When managing multiple wallets, every new wallet usually means another set of seed words to back up independently, which can be a hassle. BIP85 offers a different path: use one "master mnemonic" to derive multiple "child mnemonics," so backup only requires keeping the master mnemonic safe.

A leading global cryptocurrency platform,suitable for both beginners and experienced traders.
New user benefit: 20% off trading fees upon registration!!
But there is a key point that is easy to misunderstand: BIP85 does not increase security, and it does not make child wallets independent at the recovery level. It solves the problem of "too many backups, easy to lose," at the cost of concentrating the recovery ability of all child wallets into the master mnemonic. Understanding this trade-off is the prerequisite for using it well.
How BIP85 Works
BIP85 is a standard in the Bitcoin Improvement Proposals, with the full name "Deterministic Entropy From BIP32 Keychains." Its core mechanism is: using your existing wallet's master seed as input, it deterministically generates new entropy through a specific derivation path, and then converts that entropy into a standard BIP39 mnemonic phrase.
This new mnemonic is the "child mnemonic." It is no different from a mnemonic generated by an ordinary wallet and can be imported into any BIP39-compatible wallet. The key is "deterministic": the same master mnemonic, the same word count, and the same index will always produce exactly the same child mnemonic. This means you do not need to back up the child mnemonic itself. As long as you remember these three parameters, you can re-derive it at any time.
The derivation process is one-way. You can derive a child mnemonic from the master mnemonic, but you cannot reverse-engineer the master mnemonic from a child mnemonic, nor can you derive one child mnemonic from another. This allows child wallets to be used in relatively less secure environments, such as a mobile hot wallet. Even if a child mnemonic is leaked, the master wallet and other child wallets remain safe.
When BIP85 Is Suitable
If you only have one or two wallets and back up each mnemonic carefully, you may not need BIP85. Its value becomes apparent as the number of wallets grows.
Daily hot wallet on your phone. Many people keep most of their assets in a hardware wallet and leave a hot wallet on their phone for daily small payments. Use BIP85 to derive a child mnemonic from the hardware wallet's master mnemonic and import it into the mobile wallet. When changing phones or recovering the wallet later, you do not need to search for those 12 words that may have been lost long ago. As long as the hardware wallet still exists, you can re-derive the same child mnemonic.
Wallets for family or friends. You can derive a child mnemonic for family members and let them use it themselves. But you need to make it clear to them: as the holder of the master mnemonic, you can re-derive this child mnemonic at any time, so this is not an independently owned wallet. If the other person needs full autonomous control, they should generate their own mnemonic.
Avoid mnemonic reuse. Some users import the same mnemonic into multiple wallets. BIP85 provides an alternative: derive a different child mnemonic for each wallet, avoiding exposure of the same private keys across multiple software environments.
The following situations are not suitable for BIP85: you want child wallets to be completely isolated from the master wallet in security terms; you plan to hand a child wallet to someone else as a fully independent asset; you do not want to increase the complexity of records needed for recovery.
What to Back Up and How to Recover
BIP85's backup strategy is different from ordinary wallets. You do not need to copy every child mnemonic and hide it in different places. The only thing that needs secure backup is the master mnemonic. But you must also keep a "recovery map," otherwise you will not be able to restore the correct child wallets in the future.
Recovering a BIP85 child wallet requires all of the following information:
Master mnemonic (and optional passphrase, if the master wallet uses one)
Child mnemonic word count (12, 18, or 24 words)
Index number (the number used during generation, starting from 0)
Different word counts and indexes produce completely different child mnemonics. For example, a 12-word child mnemonic at index 0 and a 12-word child mnemonic at index 1 are two unrelated wallets. Forgetting the index does not directly cause asset loss, but it turns recovery into a trial-and-error process: you may need to try from 0 onward one by one until you find the correct child wallet. If the master wallet uses a passphrase, you must use exactly the same passphrase during recovery. Otherwise you will open a different master wallet, and the derived child mnemonics will be completely different.
Recording the "recovery map" does not require the same level of secrecy as copying a mnemonic, because it does not contain any private key information. You can use a simple table to note the purpose, word count, and index of each child wallet. But the backup of the master mnemonic must follow the standard you use for backing up core assets, because anyone holding the master mnemonic can derive all child wallets you generated with BIP85.
