Respuestas a preguntas reales
De las 551 preguntas del tag wallet-recovery de Bitcoin Stack Exchange, sólo 5 son de alguien que perdió una palabra de la semilla. Éstas son las otras.
Todas se leen sin JavaScript, no guardan nada y no pueden enviar información a ningún lado. Ninguna te pide tu frase semilla — si un sitio te la pide, te está pidiendo la billetera.
En castellano
- Restauré mi semilla y la wallet está vacíaCasi nunca es plata perdida. Una misma semilla abre cuatro billeteras distintas y sólo una tiene tus fondos: el problema es el tipo de dirección, no la clave.
- Restauré mi semilla pero había una passphrase y no la recuerdoCon BIP-39 no existe la passphrase incorrecta: cualquier texto que escribas abre una billetera válida y vacía, sin ningún mensaje de error. Qué significa eso y qué se puede hacer.
- Mi semilla de Electrum no funciona en otra walletElectrum no genera semillas BIP-39: su frase lleva adentro un número de versión. Por eso otra billetera la rechaza o —peor— la acepta y te muestra una cuenta vacía.
- Perdí o se me rompió la hardware wallet: ¿perdí los bitcoin?El aparato no guarda tus bitcoin. Guarda una llave que se puede reconstruir. Lo que decide si los recuperás no es el dispositivo: es qué anotaste además de las doce palabras.
- xpub, ypub, zpub: cuál es la diferencia y por qué importaEl prefijo de tu clave pública maestra no es un detalle de formato: codifica qué tipo de dirección deriva esa rama. Por eso la misma semilla puede mostrarte saldo cero sin que nada falle.
- Cómo probar que tu frase semilla funciona sin mover los bitcoinLa suma de verificación dice que la frase tiene la forma correcta, no que sea la tuya. Cómo comprobar que lo que anotaste abre tu billetera, usando sólo la parte pública y sin mover un satos
- Qué anotar además de las doce palabrasSi la dirección no coincide con ninguno de los cuatro formatos, falta un dato que no es la semilla. Cuáles son, por qué no son secretos, y por qué casi nadie los anota.
- Mi respaldo funciona: ¿y ahora qué?Comprobaste que tu papel deriva tu dirección. Qué probaste exactamente, qué NO probaste todavía, y las cinco líneas que conviene anotar al lado.
- Clasifiqué 551 preguntas de recuperación de wallets: casi nadie perdió la semillaDe las 551 preguntas del tag wallet-recovery de Bitcoin Stack Exchange, sólo 5 son de alguien que perdió una palabra. 429 son 'tengo el respaldo y no puedo reconstruir la wallet'. Qué les fa
- Faltan transacciones después de restaurar mi semillaEl escaneo se detiene tras 20 direcciones sin uso: por eso una wallet puede no mostrar fondos que están más allá de ese hueco.
- Cómo se lee tu diagnósticoQué significa un riesgo estructural, por qué el motor puede declarar un empate en vez de inventar un orden, y por qué nada figura como probado hasta que lo probás.
- ¿Qué es barrer (sweep) una clave y en qué se diferencia de restaurarla?Barrer una clave manda tus fondos con una transacción real a una billetera nueva y queda en la cadena; restaurar solo los muestra donde están. Pagás comisión en un caso, en el otro no.
- ¿Puede una billetera creada antes de 2021 tener una dirección bc1p?Las direcciones bc1p de Taproot existen desde noviembre de 2021: si tu billetera es anterior y muestra una, hay algo que no cierra.
- ¿Por qué mi wallet restaurada muestra direcciones bc1p y no mis bitcoin?BIP-86 es el estándar de derivación que genera direcciones bc1p de una sola clave. Si tu wallet restaurada las muestra, está usando el propósito 86'.
- Mi wallet dice que el descriptor tiene checksum inválido: ¿lo copié mal?El checksum de un descriptor detecta cualquier error de un solo símbolo, y también dos o tres errores en descriptores largos, pero no confirma que el descriptor sea el tuyo.
- Compartí mi xpub y una clave privada hija: ¿pueden vaciar mi wallet?Si alguien tiene tu xpub y una sola clave privada hija no endurecida, tiene el equivalente a tu clave privada extendida: todas las claves del árbol.
- deriveaddresses me pide checksum en el descriptor: por qué no imprime direccionesBitcoin Core no imprime direcciones si el descriptor no trae checksum: deriveaddresses lo exige en la entrada y solo muestra las direcciones que va a producir.
