Log InSign UpBook a Consultation
Blogs

What Is a Private Key? Public vs Private Keys

The secret number that controls your crypto. How public and private keys work, how they differ, and how to protect them.

Featured guide
Table of Contents

Key points

  • A private key is a secret 256-bit number that authorizes transactions from a crypto address.
  • A public key is calculated from the private key and can be shared; the calculation cannot be reversed.
  • Signing a transaction proves you hold the private key without ever revealing it.
  • A recovery phrase of 12 to 24 words can regenerate every private key in a modern wallet.
  • Nobody can reset or recover a lost private key, so whoever holds it effectively owns the funds.

In crypto, a private key is a secret number that authorizes transactions from a blockchain address. Whoever holds it can move the funds at that address, which is why it must stay private. Its partner, the public key, is derived from it and can be shared freely as the math only works in one direction.

Every wallet, exchange, and custodian ultimately comes down to one question: who holds the private key? Over the next few sections, this guide explains what the key is, how public and private keys differ, how signatures prove ownership, and how keys relate to the recovery phrase in your wallet.

What is a private key in crypto?

A private key in crypto is a randomly generated number that gives its holder control over a blockchain address. In Bitcoin, it is “a single unsigned 256 bit integer (32 bytes),” according to the Bitcoin Wiki. Wallets hide it behind a recovery phrase.

Think of a blockchain address as a glass mailbox. Anyone can look inside and anyone can drop funds in. Only the private key opens the slot that lets funds out.

On a blockchain, the network never checks your name. If a transaction carries a valid signature from the right private key, the network accepts it; if it does not, nothing moves, no matter who you are or what paperwork you hold. Possession of the key is ownership, in practice if not always in law.

How are private keys created?

Private keys are created by generating a very large random number, usually inside a wallet app or hardware device. Security depends entirely on that randomness. A key chosen by a person, or produced by a weak random-number generator, can be guessed; a truly random one cannot be found by any known method.

Randomness is the whole point

When a wallet creates a key, it draws on sources of randomness in the device to pick a number from an enormous range. Bad randomness is the danger. Brain wallets, whose keys came from memorable phrases, were emptied by attackers who simply fed common words, song lyrics, and famous quotes into software that checked each one for funds.

Why guessing a key is not realistic

With 256 bits, the number of possible private keys is 2 to the power of 256, roughly 1.16 times 10 to the 77th power (a number with 78 digits, far beyond what any computer could count through). Faster computers do not change that. No attacker targets keys this way; they target the people and devices that hold them.

What is a public key?

A public key is a number calculated from a private key using elliptic curve cryptography. It can be shared openly, because working backward from a public key to the private key is not feasible with known methods. In transactions, the network uses the public key to check that a transaction was signed by the matching private key.

One-way math

Bitcoin and Ethereum both use an elliptic curve called secp256k1. By multiplying a point on that curve by the private key, the wallet produces the public key. Going the other way would require solving a problem that no known method can crack at this size. As the Bitcoin Wiki puts it, “a public key can be calculated from a private key, but not vice versa.”

Public keys and wallet addresses

What you share to receive funds is usually an address, not the raw public key. The address is a shorter code derived from the public key by hashing it, and the format differs from one blockchain to another. Sending to the wrong network's format can be a permanent mistake.

Public key vs private key: what is the difference?

The difference between a public key and a private key is who gets to see it. A private key stays secret. By contrast, a public key can be shared with anyone who needs to send you funds or verify your signature. Losing a public key costs nothing; losing a private key costs everything at that address.

FeaturePrivate keyPublic key
What it isA secret 256-bit random numberA number calculated from the private key
Who can see itOnly the ownerAnyone
What it doesSigns transactionsVerifies signatures; produces the address
Can it be derived from the other?NoYes, from the private key
If someone else gets itThey can take the fundsNothing happens
If you lose itFunds at that address are inaccessibleIt can be recalculated

How does a private key prove ownership?

A private key proves ownership by producing a digital signature. When you send crypto, your wallet signs the transaction with your private key, and every node on the network checks that signature against your public key. A valid signature proves the key was used, without the key itself ever appearing on the network.

Every signature fits one transaction. Change the amount or the destination by a single character and the signature no longer matches, so nobody can take a signed transaction, edit it on the way, and redirect the funds somewhere else. Because of that property, it is safe to broadcast signed transactions to thousands of strangers.

Signatures cannot read intent, though. If malware or a fake website gets you to approve a transaction you misread, the signature is just as valid. Many thefts happen right there.

What is the difference between a private key and a seed phrase?

A seed phrase, or recovery phrase, is a list of 12 to 24 words from which a wallet generates its private keys. Under the BIP-39 standard, proposed in 2013, the words come from a fixed list of 2,048. One phrase can regenerate every private key in the wallet, so protecting the phrase protects all of them.

One phrase, many keys

Modern wallets are hierarchical deterministic (HD) wallets. From a single seed, they derive a whole tree of private keys, one for each address you use, in a fixed and repeatable order. Restore the same phrase in a compatible wallet and the same keys, addresses, and balances reappear.

