Skip to content
Banking on Bitcoin

Technology

Public Key vs Private Key in Bitcoin: What's the Difference?

A private key is the secret that authorizes spending, and a public key is derived from it. See how keys, addresses and signatures fit together in Bitcoin.

By · Published

Illustration of a large glowing orange bitcoin coin on a dark background

Key takeaways

  • A private key is a secret number that lets you authorize spending. Whoever holds it controls the coins, so it is never shared.
  • A public key is calculated from the private key with one-way elliptic-curve maths. No known method on ordinary computers can work backward from it to the private key.
  • An address is built from the public key, and the address is what you share to get paid.
  • A digital signature proves you hold the private key without revealing it, and every node checks the signature using the public key.
  • Addresses are safe to share. Private keys and seed phrases never are.

What is a private key?

A private key is a very large secret number that your wallet picks at random and that authorizes spending of the bitcoin locked to it. In Bitcoin it is a 256-bit number, and the range of possible keys is so large that nobody can guess one by searching.

The key does not contain bitcoin. Your coins are entries on the public ledger, and each is locked with a condition that says, in effect, “this can be spent by whoever produces a valid signature for this key.” The private key is what produces that signature. This is why the network never asks who you are. It asks only whether the signature checks out, as How Does Bitcoin Work? describes.

Most people never see a raw private key. A wallet handles them in the background, and the thing you are asked to write down is a seed phrase, covered below.

What is a public key, and how is it made?

A public key is a number calculated from a private key using elliptic-curve mathematics, built so that the calculation only works in one direction. Bitcoin uses a specific curve called secp256k1. The wallet starts from a fixed, agreed point on that curve and combines it with your private key, and the result is your public key.

Going forward is quick. Going backward, finding the private key behind a given public key, is believed to be infeasible with any known method on ordinary computers. That one-way property is what makes it safe to show a public key to the world while the private key stays secret.

Notice what these keys are not. Bitcoin uses them to sign, not to encrypt. Nothing on the blockchain is hidden, and anyone can read every transaction. What is secret is the right to spend.

How do addresses fit in?

An address is a shorter label made from the public key, and it is what you share to receive bitcoin. The chain runs in one direction: private key, then public key, then address.

For many address types, including those starting with 1 and bc1q, the wallet runs the public key through hash functions and adds a checksum that catches typing errors. The address therefore contains a fingerprint of the key rather than the key itself. Taproot addresses, which start with bc1p, work a little differently and encode a key directly. What Is a Bitcoin Address? compares the formats.

Because each step is one-way, you cannot get from an address back to a private key, and for the hash-based types you cannot even recover the public key from the address alone. The public key becomes visible only when you spend, since the transaction has to carry what nodes need to check the signature.

How does a signature prove you own the coins?

A digital signature is a value your wallet calculates from your private key and the details of one specific transaction, and anyone can check it with the public key without learning the private key. Spending works in four steps.

  1. You tell your wallet to send coins, and it builds a transaction listing which coins are spent and where they go.
  2. The wallet uses the private key to produce a signature over that transaction’s data.
  3. The transaction goes out carrying the signature and, where needed, the public key.
  4. Every node checks that the key matches the condition the coins were locked with and that the signature is valid for this exact transaction. A valid one is accepted. An invalid one is discarded.

A signet ring and wax seal make a decent analogy. The ring is the private key. A record of what the genuine seal looks like is the public key, which anyone can hold and compare against. The comparison confirms the letter came from the ring’s owner, and it gives no one the means to make a copy of the ring.

The analogy has one limit worth knowing. A Bitcoin signature depends on the transaction it signs, so it cannot be lifted and attached to a different payment. Change the amount or the recipient and the signature no longer verifies.

What is safe to share, and what never is?

Addresses are safe to share, and private keys and seed phrases never are. The table covers the items you are likely to meet.

