Onpode
Cover art for Why your private key is your asset — the math that lets you prove ownership without intermediaries

Why your private key is your asset — the math that lets you prove ownership without intermediaries

October 7, 2026 · 10 min

Eliza Ward & Brian Reed

A blockchain private key is not a password — it is the sole cryptographic proof of ownership, generated via ECDSA on the secp256k1 curve. Losing it means funds remain permanently visible on-chain but can never be moved. Millions of bitcoins are already locked this way, a structural consequence of the design, not a bug.

Blockchain systems establish digital ownership through asymmetric cryptography rather than institutional record-keeping. When a user creates a blockchain account, two mathematically linked keys are generated: a private key kept secret by the owner, and a public key (or an address derived from it) visible to anyone on the network.

0:0010:18
Get the next episode on Crypto →

Follow it free — new episodes land in your feed.

Or make your own — any topic, in minutes

More Onpode episodes on Crypto →

About this episode

There's a strange kind of loss unique to crypto: funds that are provably on the blockchain, visible to anyone with a block explorer, that will never move again. Not because they were stolen, but because the private key is gone. This episode works through why that happens — and why it was always going to. The conversation starts with asymmetric cryptography and gets specific fast. The elliptic curve algorithm Bitcoin and Ethereum run on (ECDSA on secp256k1) generates signatures that prove ownership without ever exposing the key itself. Solana uses a different curve. The irreversibility is identical. That mathematical permanence is the whole point — and it's also why millions of bitcoins are permanently frozen. From there, the episode moves into what this actually asks of ordinary people: carry a seed phrase — one piece of paper, one hardware device — and never lose it, or the funds are gone. A 2020 USENIX SOUPS study found that a meaningful share of users didn't understand that the key controls the funds, not some account credential on a server. Which raises a harder question than the cryptography does: is self-custody protection, or is it Bitcoin's promise landing on someone who didn't know they were holding it alone? The custodial retreat — handing keys back to exchanges — solves the fragility problem and reintroduces counterparty risk. Different tradeoff, same tension. The math is settled. What isn't is whether people can reliably carry what the math asks of them.

Frequently asked

What is a private key in cryptocurrency and why does it matter?

A cryptocurrency private key is the sole mathematical proof that you control funds in a blockchain wallet. Using ECDSA or EdDSA, the key signs every transaction, and the network verifies that signature without ever seeing the key itself. No private key means no valid signature, so the funds can never be moved — by anyone.

What happens if you lose your crypto private key or seed phrase?

Losing a crypto private key or its seed phrase makes the associated funds permanently inaccessible. The wallet balance remains publicly visible on the blockchain indefinitely, but no transaction can ever be authorized without the original ECDSA or EdDSA signature. There is no recovery path, no customer support, and no override — the loss is final by design.

Why does Bitcoin use elliptic curve cryptography instead of RSA?

Bitcoin uses 256-bit elliptic curve cryptography on the secp256k1 curve because it delivers security equivalent to 3,072-bit RSA with a far smaller key size. That efficiency enables millions of transactions daily. Ethereum also uses secp256k1 with ECDSA, while Solana and Cardano use Ed25519 with EdDSA — a different curve but the same irreversible ownership model.

What is the difference between a custodial and non-custodial crypto wallet?

In a custodial wallet — offered by exchanges like Coinbase or Binance — a third party holds the private key and provides password recovery, but reintroduces counterparty risk from hacks or insolvency. A non-custodial wallet gives the user sole control of the private key, eliminating that counterparty risk but making any key loss permanent and unrecoverable.

Do most crypto users understand how private keys work?

Research published in the 2020 USENIX SOUPS study found widespread misconceptions about private keys among cryptocurrency users. Many believed funds were held in a remote account rather than controlled purely by a local cryptographic key. This means users choosing non-custodial wallets may not realize a single hardware failure or lost seed phrase ends access permanently.

