Skip to content

Shelf 4 · Safety · 22 / 45

Wallets & Security

Wallets protect keys, not coins. Learn the difference between receiving addresses, private keys, and recovery phrases, then check custody and backup requirements.

Check this article’s sources (9)

Article brief

A Bitcoin wallet contains no bitcoin. It contains the keys that authorize changes to assets recorded on the public ledger.

A useful mental model

Think of it as a keyring for deposit boxes whose records are copied worldwide. Addresses, private keys, and seed phrases then take on distinct roles.

Where the analogy stops

Bitcoin outputs are ledger records, not physical boxes. Wallets also derive keys and sign, and a lost device need not mean lost funds if a correct backup exists.

Once you know exactly what needs protection, you can balance convenience and safety against your own threat model.

Open the glossary
Article contents10 chaptersJump to a chapter

1What is a Bitcoin wallet?

Figure 1 The private key creates proof that spending was authorized, and the network verifies that signature with the public key. The transaction and signature travel; the private key does not.

A Bitcoin wallet is software or hardware that manages the "private keys" needed to send and receive Bitcoin. It doesn't actually store Bitcoin itself — it manages the "keys" to access your assets on the blockchain.

A private key is a randomly selected number, and only its holder can make a valid spending signature. A public key is derived from it by a one-way computation and is used to verify signatures. An address is not the public key itself: it encodes the information needed to construct a receiving locking script or witness program in a human-manageable string.

What an address carries depends on the output type. P2PKH and P2WPKH normally carry a public-key hash. P2SH and P2WSH carry a script hash. P2TR places BIP 341's 32-byte x-only tweaked public key in the witness program, so that public key is visible from output creation. "An address is always a public-key hash" and "a public key always remains hidden until first spend" are therefore both incorrect.

In practice, addresses are meant to be shared, and public keys are not secret. Whether a public key is visible from output creation or first appears at spending still matters for privacy and future quantum-risk analysis. The values that must never be disclosed are the private key and the seed phrase from which it is derived.

"Not your keys, not your coins" is a famous saying in the crypto community. When you keep Bitcoin on an exchange, technically that exchange controls the private keys.

2Hot wallets

Hot wallets manage private keys while connected to the internet. They include smartphone apps, desktop applications, and browser extensions.

Advantages: payments go out immediately, the software is easy to use and usually free, and it suits everyday spending.

Disadvantages: a permanent internet connection means exposure to hacking and malware. Hot wallets are not suited to holding large amounts of Bitcoin.

Best practice: keep only small amounts for daily use in a hot wallet, and move the bulk of your holdings to a cold wallet.

3Cold wallets

Cold wallet is the umbrella term for keeping private keys in an environment that is not routinely connected to the internet. By keeping the key material off online machines, it raises resistance to remote theft.

Hardware wallets: Dedicated signing devices that seal the private key inside and are used in the pattern "receive the transaction data, sign it inside the device, hand back only the signed data." This is where the misconception sits: you do connect the device to a computer or phone to use it. The security rests not on staying disconnected but on the private key never leaving the device even while connected. Some models additionally support air-gapped operation, exchanging signed data by QR code or SD card without any connection at all, which is a distinct level worth keeping separate in your mind. This site recommends no particular product or manufacturer.

Paper wallets: An older method of printing the private key on paper, no longer recommended. The printing path (computer, printer, and their logs) can retain the key, and because spending part of a balance sends the remainder to a different address as "change," people end up with paper they believe still holds funds that have in fact moved. If you want paper, the usual approach is writing down the seed phrase described in the next section by hand.

Steel wallets: seed phrases engraved on metal plates. They resist fire and water, which suits long-term storage.

4Seed phrases (recovery phrases)

A seed phrase (mnemonic phrase) is a sequence of English words used as a wallet backup. The BIP-39 standard allows 12, 15, 18, 21, or 24 words; 12 and 24 are what you actually encounter in the wild.

Compatible wallets can derive keys from the phrase. Recovery may also require an additional passphrase, address format or derivation path, and multisig configuration. A phrase alone does not restore every kind of wallet.

