Skip to content

Private Key

A private key is the secret cryptographic code that authorizes spending cryptocurrency from an address. Whoever holds the private key controls the coins, which is why keeping it secret is the whole of crypto security.

Last reviewed by Steven Fox, CFP®, EA on

Quick Summary

  • A private key is a secret number that proves you have the right to move the crypto at a given address.
  • It works alongside a public key, which is safe to share and produces your receiving address; the private key is never shared.
  • Control of the private key is control of the coins, so anyone who obtains it can spend the funds, and losing it with no backup makes them unrecoverable.
  • This is the meaning behind "not your keys, not your coins", because if a company holds your private key, it, not you, ultimately controls your crypto.

Definition

A private key is a large secret number that authorizes transactions from a cryptocurrency address. Every crypto address has a matching private key, and the network accepts a transaction only if it is signed by the correct one. The private key must be kept secret, because possession of it is what proves the right to spend the coins at that address, no name, password, or account is involved. Its counterpart is the public key, from which the receiving address is derived and which can be shared freely; the private key never is.

Advanced Explanation

Cryptocurrency uses public-key cryptography, a pairing of two mathematically linked numbers. The public key produces an address you hand out to receive funds, and it can be shared with anyone. The private key is the secret half: it generates the digital signature that authorizes moving coins out of the address, and the network verifies that signature against the public key without the private key ever being revealed. The relationship is one-way, the public key can be derived from the private key but not the reverse, which is what makes it safe to publish an address while the spending power stays secret.

The consequences of this design are stark and unforgiving. Because control of the private key is control of the coins, there is no higher authority to appeal to. If someone steals your private key, they can drain the address and the transaction is irreversible; no bank can claw it back. If you lose your private key and have no backup, the coins remain visible on the blockchain forever but no one, including you, can ever move them. Estimates of bitcoin permanently lost to forgotten or destroyed keys run into the millions of coins.

In practice, people rarely handle the raw private key directly. A wallet manages it, and a recovery phrase, a sequence of ordinary words, encodes it in a form that can be written down and used to regenerate the key if a device is lost. This is also the point of the crypto maxim "not your keys, not your coins": when an exchange or app holds the private key on your behalf, you are trusting that company with ultimate control of your crypto, whereas holding the key yourself means no company can lose or freeze it, and also that no company can help you if you make a mistake.

Used in a Sentence

“A scammer tricked the investor into revealing his private key, and within minutes the entire balance at that address had been transferred away with no way to reverse it.”

How It Works

When you want to send crypto, your wallet uses the private key to create a digital signature unique to that transaction. The signature proves the transaction was authorized by the keyholder without exposing the key itself. The network checks the signature against the address's public key, and if it matches, records the transfer on the blockchain. Anyone can verify the signature; only the private key could have produced it.

A hypothetical shows why secrecy is absolute. Suppose Lin holds crypto worth $30,000 at an address she controls. As long as her private key is known only to her, only she can sign transactions moving those funds. If she is phished into entering her key or her recovery phrase on a fake website, the attacker can immediately sign a transaction sending all $30,000 to an address they control, and because the transaction was validly signed, the network executes it and it cannot be undone. The theft did not require breaking any encryption; it only required getting the key. That is why no legitimate service ever asks for your private key.

Pros and Cons

Pros

  • Provides genuine, self-sovereign control: holding the key means no company can freeze or seize the coins.
  • Enables transactions to be authorized and verified without revealing any secret to the network.
  • The public and private key split lets you share a receiving address safely while keeping spending power secret.

Cons

  • Total responsibility: whoever holds the key controls the coins, so theft of the key is theft of the funds, irreversibly.
  • Losing the key with no backup makes the crypto permanently unrecoverable.
  • No recovery mechanism and no authority to appeal to, unlike a bank account.
  • Phishing and malware aimed at capturing keys are constant threats.

People Also Asked

Answers to the most frequently asked questions.

What is the difference between a public key and a private key?
A public key produces the address others use to send you crypto and is safe to share. A private key is the secret that authorizes spending from that address and must never be shared. The public key can be derived from the private key but not the other way around, which is what lets you publish an address while keeping spending power secret.
What happens if someone gets my private key?
They gain full control of the crypto at that address and can transfer it all away, and the transaction cannot be reversed. There is no bank or authority to recover the funds. This is why no legitimate wallet, exchange, or support service will ever ask for your private key, and why any request for it is a scam.
What if I lose my private key?
If you have no backup, the crypto at that address becomes permanently inaccessible. It remains visible on the blockchain, but without the key no one can move it, including you. This is why wallets generate a recovery phrase that can regenerate the key, and why backing up that phrase safely is essential.
Do I ever type my private key directly?
Rarely. A wallet manages the private key for you and uses it to sign transactions behind the scenes, and a recovery phrase encodes it for backup. Because entering a raw key exposes it, most everyday use never touches it directly, and being asked to type one on a website is a strong sign of a phishing attempt.

Sources

AdviceOnly maintains high editorial standards to improve the quality and accuracy of our educational content. Content is written with the assistance of artificial intelligence tools following a rigorous quality assurance process, and periodically reviewed by credentialed and experienced human financial advisors. References used include government data, academic papers, interviews with industry experts, and reputable primary sources. You can learn more about our efforts to produce accurate content in our editorial policy.

  1. U.S. Securities and Exchange Commission. "Crypto Asset Custody Basics for Retail Investors" (Investor Bulletin, Investor.gov).
  2. U.S. Securities and Exchange Commission. "Crypto Assets" (Investor.gov).

Have a question a definition can't answer?

Advice-only advisors answer questions like this for a transparent flat fee — no products, no commissions, no asset management.

Find an Advisor