# Private keys, public keys and seed phrases: what actually controls your bitcoin

A private key is a secret scalar used to authorize spending conditions involving its public key. A Bitcoin output can require one key, multiple keys or other script conditions. A BIP39 seed phrase encodes entropy and derives a wallet seed together with an optional passphrase. Recovering the intended wallet also requires compatible derivation paths and script types; the phrase alone is not a universal backup for every wallet.

Evidence: [Secp256k1](https://en.bitcoin.it/wiki/Secp256k1); [BIP 32: Hierarchical Deterministic Wallets](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0032.mediawiki); [BIP 39: Mnemonic code for generating deterministic keys](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0039.mediawiki); [BIP 44: Multi-Account Hierarchy for Deterministic Wallets](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0044.mediawiki)

Canonical: https://degreesofsatoshi.com/encyclopedia/private-keys-and-seed-phrases/
Published: 2026-09-23
Substantively modified: 2026-10-02
Independently verified by an automated reviewer: 2026-10-02T18:26:58.075Z

AI-assisted research and drafting with a separate automated source-verification pass; no external expert or named human review is implied.

## Key facts

- **Private key:** “A secret number that allows bitcoins to be spent”; 256 bits long ([Private key](https://en.bitcoin.it/wiki/Private_key))
- **Curve:** secp256k1, defined in the Standards for Efficient Cryptography ([Secp256k1](https://en.bitcoin.it/wiki/Secp256k1))
- **Seed phrase standard:** BIP39, dated 10 September 2013 ([BIP 39: Mnemonic code for generating deterministic keys](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0039.mediawiki))
- **Phrase length:** BIP39 permits 12, 15, 18, 21 or 24 words for 128, 160, 192, 224 or 256 bits of entropy ([BIP 39: Mnemonic code for generating deterministic keys](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0039.mediawiki))
- **Word list:** 2,048 entries; the English list can be distinguished by each word’s first four letters ([BIP 39: Mnemonic code for generating deterministic keys](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0039.mediawiki))
- **Key tree:** BIP32 derives a hierarchical key tree from one seed; imported unrelated keys are not recreated by that seed ([BIP 32: Hierarchical Deterministic Wallets](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0032.mediawiki))
- **Wallet layout:** BIP44 (24 April 2014): purpose, coin type, account, change, index ([BIP 44: Multi-Account Hierarchy for Deterministic Wallets](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0044.mediawiki))

## A private key authorizes the spending conditions that use it

A Bitcoin private key is a secret scalar used to produce signatures, commonly encoded in 32 bytes. A signature can satisfy spending conditions involving the corresponding public key, but an output may require additional keys or other conditions.

A deterministic wallet can derive many keys from a seed, with extended keys and derivation paths describing the hierarchy. The way the wallet encodes or stores a key does not replace the output’s actual authorization conditions.

Losing or exposing a key has consequences determined by that policy. One missing key can prevent a single-key spend, while a threshold arrangement may retain another authorized recovery path. An attacker still needs enough authority to satisfy the actual script.

Evidence: [BIP 32: Hierarchical Deterministic Wallets](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0032.mediawiki); [Bitcoin Developer Guide: Transactions](https://developer.bitcoin.org/devguide/transactions.html); [Output Script Descriptors General Operation](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0380.mediawiki)

## A public key comes from the private key, and the trip is one way

From the private key, the wallet computes a public key using elliptic curve mathematics on a curve called secp256k1. The Bitcoin Wiki describes it as “the parameters of the elliptic curve used in Bitcoin’s public-key cryptography,” defined in the Standards for Efficient Cryptography, with the equation y² = x³ + 7. You do not need the equation to use Bitcoin. What matters is the shape of the operation: multiplying a fixed starting point on the curve by your private key gives a public key, and there is no known practical way to run that multiplication backwards.

A public key lets others verify signatures made with the corresponding secret. Public information can still reveal transaction relationships. Receiving addresses encode supported payment destinations; different address types can refer to public-key material or script commitments rather than all being the same hash format.

The wiki notes two reasons the curve was chosen. Its constants “were selected in a predictable way, which significantly reduces the possibility that the curve’s creator inserted any sort of backdoor,” and its structure allows implementations that are “often more than 30% faster than other curves.” A point on the curve, which is what a public key is, takes 33 bytes to write in compressed form or 65 bytes uncompressed.

