Finance · Fintech · Crypto — explained

Bitfolio

An independent explainer desk · No ads · No affiliate links

TechExplainer

How do crypto wallets and private keys work, and what happens if you lose them?

A crypto wallet does not hold coins. It holds the secret that proves you control them. Understanding that one idea explains almost every way people keep, and lose, crypto.

Two metal keys lying on a dark wooden surface
Photo: “Keys” by Richard-G, CC BY 2.0, via flickr.com · Edited: duotone, cropped.

The short answer

A crypto wallet is software or a device that stores your private keys and uses them to sign transactions. The coins stay on the blockchain. Whoever has the private key, or the seed phrase behind it, controls the funds; lose it and there is usually no way back.

Key takeaways

  1. Your crypto is recorded on the blockchain; a wallet stores the private keys that let you move it.
  2. A public key is derived from the private key, and an address is derived from the public key, so you can share an address safely but never the private key.
  3. A seed phrase of 12 to 24 words can regenerate your keys, which makes it as valuable as the funds themselves.
  4. With a custodial account, a company holds the keys for you; with self-custody, you do, and there is no help desk if you lose them.
  5. The FBI advises not responding to unsolicited requests for your seed phrase, passwords or one-time codes.

What does a crypto wallet actually hold?

The name is misleading. A leather wallet holds cash; a crypto wallet holds no coins at all. Ethereum's documentation puts it bluntly: you never really hold cryptocurrency, you hold private keys, and the funds are always on the blockchain's ledger2. The wallet is the tool that stores those keys and lets you use them.

NIST describes a wallet as something that can store private keys, public keys and their associated addresses, and that may also add up your balance1. ethereum.org draws a further line: an account is the thing recorded on the blockchain, while a wallet is the interface or app you use to interact with it2. Many different wallet apps can open the same account, as long as they have the key.

Note

The one sentence to remember

Whoever holds the private key controls the funds. NIST notes that if a private key is stolen, the thief gains full access to every asset it controls1.

How do private keys, public keys and addresses fit together?

Crypto uses asymmetric (public-key) cryptography: a pair of keys that are mathematically linked1. The private key is a secret number. The public key is calculated from it, but you cannot run the calculation backwards. When you send funds, your wallet uses the private key to create a digital signature, and anyone with your public key can check that the signature is genuine without ever seeing the secret1.

Figure · From secret key to shareable address (Ethereum)

From secret key to shareable address (Ethereum)01Private key64 hex characters,secret02Public keyderived with ECDSA03Keccak-256 hashkeep the last 20bytes04Address0x + 40 hexcharacters
  1. 01Private key64 hex characters, secret
  2. 02Public keyderived with ECDSA
  3. 03Keccak-256 hashkeep the last 20 bytes
  4. 04Address0x + 40 hex characters
Source: [2]

On Ethereum, a private key is 64 hexadecimal characters; the public key is derived from it using the Elliptic Curve Digital Signature Algorithm (ECDSA); and the address is the last 20 bytes of the Keccak-256 hash of the public key, with 0x in front2, giving 42 characters in total. NIST describes the same general pattern for blockchains: public key, then hash, then address1.

Worked example

Why nobody can guess your key

Sixty-four hexadecimal characters allow 16 to the power of 64 combinations, the same as 2 to the power of 256: a 78-digit number of possible keys, about 1.16 × 10^77 (calculated for this page). That is why NIST says it is computationally infeasible to regenerate a private key1. The weak point is not the maths; it is people revealing or losing their keys.

What is a seed phrase, and why does it matter so much?

Writing down 64 random characters is error-prone, so wallets typically give you a seed phrase (also called a recovery phrase) to write down instead3. One standard for this, BIP-39, turns random data into a list of words picked from a fixed list of 2,0484. The words are then run through a key-stretching function, PBKDF2 with 2,048 rounds of HMAC-SHA512, to produce a 512-bit seed from which the wallet's keys are generated4.

BIP-39 seed phrase lengths Source: [4]

WordsRandom bits (entropy)Checksum bits
121284
151605
181926
212247
242568

Because the phrase regenerates every key, it is as powerful as the keys themselves. ethereum.org calls writing it down safely the only way you will be able to recover your wallet3. BIP-39 also allows an optional extra passphrase: every passphrase produces a valid wallet, but only the right one opens yours4, so forgetting it locks you out just as surely as losing the words.

Custodial or self-custody: who holds your keys?

When you buy crypto on a centralised exchange and leave it there, you usually log in with a username and password and the exchange controls the keys. ethereum.org notes that this means trusting the exchange with custody of your funds3. With a self-custody (non-custodial) wallet, the provider never holds your funds; it simply gives you a window onto your assets and tools to manage them3.