- ¿Cuál descriptor elijo: pkh(), sh(wpkh()), wpkh() o tr()?Los cuatro tipos de descriptor de una sola clave en Bitcoin Core son pkh(), sh(wpkh()), wpkh() y tr(); cada uno corresponde a una forma de dirección.
- ¿Por qué mi descriptor no me deja firmar?Un descriptor de solo claves públicas no puede firmar: Bitcoin Core devuelve hasprivatekeys: false. Qué significa y qué hacer.
- Mi saldo bajó más de lo que gasté: ¿dónde está el vuelto?El vuelto de un pago no desaparece: va a una dirección nueva de tu propia billetera, en la rama de cambio /1/ del camino BIP-44.
- ¿Dónde está guardada mi clave maestra?No está en ningún servidor ni en la app: tu clave maestra se calcula con HMAC-SHA512 a partir de tu semilla y la frase Bitcoin seed. Por eso el mismo respaldo da lo mismo en cualquier wallet
- ¿Dónde está guardado mi saldo de Bitcoin?Tu saldo no está anotado en ningún lado: es la suma de salidas sin gastar (UTXOs) que tus claves pueden mover. La blockchain no tiene cuentas.
- Escribí mal la passphrase y me abrió una wallet distinta: ¿es normal?BIP-39 no tiene passphrase equivocada: cualquier cadena que escribas genera una wallet válida y distinta, sin error ni aviso. Por eso un error de tipeo no se detecta.
- ¿Este descriptor tiene mis claves privadas?Podés usar getdescriptorinfo para ver si un descriptor trae material privado: el campo hasprivatekeys lo dice sin gastar bitcoin.
- ¿Puedo firmar una transacción Bitcoin sin conectar mi wallet a internet?El formato PSBT lleva todo lo que necesita un firmante: podés firmar una transacción sin ver la cadena ni acceder a las salidas que estás gastando.
- Junté partes de SLIP-39 de dos respaldos distintos y no me deja restaurarLas partes de SLIP-39 de repartos distintos no se combinan aunque usen el mismo esquema y tengan la misma pinta: juntarlas puede dejarte sin acceso. Etiquetá bien.
- Mi billetera muestra una dirección distinta cada vez: ¿es normal?Ver una dirección nueva al recibir no es un error: es privacidad por diseño. Las direcciones viejas siguen siendo tuyas y funcionan para siempre.
- Mi descriptor de Bitcoin Core tiene un xprv: ¿puse mal la wallet?Bitcoin Core acepta material privado en un descriptor: donde va una clave pública o un xpub, también entra un xprv o un WIF. Esto no lo vuelve un respaldo completo.
- Mi frase de 12 palabras no funciona en Bitcoin CoreBitcoin Core nunca soportó frases BIP-39: no podés restaurar tus 12 palabras ahí de forma nativa. Su respaldo es otro formato (wallet.dat / descriptores).
- Mi respaldo tiene 20 o 33 palabras por parte: ¿es SLIP-39?SLIP-39 divide la semilla en partes Shamir: cada parte tiene 20 palabras para 128 bits, y 33 palabras para 256 bits.
- ¿Necesito una semilla distinta para cada wallet?BIP-85 permite derivar de una sola semilla la entropía de todas tus wallets: no hace falta guardar un respaldo distinto por cada una.
- Mi paper wallet tiene una clave privada suelta y no una frase de 12 palabrasLas paper wallets viejas guardan una clave privada WIF (empieza con 5, K o L, o 6P si está cifrada con BIP-38), no una frase semilla: ningún juego de 12 palabras la reconstruye.
- ¿Por qué mi dirección de Bitcoin empieza con 1, 3 o bc1?Las direcciones clásicas empiezan con 1, las SegWit anidadas en P2SH con 3 y las nativas con bc1. El prefijo es el formato, no una alarma.
- ¿Por qué no aparece mi dirección de Bitcoin en el explorador?Una dirección que nunca recibió fondos no figura en la blockchain: los exploradores indexan transacciones, no direcciones posibles.
- ¿Puede mi frase semilla tener otra cantidad que no sea 12, 15, 18, 21 o 24 palabras?BIP-39 define frases de 12, 15, 18, 21 o 24 palabras, y ninguna otra cantidad. Si tu respaldo tiene otro largo, no es BIP-39; acá te contamos qué hacer.
