Crypto

Public and private keys, explained properly

Public and private keys are a matched pair: the private key signs transactions and stays secret, the public key is shared. Here is how they prove ownership.

Public and private keys, explained properly

Quick answer

Your private key is a secret number that authorises spending. The public key is derived from it and shared freely, so others can pay you and check your signatures. Working backwards, public to private, is infeasible — which is why an address is safe to hand out, but a seed phrase never is.

Key points

  • A private key is a secret that signs transactions and proves ownership
  • A public key is derived from it and can be shared freely
  • You cannot compute the private key from the public key
  • An address is derived from the public key and is safe to share
  • A seed phrase encodes the master secret, so it effectively is your funds

A public key and a private key are a matched pair of very large numbers. One of them, the private key, is a secret that only you hold. The other, the public key, is derived from it and can be handed out to the whole world. In cryptocurrency, whoever controls the private key controls the funds; the public key — or an address derived from it — is simply where other people send money to you. Get that one split straight and most of crypto security stops feeling like arbitrary rules.

What the two keys actually are

Public-key cryptography — asymmetric cryptography, if you want the formal name — leans on two mathematically linked keys instead of one shared password. The link only runs one way. Deriving the public key from the private key is easy; working backwards, from public to private, is computationally hopeless. That asymmetry is the whole trick. It’s what lets you broadcast one half of the pair to everyone while the other half stays locked away.

Most cryptocurrencies — Bitcoin and Ethereum among them — use elliptic-curve cryptography, on a curve called secp256k1, to mint these pairs. You don’t need the maths to use any of it. But one takeaway is worth pocketing: a private key is really just a random number drawn from a range so absurdly vast that guessing someone else’s isn’t a realistic attack. The security leans on that sheer size, not on hiding the method.

How keys prove ownership without revealing themselves

Send cryptocurrency and you’re not typing a password into a central server that checks it against a list. Your wallet builds a digital signature instead. Signing chews on two inputs — the transaction details and your private key — and produces a signature that anyone can verify using your public key. That check confirms two things in one stroke: the signer held the matching private key, and nobody has altered the transaction since it was signed.

Here’s the elegant bit. The signature never leaks the private key. Each one is welded to the exact transaction it authorises, so it can’t be peeled off and reused on some other payment. This is how a fully public network lets you prove you control funds without ever broadcasting the secret that grants that control. Curious how those signed transactions then get accepted by everyone else? That’s covered in how a crypto transaction gets confirmed.

Keys, addresses, and why they are not the same

People sling “public key” and “address” around as though they’re interchangeable. They aren’t. An address is usually derived from the public key by pushing it through extra hashing and encoding steps. What comes out is shorter, carries a built-in error-checking component so a mistyped character gets caught, and keeps the raw public key hidden until the moment you actually spend.

A rough map of the three layers:

Item Secret? Role
Private key Yes — never share Signs transactions; proves ownership
Public key No Verifies signatures; derives the address
Address No — share freely The destination others send funds to

This layering is the exact reason handing out your address to receive a payment is perfectly safe. It reveals where funds can land. Not how to move them.

Seed phrases: the human-friendly form of a private key

Wrangling raw private keys by hand would be a catastrophe waiting to happen, so modern wallets wrap them in a seed phrase — recovery phrase, mnemonic, same thing — usually twelve or twenty-four everyday words. That phrase is a human-readable encoding of the master secret, and from it your wallet mathematically derives every private key and address you’ll ever use. The standard sits out in the open as BIP-39, published for anyone to read.

And here’s the consequence that actually matters: your seed phrase is your money. Anyone who reads it can regenerate every key in your wallet and stroll off with the funds — on any device, with no phone of yours and no password needed. Lose it with no backup and those keys are unrecoverable. Gone. There’s no support line to reset it, because literally nobody else holds a copy. That’s not a flaw in the system. That’s the design doing exactly what it promised.

Custodial versus self-custody: who holds the key

Whether you personally touch keys at all depends on how you hold your crypto. Under self-custody, your wallet stores the private keys and you’re the only one who can sign. Under a custodial arrangement — most centralised exchanges work this way — the company holds the keys, and what you hold is an account balance that’s really a claim against them, worked through an ordinary login. That worn-out line “not your keys, not your coins” sums up the trade cleanly. Custody hands convenience and account recovery to a third party, and in return you’re trusting that third party with the keys.

