{
  "$schema": "https://degreesofsatoshi.com/encyclopedia/schemas/article-v1.json",
  "schemaVersion": "1.0.0",
  "id": "ethereum-validator-keys",
  "canonical": "https://degreesofsatoshi.com/encyclopedia/ethereum-validator-keys/",
  "collection": "ethereum",
  "title": "Validator signing keys and withdrawal credentials: different powers",
  "description": "Separate a validator’s online signing key from withdrawal credentials and the address controlling its funds.",
  "aliases": [
    "validator signing withdrawal key",
    "Ethereum withdrawal credentials"
  ],
  "dates": {
    "published": "2026-10-02",
    "modified": "2026-10-02",
    "verified": "2026-10-02T19:27:58.939Z",
    "dataAsOf": "2026-10-02"
  },
  "authorship": {
    "publisher": "Degrees of Satoshi editorial project",
    "process": "AI-assisted research and drafting with a separate automated source-verification pass; no external expert or named human review is implied."
  },
  "quickAnswer": {
    "text": "An Ethereum validator uses a signing key for consensus duties such as votes and block proposals. Withdrawal credentials separately determine withdrawal authority and destination. An attacker with only the signing key can disrupt or slash the validator even when unable to spend withdrawals sent to your address. Protect both forms of authority according to their different roles.",
    "claimId": "ethereum-validator-keys-quick-answer",
    "sourceIds": [
      "x425-eth-eth-keys",
      "x425-eth-eth-saas",
      "x425-eth-launchpad-faq"
    ]
  },
  "keyFacts": [
    {
      "label": "Signing",
      "value": "Validator signing keys authorize proposals and attestations.",
      "sourceIds": [
        "x425-eth-eth-keys"
      ],
      "id": "signing",
      "claimId": "ethereum-validator-keys-fact-signing"
    },
    {
      "label": "Credentials",
      "value": "Withdrawal credentials belong to the validator’s consensus record.",
      "sourceIds": [
        "x425-eth-launchpad-faq"
      ],
      "id": "credentials",
      "claimId": "ethereum-validator-keys-fact-credentials"
    },
    {
      "label": "Online exposure",
      "value": "Routine validator signing requires online signing capability.",
      "sourceIds": [
        "x425-eth-eth-keys"
      ],
      "id": "online-exposure",
      "claimId": "ethereum-validator-keys-fact-online-exposure"
    }
  ],
  "prerequisites": [
    "ethereum-proof-of-stake-finality"
  ],
  "sections": [
    {
      "id": "roles",
      "heading": "Do not treat every staking key as a spending key",
      "sourceIds": [
        "x425-eth-eth-keys",
        "x425-eth-launchpad-faq"
      ],
      "paragraphs": [
        "Validator signatures use the BLS signature scheme designed for consensus participation. They are distinct from the ordinary Ethereum account key controlling an execution address. A public validator identifier is likewise different from a normal payment address.",
        "Older validators can have BLS withdrawal credentials that need a transition to an execution address. Modern withdrawal types point to an execution address, so recovery procedures must match the actual credentials."
      ]
    },
    {
      "id": "example",
      "heading": "Signing compromise can hurt without redirecting withdrawals",
      "sourceIds": [
        "x425-eth-eth-keys",
        "x425-eth-eth-saas"
      ],
      "paragraphs": [
        "Suppose withdrawals point to an account you control, while an operator holds the validator signing key. If that key is misused to sign conflicting duties, the validator can be slashed. Keeping the withdrawal address does not undo the penalty.",
        "The separation still matters: signing authority alone is not the same as the private key that can spend funds already received by your withdrawal account."
      ]
    },
    {
      "id": "backup",
      "heading": "Record which recovery material restores which authority",
      "sourceIds": [
        "x425-eth-launchpad-faq",
        "x425-eth-eth-keys",
        "x425-eth-eip3076"
      ],
      "paragraphs": [
        "A validator keystore, its unlocking password, a staking mnemonic and an execution-account backup are not interchangeable. Document the setup while it works, including the public validator identifier and withdrawal credentials, without exposing secrets.",
        "Before a migration, also preserve signing history through the client’s slashing-protection process. Recovering the key alone does not tell a new client what it already signed."
