Sources
- Bitcoin developer guide: Wallets (private key formats, HD wallets)
- ethereum.org: Ethereum accounts (key pairs and address derivation)
- BIP-39: Mnemonic code for generating deterministic keys
- BIP-32: Hierarchical Deterministic Wallets
- Satoshi Nakamoto, Bitcoin: A Peer-to-Peer Electronic Cash System (2008)
Last reviewed 28 Sep 2026 by Akriti Seth. Originally published 28 Sep 2026.
Key takeaways
- A private key is a secret number that lets you sign transactions and move the crypto held at a blockchain address.
- It is linked to your public key and address by one-way maths: you can share the address safely, but nobody can work backwards from it to the key.
- Anyone who sees your private key or seed phrase can take your coins, and nobody can reverse the transfer.
A private key is a secret number that proves you control a crypto address and lets you sign transactions that move the coins held there. Your coins never leave the blockchain; the private key is what gives you the power to move them. Whoever knows the key controls the funds, so keeping it secret is the most important job in crypto security.
Here’s how private keys work, how they relate to public keys, addresses and seed phrases, and the mistakes that most often cost people their coins.
How does a private key work?
A blockchain is a shared record of which address holds which coins. To move coins from an address, you broadcast a transaction that says where they should go, signed with the private key for that address. Every node on the network can check the signature against the address without ever seeing the key itself.
In bitcoin, a private key in its standard format is “simply a 256-bit number”, according to the Bitcoin developer guide, chosen from a range set by the secp256k1 elliptic-curve standard that bitcoin uses. On Ethereum, ethereum.org’s documentation describes a private key as 64 hexadecimal characters. Either way, the number is so large that guessing someone else’s key at random is not a realistic attack.
From the private key, wallet software calculates a public key using elliptic-curve maths, and from the public key it calculates an address. On Ethereum, the address is the last 20 bytes of a hash of the public key, written as 42 characters starting with “0x”. Each step works in one direction only. As ethereum.org puts it, you can derive a public key from a private key, “but you cannot derive a private key from public keys”.
What is a seed phrase, and how is it different from a private key?
Most modern wallets don’t show you a private key at all. They show you a seed phrase (also called a recovery phrase or mnemonic): usually 12 or 24 ordinary words.
The seed phrase is a human-friendly backup of the random number your wallet started from. The BIP-39 standard, which most wallets follow, turns between 128 and 256 bits of randomness into 12 to 24 words from a fixed list of 2,048 words, with a small checksum to catch typing errors. A second standard, BIP-32, lets a wallet derive a whole tree of private keys from that one seed. That’s why restoring 12 words on a new device brings back every account at once.
The practical upshot: your seed phrase is a master key. Leaking it is worse than leaking a single private key, because it exposes every address the wallet ever created.
Where did private keys in crypto come from?
Private and public keys come from public-key cryptography, which long predates crypto and also secures things like encrypted web traffic. Bitcoin’s design put digital signatures at the centre of ownership. In the bitcoin white paper, published in 2008, Satoshi Nakamoto wrote: “We define an electronic coin as a chain of digital signatures.”
That sentence still describes how it works. Each owner signs the coins over to the next, and the private key is the pen.
Private key vs public key vs address vs seed phrase
| Private key | Public key | Address | Seed phrase | |
|---|---|---|---|---|
| What it is | Secret number that signs transactions | Number derived from the private key | Shortened, hashed form of the public key | Word backup of your wallet’s master secret |
| Safe to share? | Never | Generally yes | Yes; it’s how people pay you | Never |
| What someone can do with it | Move your coins | Verify your signatures | Send you coins, view your balance | Rebuild your whole wallet and move everything |
| Typical format | 64 hex characters (Ethereum) | Longer hex string | “bc1…” (bitcoin) or “0x…” (Ethereum) | 12 or 24 words |
| Can it be recovered if lost? | Only from your seed phrase or a backup | Yes, from the private key | Yes, from the private key | No |
Who holds your private key?
This is the question that decides who really controls your coins.
- Self-custody wallet. A software wallet on your phone or a hardware wallet holds the keys on your device. You alone control them, and you alone are responsible for the backup.
- Exchange account. When you leave coins on an exchange, the exchange holds the keys. Your balance is a claim on the exchange, and your protection depends on its security, licence and terms.
- Custodian. Funds and companies often pay a specialist custodian to hold keys under strict controls, such as requiring several separate approvals before any transfer.
There is no single right answer. Self-custody removes the risk of a company failing; a custodian removes the risk of you losing a piece of paper. If you want to see how a regulated fund handles the question, our guide to what a spot bitcoin ETF is explains how ETF coins sit with a custodian.
Risks and criticisms
- No undo button. A signed transaction can’t be reversed. If a thief gets your key, the network treats their transfer as legitimate.
- Phishing. Fake wallet apps, support chats and “wallet validation” sites exist to trick people into typing a seed phrase. Legitimate companies never ask for it.
- Single point of failure. A seed phrase written on one piece of paper can be lost in a fire or found by someone else. Some people split backups across locations or use multisignature setups, which add complexity.
- Malware and clipboard hijacking. Some malware swaps a copied address for an attacker’s address, or scans files and photos for seed phrases.
- Future cryptography. Researchers continue to study whether future quantum computers could derive private keys from exposed public keys. This is a long-term debate, not a present-day attack on ordinary wallets.
How to keep your private keys safe
- Write your seed phrase on paper or metal, offline, when you set up a wallet. Don’t photograph it, email it or store it in cloud notes.
- Store the backup somewhere private and durable, and consider a second copy in a separate secure place.
- Never type your seed phrase into a website, chat window or form. Only enter it into the wallet itself, and only when restoring.
- Consider a hardware wallet for larger balances. It signs transactions on the device, so the key never touches your computer.
- Check addresses before sending. Compare the first and last characters on the device screen, and send a small test amount first.
Common mistakes
- Taking a screenshot of the seed phrase “just for now”.
- Sharing a seed phrase with someone claiming to be wallet or exchange support.
- Assuming an exchange balance is a private key you control.
- Importing the same seed phrase into several apps, which multiplies the places it could leak.
- Losing the only backup and discovering that no one, including the wallet maker, can recover it.
Frequently asked questions
Can someone guess my private key?
Not in practice. A key is chosen from a range of about 2^256 numbers, far too many to search, provided your wallet generated it with proper randomness.
Is my wallet address the same as my private key?
No. The address is derived from your public key and is meant to be shared. The private key must stay secret.
What happens if I lose my private key?
If you still have your seed phrase, you can restore your wallet and keys. If you’ve lost both, the coins can’t be moved by anyone.
Does an exchange give me my private key?
Usually not. Exchanges control the keys for customer balances. To hold your own keys, you withdraw to a self-custody wallet.
This article was written by Begoña Iriondo, an AI author persona at CryptoWatchDesk, and was reviewed, fact-checked and edited by Akriti Seth. It is not investment advice. Begoña Iriondo holds no crypto assets.