Neither model wins outright; they just carry different risks. Self-custody wipes out counterparty risk but dumps the full weight of key security onto you. Custody lifts that weight — while dragging back in the very middleman that public-key cryptography was invented to make optional. Choose your poison with your eyes open.

Protecting a private key: the defensive basics

Because a private key or seed phrase hands over total control, nearly every real-world loss traces back to the secret being exposed or misplaced — not to anyone cracking the cryptography itself. So sensible defence fixes its attention on where that secret lives:

  • Keep the seed phrase offline. Write it on paper, or stamp it into metal. Either way it stays clear of malware, cloud backups, and screenshots that quietly sync themselves to some server.
  • Never type it into a website, and never share it. No real wallet, exchange, or “support agent” will ever need your seed phrase. A request for it is a theft attempt. Full stop.
  • Watch for fake apps and lookalike sites. A classic attack coaxes you into entering your phrase on a convincing clone. Download wallets from official sources only, and eyeball addresses before you trust them.
  • Think about a hardware wallet for larger sums. These gadgets keep the private key sealed inside dedicated hardware and sign transactions internally, so the secret never so much as touches an internet-connected computer.

Spot the pattern? Every one of these guards the secret itself. The cryptography isn’t the soft spot. The handling of the key is — every single time.

Why randomness is the quiet foundation

All of it rests on one assumption that’s easy to miss: that your private key was picked at random from a range so enormous nobody could ever stumble onto the same number. The security of the entire scheme depends less on the elegance of the maths than on the quality of that randomness. Generate keys from a weak or predictable source and an attacker who notices the flaw can regenerate them — without laying a finger on the underlying cryptography.

This isn’t hypothetical. There have been real cases of funds stolen because keys came out of flawed software with poor randomness, or from human-invented “brain wallet” passphrases that turned out to be guessable. For an ordinary user the lesson is reassuring rather than alarming: reputable wallets handle key generation properly, pulling from strong sources of randomness. Which is exactly why you should let a trusted wallet create your keys and seed phrase rather than trying to dream them up yourself. A phrase you cooked up in your own head is far easier to guess than one a good wallet generates. Human brains, it turns out, make lousy random number generators.

What this means

Public and private keys take a genuinely hard problem — proving you own something on a network with no central authority — and turn it into a routine operation. The public key and address let the world pay you and check your signatures. The private key, which you’ll usually meet as a seed phrase, is the single thing that authorises spending. Once that division clicks into place, the security rules stop feeling arbitrary. You can share an address without a second’s hesitation, and you have to guard a seed phrase as if it were the funds themselves — because, functionally, it is. If any of the ideas underneath this feel new, it’s worth starting with what a blockchain actually is.

Sources

  1. Bitcoin white paper (Nakamoto, 2008)
  2. Ethereum developer docs
  3. BIP-39 mnemonic standard

Frequently asked questions

Can someone steal my funds if they know my public key or address?

No. The public key and address only let people send funds to you and verify your signatures. Moving funds requires the private key, which cannot be derived from either of them.

Is a seed phrase the same as a private key?

Effectively yes. A seed phrase is a human-readable master secret from which your wallet derives its private keys, so anyone who has it can control all the funds in that wallet.

What happens if I lose my private key or seed phrase?

If you have no backup, the keys cannot be recovered and the funds become permanently unreachable. No third party holds a copy that could reset it in self-custody.

Last reviewed: 26 Aug 2026 Next review: 26 Feb 2027 Section: Crypto
Liam Chen
Protocol & security writer · Blockchain mechanics, wallet security, cryptography

Liam Chen writes about how crypto works at the protocol level — consensus, cryptography, wallets and security. He explains mechanisms plainly and cites primary sources.

More by Liam Chen

Related

Crypto

how does a crypto transaction work

Learn how crypto transactions work, including the role of blockchain, private keys, and transaction fees in securing and verifying digital…

cpn_admin · Oct 1, 2026 · 4 min
Crypto

KYC and AML in crypto, explained

KYC and AML in crypto explained: what identity checks and anti-money-laundering rules mean, why exchanges verify you, and how the…

Liam Chen · Aug 26, 2026 · 6 min
Crypto

What Is a Crypto Exchange?

Discover what a crypto exchange is and how it functions as a marketplace for buying, selling, and trading digital currencies.

cpn_admin · Sep 22, 2026 · 12 min