Grounded in 12 sources
How Cryptocurrency Users Choose and Secure Their Wallets ↗ · dl.acm.org
Of Secrets and Seedphrases ↗ · dl.acm.org
What Problem Does Blockchain Actually Solve? (It’s Not “Decentralization”) ↗ · medium.com
Private Key and Public Key in Cryptocurrency ↗ · medium.com
Private Key & Public Key ↗ · bit.com
Custodial vs. Non-Custodial Wallets: Where is Your Crypto Held? | BitGo ↗ · bitgo.com
Cryptographic Signature: Definition & Use in Blockchain ↗ · chainscorelabs.com
Elliptic Curve Cryptography: The Math Behind Crypto Security | Cobo ↗ · cobo.com
How Should I Secure My Seed Phrases: Best Ways to Store and Protect Your Seed Phrases - Coin Bureau ↗ · coinbureau.com
Verifiable Ownership Framework builds trust in crypto ownership ↗ · coingeek.com
Cryptography and Wallets in Blockchain Design ↗ · dsvynarenko.hashnode.dev
Public-key cryptography - Wikipedia ↗ · en.wikipedia.org
Read transcript

Brian Reed: Eliza, okay, I need to tell you what happened to me this week — I was helping my cousin set up a crypto wallet, and at some point he goes, 'so where do I write down the password?' And I realized I had no idea how to explain that what he was writing down wasn't a password.

Eliza Ward: Oh, that's exactly it — because it's not a password. It's a seed phrase, which encodes the private key, which is... actually the only proof he owns anything in that wallet.

Brian Reed: And if he loses it—

Eliza Ward: Gone. Actually gone. Not locked-out-call-support gone. The funds are still visible on the blockchain — anyone can look — but no one can ever move them. That's the irreversibility baked into Bitcoin since its launch in 2008 and 2009. There's no central authority to override the signature requirement.

Brian Reed: That's — I mean, that's a genuinely weird kind of loss. The money exists, you can point at it, it just can't be yours anymore.

Eliza Ward: Millions of bitcoins, permanently. That's not a rounding error — that's a structural consequence of making ownership purely mathematical. Which is what we're really trying to work out today: what does it actually mean to own something when the proof is cryptographic, and what happens when that proof disappears?

Brian Reed: And whether the system was ever actually built for people like my cousin.

Eliza Ward: Which is the right question — and the answer is actually in how the math works, so let me try this. Imagine a padlock anyone can click shut, but only one key in the world opens it. You hand out copies of that padlock — that's your public key. Someone locks a message for you. Only you can open it. That's asymmetric cryptography. Two linked keys, one secret, one shared.

Brian Reed: So the bank's ledger just... gets replaced by the padlock?

Eliza Ward: Exactly — the signature is the voucher. When you send bitcoin, your private key signs that specific transaction. Produces a unique string. And anyone on the network can check it against your public key and confirm: yes, the person with that private key authorized this. No bank involved. The math is the proof.

Brian Reed: Wait — and the key itself never gets exposed? Like, the signature doesn't just... hand it over?

Eliza Ward: Never. That's the — okay, this is the part that took me a beat to actually internalize. The signature proves you hold the private key without revealing it. It's unique to both the transaction data and the key. Change one character of the transaction, the signature breaks. Different key, different signature. But the key stays hidden.

Brian Reed: So trustless verification isn't, like, a slogan — the math literally makes the institution unnecessary.

Eliza Ward: Right — Satoshi Nakamoto built this into the Bitcoin whitepaper in 2008. The whole point was: no one has to vouch for you. ECDSA — the algorithm Bitcoin and Ethereum run on — generates your keys from a curve called secp256k1. Solana uses a different curve, Ed25519, through EdDSA. Different math, same core promise. Your signature is your authority. Which means your cousin's seed phrase wasn't a password — it was the only copy of the padlock key.

Brian Reed: And if it's gone, no one calls a locksmith. There's just... no door anymore.

Eliza Ward: And the door was always going to be gone — that's what I want to make clear — this isn't a bug someone forgot to patch. Satoshi Nakamoto designed it this way in 2008. No institution means no override. That's the feature.

Brian Reed: Here's the part that breaks people's brains, though. Picture this: someone transfers eight thousand dollars in Ethereum to a non-custodial wallet. Writes down the twelve-word seed phrase on a piece of paper — a proper backup, exactly what you're supposed to do — tucks it in a kitchen drawer. Six months later, a grease fire. Paper's ash. And the Ethereum is just... sitting there. On the blockchain. Balance intact. Publicly visible. Permanently frozen.

Eliza Ward: Is there any way back?

