kids a seed deterministically derived
from your master.
- Hardware-wallet-internal sub-seeds — Coldcard's "Drunken Sailor"
uses BIP85 to spawn sub-seeds for deniability.
- App keys — derive a deterministic Nostr key, GPG key, encryption
key for cloud backup.
- Device backups — Foundation Passport uses BIP85 for reproducible
device-id seed.
Hardware wallet support
| Device |
BIP85 |
| Coldcard Mk4 / Q |
yes (full app catalogue) |
| Trezor (T / Safe) |
yes via Suite |
| Ledger |
yes via 3rd-party app |
| BitBox02 |
partial |
| SeedSigner |
yes |
| Krux |
yes |
| Specter DIY |
yes |
Implementation
def bip85_derive(master_xprv, path, app_args):
child_xprv = derive_path(master_xprv, path)
k = child_xprv.private_key
entropy = HMAC_SHA512(key="bip-entropy-from-k", msg=k)
return apply_app(app_id, entropy[:N], app_args)
# For BIP39 mnemonic at index 0, 12 English words:
seed12 = bip85_derive(master, "m/83696968'/39'/0'/12'/0'", "bip39_12")
Security implications
- A child seed derived via BIP85 is fully independent in terms of
keys derived under it (different secp256k1 group, different addresses).
- BUT: anyone with the parent seed can derive ANY child. Compromising
the parent compromises all children.
- Conversely, a child can be backed up / shared / lost without
affecting the parent.
Common pitfalls
- Treating BIP85 child as "stronger" than parent — they're equally
strong, just deterministically related.
- Confusing BIP85 path with BIP44 path — BIP85 always starts at
m/83696968', never at m/44'/0'/....
- Generating a child mnemonic and sharing it without realizing the
parent backup also unlocks it.
- Re-deriving with a different
lang or words count — produces
totally different output.
See also
1---2name: bitcoin-wallet-entropy3description: BIP85 deterministic entropy: derive child entropy/seeds from a parent BIP32 path. Used for sub-wallets, cross-app keys, deterministic randomness without separate backups. USE WHEN: spawning sub-wallets from one master seed, generating encryption keys deterministically, building a "memory" of one seed.4---56# BIP85 — Deterministic Entropy78BIP85 lets a single BIP32 master key generate **deterministic9entropy** at child paths. Each child can become:10- A separate BIP39 mnemonic.11- A WIF private key.12- A separate xprv.13- HEX bytes for any other use.1415The parent seed still backs everything; only one paper backup needed.1617## Path structure1819```20m/83696968'/<app_id>'/<index>'21```2223- `83696968'` = ASCII for `BIP85` (`0x4F` `0x4E` `0x53` `0x4F`...24 actually it's the ASCII codes). Hardened.25- `app_id` = which sub-application (BIP39 mnemonic, WIF, xprv, etc.).26- `index` = nth child for this app.2728## App IDs (selected)2930| App ID | Output | Path suffix |31|--------|--------|-------------|32| 39 | BIP39 mnemonic | `<app_id=39>'/<lang>'/<words>'/<index>'` |33| 2 | HD-Seed WIF | `<app_id=2>'/<index>'` |34| 32 | XPRV | `<app_id=32>'/<index>'` |35| 128169 | HEX bytes | `<app_id=128169>'/<num_bytes>'/<index>'` |36| 707764 | PWD-base85 | password generator |3738## BIP39 example3940```41parent: m/83696968'/39'/0'/12'/0' (English, 12 words, index 0)42HMAC-SHA512(key="bip-entropy-from-k", msg=childkey) → 64 bytes43take first 16 bytes → 128 bits of entropy44add BIP39 checksum → 12-word mnemonic45```4647The result is a deterministic 12-word mnemonic. Any future derivation48from the parent at the same path always returns the same 12 words.4950## Why BIP855152Use cases:53- **Multi-account separation** — one master, many independent BIP3954 wallets for different purposes (savings, payments, hot wallet).55- **Children's wallets** — give kids a seed deterministically derived56 from your master.57- **Hardware-wallet-internal sub-seeds** — Coldcard's "Drunken Sailor"58 uses BIP85 to spawn sub-seeds for deniability.59- **App keys** — derive a deterministic Nostr key, GPG key, encryption60 key for cloud backup.61- **Device backups** — Foundation Passport uses BIP85 for reproducible62 device-id seed.6364## Hardware wallet support6566| Device | BIP85 |67|--------|-------|68| Coldcard Mk4 / Q | yes (full app catalogue) |69| Trezor (T / Safe) | yes via Suite |70| Ledger | yes via 3rd-party app |71| BitBox02 | partial |72| SeedSigner | yes |73| Krux | yes |74| Specter DIY | yes |7576## Implementation7778```python79def bip85_derive(master_xprv, path, app_args):80 child_xprv = derive_path(master_xprv, path)81 k = child_xprv.private_key82 entropy = HMAC_SHA512(key="bip-entropy-from-k", msg=k)83 return apply_app(app_id, entropy[:N], app_args)8485# For BIP39 mnemonic at index 0, 12 English words:86seed12 = bip85_derive(master, "m/83696968'/39'/0'/12'/0'", "bip39_12")87```8889## Security implications9091- A child seed derived via BIP85 is **fully independent** in terms of92 keys derived under it (different secp256k1 group, different addresses).93- BUT: anyone with the parent seed can derive ANY child. Compromising94 the parent compromises all children.95- Conversely, a child can be backed up / shared / lost without96 affecting the parent.9798## Common pitfalls99100- Treating BIP85 child as "stronger" than parent — they're equally101 strong, just deterministically related.102- Confusing BIP85 path with BIP44 path — BIP85 always starts at103 `m/83696968'`, never at `m/44'/0'/...`.104- Generating a child mnemonic and sharing it without realizing the105 parent backup also unlocks it.106- Re-deriving with a different `lang` or `words` count — produces107 totally different output.108109## See also110111- [hd/SKILL.md](../hd/SKILL.md)112- [backup/SKILL.md](../backup/SKILL.md)113- [../../cryptography/bip32/SKILL.md](../../cryptography/bip32/SKILL.md)