Evidence: [Secp256k1](https://en.bitcoin.it/wiki/Secp256k1); [Bitcoin: A Peer-to-Peer Electronic Cash System](https://bitcoin.org/bitcoin.pdf); [Output Script Descriptors General Operation](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0380.mediawiki); [Bitcoin Developer Guide: Transactions](https://developer.bitcoin.org/devguide/transactions.html)

## Match the backup to the wallet’s derivation rules

BIP-39 first normalizes the mnemonic and optional passphrase using Unicode NFKD, then derives a seed. A different normalized passphrase derives a different seed without a built-in correct-passphrase signal. A wallet-file password is a separate encryption mechanism.

Recovering the intended outputs also requires the relevant derivation paths and script conventions. A descriptor can preserve this context. For multisignature arrangements, one participant’s seed does not automatically replace the other keys or the policy information.

Evidence: [BIP 39: Mnemonic code for generating deterministic keys](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0039.mediawiki); [BIP 32: Hierarchical Deterministic Wallets](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0032.mediawiki); [Output Script Descriptors General Operation](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0380.mediawiki); [Bitcoin Developer Guide: Transactions](https://developer.bitcoin.org/devguide/transactions.html); [walletpassphrase RPC](https://bitcoincore.org/en/doc/29.0.0/rpc/wallet/walletpassphrase/)

## One seed grows a whole tree of keys

BIP-32 derives a master extended key from a seed and derives child keys along a hierarchy. An extended private key can derive descendants within its branch. An extended public key can derive only non-hardened public descendants and does not contain ordinary signing authority.

A public export can expose a branch’s past and future activity. BIP-32 also describes how a parent extended public key combined with a corresponding non-hardened descendant private key can expose the parent private key. Read-only information is therefore not necessarily harmless to share.

BIP-44 specifies one wallet hierarchy: hardened purpose, coin-type and account levels, followed by receiving/change and address-index levels. Its account-discovery process uses a 20-unused-address gap limit on the external chain. Other wallet policies can use different paths or scripts, so a seed alone does not identify every recovery convention.

Evidence: [BIP 32: Hierarchical Deterministic Wallets](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0032.mediawiki); [BIP 44: Multi-Account Hierarchy for Deterministic Wallets](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0044.mediawiki); [Output Script Descriptors General Operation](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0380.mediawiki)

## “Not your keys, not your coins,” said plainly

The saying gets repeated so often it can sound like a slogan. Read literally, it is a description of where the risk sits. If a company holds the private keys, what you have is a claim on that company, recorded in its database. The bitcoin.org security page says the same thing without the rhyme: “When a third party controls your keys, you rely entirely on their security and honesty,” and “history has shown that exchanges and online wallets can be hacked, fail, or freeze access to funds.”

The site’s dossier on the [collapse of Mt. Gox](/history/mt-gox-collapse/) is the long version of that sentence. Customers had balances; the company had the keys; when the company could no longer honor withdrawals, the balances became claims in a bankruptcy. That is not an argument that everyone must hold their own keys. Holding them yourself means there is no one to call if the phrase is lost or a device is compromised. It is an argument for knowing which arrangement you are in.

Check who can authorize an on-chain spend and what the documented recovery process restores. The ability to reset an application password alone does not establish who controls the signing keys. Custody and recovery need to be evaluated from the actual arrangement.

Evidence: [Securing your wallet](https://bitcoin.org/en/secure-your-wallet)

## A seed is only one part of a recovery plan

BIP-39 applies Unicode NFKD normalization to the mnemonic and optional passphrase before deriving the seed. A different normalized passphrase derives a different valid seed without a built-in indication of which wallet was intended.

Recovery also requires compatible derivation paths and script types. Imported keys, multisignature policies and cosigner information may need separate backups. The relevant wallet documentation determines the complete recovery procedure.

Evidence: [BIP 39: Mnemonic code for generating deterministic keys](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0039.mediawiki); [BIP 32: Hierarchical Deterministic Wallets](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0032.mediawiki)

## Questions

### Can someone guess my private key?

Properly generated secp256k1 private keys have an enormous search space, making random guessing impractical. Key generation, compromised devices and exposed recovery material are separate risks. The displayed decimal length is not a security test.

Evidence: [BIP 32: Hierarchical Deterministic Wallets](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0032.mediawiki); [Securing your wallet](https://bitcoin.org/en/secure-your-wallet)

### Is a seed phrase the same as a private key?

No. Under BIP39 the words encode random bits plus a checksum, and those bits are stretched into a seed. Under BIP32 the wallet then derives every private key from that seed in a fixed order. One phrase yields all the keys, which is why it is both the backup and the thing to guard. Recovery still requires the correct optional passphrase, compatible derivation paths and script types; imported keys or multisignature policy data may require additional backups.

Evidence: [BIP 39: Mnemonic code for generating deterministic keys](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0039.mediawiki); [BIP 32: Hierarchical Deterministic Wallets](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0032.mediawiki)

### What happens if I lose my seed phrase?

A functioning signing wallet or another valid backup may still allow recovery or a transfer. If no remaining key material or authorized recovery path can satisfy the spending conditions, the outputs remain on-chain without a practical way for you to spend them. Multisignature and recovery policies must be considered separately.

Evidence: [BIP 32: Hierarchical Deterministic Wallets](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0032.mediawiki); [Output Script Descriptors General Operation](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0380.mediawiki); [Bitcoin Developer Guide: Transactions](https://developer.bitcoin.org/devguide/transactions.html)

### Can I make up my own 12 words?

Not safely. A BIP39 phrase includes a checksum computed from the random bits, so a made-up sentence will almost always fail it, and the standard requires wallets to warn when it does. More importantly, words chosen by a person are far less random than the 128 or 256 bits the standard expects a wallet to draw.

Evidence: [BIP 39: Mnemonic code for generating deterministic keys](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0039.mediawiki)

### What does “not your keys, not your coins” mean?

If a company holds the private keys, your balance is a claim on that company rather than a coin you control. Bitcoin.org puts it as relying “entirely on their security and honesty.” Holding the keys yourself removes that dependency and adds another: there is no one to help if you lose them.

Evidence: [Securing your wallet](https://bitcoin.org/en/secure-your-wallet)

## Claims and scope

### private-keys-and-seed-phrases-quick-answer

A private key is a secret scalar used to authorize spending conditions involving its public key. A Bitcoin output can require one key, multiple keys or other script conditions. A BIP39 seed phrase encodes entropy and derives a wallet seed together with an optional passphrase. Recovering the intended wallet also requires compatible derivation paths and script types; the phrase alone is not a universal backup for every wallet.

Scope: {"collection":"bitcoin","dataAsOf":null,"blockHeight":null}

### private-keys-and-seed-phrases-fact-private-key

Private key: “A secret number that allows bitcoins to be spent”; 256 bits long

Scope: {"collection":"bitcoin","dataAsOf":null,"blockHeight":null}

### private-keys-and-seed-phrases-fact-curve

Curve: secp256k1, defined in the Standards for Efficient Cryptography

Scope: {"collection":"bitcoin","dataAsOf":null,"blockHeight":null}

### private-keys-and-seed-phrases-fact-seed-phrase-standard

Seed phrase standard: BIP39, dated 10 September 2013

Scope: {"collection":"bitcoin","dataAsOf":null,"blockHeight":null}

### private-keys-and-seed-phrases-fact-phrase-length

Phrase length: BIP39 permits 12, 15, 18, 21 or 24 words for 128, 160, 192, 224 or 256 bits of entropy

Scope: {"collection":"bitcoin","dataAsOf":null,"blockHeight":null}

### private-keys-and-seed-phrases-fact-word-list

Word list: 2,048 entries; the English list can be distinguished by each word’s first four letters

Scope: {"collection":"bitcoin","dataAsOf":null,"blockHeight":null}

### private-keys-and-seed-phrases-fact-key-tree

Key tree: BIP32 derives a hierarchical key tree from one seed; imported unrelated keys are not recreated by that seed