- Puse mi semilla pero no aparece mi billetera multifirmaSi usabas una multifirma, tener tus palabras no alcanza. Necesitás las claves públicas de todos los participantes para que la wallet sepa qué direcciones buscar.
- ¿Por qué mi wallet restaurada tarda días en sincronizar?Saber en qué año creaste la billetera convierte un re-escaneo de días en minutos: el nodo puede arrancar desde esa altura en vez de revisar toda la cadena.
- Restauré mi semilla y la wallet muestra testnet: ¿dónde están mis bitcoin?El segundo nivel del camino de derivación usa coin_type 0 para Bitcoin y 1 para testnet, según SLIP-0044. Si ves saldo en testnet, tu wallet está mirando en la red equivocada.
- Restauré mi semilla y desaparecieron las etiquetasCuando restaurás tu wallet desde la semilla, la plata vuelve pero las etiquetas no: no hay un estándar definido para transferirlas. BIP-329 existe para eso.
- ¿Son suficientes 12 palabras para mi semilla?12 palabras son 128 bits de entropía y 24 son 256, pero nadie fuerza 2^128: la diferencia en la práctica es cero.
In English
- My seed restores but the wallet is emptyIt is almost never lost money. One seed opens four different wallets and only one holds your coins: the problem is the address type, not the key.
- My seed restored but there was a passphrase and I don't remember itBIP-39 has no wrong passphrase: every string you type opens a valid, empty wallet with no error message. What that means, and what can still be done.
- My Electrum seed does not work in another walletElectrum does not generate BIP-39 seeds: its phrase carries a version number inside. That is why another wallet rejects it — or worse, accepts it and shows you an empty account.
- I lost or broke my hardware wallet: are my bitcoin gone?The device does not hold your bitcoin. It holds a key that can be rebuilt. What decides whether you get them back is not the device: it is what you wrote down besides the twelve words.
- xpub vs ypub vs zpub: what the difference is and why it mattersThe prefix on your master public key is not a formatting detail: it encodes which address type that branch derives. That is why the same seed can show you a zero balance with nothing failing
- How to test your seed phrase without moving your coinsThe checksum says the phrase has the right shape, not that it is yours. How to prove what you wrote down rebuilds your wallet, using only the public side and without moving a satoshi.
- What to write down besides your 12 wordsIf the address doesn't match any of the four formats, a piece is missing — and it isn't the seed. What those pieces are, why they aren't secrets, and why almost nobody writes them down.
- My backup works: now what?You proved your paper derives your address. What that did prove, what it did not prove yet, and the five lines worth writing next to it.
- I classified 551 wallet-recovery questions: almost nobody lost their seedOf the 551 questions in the wallet-recovery tag on Bitcoin Stack Exchange, only 5 are from someone who lost a seed word. 429 are variants of 'I have the backup and cannot rebuild the wallet'
- Restored my seed but some transactions are missingScanning stops after 20 unused addresses in a row, so a wallet can miss transactions that are further out and show an incomplete balance even with the right seed.
- How to read your diagnosisWhat a structural risk actually means, why the engine will declare a tie instead of inventing an order, and why nothing counts as proven until you prove it.
- Why does my restored wallet show bc1p addresses instead of my bitcoins?BIP-86 is the derivation standard that generates single-key bc1p addresses. If your restored wallet shows them, it's using purpose 86'.
- Can my seed phrase have a word count other than 12, 15, 18, 21, or 24?BIP-39 defines phrases of 12, 15, 18, 21, or 24 words, and no other amount. If your backup has a different length, it is not BIP-39; here's what to do.
- deriveaddresses asks for a checksum: why Bitcoin Core won't print addresses without itBitcoin Core won't print addresses unless the descriptor includes its checksum: deriveaddresses demands it in the input and only lists the addresses the descriptor will produce.
- Which descriptor should I choose: pkh(), sh(wpkh()), wpkh(), or tr()?Bitcoin Core lists four single-key descriptor types: pkh(), sh(wpkh()), wpkh(), and tr(). Each corresponds to a different address format.
- Why won't my descriptor let me sign?A public keys only descriptor cannot sign: Bitcoin Core returns hasprivatekeys: false. What it means and what to do.
- Do I need a separate seed for each wallet?BIP-85 lets you derive entropy for every wallet you use from a single seed, so you don't need to keep a separate backup for each.
- Does this descriptor have my private keys?You can use getdescriptorinfo to check if a descriptor has private material: the hasprivatekeys field tells you without using it.
