How does cryptography secure cryptocurrency?
Cryptography secures crypto with key pairs and digital signatures that prove who may spend coins, and with hashes that make records hard to alter.
Cryptography is the mathematics of securing information. In cryptocurrency it does two main jobs. It proves that the person spending coins is entitled to do so, and it makes the transaction record very hard to alter.
What is cryptography?
Cryptography protects information with codes. The padlock icon in a web browser means it is shielding the connection.
Blockchains use it less for secrecy, since most blockchain data is public. Crypto relies on two other tools: digital signatures, which prove who authorized something, and hashes, which reveal whether data has been changed.
How do public and private keys work?
Every user has a pair of mathematically linked numbers called keys.
- The private key is a very large random number that must be kept secret.
- The public key is calculated from the private key and can be shared with anyone.
The calculation runs in one direction only. Getting the public key from the private key takes a moment. Working backward is not feasible with any existing computer. A wallet address is in turn derived from the public key.
Think of a locked mailbox with a slot. The address on the front is public, and anyone can drop money in. Only the person holding the key can open the box and take money out.
What is a digital signature?
When you send crypto, your wallet uses your private key to produce a digital signature for that exact transaction. Anyone can use your public key to check two things: that the signature was made by the matching private key, and that the transaction has not been altered since. They can do this without ever seeing the private key. It is like a wax seal that cannot be forged and that breaks if a single letter of the document is changed.
Hashes do the second job. A hash is a digital fingerprint of data, and each block stores the fingerprint of the one before it.
What are the weak points?
The underlying mathematics has not been broken. Failures have come from the people and software around it, as the guide to how crypto gets hacked describes:
- Stolen keys. Thieves trick users into revealing a private key or the seed phrase that backs it up, or they plant malicious software. A valid signature proves the key was used, not who used it.
- Lost keys. There is no recovery process.
- Faulty software. Wallets that generated keys with poor randomness have been emptied.
A longer-term concern is quantum computing. A sufficiently powerful quantum computer could, in theory, work out a private key from a public key. No machine capable of that is publicly known to exist. In August 2024, the US National Institute of Standards and Technology published its first finalized standards for encryption and signatures designed to resist such machines. Moving a blockchain to such methods would require a coordinated upgrade by its users.
This guide explains how things work. It is not financial, legal or tax advice. Last updated .