Bitcoin’s latest improvement draft, identified as BIP138, was added to the repository on September 21. The proposal targets a specific weakness of multisignature wallets: losing the descriptor that describes the signing keys and spending rules. While a seed phrase can recreate a signer’s private keys, it cannot rebuild a complex script if the descriptor is missing. BIP138 suggests keeping that missing information in an encrypted container so the wallet can be reconstructed even after a seed loss.

Structure of the encrypted backup

The backup file is designed to hold descriptors, policy definitions, and other metadata that are not derivable from a seed. Before encryption, any private key material must be stripped out, leaving only public-key-related data. The file can be decrypted by anyone who possesses an “eligible” extended public key (xpub) that matches the wallet’s configuration. The xpub itself does not grant the ability to sign transactions; it merely allows the holder to read the encrypted metadata.

Privacy considerations and potential exposure

A key safeguard in the draft is the exclusion of certain public keys from being considered eligible decryption keys. Keys that appear directly in a script or that could be revealed through spending are barred from opening the backup. This prevents an on-chain public key from automatically becoming a decryption credential. However, the proposal notes a conditional risk: if a service already knows an account’s xpub—perhaps because it was disclosed before the multisig was created—and that same xpub is later used as an eligible key, the service could obtain a copy of the backup and decode the stored descriptors. While this would not let the service sign transactions, it would reveal the wallet’s structure and other non-spending data.

Implementation status and compatibility

A public Rust reference implementation and command-line build instructions are available, but the draft remains a specification rather than a network-level change. Existing wallets such as Liana employ an older backup format that is not compatible with the BIP138 layout, meaning current software would need updates to adopt the new method. The draft does not guarantee that all wallets will support the format immediately, nor does it mandate any changes to the Bitcoin protocol itself.

Why it matters

Multisignature setups are increasingly popular for custodial services, corporate treasuries, and high-value holders seeking extra layers of security. By providing a way to back up the non-seed components of a multisig wallet, BIP138 could reduce the risk of permanent fund loss due to descriptor corruption. At the same time, the conditional exposure of metadata to parties that already know an xpub adds a subtle privacy consideration that developers and users must weigh. The balance between recoverability and confidentiality will shape how quickly the community embraces the draft and whether wallet providers integrate the encrypted backup format into their products.

Why it matters

The proposal offers a practical solution to a known recovery problem for complex Bitcoin wallets, but its reliance on xpubs introduces a new attack surface. Adoption decisions will hinge on how the ecosystem evaluates the trade-off between enhanced backup capability and the potential for metadata leakage.