On this page
Keys & signatures: how you prove a coin is yours
Each wallet has a private key (a secret number) and a derived public key. From the public key you get your address, which you can share freely. To spend funds, you produce a digital signature using your private key; anyone can verify it against your public key without ever learning the private key.
Sign with one key, check with the other
Standard Explanation
- Private key → kept secret; used to sign.
- Public key → derived from private; used to verify.
- Address → derived from public key; shareable.
- Signature → proves a transaction was authorized by the key holder.
Public-key cryptography relies on trapdoor functions — operations easy to compute but infeasible to reverse. In ECDSA (used by Bitcoin and Ethereum), the private key is a scalar d, the public key is d·G for a known generator point G on an elliptic curve. Recovering d from d·G is the elliptic-curve discrete logarithm problem, believed infeasible for well-chosen curves. Signatures prove you know d without revealing it.