Every bitcoin you will ever own is protected by a single number. Not a password you chose, not an account at a company, just a number, so large that if you wrote it out in decimal it would run to 78 digits.

Anyone who knows that number can move the coins. Anyone who loses it, loses them. No help desk exists to reset it, because there is nothing to reset: the number is the ownership.

That sounds terrifying until you understand how the pieces fit. A private key, a public key, a signature, an address and a seed phrase are five links in one chain, and each link only points in one direction.

Your Private Key Is Just a Very Large Number

Bitcoin uses an elliptic curve called secp256k1, published by the Standards for Efficient Cryptography Group in a document called SEC 2. A private key is any whole number from 1 up to the curve's "order", a fixed constant slightly below 2 to the power of 256, or roughly 1.158 × 10^77.

That range is the entire security argument. Your wallet picks a number at random from it. The space is so vast that guessing someone else's key, even with every computer on Earth running for longer than the universe has existed, is not a realistic attack. What gets people robbed is never brute force. It is copied backups, malware, and someone being talked into typing their words into a fake website, which is covered in How to Spot and Avoid Bitcoin Scams.

The One-Way Street to a Public Key

Your public key is computed from the private key by a special kind of multiplication: the private key times a fixed starting point on the curve, called the generator point G. The result is another point on the curve, written out as 33 bytes in the compressed form modern wallets use.

The magic is the asymmetry. Going forward takes a laptop a fraction of a millisecond. Going backward, recovering the private key from the public key, is the elliptic curve discrete logarithm problem, and no practical method for solving it at this size is publicly known.

Analogy: Think of mixing paint. Combining a secret color with a public base color is easy, and anyone can see the result. But nobody can look at the mixed can and separate it back into the exact secret shade you started with.

So your public key can be shown to the world. It reveals nothing useful about the private key behind it.

Signatures: Proof Without Showing the Secret

When you spend bitcoin, you never send your private key anywhere. Your wallet uses it to produce a digital signature over the specific transaction you are making. Anyone holding your public key can check that signature and confirm two things: it was made by whoever holds the matching private key, and the transaction has not been altered since it was signed.

Because the signature is bound to that exact transaction, it cannot be lifted and reused to authorize a different payment. Change one satoshi in the amount and the signature fails.

Bitcoin originally used ECDSA signatures. The Taproot upgrade, which activated in November 2021, added Schnorr signatures as specified in BIP-340. They are smaller and allow several signers to combine their approval into what looks like a single signature. How these signatures unlock specific coins is explained in How Transactions Work.

Addresses: The Part You Actually Share

An address is a shareable, error-checked encoding of what a payment will be locked to. Most older address types store a hash of your public key or script (SHA-256 followed by RIPEMD-160) rather than the key itself. Taproot addresses encode a public key directly. Either way, the address is built so that typos are almost always caught before money moves.

Starts withTypeDefined in, year activatedWhat it locks to
1Legacy (P2PKH)Original 2009 softwareA hash of one public key
3Pay to Script Hash (P2SH)BIP-13 and BIP-16, 2012A hash of a script, often multisig
bc1qNative SegWit v0BIP-141 and BIP-173, 2017A hash of a key or script
bc1pTaproot (SegWit v1)BIP-341 and BIP-350, 2021A tweaked public key

Wallets generate a fresh address for each payment you receive. That habit traces back to section 10 of the whitepaper, which recommends a new key pair for each transaction to keep payments from being linked to a common owner.

Seed Phrases: Thousands of Keys in a Few Words

Modern wallets do not back up keys one at a time. They back up a seed phrase, and here BIP-39 does the heavy lifting.

Your wallet generates 128 to 256 bits of randomness. It appends a short checksum taken from the SHA-256 hash of that randomness, then splits the result into 11-bit chunks. Each chunk picks one word from a fixed list of 2,048 words. The BIP-39 table works out like this:

Random bitsChecksum bitsWords
128412
160515
192618
224721
256824

The words are then stretched through 2,048 rounds of a function called PBKDF2 (using HMAC-SHA512) into a 512-bit seed. BIP-32 turns that seed into a hierarchical tree of private keys, which is why one backup covers every address your wallet will ever use.

Two practical details matter. The checksum means a mistyped word is usually caught on restore. And BIP-39 supports an optional passphrase, sometimes called a 25th word. Every passphrase produces a valid but completely different wallet, so a forgotten passphrase is as final as a lost seed.

Flow diagram showing how a Bitcoin wallet derives keys: random entropy becomes a 12 or 24 word seed phrase, which is stretched into a 512 bit seed, which produces a tree of private keys, then public keys through one-way elliptic curve math, then shareable addresses.
Every arrow points one way. You can go down the chain easily, but never back up.

Where Things Go Wrong

The math is not the weak point. People are. Real losses come from a short list:

  • Photographing or typing the seed phrase into a phone, cloud note or website, where malware or a phishing page can grab it.
  • A single backup that burns, floods or gets thrown out.
  • Trusting someone who asks for the words. No legitimate wallet maker, exchange or support agent ever needs them.
  • Generating keys on a compromised device, which may leak the randomness at the start of the chain.

This is the logic behind hardware wallets: keys are created and kept on a dedicated device, and only signatures leave it. The trade-offs between storage options are covered in Hot Wallets vs. Cold Wallets, and our hardware wallet comparison lays out how two well-known devices differ.

What This Means for You

  1. The seed phrase is the money. Anyone who sees those words can take everything, so treat them like the coins themselves, not like a password.
  2. Public keys and addresses are safe to share. The math runs in one direction only, so revealing them gives away nothing that can spend your coins.
  3. Write it down offline, and keep more than one copy. Paper or metal backups stored in separate places protect against both theft and accidents.
  4. A passphrase adds protection and risk. It shields you if the words are found, but forgetting it locks you out just as surely.
  5. Nobody legitimate will ever ask for your words. Any request for them is a scam, whoever claims to be asking.

A number nobody can guess, guarded by words nobody else should ever see.