FULL TIME CRYPTO
Text size

Safety & Wallets field guide

Private Keys.

The secret that controls your crypto

A private key—or recovery phrase—is the proof that lets someone authorize a transaction. Anyone who gets it can usually take the assets. Never type it into a website, send it in a message, or share it with support.

What it isWhy it mattersWhat can go wrongWhat to do next

Why this matters

Whoever has the key has the crypto.

A private key is the authority to move assets. There is no password-reset desk when a self-custody key is stolen or destroyed.

01

Know this

Get the idea right.

A recovery phrase can recreate every key in a wallet. Treat it like the money itself, not like an ordinary password.

02

Watch this

See the risk early.

Support agents, giveaways, wallet checks, and airdrops asking for your phrase are scams.

03

Do this next

Turn knowledge into a habit.

Store the recovery phrase offline in more than one secure place and never photograph or cloud-sync it.

Go beyond the summary

The subject in plain English.

The private key is authority, not identity. A recovery phrase can recreate many private keys, which is why anyone who obtains it can often take everything without knowing your password.

01

Private and public are different

A public address can be shared to receive funds. A private key signs transactions and must remain secret.

02

The recovery phrase is a master backup

Many wallets derive multiple accounts from one recovery phrase. Exposing it can compromise every derived account, including ones created later.

03

Passwords protect devices—not the chain

A wallet password may encrypt the local app. It does not replace the private key and cannot stop someone who already has the recovery phrase.

04

Signing is an action

A signature may authorize a transfer, a smart-contract approval, or a login message. Read what the wallet says you are authorizing.

What the key proves

Where this matters.

  • Authorize cryptocurrency transfers
  • Prove control of a blockchain account
  • Recover accounts in compatible wallet software
  • Sign application and governance messages

Before you act

Verify before you sign.

  1. Write recovery material offline and verify every word and position.
  2. Keep more than one secure backup away from fire, theft, and casual access.
  3. Never photograph, email, cloud-sync, or paste a recovery phrase.
  4. Use a small test wallet to practice recovery before depositing more.
  5. Assume any phrase entered into a website is permanently compromised.
  6. Do not share a recovery phrase, private key, or remote access with anyone.

Common questions

Clear answers before money moves.

Can I change a compromised recovery phrase? +

No. Move assets to a completely new wallet created from new recovery material.

Will legitimate support ask for my phrase? +

No. Anyone requesting it is attempting to gain control of the wallet.

What happens if I lose one word? +

Recovery may become difficult or impossible. Do not rely on memory or an incomplete backup.

Can I safely store it in a password manager? +

That creates a different risk profile. For meaningful self-custody, an offline backup avoids exposing the master secret to cloud-account compromise.

Primary sources

Verify the guide.

Details and threats change. Use the original documentation and public-interest sources to confirm current guidance before acting.

Check the source

Read beyond the summary.

This guide is a starting point. Use the original documentation and public-interest resources below to verify the details and see what may have changed.

Keep learning

Connect the dots.

More from Safety & Wallets.
Plain English. No hype.

Explore the full Learning Center