NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #4749 most downloaded on npm
Secure, audited & minimal implementation of BIP32 hierarchical deterministic (HD) wallets over secp256k1
Last release 1 months ago
28 Aug 2026
Release timing varies
gaps range from 8 days to 7 months
Nearly every release is documented
notes for 23 of 23 stable releases
Nothing withdrawn
no release was ever pulled
5 years old
25 releases · first in 2022
One column per quarter.
The privateKey , publicKey , chainCode , identifier , pubKeyHash now return copies instead of live buffers
Hardening:
privateKey, publicKey, chainCode, identifier, pubKeyHash now return copies instead of live buffersderiveChild no longer blindly try-catches. Use proper filtered-by-kind error handling. Retries will stop at lastfromExtendedKey now rejects checksum-valid payloads that are not exactly 78 bytesHDKey constructor validation: depth must be an integer in 0..255 (throws RangeError), index and parentFingerprint must be valid uint32 values, and chainCode must be exactly 32 bytesderive(path) now rejects paths up front that would exceed the maximum serializable depth of 255toPrivateJSON() for explicit private (xpriv + xpub) export; toJSON() currently still includes xpriv for backwards compatibility (planned to become public-only in v3, so migrate to toPrivateJSON() for private round-trips)fromJSON now also accepts { xpub } to restore a public-only keyFull Changelog: 2.3.0...2.4.0
Improve validation and error messages.
Full Changelog: 2.2.0...2.3.0
April 2026 self-audit (all files): no major issues found
Uint8Array, while TS 5.9+ made it generic Uint8Array<ArrayBuffer>TS2345(We're skipping v2.1, to align with other noble / scure packages)
Full Changelog: 2.0.1...2.2.0
Upgrade noble-hashes to v2.0.1 and noble-curves to v2.0.1
Full Changelog: 2.0.0...2.0.1
The package is now ESM-only. ESM can finally be loaded from common.js on node v20.19+
Full Changelog: 1.7.0...2.0.0
Nothing published for this version
Bump hashes to v1.8.0 , curves to v1.9.0 , base to v1.2.5
Full Changelog: 1.6.2...1.7.0
Use typescript verbatimModuleSyntax to support future node.js type stripping
Full Changelog: 1.6.1...1.6.2
Bump noble-curves to 1.8.0 and noble-hashes to 1.7.0
Full Changelog: 1.6.0...1.6.1
Bump hashes to v1.6.0 , curves to v1.7.0 , base to 1.2.0
Full Changelog: 1.5.0...1.6.0
Improve typescript compatibility by emitting separate types for cjs / esm
Full Changelog: 1.4.0...1.5.0
Fix HDKeyOpt type by @arobsn in https://github.com/paulmillr/scure-bip32/pull/14
HDKeyOpt type by @arobsn in https://github.com/paulmillr/scure-bip32/pull/14Full Changelog: https://github.com/paulmillr/scure-bip32/compare/1.3.3...1.4.0
noble-curves to 1.3.0: https://github.com/paulmillr/noble-curves/releases/tag/1.3.0
Full Changelog: https://github.com/paulmillr/scure-bip32/compare/1.3.2...1.3.3
Improve tree-shaking, decrease bundle size
Full Changelog: https://github.com/paulmillr/scure-bip32/compare/1.3.1...1.3.2
Update noble-curves from 1.0.0 to 1.1.0: https://github.com/paulmillr/noble-curves/releases/tag/1.1.0
Full Changelog: https://github.com/paulmillr/scure-bip32/compare/1.3.0...1.3.1
Use stable noble-curves. Full Changelog: https://github.com/paulmillr/scure-bip32/compare/1.2.0...1.3.0
Use stable noble-curves.
Full Changelog: https://github.com/paulmillr/scure-bip32/compare/1.2.0...1.3.0
Switch from noble-secp256k1 to noble-curves.
Switch from noble-secp256k1 to noble-curves.
Full Changelog: https://github.com/paulmillr/scure-bip32/compare/1.1.5...1.2.0
Added source maps Full Changelog: https://github.com/paulmillr/scure-bip32/compare/1.1.4...1.1.5
Added source maps
Full Changelog: https://github.com/paulmillr/scure-bip32/compare/1.1.4...1.1.5
Update dependencies Full Changelog: https://github.com/paulmillr/scure-bip32/compare/1.1.3...1.1.4
Update dependencies
Full Changelog: https://github.com/paulmillr/scure-bip32/compare/1.1.3...1.1.4
Improves compatibility with new version of noble/secp256k1
Full Changelog: https://github.com/paulmillr/scure-bip32/compare/1.1.2...1.1.3
Improves compatibility with new version of noble/secp256k1
Full Changelog: https://github.com/paulmillr/scure-bip32/compare/1.1.1...1.1.2
Improve type check in fromMasterSeed()
fromMasterSeed()Full Changelog: https://github.com/paulmillr/scure-bip32/compare/1.1.0...1.1.1
Remove viral esModuleInterop option from typescript compiling
esModuleInterop option from typescript compilingFirst post-audit stable release
First post-audit stable release
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →