Skip to content
MyCryptoStart
Security Explainer beginner

What Is a Private Key? (And Why It's Secret)

A private key is the secret code that proves you own your crypto and lets you spend it. Learn how it works and how to keep it safe.

Lucas Almeida 5 min read

Key takeaways

  • A private key is a secret string of characters that proves ownership of a crypto address and lets you spend the funds held there.
  • It is paired with a public key. The public key is shareable (like an address), the private key is not (like the key that opens it).
  • In practice you usually hold a seed phrase (12–24 words) that generates all your private keys, rather than the keys themselves.
  • Whoever has your private key has full and irreversible control of your funds — never share it or type it into a website.
  • Private-key compromise was the single largest cause of crypto theft in 2024, at 43.8% of roughly US$2.2 billion stolen.

A private key is a secret string of characters that proves you own a cryptocurrency address and lets you spend the funds held there. Think of it as the key to a safe-deposit box: the box has a number anyone can see, but only the key opens it.

If someone else gets your private key, they control your funds — and the loss is permanent. Nothing about a crypto transaction can be reversed, and no support team can get your money back.

What is a private key?

A private key is a secret code that proves you own a specific crypto address and lets you spend its funds. It is the single most important thing you will ever handle in crypto.

When you create a wallet, the software generates a random number. That number is your private key. From it, the wallet mathematically derives your public key, and from that, your address — the string of characters you share with people who want to send you money.

Here is the plain-English version:

  • Address (public): share it freely. It is like an email address or a bank account number. People use it to send you crypto.
  • Private key (secret): never share it. It is like a password or a physical key. Anyone who has it can open your funds and take everything.

The relationship is one-way. Your public key can always be generated from your private key, but your private key cannot be reverse-engineered from your public key. That one-way property is what makes the whole system secure.

How do public and private keys work together?

Every private key is paired with a public key, and the two work together through a one-way mathematical function. You can go from private to public in one direction only.

The underlying technology is called public-key cryptography (asymmetric encryption). It is the same idea behind HTTPS and digital signatures, not something unique to crypto.

A useful analogy is a mailbox:

  • The mailbox slot is your address. Anyone can see it and drop mail in.
  • The mailbox key is your private key. Only the person holding it can open the box and take the mail out.

When someone sends you Bitcoin or Ethereum, they send it to your public address. Only the holder of the matching private key can then spend it.

The golden rule: your address proves where money should go; your private key proves it is yours to move.

What does a private key look like?

A private key is a very large number, usually shown as a long string of letters and digits. The exact format depends on the blockchain.

BlockchainPrivate key format
BitcoinA 256-bit number, often written in a compact “WIF” format (~52 characters, starting with 5, K, or L)
Ethereum64 hexadecimal characters (usually prefixed with 0x)

Here is what an Ethereum-style private key looks like in shape (this is an example only — never use a key you see published anywhere):

0xafdfd9c3d2095ef6… (64 characters in total)

The scale matters more than the format. A private key is a random number with about 2^256 possible values — a 1 followed by 77 zeros. That number is so large that guessing a specific key is, for all practical purposes, impossible. The security of your crypto does not come from the key being hidden; it comes from the key being unguessable.

What does a private key actually do?

A private key’s main job is to digitally sign transactions, proving you authorized them without ever revealing the key itself.

When you send crypto, your wallet does three things behind the scenes:

  1. It builds a transaction that says “send 0.5 BTC from address A to address B.”
  2. It signs that transaction using your private key, producing a digital signature.
  3. It broadcasts the signed transaction to the network, where anyone can verify — using your public key — that the signature is genuine and came from the owner.

The elegant part: the network can prove you signed the transaction without ever seeing your private key. Your private key stays on your device the entire time.

Here is the same idea as a concrete example. When Alice sends 0.1 BTC to Bob:

  1. Alice’s wallet builds the message “send 0.1 BTC from Alice’s address to Bob’s address.”
  2. It signs that message with Alice’s private key, producing a signature.
  3. The network checks the signature against Alice’s public key — it either matches or it does not.
  4. If it matches, the network accepts the transaction and Bob sees the 0.1 BTC.

Notice what never happened: Alice’s private key never left her device. Only the signature traveled across the network, and a signature cannot be reversed into the key that made it.

That is why possession of the private key is possession of the funds. The blockchain does not know or care who you are — it only recognizes whoever can produce a valid signature for that key.

Private key vs. seed phrase: what’s the difference?

A private key controls one address; a seed phrase (12–24 words) generates and restores every key in a wallet. You rarely handle raw private keys day to day.

Modern wallets use a standard called BIP-39 to turn your private keys into a human-friendly seed phrase (also called a recovery phrase or mnemonic). Instead of writing down a long string of random characters, you write down 12 to 24 ordinary words.

The key difference in scope:

Private keySeed phrase
FormatLong random string12–24 dictionary words
ControlsOne addressThe entire wallet (all addresses)
Main useSigning transactionsBackup and recovery
Shareable?NeverNever
Lost?Lose that one addressLose the whole wallet

A common analogy: a private key is the key to one apartment, while a seed phrase is the master key code for the whole building.

Both must be protected with the same care, because both grant full control if they fall into the wrong hands. See our Security guides for how to protect them.

Who holds your private key? Custodial vs. self-custody

On a custodial exchange, the exchange holds the keys for you; in a self-custody wallet, you do. The phrase to remember is “not your keys, not your coins.”

There are two fundamentally different ways to hold crypto:

Custodial (an exchange holds the keys). When you keep crypto on a platform like Binance or OKX, the platform controls the private keys. You log in with an email and password. This is convenient — the exchange handles security and lets you trade easily — but you are trusting the platform not to be hacked, go bankrupt, or freeze your account.

