Skip to article
Degrees of SatoshiFollow the connections.
Degrees of Satoshi/ Encyclopedia

Encyclopedia Bitcoin basics · Entry 382

Private keys, public keys and seed phrases: what actually controls your bitcoin

Theme
Bitcoin basics
Sources
10 cited records
Reading time
About 7 minutes
Automated verification
Substantive update
In this article

At a glance

Key facts

Key facts for Private keys, public keys and seed phrases: what actually controls your bitcoin
FactDetailSource
Private key“A secret number that allows bitcoins to be spent”; 256 bits long[1]
Curvesecp256k1, defined in the Standards for Efficient Cryptography[2]
Seed phrase standardBIP39, dated 10 September 2013[4]
Phrase lengthBIP39 permits 12, 15, 18, 21 or 24 words for 128, 160, 192, 224 or 256 bits of entropy[4]
Word list2,048 entries; the English list can be distinguished by each word’s first four letters[4]
Key treeBIP32 derives a hierarchical key tree from one seed; imported unrelated keys are not recreated by that seed[5]
Wallet layoutBIP44 (24 April 2014): purpose, coin type, account, change, index[6]
01

A private key authorizes the spending conditions that use it

A Bitcoin private key is a secret scalar used to produce signatures, commonly encoded in 32 bytes. A signature can satisfy spending conditions involving the corresponding public key, but an output may require additional keys or other conditions.

A deterministic wallet can derive many keys from a seed, with extended keys and derivation paths describing the hierarchy. The way the wallet encodes or stores a key does not replace the output’s actual authorization conditions.

Losing or exposing a key has consequences determined by that policy. One missing key can prevent a single-key spend, while a threshold arrangement may retain another authorized recovery path. An attacker still needs enough authority to satisfy the actual script.

02

A public key comes from the private key, and the trip is one way

From the private key, the wallet computes a public key using elliptic curve mathematics on a curve called secp256k1. The Bitcoin Wiki describes it as “the parameters of the elliptic curve used in Bitcoin’s public-key cryptography,” defined in the Standards for Efficient Cryptography, with the equation y² = x³ + 7. You do not need the equation to use Bitcoin. What matters is the shape of the operation: multiplying a fixed starting point on the curve by your private key gives a public key, and there is no known practical way to run that multiplication backwards.

A public key lets others verify signatures made with the corresponding secret. Public information can still reveal transaction relationships. Receiving addresses encode supported payment destinations; different address types can refer to public-key material or script commitments rather than all being the same hash format.

The wiki notes two reasons the curve was chosen. Its constants “were selected in a predictable way, which significantly reduces the possibility that the curve’s creator inserted any sort of backdoor,” and its structure allows implementations that are “often more than 30% faster than other curves.” A point on the curve, which is what a public key is, takes 33 bytes to write in compressed form or 65 bytes uncompressed.

03

Match the backup to the wallet’s derivation rules

BIP-39 first normalizes the mnemonic and optional passphrase using Unicode NFKD, then derives a seed. A different normalized passphrase derives a different seed without a built-in correct-passphrase signal. A wallet-file password is a separate encryption mechanism.

Recovering the intended outputs also requires the relevant derivation paths and script conventions. A descriptor can preserve this context. For multisignature arrangements, one participant’s seed does not automatically replace the other keys or the policy information.

04

One seed grows a whole tree of keys

BIP-32 derives a master extended key from a seed and derives child keys along a hierarchy. An extended private key can derive descendants within its branch. An extended public key can derive only non-hardened public descendants and does not contain ordinary signing authority.

A public export can expose a branch’s past and future activity. BIP-32 also describes how a parent extended public key combined with a corresponding non-hardened descendant private key can expose the parent private key. Read-only information is therefore not necessarily harmless to share.

BIP-44 specifies one wallet hierarchy: hardened purpose, coin-type and account levels, followed by receiving/change and address-index levels. Its account-discovery process uses a 20-unused-address gap limit on the external chain. Other wallet policies can use different paths or scripts, so a seed alone does not identify every recovery convention.

05

“Not your keys, not your coins,” said plainly

The saying gets repeated so often it can sound like a slogan. Read literally, it is a description of where the risk sits. If a company holds the private keys, what you have is a claim on that company, recorded in its database. The bitcoin.org security page says the same thing without the rhyme: “When a third party controls your keys, you rely entirely on their security and honesty,” and “history has shown that exchanges and online wallets can be hacked, fail, or freeze access to funds.”

The site’s dossier on the collapse of Mt. Gox is the long version of that sentence. Customers had balances; the company had the keys; when the company could no longer honor withdrawals, the balances became claims in a bankruptcy. That is not an argument that everyone must hold their own keys. Holding them yourself means there is no one to call if the phrase is lost or a device is compromised. It is an argument for knowing which arrangement you are in.

Check who can authorize an on-chain spend and what the documented recovery process restores. The ability to reset an application password alone does not establish who controls the signing keys. Custody and recovery need to be evaluated from the actual arrangement.