ItemSafe to share?Why
AddressYesIt is where payments go, and knowing it does not let anyone spend. It does let others see its public history
Public keyGenerally, but rarely neededIt cannot reveal the private key. An address is enough to get paid
Extended public keyTreat as privateIt cannot spend, but whoever has it can generate every address in that account and see the whole history
Private keyNeverWhoever has it can spend the coins
Seed phraseNeverIt regenerates every private key in the wallet

The last two rows are the ones scammers go after. No genuine wallet maker, exchange or support agent will ask for either, and a site that offers to “verify” or “import” them is trying to take your coins.

How does a seed phrase relate to keys?

A seed phrase is a readable form of one master secret from which a wallet generates all of its key pairs. Modern wallets are called hierarchical deterministic: from the single seed they derive a long sequence of private keys, and from each one a public key and an address, always in the same order.

That is how a wallet can hand you a fresh address for every payment without asking you to back up each key separately. It is also why entering the same words into a compatible wallet brings back every address at once. The consequence is that the phrase is even more sensitive than any single key, because one phrase unlocks all of them. What Is a Seed Phrase? covers storage and recovery.

A hardware wallet takes the idea further by keeping the private keys inside a dedicated device that signs for you, so they never touch a connected computer. What Is a Hardware Wallet? explains how that works, and Bitcoin Wallets Explained compares it with the other wallet types.

What are ECDSA and Schnorr signatures?

ECDSA and Schnorr are the two signature schemes Bitcoin uses, and both work with the same kind of key pair: the private key signs, and the public key verifies. ECDSA is the original scheme, in use since Bitcoin launched in 2009 and still used for most address types. Schnorr signatures were added by the Taproot upgrade in November 2021 and are used with bc1p addresses, and their mathematical structure makes it easier to combine several keys into one.

Your wallet chooses the scheme to match the address type, so you do not have to pick one. What Is Taproot? explains what Schnorr signatures make possible.

What happens if a key is lost or exposed?

A lost private key means the coins it controls can no longer be spent, and an exposed private key means anyone can spend them. Neither situation can be undone. There is no account to recover and no help desk to call, because the network checks signatures and does not check identities.

In practice, this turns key safety into backup discipline. Keep the seed phrase offline on paper or metal, never type it or a private key into a website, and test recovery with a small amount before relying on it. What Happens to Lost Bitcoin? shows how permanent a loss is.

There is one theoretical concern about exposed public keys. A very large future quantum computer could in principle derive a private key from a public key that is already visible on the blockchain. No such machine exists today, and expert opinions on timing differ widely, so Could Quantum Computers Break Bitcoin? separates what is at risk from what is not.

This article is educational. For decisions about holding or passing on a larger amount, consider a qualified financial or legal professional. If you are new to Bitcoin, the Start Here path covers the fundamentals in order.

Where to go next

Frequently asked questions

What is the difference between a public key and a private key?

A private key is a secret number that lets you authorize spending of your bitcoin, so it must never be shared. A public key is calculated from the private key and can be shared safely, because it cannot be used to work out the private key. The private key signs transactions and the public key lets others check the signature.

Can you get a private key from a public key?

Not with any known method on ordinary computers. The calculation that turns a private key into a public key works in one direction only. A large enough quantum computer could in theory reverse it, but no such machine exists today.

Is a bitcoin address the same as a public key?

No. For many address types, an address is made from a hash of the public key, so it is a shorter label derived from the key and not the key itself. Taproot addresses starting with bc1p encode a key directly. You share the address to receive payments.

Is it safe to share my public key?

A public key cannot be used to spend your bitcoin or to recover your private key, so sharing it is not an immediate danger. There is rarely a reason to, though, because an address is enough to get paid. Extended public keys are more sensitive, since they let anyone see every address and payment in a wallet.

What happens if someone gets my private key?

They can spend the bitcoin controlled by that key, and the theft generally cannot be reversed because the network checks signatures, not identities. The same applies to your seed phrase, which can regenerate all of your wallet's private keys. Never type either into a website or share it with anyone.

Related articles