Generating Child Mnemonics on Hardware Wallets
BIP85 is a relatively new feature, and not all hardware wallets support it. Currently, devices with native BIP85 support include COLDCARD (Mk4, Mk5, Q series), BitBox02, KeepKey, AirGap Vault, and Specter DIY. Ledger and Trezor do not currently support BIP85.
If you are using a hardware wallet that supports BIP85, the general process is as follows. Exact button names and menu levels may differ depending on the firmware version, so it is recommended to check the official documentation for the current version of your device before operating.
On COLDCARD: Go to Advanced/Tools, select Derive Seed B85 (Mk4/Mk5) or Derive Seeds (BIP-85) (Q series). Choose the output format, usually BIP39 mnemonic, enter the index number (0–9999), and the device will display the derived child mnemonic.
On BitBoxApp: Connect and unlock the BitBox02, and make sure the target master wallet is loaded. Go to Settings → Expert settings → Show BIP-85 child key. Confirm Derive BIP-39 mnemonic? on the device, choose the word count and index, and record the child mnemonic shown on the device screen.
On KeepKey: Go to Settings → BIP85 Derived Seeds, select the index and word count, and the device screen will display the child mnemonic after generation.
One operational detail is worth noting: child mnemonics should only be recorded on offline media. Do not photograph, scan, copy to a computer or phone, enter into a password manager, or store in the cloud. Write them down with pen and paper, or if the wallet supports it, import them directly into the target wallet through a secure method to avoid leaving plaintext copies in intermediate steps.
Recovery Paths
When recovering a BIP85 child wallet, the path differs depending on what you have.
If you have the master mnemonic and recovery map: This is the most complete path. Reload the master wallet on a BIP85-capable device, re-derive using the same word count and index, obtain exactly the same child mnemonic, and import it into the target wallet.
If you only have the master mnemonic and forgot the index: You can still recover, but you will need to try. Start from index 0 and derive one by one using the word count you remember, checking whether the generated addresses match the original wallet. If you also forgot the word count, you will need to try 12, 18, and 24 words as well. This is where the value of the recovery map becomes clear: without it, recovery can be quite time-consuming.
If you only have the child mnemonic and no master mnemonic: You can use the child mnemonic to directly recover that child wallet. This mnemonic is a standard BIP39 mnemonic and can be imported into any compatible wallet. But you cannot use it to recover the master wallet or other child wallets, nor can you re-derive this child mnemonic, because it is itself the result of derivation, not the source.
If the master wallet uses a passphrase: You must enter exactly the same passphrase during recovery. A wrong or missing passphrase will lead to a different master wallet, and the derived child mnemonic will have no relation to the original child wallet.
A Limitation That Is Easy to Overlook
After a BIP85 child mnemonic is generated, it can be imported into any BIP39-compatible wallet. But if you import the child mnemonic into a software wallet, that child wallet becomes a hot wallet. Its security depends on the computer or phone you imported it into, not on the hardware wallet that generated it. BIP85's deterministic recovery ability does not make a software wallet more secure.
Also, when using BIP85 to create wallets for others, the other party needs to understand that you still retain the ability to recover them. Technically, this is a set of "mnemonics that can be regenerated by the creator," not an independent proof of ownership.

A leading global cryptocurrency platform,suitable for both beginners and experienced traders.
New user benefit: 20% off trading fees upon registration!!
References
- Bitcoin BIPs·BIP 85: Deterministic Entropy From BIP32 Keychains, no update date indicated; checked on 2026-10-05.
- KeepKey·BIP85 Derived Seeds, no update date indicated; checked on 2026-10-05.
- BitBox·What is BIP-85 and how does it work?, published 2025-04-11; checked on 2026-10-05.
- BitBox·One backup, infinite possibilities: BIP-85 child keys explained, published 2025-08-13; checked on 2026-10-05.
- BitBox·How to generate a BIP-85 child key with your BitBox, published 2026-07-29; checked on 2026-10-05.
- BitBox·What are BIP-85 child keys, and should you use them?, published 2026-07-29; checked on 2026-10-05.
- Coinkite·One COLDCARD, Many Wallets: Better Backups with BIP-85, published 2026-07-28; checked on 2026-10-05.
- AirGap·Setup BIP-85, no update date indicated; checked on 2026-10-05.