The essential rules: write your seed phrase on paper and store it somewhere safe. Never keep it digitally (screenshots, cloud storage, email). Never share it with anyone.

Losing the phrase need not immediately mean losing funds if a working device or another valid backup remains. If both the spending keys and all recovery methods are lost, the network cannot reissue them. Published totals for lost BTC are estimates: a June 2020 Chainalysis analysis put coins untouched for at least five years at about 3.7 million BTC, roughly a fifth of the supply then issued. An earlier estimate gave a range of 17–23% (2.78–3.79 million BTC).

What deserves attention is that "has not moved in a long time" is not proof of "cannot be accessed." The same criterion sweeps in coins that are simply being held on purpose. How to read the assumptions and the spread of these estimates is covered in "Why Lost Bitcoin Cannot Be Recovered — Irreversibility Explained," alongside a separate study putting self-custody losses at about 1.57 million BTC and exchange losses at about 1.51 million BTC.

5Three checks before recovering a wallet

Recovery is not simply logging in again. Before entering secret information, check the official recovery instructions and backup format for the wallet you used.

Comparison table for Three checks before recovering a wallet
What to checkWhat matters
PIN or login passwordOpens a device or service; not necessarily a substitute for a recovery phrase
Recovery phrase and additional passphraseBIP-39 derives a different wallet for a different passphrase. An empty balance does not prove you entered the right one
Wallet format and configurationRecovery may require derivation paths, address formats, or multisig configuration

Do not erase your only working device just to test a backup. Never send a phrase to this library, a chat, or a support agent. For recovery, follow the official procedure on a compatible wallet or device whose origin you have verified.

6One seed, a tree of keys: HD wallets (BIP-32/44)

Figure 2 An HD wallet deterministically derives many keys and addresses from one seed through account, receive and change branches. Backing up the seed is therefore a way to recover the whole tree.

A single seed phrase can restore an entire wallet because modern wallets are built to derive an unlimited number of keys from one seed. This is the HD (hierarchical deterministic) wallet, specified by BIP-32. A parent key is generated from the seed, and child keys, grandchild keys, and so on branch off from it by a fixed computation, so there is no need to store each key separately. Given the seed and the derivation path, the same tree of keys can be reproduced at any time.

BIP-44 gives those branches a shared meaning. It fixes the hierarchy in order: the standard in use, the coin type, the account number, whether the branch is for receiving or for change, and the index, which is what a notation like m/44'/0'/0'/0/0 spells out. This structure is why a fresh address can be generated automatically for every receipt, making the basic privacy practice of never reusing an address workable. It is also why change returns automatically to another address of your own: a different branch of the same tree.

BIP-39 also allows an optional string, a passphrase, to be combined with the seed phrase. The same twelve words with a different passphrase produce an entirely different tree of keys. It raises the bar by one level, but forgetting the passphrase means no restore even with the words written down correctly. If it never reaches the family, they restore an empty wallet and conclude nothing was left (the estate side of this is covered in "Bitcoin Inheritance and Estate Planning").

Three practical implications follow. What you back up is the seed phrase, not individual addresses or keys. A restore may also require derivation details: which standard and which address format were in use. And if you use a passphrase, its existence and storage must be designed through a channel separate from the seed phrase itself.

7Multisig and PSBT: not betting everything on one key

Multisig (multi-signature) requires signatures from a set number of several keys before coins can move. In a 2-of-3 arrangement there are three keys and any two signatures authorize a spend. One key stolen does not move the funds; one key lost does not lock them away. The point is to avoid a single point of failure.

How the keys are distributed depends on the purpose: an individual splitting three keys between home, another location, and a trusted third party; family members or business partners each holding one; a provider holding one on your behalf. The costs are equally clear. Setup and recovery are more involved than a single key, there are more places to look after, and the configuration data described below must be preserved as well.

Because the keys live on separate devices, signing cannot finish on one machine. PSBT, the partially signed Bitcoin transaction format defined in BIP-174, standardizes this. An unsigned transaction is handled as a single piece of data, passed from device to device accumulating signatures, and becomes broadcastable once the required number is present. This common format is what makes air-gapped setups and mixed-manufacturer arrangements possible.