      ]
    }
  ],
  "faq": [
    {
      "question": "Is the validator public key a wallet address for payments?",
      "answer": "No. It identifies a validator in the consensus system. Execution withdrawals use the address specified by the validator’s withdrawal credentials.",
      "sourceIds": [
        "x425-eth-eth-keys",
        "x425-eth-launchpad-faq"
      ]
    },
    {
      "question": "Does a keystore backup include all signing history?",
      "answer": "Not necessarily. EIP-3076 specifically addresses transferring signing history separately from the key material when changing validator clients.",
      "sourceIds": [
        "x425-eth-eip3076"
      ]
    }
  ],
  "claims": [
    {
      "id": "ethereum-validator-keys-quick-answer",
      "articleSlug": "ethereum-validator-keys",
      "statement": "An Ethereum validator uses a signing key for consensus duties such as votes and block proposals. Withdrawal credentials separately determine withdrawal authority and destination. An attacker with only the signing key can disrupt or slash the validator even when unable to spend withdrawals sent to your address. Protect both forms of authority according to their different roles.",
      "sourceIds": [
        "source-c37ef41d3c4ba6d9",
        "source-1b2cc02258c65baa",
        "source-d14a53a7dccb47be"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-c37ef41d3c4ba6d9",
          "locator": "Validator key; withdrawal key"
        },
        {
          "sourceId": "source-1b2cc02258c65baa",
          "locator": "How it works; keys; counterparty risk"
        },
        {
          "sourceId": "source-d14a53a7dccb47be",
          "locator": "Validators; deposits; activation; rewards; key management"
        }
      ],
      "scope": {
        "collection": "ethereum",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T19:27:58.939Z",
        "reviewer": "Independent automated verification agent verify_bitcoin_stablecoins_100",
        "notes": [
          "Read validator keys, withdrawal credentials and withdrawal-key sections. Online BLS signing and execution-address control are distinct; legacy 0x00 credentials need transition. Keystore is not signing history, checked against EIP3076. Excluded source’s stale claim that only signing keys can currently initiate exits."
        ]
      }
    },
    {
      "id": "ethereum-validator-keys-fact-signing",
      "articleSlug": "ethereum-validator-keys",
      "statement": "Signing: Validator signing keys authorize proposals and attestations.",
      "sourceIds": [
        "source-c37ef41d3c4ba6d9"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-c37ef41d3c4ba6d9",
          "locator": "Validator key; withdrawal key"
        }
      ],
      "scope": {
        "collection": "ethereum",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T19:27:58.939Z",
        "reviewer": "Independent automated verification agent verify_bitcoin_stablecoins_100",
        "notes": [
          "Read validator keys, withdrawal credentials and withdrawal-key sections. Online BLS signing and execution-address control are distinct; legacy 0x00 credentials need transition. Keystore is not signing history, checked against EIP3076. Excluded source’s stale claim that only signing keys can currently initiate exits."
        ]
      }
    },
    {
      "id": "ethereum-validator-keys-fact-credentials",
      "articleSlug": "ethereum-validator-keys",
      "statement": "Credentials: Withdrawal credentials belong to the validator’s consensus record.",
      "sourceIds": [
        "source-d14a53a7dccb47be"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-d14a53a7dccb47be",
          "locator": "Validators; deposits; activation; rewards; key management"
        }
      ],
      "scope": {
        "collection": "ethereum",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T19:27:58.939Z",
        "reviewer": "Independent automated verification agent verify_bitcoin_stablecoins_100",
        "notes": [
          "Read validator keys, withdrawal credentials and withdrawal-key sections. Online BLS signing and execution-address control are distinct; legacy 0x00 credentials need transition. Keystore is not signing history, checked against EIP3076. Excluded source’s stale claim that only signing keys can currently initiate exits."
