PipeFlare

Private Key vs Public Key Crypto Explained

Understand private key vs public key crypto mechanics. Learn how key pairs generate addresses, sign transactions, and secure funds on blockchains.

Updated October 2026 · Reviewed by the PipeFlare team

A private key is a secret number that authorises spending from a wallet address, while a public key is derived from it using one-way maths to prove ownership safely.

Anyone with access to your private key can take your funds permanently, because blockchain transactions cannot be reversed and have no password resets.

Category

Wallet security

Difficulty

Beginner

Where you'll see it

Non-custodial wallets, hardware wallets, and QR codes.

First introduced

Not stated in the primary documentation

About private key vs public key

In private key vs public key crypto architectures, a private key is a secret number that lets you authorise spending from an address. A public key is calculated directly from that private key using one-way mathematical rules, and the public wallet address you give out to receive payments is derived from the public key. While you can share your public key or address with anyone, the private key must remain entirely secret. Holding the private key gives absolute control over the funds associated with its address. Crypto coins do not sit inside an application on your phone or computer. The underlying blockchain ledger simply attributes balances to public addresses, and your private key acts as the mathematical proof that you are allowed to move those coins. Anyone who discovers your private key can transfer your entire balance immediately. Because blockchain transactions are final once confirmed, no support desk or company can reverse an unauthorised transfer.

How it actually works

Cryptographic key systems rely on asymmetric mathematics to manage ownership on decentralized networks. On networks like Ethereum and Bitcoin, a private key is a secret number that is 256 bits long. From this secret value, software calculates a paired public key using elliptic curve cryptography on the secp256k1 curve. This mathematical transformation operates in only one direction. Calculating the private key back from a public key is practically infeasible. To produce the public address that you share to receive funds, the network software hashes and formats the public key. The address is safe to distribute publicly, though every transaction sent to or from that address remains permanently visible on the public blockchain ledger.

Moving cryptocurrency requires creating a digital signature rather than transmitting the private key over the internet. When you broadcast a transaction from a crypto wallet, your software uses the private key to generate a unique digital signature over the specific transaction data. Network nodes inspect this mathematical signature using your known public key to verify that the creator holds the genuine private key. The nodes can confirm validity without ever seeing the secret 256-bit number itself. The private key itself is never sent to the network.

Modern applications simplify the management of these numerical strings through deterministic standards documented in the Bitcoin Improvement Proposals. Instead of forcing users to track raw 256-bit values for every new address, systems use a seed phrase. Defined under BIP-39, a seed phrase is a sequence of 12 or 24 words that encodes a root seed. Following the BIP-32 standard, a hierarchical deterministic wallet uses this single root seed to calculate numerous private keys systematically. Backing up the recovery phrase therefore backs up every private key the wallet will ever generate. Anyone who obtains that 12 or 24-word sequence gains control of all the underlying keys and funds.

A blockchain private key can appear in several formats depending on the interface. It may display as a raw hexadecimal string, a Wallet Import Format string in Bitcoin, or an encoded image. A private key QR code is simply another visual representation of the underlying secret number. Scanning a private key QR code grants immediate access to spend the assets tied to it, making the image just as sensitive as the text itself. Storing funds in a non-custodial wallet means you hold these keys directly, in contrast to custodial exchange accounts where the operating company holds the keys on your behalf. Readers who want more isolation can read about cold wallet vs hot wallet setups, where dedicated hardware chips sign transactions inside the device so the key need not touch an internet-connected computer, or a multisig wallet, which requires multiple separate private keys to approve an outgoing transfer.

Start here

  1. 1Verify where your keys live (see [Self-custody vs custodian](/learn/self-custody-vs-custodian)) so you know whether you or an exchange holds the spending authority.
  2. 2Check public balances by searching your public address in a block explorer (see [What is a blockchain explorer](/learn/what-is-a-blockchain-explorer)) rather than typing private data into unverified online checkers.
  3. 3Follow [How to store a seed phrase safely](/learn/how-to-store-a-crypto-seed-phrase-safely) to keep your recovery words secure.
  4. 4Reject every request from websites, support chats, forms, or key generator tools that ask you to reveal, enter, or scan a private key or recovery phrase.

Strengths

  • Mathematical derivation lets you safely share public keys and receiving addresses without exposing the secret 256-bit number needed to authorise spends.
  • Asymmetric digital signatures allow decentralized nodes to verify that a transaction is genuine while the private key remains secure on your personal device.
  • Deterministic standards like BIP-32 and BIP-39 enable a single 12 or 24-word backup phrase to generate and recover all associated private keys.

Common misunderstandings

  • Losing your private key or recovery phrase permanently locks your funds, because blockchains feature no central account recovery or password resets.
  • Irreversible transaction processing means that if a thief copies your private key or scans your private key QR code, stolen assets cannot be recovered.
  • Pasting a private key into an online balance checker or generator page immediately compromises the wallet by handing spending power to third parties.

Common questions

What is the difference between a private key and a public key?

A private key is a secret 256-bit number that you use to authorise spending and create digital signatures for outgoing transactions. A public key is calculated from the private key using one-way elliptic curve cryptography on curves like secp256k1, making it safe to share publicly. Anyone who holds the private key controls the funds, while the public key only allows the network to verify signatures.

Is a public key the same as a wallet address?

A public key is not identical to a wallet address, although they are mathematically linked. Network software derives an address by hashing and formatting the public key into a shareable string. The address is the exact destination you provide to other users when receiving funds, while keeping the underlying ledger balances publicly visible.

Is it safe to share my public key?

Sharing your public key or public receiving address is safe because one-way mathematics prevents anyone from calculating your private key from it. Other participants need your address to send you payments. Keep in mind that every transaction sent to or from that public address remains visible to anyone inspecting the public blockchain ledger.

Can someone steal crypto with only my public address?

No, an external party cannot steal your cryptocurrency using only your public address. Spending funds requires generating a valid digital signature using the secret private key. Because network nodes require this mathematical proof before confirming transactions, holding an address alone gives nobody the ability to move the associated assets.

What is a private key QR code?

A private key QR code is simply a visual, scannable format for the secret numerical string or Wallet Import Format data. Because scanning the code reads the exact private key, anyone who scans it obtains full control over the wallet's funds. It must be guarded with the exact same secrecy as the raw written number.

What happens if I lose my private key?

If you lose your private key along with its corresponding seed phrase backup, your funds cannot be recovered by anyone. Blockchains operate without customer support desks, chargeback systems, or password reset tools. Once the only copy of the private key is gone, the coins remain locked at that address on the ledger.

Sources

Related guides

Ready to put this into practice?

Exchange sign-up bonuses pay both you and a referrer after a qualifying trade.

See bonuses →