Brian Reed: None. And — I mean, that's the thing I keep returning to — it's not like the money is gone in the way cash burns. The funds are provably there. Any block explorer will show you the balance. You just can never produce the ECDSA signature on secp256k1 that the network requires, so the network will never move them. No signature, no transaction. The math doesn't care about the fire.

Eliza Ward: So the seed phrase is also a single point of failure.

Brian Reed: Exactly — it's not a solution, it's a deferral. The seed phrase encodes the private key in human-readable form, but losing it carries identical consequences to losing the key itself. You've just moved the fragile thing from a device to a drawer.

Eliza Ward: And this is why 256-bit ECC matters here — wait, actually, let me frame it right. The reason Bitcoin and Ethereum use elliptic curve cryptography over something like RSA is that 256-bit ECC gives you security equivalent to 3072-bit RSA. Tiny key, enormous security. That efficiency is what lets millions of transactions run daily. But that same mathematical permanence — the one-way trapdoor — is why there's no recovery path.

Brian Reed: Solana and Cardano made a different implementation choice — EdDSA on Ed25519 instead of ECDSA on secp256k1 — but the irreversibility is identical. Different curve, same wall.

Eliza Ward: Right — and that's what makes the millions of permanently lost bitcoins not an anomaly. It's a structural outcome of the design. The math that makes the institution unnecessary is the exact same math that makes the loss permanent.

Brian Reed: And what that's actually doing to user behavior — why people are handing their keys back to custodial services — that's the part that gets genuinely uncomfortable, especially once you see what researchers found when they actually tested whether people understand any of this.

Eliza Ward: And that behavior — handing the keys back — is actually the clearest signal that the system's core promise has a problem. BitGo publishes a comparison of custodial versus non-custodial wallets, and the takeaway is that every point on that spectrum is a different tradeoff. None of them eliminate the underlying tension. You just move the risk around.

Brian Reed: So custodial wallets — what, a Coinbase or a Binance holds the private key for you?

Eliza Ward: Third party holds the keys, you get a password reset button. Recovery is real. But counterparty risk is back — exchange hacks, insolvency, mismanagement. The thing blockchain was architected to eliminate.

Brian Reed: So you've hired a new bank and called it something else.

Eliza Ward: That's — yeah, that's the structural irony. And the 2020 USENIX SOUPS study is where this gets uncomfortable, because researchers actually tested user mental models and found widespread misconceptions about what private keys even do. People didn't understand that the key controls the funds, not — I mean, not some account credential somewhere.

Brian Reed: Wait, like — they thought there was a server somewhere holding their balance?

Eliza Ward: Essentially. And the wallets weren't correcting that. Which means someone choosing non-custodial — choosing full ECDSA key control, no counterparty — might genuinely not grasp that a single hardware failure ends it. That's not sovereignty. That's unassisted exposure.

Brian Reed: Okay but — the self-custody position isn't wrong, is it? A non-custodial wallet with a hardware wallet and, say, MPC actually does eliminate exchange-hack risk. That's real.

Eliza Ward: It's real if the user understands what they're signing and where the key actually lives. The SOUPS findings say a meaningful portion don't. So the question isn't which wallet type is better in theory — it's whether self-custody is protection or just... Bitcoin's promise landing on someone who didn't know they were holding it alone.

Brian Reed: And the custodial retreat doesn't answer that — it just confirms it's happening.

Eliza Ward: And the math is settled. ECDSA, EdDSA, secp256k1, Ed25519 — nobody serious disputes that the cryptography works. Billions of transactions, the signatures hold. That part is done. What's not done is — I mean, what's actually unproven is whether ordinary people can reliably carry what the math asks of them.

Brian Reed: We traded the bank's ledger for a math problem. The math problem is solved. The human problem isn't.

Eliza Ward: That's — yeah. That's where I land too. And it's uncomfortable because it's not a criticism of the cryptography. It's a question about custody at scale. Millions of bitcoins gone isn't a flaw in ECDSA. It's what happens when you hand billions of people a single irreversible point of failure and call it sovereignty.

Brian Reed: And the answer might be new institutions wearing blockchain's clothes. Or it might be something else. We don't actually know yet.

Eliza Ward: No. We don't. Good talk — genuinely.

Why your private key is your asset — the math that lets you prove ownership without intermediaries · Onpode