Skip to content
Derivation Path Recovery - Crypto Wallet Recovery New Zealand

Derivation path recovery

Derivation Path Recovery

HD wallet path scanning across standards, accounts and address gaps

A single BIP-39 phrase does not produce one wallet. Through hierarchical deterministic derivation it generates an entire tree of addresses, and the phrase's checksum validates the words but encodes nothing about which branch of that tree your funds are on. Different wallet software defaults to different paths - legacy, nested SegWit, native SegWit, Taproot, across multiple account indices. When a restore shows zero but the blockchain confirms the funds are still there, the problem is almost always which branch is being scanned, not a lost phrase. Systematic path enumeration against a known address resolves the overwhelming majority of these cases.

10%recovery fee
Only charged on successful recovery

Meet the team

Meet our recovery experts

A team built on years of experience across New Zealand's most complex crypto matters.

Our methods

How we recover from the wrong derivation path

Every recovery is methodical and fully offline. Your key material never leaves our air-gapped equipment, and the work happens in an environment of your choosing.

Derivation path enumeration

Systematically scanning the address tree a single phrase generates, rather than sampling it.

  • One phrase derives a full tree of addresses through the path m / purpose' / coin type' / account' / change / index
  • The purpose level alone changes which address family a wallet displays, from the same phrase
  • Different routes through the tree surface entirely different balances
  • Scanning proceeds exhaustively across the standard branches, not by trial and error
  • A known address or transaction is used to confirm the moment the correct path is found
  • Balance verified on-chain before any migration is attempted

Standard path scanning

Covering the four established derivation standards that account for most modern wallets.

  • BIP-44 legacy at m/44', producing 1-prefix P2PKH addresses
  • BIP-49 nested SegWit at m/49', producing 3-prefix P2SH addresses
  • BIP-84 native SegWit at m/84', producing bc1q bech32 addresses
  • BIP-86 Taproot at m/86', producing bc1p addresses
  • Multiple account indices scanned explicitly, since wallets often expose only the first
  • Address gap limits extended to find balances beyond the default scan window

Non-standard and historical paths

Identifying paths used by early or unconventional wallet software.

  • Early clients that predate the current BIP-44 through BIP-86 conventions
  • Application-specific layouts that modern wallets do not offer by default
  • Paths still valid but no longer the default in current software
  • Reconstruction from the wallet's identity and the phrase's creation date
  • Non-zero change-branch and unusual account-index placements
  • Cases declared unrecoverable elsewhere that resolve to a simple non-standard path

Coin-type and cross-chain resolution

Locating funds derived under the wrong coin type or sent to a parallel chain.

  • The coin type level determines which chain's addresses a phrase derives, Bitcoin at 0, Ethereum at 60
  • EVM-compatible chains, Polygon, Arbitrum, Optimism, Base, Avalanche C-Chain, share the same key and address under coin type 60
  • Funds visible on one EVM chain but not another are an interface issue, not a loss
  • The same phrase derived under the wrong coin type produces valid but unexpected addresses
  • Transaction ID used to confirm where funds actually landed before any action
  • Incompatible chains identified and ruled out honestly before work is quoted

Multi-wallet and software cross-checking

Reconciling a phrase that behaves differently across wallet applications.

  • The same phrase imported into different wallets can default to different paths and appear to hold different balances
  • Cross-checking the phrase against the default behaviour of each major wallet
  • Identifying which application originally created the wallet from its path signature
  • Passphrase interaction checked, since a 25th word derives a separate tree entirely
  • Reconciling exchange-withdrawal address formats against the derived tree

Verification and controlled migration

Confirming the correct path before anything moves.

  • The located path confirmed against a client-supplied address or on-chain balance
  • Exact address type and account index holding the balance identified precisely
  • All work performed offline on air-gapped equipment
  • Funds migrated to a wallet you control only once the path is proven
  • Guidance on recording the correct derivation path so the balance never disappears again

Failure modes

Failure modes we handle

  • Restored wallet shows zero balance

    Check the blockchain before panicking. If the coins are still at the old address, this is a path problem, not a theft, and the funds have not moved.

  • Phrase works in one app but not another

    Different applications default to different address standards from the same phrase. Extremely common, and entirely fixable.

  • Address format changed from a 1-prefix to bc1

    Legacy versus native SegWit, the same phrase viewed under a different purpose level. Same funds, different branch of the tree.

  • Funds sent to an address the current wallet will not display

    An address type or account index the current software does not scan by default. Enumerating the tree surfaces it.

  • Only the first account visible after restore

    Multi-account structures must be scanned explicitly. The other accounts are still derived from the same phrase and still there.

  • Balance visible on one EVM chain but missing on another

    The same key controls the same address across EVM chains. This is a network-selection issue in the interface, not a loss.

A recent case like this one

View all case studies
  • $30KTRX recovered

    September 2025

    Key format conversion

    TronWatch private key rejected by every modern wallet

    Early TronWatch had exported a 128-character key. Every current wallet treated it as malformed, so the TRX looked permanently lost even though the key material was intact. We identified the obsolete export encoding, reduced it to the standard importable form, confirmed the derived address matched the holding balance, then restored access.

Scam Warning

Most “crypto recovery” services are scams

If someone contacts you first about recovering your crypto, it's a scam - we only ever work with people who come to us. The rest ask for payment upfront, promise results nobody can promise, and want your recovery phrase typed into a website. Scammers also trade lists of people who've responded before, which is often how they found you.

You'll hear back from Nic or Harry directly - not a call centre. Beware of scammers.

Contact us

Describe your situation in general terms - no recovery phrases or private keys through this form. We will call you back within 24 hours with an honest read on whether derivation path recovery is possible in your case.

  • No fee unless we succeed

    10% of what's recovered, agreed in writing beforehand. Nothing if we fail.

  • We can come to you

    Anywhere in New Zealand, at our cost, for cases of significant value.

  • Nothing is retained

    Keys and phrases are destroyed or returned at the end of the engagement. NDA signed before we start.

Never send a recovery phrase or private key through this form, or through any website. Describe the situation in general terms and we will handle the sensitive detail securely on the call.

No fee unless we succeed. We respond within 24 hours.

FAQ

Derivation path recovery - common questions

My balance is zero after restoring. Have I been hacked?

Almost certainly not. Check your original address on a block explorer first. If the coins are still sitting there, they have not moved, and the wallet is simply deriving a different branch of the address tree than the one holding your funds. This is the single most common case we see, and it is recoverable.

How can the same phrase show different balances in different wallets?

Because one phrase generates a whole tree of addresses, and each wallet chooses which branch to show you. A phrase that looks empty in one app can be full in another simply because the second app scans the path your funds are actually on.

How many paths are there to check?

The four standards, BIP-44, 49, 84, and 86, cover most modern wallets, but each has multiple account indices and change branches, and older software used non-standard layouts. We scan the standard space first, where most cases resolve, then widen to historical and application-specific paths if needed.

Can you recover coins I sent to the wrong network?

Often, yes, where the same private key controls the address on both chains, as is the case across EVM-compatible networks. We confirm key control against the destination before quoting. Where the chains are genuinely incompatible, we tell you honestly rather than take the work on.

Do I need my original wallet software?

No. The derivation is a property of the phrase and the standards, not the app. We can locate the correct path without the original software, and it often helps us identify which path to expect.

Is my crypto actually recoverable if this is a path issue?

If the funds are visible on-chain at an address your phrase derives, then yes, this is one of the most reliably recoverable situations there is. The keys were never lost, the wallet was just looking in the wrong place.