06

A seed is only one part of a recovery plan

BIP-39 applies Unicode NFKD normalization to the mnemonic and optional passphrase before deriving the seed. A different normalized passphrase derives a different valid seed without a built-in indication of which wallet was intended.

Recovery also requires compatible derivation paths and script types. Imported keys, multisignature policies and cosigner information may need separate backups. The relevant wallet documentation determines the complete recovery procedure.

Direct answers

Questions people ask

Can someone guess my private key?

Properly generated secp256k1 private keys have an enormous search space, making random guessing impractical. Key generation, compromised devices and exposed recovery material are separate risks. The displayed decimal length is not a security test.

Is a seed phrase the same as a private key?

No. Under BIP39 the words encode random bits plus a checksum, and those bits are stretched into a seed. Under BIP32 the wallet then derives every private key from that seed in a fixed order. One phrase yields all the keys, which is why it is both the backup and the thing to guard. Recovery still requires the correct optional passphrase, compatible derivation paths and script types; imported keys or multisignature policy data may require additional backups.

What happens if I lose my seed phrase?

A functioning signing wallet or another valid backup may still allow recovery or a transfer. If no remaining key material or authorized recovery path can satisfy the spending conditions, the outputs remain on-chain without a practical way for you to spend them. Multisignature and recovery policies must be considered separately.

Can I make up my own 12 words?

Not safely. A BIP39 phrase includes a checksum computed from the random bits, so a made-up sentence will almost always fail it, and the standard requires wallets to warn when it does. More importantly, words chosen by a person are far less random than the 128 or 256 bits the standard expects a wallet to draw.

What does “not your keys, not your coins” mean?

If a company holds the private keys, your balance is a claim on that company rather than a coin you control. Bitcoin.org puts it as relying “entirely on their security and honesty.” Holding the keys yourself removes that dependency and adds another: there is no one to help if you lose them.

Inspect the evidence

The answer and key facts have stable claim links. These records retain the scope and qualification when reused.

A private key is a secret scalar used to authorize spending conditions involving its public key. A Bitcoin output can require one key, multiple keys or other script conditions. A BIP39 seed phrase encodes entropy and derives a wallet seed together with an optional passphrase. Recovering the intended wallet also requires compatible derivation paths and script types; the phrase alone is not a universal backup for every wallet.

Scope: Bitcoin. Verification: verified · 2026-10-02T18:26:58.075Z.

Link to this claim
Private key: “A secret number that allows bitcoins to be spent”; 256 bits long

Scope: Bitcoin. Verification: verified · 2026-10-02T18:26:58.075Z.

Link to this claim
Curve: secp256k1, defined in the Standards for Efficient Cryptography

Scope: Bitcoin. Verification: verified · 2026-10-02T18:26:58.075Z.

Link to this claim
Seed phrase standard: BIP39, dated 10 September 2013

Scope: Bitcoin. Verification: verified · 2026-10-02T18:26:58.075Z.

Link to this claim
Phrase length: BIP39 permits 12, 15, 18, 21 or 24 words for 128, 160, 192, 224 or 256 bits of entropy

Scope: Bitcoin. Verification: verified · 2026-10-02T18:26:58.075Z.

Link to this claim
Word list: 2,048 entries; the English list can be distinguished by each word’s first four letters

Scope: Bitcoin. Verification: verified · 2026-10-02T18:26:58.075Z.

Link to this claim
Key tree: BIP32 derives a hierarchical key tree from one seed; imported unrelated keys are not recreated by that seed

Scope: Bitcoin. Verification: verified · 2026-10-02T18:26:58.075Z.

Link to this claim
Wallet layout: BIP44 (24 April 2014): purpose, coin type, account, change, index

Scope: Bitcoin. Verification: verified · 2026-10-02T18:26:58.075Z.

Link to this claim
Revision history
  1. — Initial Bitcoin encyclopedia entry at this permanent URL.
  2. — Revised direct answer to preserve source scope and qualifications. Corrected key fact: Phrase length Corrected key fact: Word list Corrected key fact: Key tree Added missing passphrase, derivation and imported-key recovery qualifications. Corrected scope or wording: and that seed is the root of everything. Corrected scope or wording: the wallet grows all of its keys
  3. — Added reusable claims, explicit source locators, and matching Markdown and JSON. This publishing change does not itself establish factual verification.
  4. — Expanded explanation: Match the backup to the wallet’s derivation rules. Worked examples are illustrative; source checks and independent verification are recorded separately.

On the Know who controls the funds path · Learn next: Reading Ethereum wallet requests: connection, signing and calls

Source register

Sources and references

Retrieval dates and locators are recorded individually.
  1. Private keyBitcoin Wiki

    Defines a private key as a secret number allowing bitcoins to be spent, gives its 256-bit size, describes Wallet Import Format lengths and prefixes, and states what to do if a key is compromised.