        ]
      }
    },
    {
      "id": "ethereum-validator-keys-fact-online-exposure",
      "articleSlug": "ethereum-validator-keys",
      "statement": "Online exposure: Routine validator signing requires online signing capability.",
      "sourceIds": [
        "source-c37ef41d3c4ba6d9"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-c37ef41d3c4ba6d9",
          "locator": "Validator key; withdrawal key"
        }
      ],
      "scope": {
        "collection": "ethereum",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T19:27:58.939Z",
        "reviewer": "Independent automated verification agent verify_bitcoin_stablecoins_100",
        "notes": [
          "Read validator keys, withdrawal credentials and withdrawal-key sections. Online BLS signing and execution-address control are distinct; legacy 0x00 credentials need transition. Keystore is not signing history, checked against EIP3076. Excluded source’s stale claim that only signing keys can currently initiate exits."
        ]
      }
    }
  ],
  "sources": [
    {
      "id": "x425-eth-eth-keys",
      "label": "Ethereum proof-of-stake keys",
      "publisher": "ethereum.org contributors",
      "url": "https://ethereum.org/en/developers/docs/consensus-mechanisms/pos/keys/",
      "locator": "Validator key; withdrawal key",
      "note": "Online validator signing versus separate withdrawal authority and credentials.",
      "version": "Documentation snapshot retrieved 2 October 2026; response hash recorded separately",
      "checkedAt": "2026-10-02T18:55:26.064Z",
      "contentSha256": "bc59c1f6f7c1b4061b0200e322370b653b9f4ac72e8484ebff173f9a7d474896",
      "recordId": "source-c37ef41d3c4ba6d9"
    },
    {
      "id": "x425-eth-eth-saas",
      "label": "Staking as a service",
      "publisher": "ethereum.org contributors",
      "url": "https://ethereum.org/en/staking/saas/",
      "locator": "How it works; keys; counterparty risk",
      "note": "Outsourced validator operation and withdrawal-key control need separate assessment.",
      "version": "Documentation snapshot retrieved 2 October 2026; response hash recorded separately",
      "checkedAt": "2026-10-02T18:55:26.034Z",
      "contentSha256": "7c61790bc7982bc6cade769163078f32e8e4e69425f477ca078fdbfcba451e70",
      "recordId": "source-1b2cc02258c65baa"
    },
    {
      "id": "x425-eth-launchpad-faq",
      "label": "Ethereum staking launchpad FAQ source",
      "publisher": "Ethereum Foundation",
      "url": "https://raw.githubusercontent.com/ethereum/staking-launchpad/dev/src/pages/FAQ/index.jsx",
      "locator": "Validators; deposits; activation; rewards; key management",
      "note": "Staking lifecycle, qualifying balances, network duties and deposit-data handling.",
      "version": "Documentation snapshot retrieved 2 October 2026; response hash recorded separately",
      "checkedAt": "2026-10-02T18:58:48.434Z",
      "contentSha256": "31805a01cc3b2f365af2789eb2fcbeed34e0bd404a3ed55d7980e51dda17a67b",
      "recordId": "source-d14a53a7dccb47be"
    },
    {
      "id": "x425-eth-eip3076",
      "label": "Slashing protection interchange format",
      "publisher": "Ethereum Improvement Proposals",
      "url": "https://eips.ethereum.org/EIPS/eip-3076",
      "locator": "Interchange format; import and export; safety",
      "note": "Signing-history transfer between validator clients does not authorize concurrent independent copies.",
      "version": "EIP-3076",
      "checkedAt": "2026-10-02T18:55:26.323Z",
      "contentSha256": "bf236c87eea59de6a6eb5fdfb802dffa5399004902cacc4f44522f4f80e95866",
      "recordId": "source-9d546a950a3e1f5d"
    }
  ],
  "related": {
    "articles": [
      "ethereum-staking-withdrawals",
      "ethereum-slashing",
      "ethereum-nodes-rpc",
      "pooled-ethereum-staking",
      "ethereum-validator-downtime"
    ],
    "dossiers": [],
    "wallets": []
  },
  "revisionHistory": [
    {
      "date": "2026-10-02",
      "kind": "published",
      "summary": "First publication after primary-source research and separate automated verification."
    }
  ],
  "citation": "Degrees of Satoshi editorial project. “Validator signing keys and withdrawal credentials: different powers.” Published 2026-10-02; updated 2026-10-02. https://degreesofsatoshi.com/encyclopedia/ethereum-validator-keys/"
}
