Deep dive for stage 5 · Self-custody — optional · ≈7 min

Keys, addresses & seed phrases simply explained

Private key, public key, address and seed phrase: how they fit together, why the path only runs one way and what 1, 3, bc1q and bc1p mean.

BeginnerUpdated 28 September 202614 sources

In short~35 sec
  1. 01Your private key is a huge random number. Whoever knows it can control the associated bitcoin.
  2. 02The public key and the address follow from the private key – in that direction only. Calculating backwards is practically impossible with today’s technology.
  3. 03The seed phrase (usually 12 or 24 words under BIP 39) is the backup for every key in your wallet.
  4. 04Addresses start with 1, 3, bc1q or bc1p. They all work; the bc1 formats catch typos better and are cheaper than 1… addresses.
  5. 05No legitimate party ever asks for your seed phrase – no support team, no exchange, not us either.

Good to read firstUnderstanding custody

Your bitcoin aren’t stored in an app – they are recorded in the blockchain. Only someone with the matching key can move them. If you hold them yourself, you hold that key: nobody can freeze it – but nobody can replace it either if you lose it along with its backup. If you leave your bitcoin on an exchange, the exchange holds the key (Understanding custody). You don’t need any maths for this – we explain everything with a picture from everyday life.

The principle: one key ring and many letterboxes

Imagine glass letterboxes: anyone can look inside and drop something in, but only someone with the matching key can open them. Bitcoin works with four building blocks:

So a wallet is a key ring with bookkeeping: it generates keys and addresses, searches the blockchain for balances and signs when you send something.

Seed phrase (12 or 24 words) → Private key (huge random number) → Public key (calculated from it) → Address (for receiving). easy to calculate; cannot be reversed. One seed can produce any number of keys and addresses.Secret – only with youSafe to share 01Seed phrase12 or 24 wordsexample word … 02Private keyhuge random number9f3c … e21a 03Public keycalculated from it02a4 … 7c1f 04Addressfor receivingbc1q … 9k2derivecurvemathshasheasy to calculatecannot be reversedExample values, shortenedOne seed can produce any number of keys and addresses.Seed phrase (12 or 24 words) → Private key (huge random number) → Public key (calculated from it) → Address (for receiving). easy to calculate; cannot be reversed. One seed can produce any number of keys and addresses.Secret – only with youSafe to share Seed phrase12 or 24 wordsexample word … Private keyhuge random number9f3c … e21a Public keycalculated from it02a4 … 7c1f Addressfor receivingbc1q … 9k2derive (BIP 32)curve maths (secp256k1)hash & encodeeasy to calculatecannot be reversed
From the seed via the private key and public key to the address: each step is easy to calculate but cannot be reversed.Own illustration based on BIP 32, BIP 39 and the Bitcoin Developer Guide

The private key: a very large random number

A private key consists of 256 bits of randomness.[1] The number of possible keys is just under 2256 – a number with 78 digits.[4] Guessing blindly at a quintillion (1018) keys per second, you would need more than 1051 years for a 50% chance of hitting one particular key (own calculation).

Two hard rules follow from this:

  1. Whoever knows the private key can spend the bitcoin. There is no authority that can say ‘no’.
  2. The randomness has to be real. Made-up keys (‘my birthday’, a song lyric) can be guessed. Always let a reputable wallet generate your keys.[4]

Public key and address: the one-way street

From the private key, the wallet calculates the public key using the elliptic curve secp256k1. For 1…, 3… and bc1q addresses, a GlossaryHash (hash value)A fixed-length digital fingerprint that a hash function calculates from any data. Even the tiniest change produces a completely different value, and the original data can’t be worked out from the hash.On the learning path: Stage 1 · Step 3 – How does Bitcoin work? →In the glossary → then turns it into the shorter address;[1] a Taproot address (bc1p) contains a public key derived from it directly.[10] Both steps are easy and always give the same result. Getting back to the private key is practically impossible with today’s technology.[4]

It’s like mixing paint: turning blue and yellow into green is easy, getting blue and yellow back out of the green is not. That is why you can show your address without giving away your key.

Why your wallet keeps showing new addresses

The whitepaper already recommends a new key pair for every transaction, so that payments can’t easily be linked to one owner.[5] If you reuse an address, others can easily trace its incoming payments, outgoing payments and balance.[1] Old addresses remain valid, but modern wallets automatically show you a new one each time you receive. More on this in Privacy with Bitcoin.

Dive deeperWill the one-way street last forever?