    Locator: Defines a private key as a secret number allowing bitcoins to be spent, gives its 256-bit size, describes Wallet Import Format lengths and prefixes, and states what to do if a key is compromised. · Retrieved: 2026-10-02T14:48:38.392499+00:00Open source
  2. Secp256k1Bitcoin Wiki

    Describes the curve Bitcoin uses, its equation, its definition in the Standards for Efficient Cryptography, the predictable choice of constants, its speed, and compressed and uncompressed point sizes.

    Locator: Describes the curve Bitcoin uses, its equation, its definition in the Standards for Efficient Cryptography, the predictable choice of constants, its speed, and compressed and uncompressed point sizes. · Retrieved: 2026-10-02T14:48:38.433042+00:00Open source
  3. Bitcoin: A Peer-to-Peer Electronic Cash SystemSatoshi Nakamoto · 2008-10-31bitcoin.org

    Section 2 defines an electronic coin as a chain of digital signatures, each owner signing the previous transaction and the next owner’s public key.

    Locator: Section 2 defines an electronic coin as a chain of digital signatures, each owner signing the previous transaction and the next owner’s public key. · Retrieved: 2026-10-02T15:04:11.761440+00:00Open source
  4. BIP 39: Mnemonic code for generating deterministic keysMarek Palatinus, Pavol Rusnak, Aaron Voisine, Sean Bowe · 2013-09-10Bitcoin Improvement Proposals (github.com/bitcoin/bips)

    Specifies 128 to 256 bits of entropy, the checksum, 11-bit indexes into a 2,048-word list, 12 to 24 word phrases, the four-letter uniqueness rule, the optional passphrase and the PBKDF2 stretch to a 512-bit seed.

    Locator: Specifies 128 to 256 bits of entropy, the checksum, 11-bit indexes into a 2,048-word list, 12 to 24 word phrases, the four-letter uniqueness rule, the optional passphrase and the PBKDF2 stretch to a 512-bit seed. · Version / scope: 927b6de9915c9262615a6399de51b200f81e5aa4 · Retrieved: 2026-10-02T15:04:11.762465+00:00Open source
  5. BIP 32: Hierarchical Deterministic WalletsPieter Wuille · 2012-02-11Bitcoin Improvement Proposals (github.com/bitcoin/bips)

    Specifies master seeds, chain codes, child key derivation, extended keys beginning xprv and xpub, and the audit and web-server use cases for public-only derivation.

    Locator: Specifies master seeds, chain codes, child key derivation, extended keys beginning xprv and xpub, and the audit and web-server use cases for public-only derivation. · Version / scope: 927b6de9915c9262615a6399de51b200f81e5aa4 · Retrieved: 2026-10-02T15:04:11.762323+00:00Open source
  6. BIP 44: Multi-Account Hierarchy for Deterministic WalletsMarek Palatinus, Pavol Rusnak · 2014-04-24Bitcoin Improvement Proposals (github.com/bitcoin/bips)

    Defines the five-level path of purpose, coin type, account, change and index, with coin type 0 for Bitcoin and an address gap limit of 20.

    Locator: Defines the five-level path of purpose, coin type, account, change and index, with coin type 0 for Bitcoin and an address gap limit of 20. · Version / scope: 927b6de9915c9262615a6399de51b200f81e5aa4 · Retrieved: 2026-10-02T15:04:11.762572+00:00Open source
  7. Securing your walletbitcoin.org

    States that a third party holding your keys means relying on its security and honesty, that exchanges and online wallets have been hacked, failed or frozen, and that online backups are highly vulnerable to theft.

    Locator: States that a third party holding your keys means relying on its security and honesty, that exchanges and online wallets have been hacked, failed or frozen, and that online backups are highly vulnerable to theft. · Retrieved: 2026-10-02T14:48:38.097528+00:00Open source
  8. Output Script Descriptors General OperationBitcoin BIPs contributors

    Descriptors describe output scripts, keys and derivation information.

    Locator: Specification; Key expressions; Checksum · Version / scope: BIP-380; immutable revision pinned in source URL · Retrieved: 2026-10-02T17:22:20.620ZOpen source
  9. Bitcoin Developer Guide: TransactionsBitcoin developer documentation contributors

    UTXO inputs, transaction outputs, change and the difference paid as a fee.

    Locator: P2PKH Script Validation; Transaction Fees And Change · Retrieved: 2026-10-02T17:03:41.190ZOpen source
  10. walletpassphrase RPCBitcoin Core

    Unlocking an encrypted wallet temporarily; distinct from a BIP-39 passphrase.

    Locator: Arguments and result fields · Version / scope: Bitcoin Core 29.0.0 RPC · Retrieved: 2026-10-02T17:03:41.013ZOpen source
How this article was made

Research and drafting use AI assistance. A separate automated review checks claims against primary sources; no external expert or named human review is implied. Publication, substantive editing, source retrieval and verification are recorded separately. This version was independently checked by an automated reviewer on 2 October 2026.

Editorial method and corrections

Degrees of Satoshi editorial project. “Private keys, public keys and seed phrases: what actually controls your bitcoin.” Published 2026-09-23; updated 2026-10-02. https://degreesofsatoshi.com/encyclopedia/private-keys-and-seed-phrases/