- I entered my seed but my multisig wallet is emptyRestoring a multisig wallet requires more than just your recovery phrase. You need the public keys of all participants to locate your bitcoin and restore your funds.
- I typed my passphrase wrong and my wallet opened a different one: is that normal?BIP-39 has no wrong passphrase: any string you type generates a valid, different wallet with no error or warning. That's why a typo in your passphrase is never detected.
- My wallet says invalid descriptor checksum: did I copy it wrong?A descriptor checksum detects any single-symbol error, and two or three errors in long descriptors, but it doesn't confirm you're using the right descriptor.
- Is a 12-word seed enough? 12 vs 24 words security12 words are 128 bits of entropy and 24 are 256, but nobody forces 2^128: the practical difference is essentially zero.
- I mixed SLIP-39 shares from different sets and now I can't restoreSLIP-39 shares from different sets are incompatible even if they look the same: mixing them can lock you out. Why it's not a flaw and how to label them.
- My 12-word seed doesn't work in Bitcoin CoreBitcoin Core never supported BIP-39 phrases: you can't restore your 12 words there natively. Its backup is another format (wallet.dat / descriptors).
- My backup has 20 or 33 words per share: is it SLIP-39?SLIP-39 splits the seed into Shamir shares: each share has 20 words for 128 bits, and 33 words for 256 bits, not a mistake.
- My Bitcoin Core descriptor has an xprv: did I set up my wallet wrong?Bitcoin Core accepts private material in a descriptor: where a public key or an xpub goes, an xprv or a WIF also works. That does not make the descriptor a complete backup.
- My wallet shows a different address every time: is that normal?Seeing a new address when you hit receive is not a glitch: it is privacy by design. Old addresses remain yours and keep working forever.
- My old paper wallet has a single private key, not a 12-word seedOld paper wallets store a single WIF private key (starts with 5, K or L, or 6P if encrypted with BIP-38), not a seed phrase: no set of 12 words reconstructs it.
- Restored my seed and my wallet shows testnet: where are my bitcoin?The second level of the derivation path is the coin_type in SLIP-0044: 0 is Bitcoin and 1 is testnet. If you see a testnet balance, your wallet is looking at the wrong network.
- I restored my seed and my labels are goneWhen you restore a wallet from seed, the coins come back but the labels don't: there's no defined standard to transfer them. BIP-329 exists for that.
- I shared my xpub and a child private key: can they drain my wallet?If someone has your xpub and a single non-hardened child private key, they have your extended private key: every key in the tree.
- Can I sign a Bitcoin transaction without connecting my wallet to the internet?The PSBT format carries everything a signer needs: you can sign a transaction without seeing the chain or the outputs being spent.
- What does sweep mean in Electrum and how is it different from restoring a key?Sweeping a key sends your funds with a real transaction to a new wallet and lands on-chain; restoring only shows where they are. One pays a fee, the other doesn't.
- Can a wallet created before 2021 have a bc1p address?Taproot bc1p addresses only exist since November 2021. If your wallet is older and shows one, something doesn't add up.
- My restored wallet says it will take days to rescan: how do I speed it up?Knowing what year you created the wallet turns a days-long rescan into minutes: the node can start from that height instead of scanning the entire blockchain history.
- Where is my Bitcoin balance stored?Your balance isn't written down anywhere: it's the sum of unspent outputs (UTXOs) your keys can move. The blockchain has no accounts.
- My balance dropped more than I sent: where did the change go?Change from a payment doesn't disappear: it goes to a new address in your own wallet, on the /1/ change branch of the BIP-44 path.
- Where is my wallet's master key stored?It's not on any server or in the app: your master key is calculated with HMAC-SHA512 from your seed and the phrase Bitcoin seed. That's why the same backup works in any standard wa
- Why does my Bitcoin address start with 1, 3 or bc1?Bitcoin addresses start with 1 (legacy), 3 (nested SegWit) or bc1 (native SegWit). The prefix identifies the format, not whether your coins are safe.
- Why doesn't my Bitcoin address show up on a block explorer?An address that never received funds won't appear on the blockchain: explorers index transactions, not possible addresses.
¿Querés comprobar tu propio respaldo en vez de leer? La ceremonia deriva tu primera dirección a partir de la clave pública extendida que anotaste y la coteja con la que muestra tu billetera. Menos de dos minutos, en tu navegador, sin pedir la semilla.