Skip to main content
£0.00 0

Basket

No products in the basket.

ASIC mining articles and advice

BIP 38 Passphrase-Protected Private Keys: Security and Recovery Guide

BIP 38 encrypted private keys explained: understand 6P records, scrypt, EC-multiply mode, password risk, test vectors and safe recovery.

BIP 38 Passphrase-protected private key guide cover

This guide explains BIP 38 Passphrase-protected private key in plain English. It covers the problem behind the BIP, why it matters and whether the proposal is part of Bitcoin today.

TL;DR

  • What it is: BIP 38 defines printable Base58Check records for private keys encrypted under a passphrase. It was designed around paper wallets and physical bitcoins, including an EC-multiply mode in which a manufacturer can create a funded address without learning the owner’s passphrase-derived private key.
  • Why it matters: BIP 38 remains a defined encrypted-key format, but it concentrates recovery in one passphrase, one record and correct legacy software. Treat every 6P string as sensitive, test recovery before funding and prefer maintained deterministic custody for new deployments.
  • Current position: Its status is Deployed, but the BIP comments discourage new implementation, and password loss or weak entropy can still make funds unrecoverable or stealable.

BIP 38 Passphrase-protected private key in simple English

BIP 38 Passphrase-protected private key: A BIP 38 string is a 58-character Base58Check record beginning with 6P. Prefix and flag bytes identify non-EC-multiply or EC-multiply form and compressed-key handling.

Simple example

A node operator is checking BIP 38 Passphrase-protected private key. AES-256 encrypts two halves of the private key after XOR processing, and the result is encoded with the format prefix and flags.

Key terms in plain English

BIP:
Bitcoin Improvement Proposal: a document describing a proposed rule, standard or process. Its status must be checked separately.
Node:
A computer running Bitcoin software that checks data and communicates with other peers.

What a 6P record contains

A BIP 38 string is a 58-character Base58Check record beginning with 6P. Prefix and flag bytes identify non-EC-multiply or EC-multiply form and compressed-key handling. Salt, encrypted halves and address-derived check data follow. The string is encrypted private-key material, not a wallet seed or an ordinary address.

Non-EC-multiply encryption

For an existing private key, scrypt derives key material from the passphrase and a four-byte address hash. AES-256 encrypts two halves of the private key after XOR processing, and the result is encoded with the format prefix and flags. Decryption must recreate and compare the address hash to reject a wrong passphrase or wrong compression interpretation.

EC-multiply workflow

The owner creates an intermediate code from a passphrase-derived factor. A printer combines it with independently chosen seed material to produce an address and encrypted key without learning the final private key. Optional lot and sequence values organise batches. Confirmation codes let the owner verify that a generated address depends on the intended passphrase.

BIP 38 Passphrase-protected private key technical diagram
EC-multiply workflow: the fields, validation boundary and operational evidence that implementations need to agree.

Password and Unicode risk

scrypt slows guessing but does not rescue a short, reused or predictable passphrase. Unicode normalisation is part of interoperability: visually identical text can have different bytes if software handles it incorrectly. Recovery notes should state the exact characters and language method without placing the passphrase beside the encrypted record.

Address-hash leakage and false matches

A 32-bit hash of the resulting address is stored in plaintext as salt and a decryption check. It permits correlation with a likely address and can collide by chance. Software must derive the complete address and compare the defined bytes while treating a hash match as a check, not proof of ownership or balance.

Operational limitations

Paper degrades, QR print quality fails and single encrypted keys do not provide deterministic change-address recovery. Importing a key into an online wallet exposes it at decryption time, while sweeping requires fee and destination verification. Modern descriptor and hardware-wallet backups often give clearer recovery and audit properties.

Recovery rehearsal

Validate both encryption modes with official test vectors on offline, maintained software. Confirm compressed and uncompressed address cases, wrong passphrases, Unicode samples and confirmation codes. Then sweep a disposable test key into a new wallet rather than reusing it.

Frequently asked questions

What is the main point of BIP 38 Passphrase-protected private key?

BIP 38 Passphrase-protected private key: A BIP 38 string is a 58-character Base58Check record beginning with 6P.

For BIP 38 Passphrase-protected private key, what should a beginner know about what a 6P record contains?

A BIP 38 string is a 58-character Base58Check record beginning with 6P.

For BIP 38 Passphrase-protected private key, what should a beginner know about non-ec-multiply encryption?

For an existing private key, scrypt derives key material from the passphrase and a four-byte address hash.

For BIP 38 Passphrase-protected private key, what should a beginner know about ec-multiply workflow?

The owner creates an intermediate code from a passphrase-derived factor. A printer combines it with independently chosen seed material to produce an address and encrypted key without learning the final private key.

Conclusion

BIP 38 remains a defined encrypted-key format, but it concentrates recovery in one passphrase, one record and correct legacy software. Treat every 6P string as sensitive, test recovery before funding and prefer maintained deterministic custody for new deployments.

Primary sources

Check the current specification status and the documentation for the exact implementation you operate before moving production funds or changing a mining node.

ASIC MINER PICKS

Recommended ASIC Mining Hardware

Compare three of our highest ranked ASIC miners currently available, with live product details and pricing.
Overall ranking
Equihash
·
ZEC
Overall rank#1of 100AvailableAll: #5 / 831
Bitmain Antminer Z15K 525KSol Equihash Zcash Miner
Bitmain
Pre-Order
Hashrate
525KSOL
Efficiency
4.73W/KSOL
Power
2483W
Earns/kWh
40.9p
Free Shipping
Price · delivered
£6,050.00
ex VAT
Est. per month
£740.97
Payback 8.2 Months
Overall ranking
Equihash
·
ZEC
Overall rank#2of 100AvailableAll: #6 / 831
Bitmain Antminer Z15 Pro 800KSol Equihash Zcash Miner
Bitmain
In stock
Hashrate
800KSOL
Efficiency
3.3W/KSOL
Power
2640W
Earns/kWh
58.6p
Price · delivered
£11,925.00
ex VAT
Est. per month
£1129.10
Payback 10.6 Months
Overall ranking
SHA-256
·
BTC
Overall rank#6of 100AvailableAll: #12 / 831
Bitmain Antminer S23e Hydro 2U 865Th SHA-256 Bitcoin Miner
Bitmain
Pre-Order
Hashrate
865TH
Efficiency
10W/TH
Power
8650W
Earns/kWh
13.2p
Free Shipping
Price · delivered
£9,382.50
ex VAT
Est. per month
£832.64
Payback 11.3 Months
Browse all ASIC miners
MORE MINING ADVICE

More ASIC Mining Articles

Read practical advice about choosing hardware, calculating electricity costs, setting up miners, hosting and maintenance.
MINER COMMUNITY

Join the ASIC Mining Discussion

Ask a question or share what has worked for you. Your experience may help another miner make a better decision.

Members can read and join the discussion

Log in to read comments from other miners. Create a free account if you would like to ask a question or share your experience.

Log in to read comments Register to join the discussion

Membership helps us protect the discussion from spam and keep answers useful.

ASIC MINING SUPPORT

Need Help Choosing an ASIC Miner?

Tell us what you want to mine, your electricity cost and where the machine will run. We can help you compare hardware, power requirements, hosting and repairs.
Contact our mining team
Browse ASIC miners