Powerful quantum computers could one day calculate the private key from a visible public key. With most formats, the public key only becomes visible once bitcoin have been spent from the address; with Taproot (bc1p), it is visible as soon as you receive. Developers are working on countermeasures, such as BIP 360: a Taproot-like output type with no visible public key for as long as the bitcoin stay unmoved (status as of September 2026: draft).[6] For you, this means: don’t reuse addresses, and keep your wallet software up to date. The wider assessment is in Criticism & risks.

Quick check

What can be calculated from a Bitcoin address?

Address formats: 1, 3, bc1q and bc1p

The beginning of an address tells you its format:

Starts with Name Standard Since What you should know
1… Legacy (P2PKH) Base58[1] 2009 Oldest format; with simple single-key wallets, spending from it costs the most
3… Script hash (P2SH) BIP 16[7] 2012 For multisig and the older SegWit variant (‘nested SegWit’)
bc1q… Native SegWit Bech32, BIP 173[8] 2017 No mixed upper and lower case, very good error detection, cheap
bc1p… Taproot Bech32m, BIP 350[9],[10] 2021 Newest standard, more privacy for complex spending conditions
  • Error detection: In the data part, Bech32 addresses avoid easily confused characters such as ‘1’, ‘b’, ‘i’ and ‘o’, and they always detect up to four mistyped characters.[8] Bech32m fixes a weakness of its predecessor and is used for Taproot addresses.[9]
  • Fees: The network fee depends on the size of the transaction, not on the amount. An input from a 1… address takes up around 148 vbytes, one from a bc1q address around 68 vbytes – so at the same fee rate you pay less than half for that part.[11] More in Transactions & fees.
  • Compatibility: In principle, you can send between all formats. If a platform doesn’t accept a format, have your wallet show you an address in a different format.

The seed phrase: the backup for all your keys

Since BIP 32, modern wallets derive a whole tree of keys from a single seed – always in the same order.[2] That is why any compatible wallet finds the same addresses again from the same seed. So that you can write the seed down, GlossaryBIP 39 (standard for seed words)The widely used standard that turns random data into 12 to 24 words from a fixed list of 2,048 words. Your wallet calculates all its keys from these words – BIP 39 is behind most seed phrases.On the learning path: Stage 5 · Step 3 – Backing up your seed phrase →In the glossary → translates it into words.[3]

2,048
words in the BIP 39 list
each word stands for 11 bits
12 or 24
usual length
128 or 256 bits of randomness plus a checksum
4
letters are enough
each word can be identified uniquely by them
1 in 16
random 12-word sequences is valid
because of the checksum (own calculation)

What matters:[3]

  • Checksum: It catches many typos, but not all – BIP 39 itself names the short checksum as a weakness. It is no substitute for copying the words carefully. Twelve words you make up yourself are usually invalid.
  • Order: The same words in a different order produce a different, usually invalid phrase.
  • Language: BIP 39 advises against non-English word lists, because most wallets only support the English one.

Passphrase: the optional ‘25th word’

You can also set a passphrase of your own choosing. Every passphrase produces a valid but different wallet. That protects you if someone finds only your words – but it also means: forget the passphrase and you lose access.[3] When this is worth it is explained in The passphrase.

Dive deeperDerivation path and xpub: good to know for later

Which keys are created from the seed is determined by the GlossaryDerivation pathThe route a wallet follows to calculate individual keys from your seed phrase, for example m/84'/0'/0'. If another wallet uses a different path when you restore, it looks empty – even though nothing has been lost.In the glossary →: m/84'/0'/0' is common for bc1q addresses and m/86'/0'/0' for bc1p addresses.[13],[14] If a wallet looks empty after recovery, often just a different path has been selected – the balance hasn’t gone. See Testing recovery.

The Glossaryxpub (extended public key)An extended public key from which all the addresses of a wallet account can be calculated. Nobody can spend bitcoin with it – but anyone who knows it can see your entire account history.In the glossary → (extended public key) enables watch-only wallets: they see all addresses and balances but cannot spend anything.[2] Even so, don’t hand it out lightly. It reveals your entire payment history, and together with a single derived private key it can, under certain circumstances, expose the whole key branch.[2]

What this means for you

  1. Let the wallet generate the seed

    Only use seeds that your wallet or TermHardware walletA small dedicated device that keeps your private keys offline and signs transactions internally.On the learning path: Stage 6 · Step 1 – Hardware wallets compared →In the glossary →AdManufacturers with a paid linkProviders from our comparisonBitBox02Hardware wallet · SwitzerlandVisit BitBox (paid link, opens in a new window)Trezor SafeHardware wallet · Czech RepublicVisit Trezor (paid link, opens in a new window)Blockstream JadeHardware wallet · Canada/USAVisit Blockstream Jade (paid link, opens in a new window)All 6 compared – including non-partners →Only buy hardware wallets from the manufacturer or an authorised reseller.*Paid link: if you sign up or buy through it, we earn a commission. Your price stays the same. How we make money → generates itself. If a device comes with words already supplied, it’s a scam.

