How Bitcoin Wallets Work
Private keys, public keys, addresses, HD wallets, and transaction signing — explained from first principles.

Ashir Khan writes about cryptocurrency security, self-custody, macro market analysis, and regulatory policy at CryptoBeacon.
Wallets don't store Bitcoin
The name "wallet" is misleading. A Bitcoin wallet doesn't hold Bitcoin the way a physical wallet holds cash. Bitcoin itself exists only as entries in the blockchain — a global ledger maintained by tens of thousands of nodes. What a wallet actually stores is a private key: a secret number that proves you have the right to spend specific Bitcoin.
Think of it this way: the Bitcoin belongs to whoever can sign for it. The private key is your signature authority. The wallet is the software or hardware that manages and protects that key.
The private key
A Bitcoin private key is a randomly generated 256-bit number — a number between 1 and approximately 1077. This number is so large that generating the same one twice by accident is considered cryptographically impossible.
The private key is usually represented as a 64-character hexadecimal string or encoded in a format called WIF (Wallet Import Format). It must be kept completely secret. Anyone who knows your private key controls your Bitcoin.
From private key to address
The private key is fed through a mathematical process called elliptic curve multiplication (using a specific curve called secp256k1) to produce a public key. This process is one-way — you can derive a public key from a private key, but you cannot reverse it.
The public key is then hashed twice — first through SHA-256, then through RIPEMD-160 — and a checksum is added. The result is encoded and presented as a Bitcoin address: the familiar string beginning with "1", "3", or "bc1" that you share with others to receive funds.
Transaction signing
When you send Bitcoin, your wallet constructs a transaction and signs it with your private key using the ECDSA algorithm (Elliptic Curve Digital Signature Algorithm). The signature proves that you authorized the transaction without revealing your private key.
The Bitcoin network verifies the signature using your public key. If the signature is valid, the transaction is accepted and broadcast to the network. Miners include it in a block, and the transfer is complete.
HD wallets and seed phrases
Early wallets generated a single private key. If you lost it, you lost everything. Modern wallets use a Hierarchical Deterministic (HD) structure, defined by the BIP-32 and BIP-44 standards. An HD wallet generates a master seed — your seed phrase — and uses it to derive a virtually unlimited tree of private/public key pairs.
This means your seed phrase is the root of your entire wallet. One 12-word or 24-word backup phrase can restore every address and key the wallet has ever generated, on any compatible wallet software. It also means that if someone finds your seed phrase, they have access to all of it.
Read more: What Is a Bitcoin Seed Phrase?
