A new Bitcoin proposal could help users recover complex multisig wallets when seed phrases aren't enough, but its encrypted backup method might reveal sensitive wallet details to third parties with the right keys.
Bitcoin's new wallet recovery proposal, BIP138, is putting users and developers in a tough spot. It offers a way to back up complex multisignature wallets, but it also brings new privacy risks. The draft is now part of the official Bitcoin Improvement Proposals list. It lays out a backup method that could save funds from wallets that would otherwise be lost-if users are willing to accept the trade-offs.
Multisig recovery gaps
Multisignature wallets need more than one person to approve a transaction. They are supposed to make it harder to lose funds if one key is lost. But the reality is messier. A standard seed phrase can bring back a single signer's private keys, but it can't always rebuild the full set of public keys and spending rules that make up a multisig wallet. If the wallet's descriptor-a file that lists these details-is lost, even a working seed phrase might not be enough to get the money back.
BIP138 enables encrypted backups of wallet descriptors and policies, but does not include private keys, ensuring that backups cannot be used to spend funds directly.
BIP138 tries to solve this by creating an encrypted backup file. This file stores wallet descriptors, policies, and other details that a seed phrase misses. It leaves out private keys before encryption, so the backup can't be used to spend funds. Instead, anyone with a valid extended public key (xpub) from the original wallet can decrypt the backup. This lets them recover the public keys and script structure needed to rebuild the wallet.
Privacy risks and recovery limits
This approach isn't risk-free. If someone already has an eligible xpub and gets a copy of the encrypted backup, they can decrypt it. That would let them see how the wallet is set up and learn details about cosigners. They still can't spend the funds, but they could learn sensitive information. BIP138 tries to lower this risk by not letting public keys that show up directly in scripts or xpub roots that could be seen on-chain be used as recovery keys. If a cosigner's key is left out, that person can't use it to decrypt the backup. This makes it harder for on-chain data to be used to get off-chain details.
This privacy warning matters most for users who have shared their xpubs with wallet services or servers in the past. If the same xpub is used again in a multisig wallet and the service gets the encrypted backup, it could decrypt the file and see how the wallet is built. This isn't a reported breach, but it shows why key management and xpub hygiene are so important for multisig users. Bitcoin Optech recommends building multisig wallets from accounts whose xpubs have never been shared outside. Reusing exported xpubs makes it more likely that someone else could decrypt the backup. The decryption secret in BIP138 depends only on the original key set. Backups can't be "switched" to a new set of keys after they're made. This ties privacy and recovery to the first xpubs used.
Bitcoin Optech notes that a standard seed phrase alone may not be sufficient to restore a multisig wallet if the descriptor and related metadata are lost. Full recovery requires not just the keys, but also the wallet structure, including the set of participating xpubs, derivation paths, and script type.
Implementation and compatibility
There is a public Rust implementation of the BIP138 backup format. But the draft is still just a proposal, not a finished standard. The Liana wallet, for example, uses an older backup format that doesn't work with BIP138. So, even though the proposal is now in the repository, it doesn't mean wallets will support it right away or that users can use its features now.
This problem-balancing security and ease of use in crypto wallets-isn't just a Bitcoin issue. As reported earlier, even tokenized portfolios and DeFi products run into restrictions and technical problems that can block users or create new risks. The BIP138 debate shows that every new fix in crypto custody can bring new headaches, especially when privacy and recovery are pulling in different directions.
Bitcoin's network is still seeing a lot of work on wallet security and infrastructure. BIP138 is still a draft, but its release shows that developers are trying to fix real-world recovery failures that have locked users out of multisig wallets. The encrypted backup idea is a technical step forward, but its privacy trade-offs mean users and wallet makers will have to think carefully before using it widely.
Bitcoin's price and network activity are still strong. Daily transaction counts have stayed above 400,000 in recent months, according to public blockchain explorers. More people are using multisig wallets, especially institutions and high-net-worth users who want extra security. But backing up and recovering these wallets is still a big challenge for both individuals and organizations.
Multisignature wallets are meant to lower the risk of losing funds if one key is compromised. But they also bring new problems for operations and recovery. Unlike single-key wallets, multisig setups need careful handling of several keys, descriptors, and metadata. Losing any key part-especially the descriptor-can make funds impossible to reach, even if some keys are still safe. As wallet technology changes, users need to stay alert about backups, xpub sharing, and the privacy risks of new recovery tools. The BIP138 proposal shows the ongoing struggle between making wallets harder to lose and keeping sensitive information private.