  2. Back up the words offline

    Paper to start with, metal for the long term. Note separately which wallet you use.

  3. Use a new address for every payment

    Your wallet usually does this automatically.

  4. Check addresses before sending

    Compare them in full, confirm on the device with a hardware wallet, and send a small test amount before larger ones.

A hardware wallet keeps your keys offline: it generates the seed phrase itself and shows addresses on its own display.

Quick check

Quick check

What is the seed phrase?

What’s next?

Frequently asked questions

Can I get a lost private key back?

Only via your seed phrase: any compatible wallet recalculates all the keys from it. Without the keys and the seed phrase, nobody can help you – there is no authority that resets keys.

Is a Bitcoin address the same as an account number?

Not quite. Your wallet manages many addresses and shows you their total as your balance. Using a new address for every payment is recommended.

Which address format should I use?

Modern wallets automatically choose bc1q (native SegWit) or bc1p (Taproot). If a sender doesn’t accept a format, have your wallet show you an address in a different format.

Can I photograph my seed phrase or store it in the cloud?

No. Anything connected to the internet can be read by others. Write the words down offline on paper or stamp them into metal.

Can someone simply guess my private key?

In practice, no – if a reputable wallet generated it at random. Numbers, words or sentences you make up yourself are dangerous – humans are poor random number generators.

Your knowledge blockchain

Every article you complete becomes a block in your personal chain – stored only in your browser.

View chain →
Sources14 sources · 5 publishers

The superscript numbers in the text refer to these sources.

  1. Bitcoin Developer Guide: Transactions – Bitcoin Project (accessed 28/09/2026)
  2. BIP 32: Hierarchical Deterministic Wallets – Bitcoin Improvement Proposals, 11.02.2012 (accessed 28/09/2026)
  3. BIP 39: Mnemonic code for generating deterministic keys – Bitcoin Improvement Proposals, 10.09.2013 (accessed 28/09/2026)
  4. Mastering Bitcoin, 3rd edition – Chapter 4: Keys and Addresses – Andreas M. Antonopoulos, David A. Harding (O'Reilly, CC BY-SA), 2023 (accessed 28/09/2026)
  5. Bitcoin: A Peer-to-Peer Electronic Cash System – Satoshi Nakamoto, 31.10.2008 (accessed 28/09/2026)
  6. BIP 360: Pay-to-Merkle-Root (P2MR) – draft – Bitcoin Improvement Proposals, 18.12.2024 (accessed 28/09/2026)
  7. BIP 16: Pay to Script Hash – Bitcoin Improvement Proposals, 03.01.2012 (accessed 28/09/2026)
  8. BIP 173: Base32 address format for native v0-16 witness outputs – Bitcoin Improvement Proposals, 20.03.2017 (accessed 28/09/2026)
  9. BIP 350: Bech32m format for v1+ witness addresses – Bitcoin Improvement Proposals, 16.12.2020 (accessed 28/09/2026)
  10. BIP 341: Taproot – SegWit version 1 spending rules – Bitcoin Improvement Proposals, 19.01.2020 (accessed 28/09/2026)
  11. Transaction size calculator – Bitcoin Optech (accessed 28/09/2026)
  12. New clipboard hijacker replaces crypto wallet addresses with lookalikes – BleepingComputer, 03.11.2022 (accessed 28/09/2026)
  13. BIP 84: Derivation scheme for P2WPKH based accounts – Bitcoin Improvement Proposals, 28.12.2017 (accessed 28/09/2026)
  14. BIP 86: Key Derivation for Single Key P2TR Outputs – Bitcoin Improvement Proposals, 22.06.2021 (accessed 28/09/2026)

This article is for education only and is not investment, tax or legal advice.

Keyboard shortcuts

⌘K /
Open search
`
Open Bitcoin terminal
T
Toggle light/dark
?
This help

Tip: type “help” in the terminal.

Pre-launch

We’re still building – block by block.

Blockchain21 is already open, and you’re welcome to look around. We haven’t officially launched yet, though: some details are still missing, may change or don’t quite fit together yet.

Not finished yet

  • Email Messages to support@blockchain21.net don’t arrive yet. Until then, you can reach us by post – the address is in the legal notice.
  • Newsletter Sign-up opens once our mailbox is running.
  • Reader account Coming later. Until then, your browser keeps your progress.
  • Partners No partnership is active yet – providers are listed without ads.
  • Info pages The privacy policy still lacks some details.

Already in place: learning path, articles, glossary, calculators and live data.

Block 0 · Genesis — Bitcoin, too, began with block 0 As of 5 October 2026