What is a private key?
A private key is a long secret number that proves ownership of crypto and authorizes spending. Anyone who learns it can take the funds.
A private key is a secret number that gives control over the cryptocurrency at a particular address. It works like a signature stamp that cannot be forged. Whoever holds the key can spend the funds, and nobody else can.
What does a private key look like?
In bitcoin and Ethereum, a private key is a randomly chosen number 256 bits long, usually displayed as 64 characters using the digits 0 to 9 and the letters a to f. The range of possible keys is so large, about a 1 followed by 77 zeros, that guessing someone else's is not a practical attack.
Most people never see their keys. A crypto wallet generates and stores them, and backs them all up as a seed phrase, a list of 12 or 24 words from which every key in the wallet can be recreated.
How do the private key, public key and address fit together?
Three pieces are linked in a one-way chain:
- The private key is generated at random.
- A public key is calculated from it using a branch of math called elliptic curve cryptography. The calculation is easy in one direction and, with today's computers, not feasible to reverse.
- An address is derived from the public key, usually by running it through a hash, a function that turns data into a short fingerprint.
The address and public key can be shared freely. People need the address to pay you. The private key stays secret.
How does a private key authorize a payment?
To spend, the wallet combines the transaction details with the private key to produce a digital signature. The network's computers check that signature against the public key. The check confirms two things: the holder of the right key approved this exact transaction, and nothing in it was altered afterward. The key itself is never transmitted.
Why should a private key never be shared?
A blockchain has no way to tell an owner from a thief. A valid signature is the only test. If someone copies a private key, they can move the funds, and the transfer is final once confirmed. No bank or support desk can reverse it.
Keys are rarely guessed or cracked. They are taken in ordinary ways: malicious software that searches a computer for wallet files, phishing pages that ask the user to type in a key or seed phrase, screenshots saved to a cloud account that is later breached, and fake support staff who ask for it directly. No legitimate wallet provider, exchange or official needs a customer's private key for any purpose.
The same logic applies to loss. If the only copy of a key is destroyed, the coins remain visible on the blockchain but can never be moved. This is the trade-off at the heart of self-custody: full control, and full responsibility.
This guide explains how things work. It is not financial, legal or tax advice. Last updated .