The part most often missed is that having the keys is not always enough to restore. A multisig restore needs the configuration: how many of how many are required, which extended public keys are involved, and how the script is assembled. That information can be exported and stored as an output descriptor (BIP-380). If you adopt multisig, keep the configuration with the same weight as the key backups, and confirm with a small amount that a restore actually works.

8Custodial versus non-custodial

Custodial wallets: an exchange or service holds the private keys. Convenient, but exposed to the service being hacked or going bankrupt. Mt.Gox and FTX are the cautionary examples.

Non-custodial (self-custody) wallets: you hold your own private keys. Full control, and full responsibility.

For custody, examine how the provider manages funds and controls withdrawals. For self-custody, plan for backup, recovery, and inheritance. Neither self-custody nor using a provider removes all risk or responsibility. This site does not recommend one custody method or provider for everyone.

Custody services built on "multisig" (requiring several signatures) have also appeared, improving the balance between convenience and security.

9Security practices worth adopting

Two-factor authentication (2FA): always enable it on exchange accounts. SMS is weak against phone-number takeover (SIM swapping), so authenticator apps supporting time-based one-time passwords (TOTP), or hardware security keys, are generally recommended instead. This site recommends no particular product.

Anti-phishing: bookmark official URLs and never log in to an exchange through a link in email or social media. Watch for subtle differences in a URL (typosquatting).

Spread your storage: do not keep everything in one place. Split it across a hot wallet (daily use), a cold wallet (long-term storage), and an exchange (trading).

Backups: keep seed phrase backups in more than one location, and tell a trusted family member where they are (estate planning).

Updates: keep wallet apps, the operating system, and browsers current. Do not put off security patches.

10Common scams, and how to avoid them

Phishing: fake sites and emails that ask for private keys or recovery phrases. Do not give them to support agents or enter them on a recovery website reached through an ad or message. This is different from a legitimate wallet recovery process you initiate yourself.

Investment scams: "Guaranteed returns" and "high-yield guarantees" are classic fraud tactics. No investment offers guaranteed returns, Bitcoin included.

Impersonation: scammers posing as celebrities or support staff and asking for a transfer. Once sent, Bitcoin cannot be recovered.

Ponzi schemes: arrangements that pay existing participants out of new participants' money. They collapse as soon as new money slows. Be wary of unusually high "referral rewards."

The basic defense: "Don't send if it seems suspicious," "Never share your seed phrase," and "If it sounds too good to be true, it probably is." Those three rules alone prevent most scams.

Primary sources

Read next

Why Lost Bitcoin Cannot Be Recovered — Irreversibility Explained14 min read
Share

Citation

Title
Wallets & Security
Source
Bitcoin Library (bitcoin.ne.jp)
Canonical URL
https://bitcoin.ne.jp/en/learn/wallets
Author
KK siiiiiixth
Topic
wallets
Published
Updated
Last verified
Editorial policy
https://bitcoin.ne.jp/en/editorial-policy
About
https://bitcoin.ne.jp/en/about
License
Content reuse terms

Operator-owned article text, original diagrams, and public data may be used for citation, summarization, indexing, search, RAG, machine analysis, and AI model training. When content is presented to readers, identify Bitcoin Library and the applicable canonical URL where technically practicable.

Revision history

  1. Simplified the introduction and added recovery checks. Corrected unconditional claims about lost phrases and distinguished legitimate wallet recovery from phishing. Reverification covers the changed explanations only; the article-wide verification date is unchanged.
  2. Corrected the claim that an address is always a public-key hash. Distinguished P2PKH/P2WPKH, P2SH/P2WSH, and P2TR encoding and public-key exposure so the wallet article matches the quantum-risk evidence.
  3. Added bilingual diagrams for signature verification and the HD-wallet tree from seed through accounts, receive/change branches, and addresses.
  4. Separated private key, public key and address into three layers; added new sections on HD wallets (BIP-32/44, passphrase) and multisig/PSBT; corrected the definition of cold storage, deprecated paper wallets, fixed BIP-39 word counts, replaced the flat "20% lost" claim with a sourced estimate range, and genericized product names