Hermes / Key → Address

Key → Address

A Bitcoin address is the end of an assembly line. It starts with one random number, your private key, and runs through elliptic-curve multiplication, two hash functions, and a checksummed encoding. Every step is computed here, for real, by hand. Change one bit of the secret and the whole address avalanches.

① Private key256-bit secret
↓  multiply by G on secp256k1
② Public key (SEC)
↓  SHA-256
③ SHA-25632 bytes
↓  RIPEMD-160
④ HASH16020 bytes
↓  prepend version byte, append 4-byte checksum, Base58
⑤ Address
⑤′ SegWit address

Private key

WIF: the private key, encoded

The same secret in Wallet Import Format: version byte + key + checksum, Base58. This is what you back up.

Things to notice

One way only

You can run this line top to bottom in microseconds. Running it backwards, address to public key to private key, would mean breaking both the curve and the hashes.

The avalanche

Hit Flip one bit. A single changed bit in the secret produces a completely unrelated address (changed characters in red). No partial credit, and that's a good hash.

The checksum saves you

Those last 4 bytes are a hash of everything before them. Mistype an address and the checksum won't match, so your wallet refuses to send. Typos can't burn coins.