The most common explanation goes like this: the public key is used to lock, the private key to unlock. For secret messages, that is true. But when you send cryptocurrency, nothing is locked. Transactions on Bitcoin and Ethereum can be read by anyone. The network just needs to ensure one thing: the command to move the funds truly comes from its owner. This task is called a digital signature, and the direction of the keys is reversed.
Two tasks, opposite key directions
| Task | Private key used for | Public key used for | Example |
|---|---|---|---|
| Message encryption | unlocking messages sent to you | locking messages before sending to you | encrypted email |
| Digital signature | creating a signature | verifying a signature | Bitcoin and Ethereum transactions |
The NIST digital signature standard, FIPS 186-5, states it clearly. A signature is created with the private key, then verified with the corresponding public key. The public key does not need to be kept secret, but its authenticity must be maintained. Only the holder of the private key can create a signature, while anyone can verify it.
In Bitcoin, the signature binds almost the entire content of the transaction: which funds are spent, to where, and how much. Change just one part, and the signature no longer matches.
From private key to address, the path is one-way
| Layer | Form | Can it be shared? |
|---|---|---|
| Private key | random 256-bit number; in Ethereum written as 64 hexadecimal characters | Never |
| Public key | derived from the private key via elliptic curve (ECDSA) | Can be shared |
| Address | hash of the public key. In Ethereum: last 20 bytes of the Keccak-256 hash, prefixed with 0x, totaling 42 characters |
Can be shared, this is what you provide to receive funds |
The private key can derive the public key, but the public key cannot be used to guess the private key. Thus, the address is not the public key itself. In Bitcoin, the address also carries a checksum to catch typos. Its hash conceals the public key until funds from that address are spent for the first time.
Seed phrase: the master key of all keys
Most wallets do not present the private key, but rather a series of words. The specification, BIP-39, takes words from a list of 2,048 words. The first four letters are enough to identify each word.
| Number of words | Random entropy | Checksum |
|---|---|---|
| 12 | 128 bits | 4 bits |
| 15 | 160 bits | 5 bits |
| 18 | 192 bits | 6 bits |
| 21 | 224 bits | 7 bits |
| 24 | 256 bits | 8 bits |
Two details that are often overlooked:
- The checksum is short. A typo in one word is not always detected, and the checksum cannot correct it.
- An additional passphrase is never "wrong". Any passphrase generates a valid wallet. A typo in one letter does not trigger an error message; instead, it opens another wallet.
Anyone holding the seed phrase can access all accounts in that wallet. Therefore, the seed phrase should be written on paper, not photographed. Screenshots can be synced to cloud storage.
In exchanges, the keys are held by the provider
When assets are stored in a centralized exchange, you log in with a username and password that can be recovered like a regular account. The keys are held by the provider, and you entrust your funds to them. In a self-custody wallet, there is no customer service. A lost seed phrase without a copy cannot be recovered by anyone.
The difference is felt when the owner passes away. Assets in an exchange are tied to an account, so the path goes through the provider. Assets in a self-custody wallet can only be moved by the person holding the seed phrase.
Three misconceptions to debunk
- "Address is the same as public key." The address is a hash of the public key.
- "Private key is used to decrypt transactions." Transactions are not encrypted. The private key signs them.
- "Officials can recover lost crypto if given the private key." This is a scam pattern noted by ethereum.org. Official services never ask for your private key or seed phrase.
If you prefer to see a brief explanation directly, there is a clip. A general overview of blockchain can be found in the basic blockchain article.
Sources
- NIST, FIPS 186-5: Digital Signature Standard (DSS), February 3, 2023.
- NIST CSRC Glossary, asymmetric cryptography.
- Bitcoin Developer Guide, Transactions.
- ethereum.org, Ethereum accounts, updated August 6, 2026.
- BIP-39, Mnemonic code for generating deterministic keys.
- ethereum.org, Ethereum wallets.
- ethereum.org, Ethereum security and scam prevention.