Figure · Two ways to hold crypto

Two ways to hold cryptoCustodial (exchange)Company holds the keysPassword reset is possibleExposed if the company failsSelf-custody walletYou hold the keysNo help desk to recover themLost seed phrase = lost funds

Custodial (exchange)

  • Company holds the keys
  • Password reset is possible
  • Exposed if the company fails

Self-custody wallet

  • You hold the keys
  • No help desk to recover them
  • Lost seed phrase = lost funds

Common types of self-custody wallet (types as listed by ethereum.org)

TypeWhere the keys usually liveTrade-off
Hardware walletOn a dedicated physical device kept offline3Harder to reach for online attackers; costs money and can be lost
Mobile appOn your phoneConvenient; as safe as the phone
Browser extensionIn your web browserEasy for web apps; exposed to malicious sites
Desktop appOn your computerFull-featured; exposed to malware on that machine

Neither model is automatically safer. Custody shifts the risk from your own mistakes to the company's security and solvency, which is why our guide to crypto custody and the checks in how to check a regulated firm are worth reading before choosing.

How do people lose access to their crypto?

There are two basic ways to lose access. The key is lost: NIST notes that assets tied to a lost private key are lost, because the key cannot be regenerated1. Or the key is stolen, sometimes through trickery rather than technical hacking. In a June 2025 alert, the FBI described criminals using fake token "airdrops", phishing emails and social media to get wallet users to connect their wallets and reveal credentials5.

Protecting a seed phrase: the basics

  1. 1

    Write it down offline

    Write the words down physically, as ethereum.org advises, rather than storing them digitally in a screenshot, email or cloud note3.

  2. 2

    Store copies safely

    Keep the record somewhere secure and private, and consider a second copy in a separate place in case of fire or theft.

  3. 3

    Never type it on request

    The FBI advises not responding to unsolicited requests for passwords, seed phrases or one-time codes5.

  4. 4

    Verify before you connect

    Check offers of free tokens directly with the provider before connecting a wallet or sharing any information5.

Risk warning

There is no customer support for self-custody

ethereum.org warns that transactions cannot be reversed and wallets cannot easily be recovered; you are responsible for your own keys3. If you suspect fraud, report it to the FBI's Internet Crime Complaint Center at ic3.gov5, and see our risk disclosure.

What mistakes do beginners make with wallets?

Common beginner mistakes

  1. Saving the seed phrase as a photo

    Screenshots and cloud notes can be synced, backed up or stolen along with your account. Keep the phrase offline3.

  2. Sharing it with "support"

    Unsolicited requests for a seed phrase feature in the scams the FBI warns about, and it advises not responding to them5, whatever logo the sender shows.

  3. Confusing the address with the key

    Your address is safe to share for receiving funds. Your private key and seed phrase are not, ever2.

  4. Assuming an exchange balance is self-custody

    If you log in to a platform with a username and password, you are usually trusting it to hold the keys for you3.

Frequently asked questions

Can I recover my crypto if I lose my phone?

Yes, if you still have the seed phrase: any compatible wallet can regenerate your keys from it4. Without the phrase or a backup of the keys, the funds are usually gone for good1.

Is it safe to share my wallet address?

Yes. An address is derived from your public key through a one-way hash2, so it lets people send you funds but not spend them. Bear in mind that transactions on a public chain are visible to everyone6.

Should I use a new address for every payment?

It can help privacy. The Bitcoin paper suggested using a new key pair for each transaction so payments are harder to link to the same owner6.

What is the difference between a wallet and an account?

On Ethereum, the account is the record on the blockchain; the wallet is the app or device you use to control it2.

Are hardware wallets safer than phone wallets?

They keep keys on a separate offline device3, which reduces exposure to online attacks. They do not protect you if you type your seed phrase into a fake website.

The bottom line

A crypto wallet is a keyring, not a vault. The coins live on the blockchain, and control belongs to whoever has the private key or the seed phrase behind it. Keep that phrase offline and private, treat any request for it as an attack, and decide deliberately whether you or a company should hold your keys.

Sources

  1. NIST IR 8202: Blockchain Technology Overview — National Institute of Standards and Technology, U.S. Department of Commerce, 2018 Primary source
  2. Ethereum accounts — ethereum.org developer documentation Primary source
  3. Ethereum wallets — ethereum.org Primary source
  4. BIP-39: Mnemonic code for generating deterministic keys — Bitcoin Improvement Proposals (github.com/bitcoin/bips), 2013 Primary source
  5. Cybercriminals Defraud Hedera Hashgraph Network Non-Custodial Wallet Users Through Nonfungible Token Airdrops Disguised as Free Rewards (Alert I-060325-PSA) — Federal Bureau of Investigation, 2025 Primary source
  6. Bitcoin: A Peer-to-Peer Electronic Cash System — Satoshi Nakamoto (whitepaper hosted at bitcoin.org), 2008 Primary source

How we checked this page: every figure above links to the numbered source it came from. Spotted an error? Tell the desk — see our editorial policy.

Read next