Self-custody (you hold the keys). When you move crypto to a wallet you control, you — and only you — hold the private key. This gives you full, direct ownership, but it also makes you the sole person responsible for not losing the key.

There is no single “correct” answer for everyone. Many beginners keep small amounts on an exchange for convenience and move larger amounts to a self-custody wallet.

💡 Don't have a Binance account yet? Sign up now — enter the referral code BN2688.

For a deeper look at the options, read our wallet guides on hot wallets, cold wallets, and hardware wallets.

How do people lose their private keys?

Most crypto theft happens through phishing, fake websites, and malware that trick people into typing their key or seed phrase into the wrong place. It is rarely a technical hack of the key itself.

The scale of the problem is real. Blockchain analytics firm Chainalysis reported that US$2.2 billion was stolen in crypto hacks in 2024, and private-key compromise was the single largest cause, at 43.8% of that total. A separate report from security firm CertiK put phishing as the top attack vector, with roughly US$1.05 billion lost across nearly 300 incidents that year.

The most common ways a private key gets exposed:

  • Fake support. A scammer poses as wallet or exchange support and asks for your seed phrase “to verify your account.” Real support never does this.
  • Phishing sites. A link in a message leads to a fake wallet or exchange site that asks you to enter your key or seed phrase.
  • Malware. Software on your computer or phone watches what you type or scans for stored keys.
  • Fake wallets. A convincing-looking app or browser extension that is actually designed to steal whatever you enter.
  • Storing it digitally. A key saved in a note app, screenshot, cloud drive, or email draft is one breach away from being stolen.

Notice the pattern: in almost every case, the victim gives the key away — usually by entering it somewhere they should not. That is why the rules below matter more than any amount of technical sophistication.

How to keep your private key safe

Write your key or seed phrase on paper or metal, keep it offline, never type it into a website, and consider a hardware wallet for large amounts.

The single most effective habit is to keep your private key (and your seed phrase) offline and out of any device that connects to the internet.

DoDon’t
Write your seed phrase on paper and store it somewhere physically secureStore it in a note app, screenshot, cloud drive, or email
Stamp it into metal if you are protecting a large amountType it into any website, app, or form
Keep a hardware wallet for significant holdingsShare it with “support,” friends, or family who ask
Verify wallet and exchange URLs before entering anythingEnter your key on a site you reached through a link or ad

Five habits that cover nearly every scenario:

  1. Go offline for backup. Write the seed phrase down physically. Never photograph it.
  2. Never type it online. No legitimate service ever asks you to enter a private key or seed phrase on a website.
  3. Trust, then verify. Before sending, double-check the receiving address character by character. Malware can swap a copied address for an attacker’s.
  4. Use official sources only. Install wallet apps from the developer’s official site or app store, never from a link in a message.
  5. Match your security to the amount. A small amount in a software wallet is fine; life-changing savings belong in cold storage.

The goal is not to make your crypto impossible to use. It is to make it impossible for anyone else to use.

What to do if your private key is exposed

If you believe your private key or seed phrase has been exposed, move your funds to a brand-new wallet immediately. Do not wait to see what happens.

Time is the whole game, because whoever has the key can empty the wallet at any moment. The steps are simple:

  1. Create a new wallet on a clean, trusted device.
  2. Write down the new seed phrase and store it securely offline.
  3. Move everything from the compromised wallet to the new address as fast as you can.
  4. Abandon the old wallet. Treat the old key as permanently compromised and never use it again.

If the funds are on an exchange and you believe your account (not a key) is compromised, contact the exchange’s support immediately and change your password, and turn on every security feature they offer.

There is no “undo,” no fraud department, and no recovery for a stolen private key. Prevention — the rules in the previous section — is the only real protection.

The bottom line

A private key is the secret code that gives you ownership of your crypto. Share the address, never the key. Back up your seed phrase offline, never enter it online, and move funds the moment you suspect a key has been exposed.

If you are just starting out, take the time to understand what a seed phrase is and the most common scams before you put real money at risk. Getting the security basics right early is worth far more than any trading tip.

Don't have a Binance account yet?Sign up nowenter the referral codeBN2688

Frequently asked questions

Can someone guess my private key?
No. A private key is a random number with roughly 2^256 possible values (a 1 followed by 77 zeros). The odds of guessing a specific key are effectively zero, which is what keeps the system secure.
Is a private key the same as my wallet password?
No. A password protects a device or an app. A private key proves ownership on the blockchain itself. If you forget a password you can usually reset it; if you lose a private key there is no reset.
What happens if I lose my private key?
Your funds become permanently inaccessible. Nobody — no exchange, wallet provider, or support team — can recover a lost private key. This is why backing up your seed phrase is essential.
Is it safe to share my public key or address?
Yes. Your public key (or the address derived from it) is designed to be shared so people can send you funds. Only the private key must stay secret.
Do exchanges like Binance or OKX give me a private key?
No. On a custodial exchange the exchange holds the keys on your behalf and you log in with an email and password. You only control a private key when you use a self-custody wallet.
What is the difference between a private key and a seed phrase?
A private key controls a single address. A seed phrase (12–24 words) is a backup that generates and restores every address and private key in a wallet — so it must be protected just as carefully.

Editor-in-Chief & Lead Researcher

Lucas Almeida

Editor of MyCryptoStart. Independent researcher of cryptocurrency exchanges, focused on fees, security, KYC, and onboarding — publishes step-by-step guides in plain English for beginners.

View author page →

Some links on this page are affiliate links: we may earn a commission at no extra cost to you. This content is educational and is not financial, investment, or legal advice. Affiliate disclosure · Disclaimer.