← back to the blog

Bitcoin Explained · July 7, 2025

By Adam Whistler

Public Key vs Private Key: How Signatures Prove Ownership

Public key vs private key

Every Bitcoin transaction has to prove one thing: that whoever sent it actually controls the funds. It does that without the private key ever leaving your wallet, ever being transmitted, or ever being visible to anyone, including the network verifying it. Here's the actual concept that makes that possible.

The asymmetry is the entire trick

A private key and its matching public key are mathematically linked through elliptic curve multiplication, but only in one direction. Given a private key, computing the matching public key is fast and easy. Given only the public key, computing the private key back out is, as far as anyone has ever demonstrated, computationally infeasible. This one-way relationship is called a trapdoor function, and it's the foundation everything else here is built on.

So how does a signature use that?

Bitcoin uses a scheme called ECDSA (Elliptic Curve Digital Signature Algorithm) built on top of that same math. To sign a transaction, your wallet combines your private key with the transaction's data through a specific mathematical process, producing a signature: a pair of numbers unique to that exact private key and that exact transaction. Anyone can then take that signature, the transaction data, and your public key, and mathematically verify the signature could only have been produced by whoever holds the matching private key, all without that private key ever being disclosed.

Why you can't fake it

Producing a valid signature without the private key would require solving the same infeasible reverse problem: working backward from a public key to the private key that matches it. Because that direction of the math is believed to be practically unsolvable with any realistic amount of computing power, a valid signature is treated by the entire network as conclusive proof of ownership, no separate identity check required.

Why a signature is different every time

Even for the exact same private key, signing different transactions produces different signatures, because the transaction data being signed is different each time (and modern implementations also weave in additional randomness). This matters practically: it prevents an old, previously broadcast signature from being replayed against a new, different transaction.

This tool can generate any Bitcoin private key there is, Satoshi's included. Try for a million years and you'll still come up empty.

Try the key collider now

Private key in, signature out, in one easy direction. Signature and public key in, a yes or no answer out, in the other direction, with no way to run the process backward and recover the private key. That asymmetry is what lets a total stranger anywhere on the Bitcoin network verify you own something, without trusting you or ever seeing your secret. For how that signature fits into a full transaction from start to finish, see what happens when you send Bitcoin, and for what it actually takes, computationally, to work backward from a public key to a private one, see just how absurd that keyspace really is.