Scope: {"collection":"bitcoin","dataAsOf":null,"blockHeight":null}

### private-keys-and-seed-phrases-fact-wallet-layout

Wallet layout: BIP44 (24 April 2014): purpose, coin type, account, change, index

Scope: {"collection":"bitcoin","dataAsOf":null,"blockHeight":null}

## Sources

- [Private key](https://en.bitcoin.it/wiki/Private_key) — Bitcoin Wiki. Defines a private key as a secret number allowing bitcoins to be spent, gives its 256-bit size, describes Wallet Import Format lengths and prefixes, and states what to do if a key is compromised. Locator: Defines a private key as a secret number allowing bitcoins to be spent, gives its 256-bit size, describes Wallet Import Format lengths and prefixes, and states what to do if a key is compromised.. Retrieved: 2026-10-02T14:48:38.392499+00:00.
- [Secp256k1](https://en.bitcoin.it/wiki/Secp256k1) — Bitcoin Wiki. Describes the curve Bitcoin uses, its equation, its definition in the Standards for Efficient Cryptography, the predictable choice of constants, its speed, and compressed and uncompressed point sizes. Locator: Describes the curve Bitcoin uses, its equation, its definition in the Standards for Efficient Cryptography, the predictable choice of constants, its speed, and compressed and uncompressed point sizes.. Retrieved: 2026-10-02T14:48:38.433042+00:00.
- [Bitcoin: A Peer-to-Peer Electronic Cash System](https://bitcoin.org/bitcoin.pdf) — bitcoin.org. Section 2 defines an electronic coin as a chain of digital signatures, each owner signing the previous transaction and the next owner’s public key. Locator: Section 2 defines an electronic coin as a chain of digital signatures, each owner signing the previous transaction and the next owner’s public key.. Retrieved: 2026-10-02T15:04:11.761440+00:00.
- [BIP 39: Mnemonic code for generating deterministic keys](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0039.mediawiki) — Bitcoin Improvement Proposals (github.com/bitcoin/bips). Specifies 128 to 256 bits of entropy, the checksum, 11-bit indexes into a 2,048-word list, 12 to 24 word phrases, the four-letter uniqueness rule, the optional passphrase and the PBKDF2 stretch to a 512-bit seed. Locator: Specifies 128 to 256 bits of entropy, the checksum, 11-bit indexes into a 2,048-word list, 12 to 24 word phrases, the four-letter uniqueness rule, the optional passphrase and the PBKDF2 stretch to a 512-bit seed.. Retrieved: 2026-10-02T15:04:11.762465+00:00.
- [BIP 32: Hierarchical Deterministic Wallets](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0032.mediawiki) — Bitcoin Improvement Proposals (github.com/bitcoin/bips). Specifies master seeds, chain codes, child key derivation, extended keys beginning xprv and xpub, and the audit and web-server use cases for public-only derivation. Locator: Specifies master seeds, chain codes, child key derivation, extended keys beginning xprv and xpub, and the audit and web-server use cases for public-only derivation.. Retrieved: 2026-10-02T15:04:11.762323+00:00.
- [BIP 44: Multi-Account Hierarchy for Deterministic Wallets](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0044.mediawiki) — Bitcoin Improvement Proposals (github.com/bitcoin/bips). Defines the five-level path of purpose, coin type, account, change and index, with coin type 0 for Bitcoin and an address gap limit of 20. Locator: Defines the five-level path of purpose, coin type, account, change and index, with coin type 0 for Bitcoin and an address gap limit of 20.. Retrieved: 2026-10-02T15:04:11.762572+00:00.
- [Securing your wallet](https://bitcoin.org/en/secure-your-wallet) — bitcoin.org. States that a third party holding your keys means relying on its security and honesty, that exchanges and online wallets have been hacked, failed or frozen, and that online backups are highly vulnerable to theft. Locator: States that a third party holding your keys means relying on its security and honesty, that exchanges and online wallets have been hacked, failed or frozen, and that online backups are highly vulnerable to theft.. Retrieved: 2026-10-02T14:48:38.097528+00:00.
- [Output Script Descriptors General Operation](https://raw.githubusercontent.com/bitcoin/bips/927b6de9915c9262615a6399de51b200f81e5aa4/bip-0380.mediawiki) — Bitcoin BIPs contributors. Descriptors describe output scripts, keys and derivation information. Locator: Specification; Key expressions; Checksum. Retrieved: 2026-10-02T17:22:20.620Z.
- [Bitcoin Developer Guide: Transactions](https://developer.bitcoin.org/devguide/transactions.html) — Bitcoin developer documentation contributors. UTXO inputs, transaction outputs, change and the difference paid as a fee. Locator: P2PKH Script Validation; Transaction Fees And Change. Retrieved: 2026-10-02T17:03:41.190Z.
- [walletpassphrase RPC](https://bitcoincore.org/en/doc/29.0.0/rpc/wallet/walletpassphrase/) — Bitcoin Core. Unlocking an encrypted wallet temporarily; distinct from a BIP-39 passphrase. Locator: Arguments and result fields. Retrieved: 2026-10-02T17:03:41.013Z.

## Revision history

- 2026-09-23: Initial Bitcoin encyclopedia entry at this permanent URL.
- 2026-10-02: Revised direct answer to preserve source scope and qualifications. Corrected key fact: Phrase length Corrected key fact: Word list Corrected key fact: Key tree Added missing passphrase, derivation and imported-key recovery qualifications. Corrected scope or wording: and that seed is the root of everything. Corrected scope or wording: the wallet grows all of its keys
- 2026-10-02: Added reusable claims, explicit source locators, and matching Markdown and JSON. This publishing change does not itself establish factual verification.
- 2026-10-02: Expanded explanation: Match the backup to the wallet’s derivation rules. Worked examples are illustrative; source checks and independent verification are recorded separately.

## Cite this entry

Degrees of Satoshi editorial project. “Private keys, public keys and seed phrases: what actually controls your bitcoin.” Published 2026-09-23; updated 2026-10-02. https://degreesofsatoshi.com/encyclopedia/private-keys-and-seed-phrases/