Why the phrase matters more than any single key

Because the phrase sits above every key, it is the most sensitive piece of information in the wallet. Exposing one private key risks one address. Expose the phrase, however, and every address is at risk, including ones the wallet has not created yet.

What happens if a private key is lost or stolen?

A lost private key with no backup means permanently inaccessible funds; a stolen one lets someone else move them. In June 2020, Chainalysis estimated that about 3.7 million BTC had not moved in at least five years, as reported by Decrypt, and much of it is believed to be lost because the owners no longer have their keys.

Not every dormant coin is lost; some belong to patient holders. Still, the estimate gives a sense of scale: roughly one in five BTC in existence at the time. No administrator can reset a key, and no court order can make the network accept a transaction without a valid signature.

Theft is just as final. Once an attacker signs and broadcasts a transaction, the transfer cannot be reversed. Recovery then depends on tracing the funds to a platform that is willing and able to freeze them, which happens occasionally, takes time and cooperation, and should never be counted on.

How do you protect a private key?

Protecting a private key means keeping it, and the recovery phrase behind it, off internet-connected devices and away from anyone who asks for it. Hardware wallets, offline backups, and qualified custodians all exist to solve that one problem. For the practical setup, see our guide to storing crypto safely.

  • Never type a recovery phrase or private key into a website, chat, email, or form.
  • Keep the recovery phrase offline, on paper or metal, in at least two secure locations.
  • Use a hardware wallet so private keys sign transactions without touching a connected computer.
  • Check every address and amount on the device screen before approving a transaction.
  • Plan how someone you trust could access the keys if you could not.

There is also the option of not holding keys yourself. With institutional custody, a specialist custodian secures keys using multi-party computation (MPC), which splits signing power so no single party ever holds a complete key. Since each approach trades control against responsibility, our guide to self-custody versus custodial storage compares them side by side.

Frequently asked questions

Can someone find my private key from my public key?

No, not with any known method. The public key is calculated from the private key using elliptic curve math that only works in one direction. Reversing it would take an impractical amount of computing power for a properly generated 256-bit key. Sharing your public key or address is safe.

Is a private key the same as a password?

Not quite. A password is checked by a company that can reset it if you forget it. With a private key, the blockchain itself does the checking, and nobody can reset it. If a private key is lost without a recovery phrase, access to the funds is lost as well.

Can a private key be changed?

No, a private key cannot be changed, because the address is derived from it. If you believe a key or recovery phrase has been exposed, the standard response is to create a new wallet with a new phrase and move your funds to it as quickly as possible.

Can you recover a lost private key?

Only if you still have the recovery phrase, which can regenerate every key in the wallet. Without the phrase or another backup, a lost private key cannot be recovered by anyone, including the wallet developer. The coins stay where they are.

Is it safe to share my public key?

Yes. Public keys and wallet addresses are designed to be shared so others can send you funds or verify your signatures. The only downside is privacy: anyone with your address can view its transaction history on the blockchain, so some people use a fresh address for each payment they receive from different senders.

Who holds the private key on a crypto exchange?

On a custodial exchange, the exchange holds the private keys and you hold an account balance. That arrangement lets the exchange restore your access, but it also means your funds depend on its security and solvency. To hold the keys yourself, you would withdraw to a non-custodial wallet.

Protecting your keys with UpTrade

Who holds the private key is one of the most important decisions in crypto. UpTrade lets you choose, with a broker to help you think it through.

  • Optional institutional-grade custody through Fireblocks, included at no extra cost, so no single party holds a complete key.
  • Direct ownership of your crypto, which you can withdraw to your own wallet whenever you choose.
  • A dedicated personal broker and 24/7 support, to answer questions whenever markets move.

Read more about our custody approach.

UpTrade is an AUSTRAC-registered digital currency exchange provider (DCE100856266-001). You can verify registered providers at austrac.gov.au.

→ Explore our custody solution→ Book a free consultation

This article is for general informational purposes only and does not constitute financial, investment, or tax advice. Cryptocurrency investments carry significant risk, including the possible loss of principal. Past performance is not indicative of future results. UpTrade does not make investment recommendations based on your personal financial circumstances. You should conduct your own research and seek independent financial advice before making any investment decisions.

Related articles

General information only. This article is for educational purposes and does not constitute financial, investment, legal or tax advice, nor a recommendation to buy, sell or hold any asset. Cryptocurrency is a high-risk asset and you should consider your own circumstances and seek independent advice before making any decision. UpTrade does not make price predictions.

Written by

Kane Bisogni

Head of Research & Analytics

Kane leads our international research division, delivering clear, actionable insights into crypto markets and emerging investment opportunities. A true “crypto native,” he has over seven years of hands-on experience, formal qualifications in finance and economics, and has worked across Web3 hedge funds, venture capital, and leading incubators.

Keep reading

All insights
Straight to your inbox

The desk's weekly read,
no noise.

Market updates, new explainers and the occasional Alpha Pro report, sent once a week. Unsubscribe anytime.

10,000+ investors · 1 email / week
You're subscribed!
Oops! Something went wrong while submitting the form.