What is a private key vs a seed phrase?
A private key is a secret number that signs transactions for one blockchain address; a seed phrase is a list of 12 to 24 words from which a wallet derives all of its private keys. Whoever knows the seed phrase controls every key in the wallet. The seed phrase is also called recovery phrase or mnemonic.
Private keys and seed phrases in brief
| Terms | Private key; seed phrase, also recovery phrase or mnemonic. German: privater Schlüssel, Seed-Phrase. |
|---|---|
| Standards | BIP-39 for the seed phrase, BIP-32 for deriving keys from it. Both have the status "Deployed". |
| Word list | 2,048 words; 12 words encode 128 bits of randomness, 24 words encode 256 bits. |
| A number | From 2023 to October 2024, thefts through compromised private keys made up "slightly above 50% of all crypto-asset thefts in DeFi" (EBA and ESMA, January 13, 2025). |
| EU law | Custody under Article 3(1)(17) of MiCA covers the "means of access" to crypto-assets, "where applicable in the form of private cryptographic keys". |
What is a private key in crypto?
A private key in crypto is a random number that only its owner knows and that signs transactions. The wallet vendor Trezor compares it with banking: "A private key, however, is like the password to your bank account" (Trezor). One difference matters: a bank password can be reset, a private key cannot.
The meaning is the same in Bitcoin and Ethereum. Both use elliptic curve cryptography on the curve secp256k1, and the keys are 256 bits long. An Ethereum private key, as an example, is written as 64 hexadecimal characters. The Ethereum documentation states what a private key is used for in cryptocurrency: "Your private key is what you use to sign transactions, so it grants you custody over the funds associated with your account" (ethereum.org, August 6, 2026).
Private key vs public key: what is the difference?
The private key signs, the public key lets others check the signature. The public key is computed from the private key with the Elliptic Curve Digital Signature Algorithm, and the wallet address is computed from the public key. The path runs one way only: "you cannot derive a private key from public keys", as the Ethereum documentation states. The public key and the address can be shared; the private key must stay secret.
What is a crypto wallet seed phrase?
A crypto wallet seed phrase is a sentence of common words that encodes the randomness from which a wallet creates its keys. The definition in BIP-39 is "a group of easy to remember words", and the standard gives the reason: "The sentence could be written on paper or spoken over the telephone."
The standard works in three steps. The wallet draws 128 to 256 bits of randomness and adds a checksum. It splits the bits into groups of 11, and each group picks one word from a list of 2,048. A function called PBKDF2, run 2,048 times, turns the words into a 512-bit seed. An optional passphrase changes the seed, so the same words with a different passphrase open a different wallet. The Ethereum wallet page calls the phrase "the only way you'll be able to recover your wallet" (ethereum.org, February 24, 2026).
How does one seed phrase create many private keys?
One seed phrase creates many private keys through the key tree of BIP-32, the standard for hierarchical deterministic wallets. It describes "a system for deriving a tree of keypairs from a single seed". Knowing a key high in the tree gives all keys below it: "knowing an extended private key allows reconstruction of all descendant private keys and public keys".
The tree also serves auditors. A firm can hand over its extended public keys, which lets an auditor "see all transactions from and to the wallet, in all accounts, but not a single secret key".
Private key vs recovery phrase: how do they compare?
A private key controls one address; the recovery phrase controls the whole wallet.
| Feature | Private key | Seed phrase |
|---|---|---|
| Form | A 256-bit number, on Ethereum 64 hexadecimal characters | 12, 15, 18, 21 or 24 words |
| Standard | Elliptic curve secp256k1 | BIP-39, with keys derived under BIP-32 |
| Scope | One address or account | Every key the wallet derives |
| Daily use | Signs transactions inside the wallet | Stays offline as a backup |
| If someone copies it | The funds at that address are exposed | The funds in the whole wallet are exposed |
In short, the seed phrase is the source, and the private keys are derived from it, as explained above for BIP-32.
Private keys and seed phrases in Germany, Austria and Switzerland
A bank or asset manager that keeps private keys or seed phrases for clients provides custody under MiCA, which applies directly in Germany and Austria. BaFin counts the storage of physical media that hold keys, "z. B. ein USB-Stick oder ein Blatt Papier", as safekeeping (BaFin, January 3, 2025). A seed phrase that a bank keeps on paper for a client can therefore fall under custody. Article 75(3) of MiCA requires a custody policy that minimizes the risk of losing the "means of access", and Article 75(8) makes the custodian liable for their loss when the incident is attributable to it.
DORA adds rules for the keys themselves. Article 7 of Delegated Regulation (EU) 2024/1774 requires financial entities to manage cryptographic keys "through their whole lifecycle", backup included, and to have methods to replace keys that are lost or compromised. BaFin supervises in Germany under the KMAG, the FMA in Austria.
Switzerland is outside the EU, so MiCA and DORA do not apply there. FINMA Guidance 08/2023 ties the protection of client crypto-assets in a custodian's bankruptcy to a clear allocation to each client, for example through an internal register. This page gives no legal advice.
Frankfurt-based DekaBank obtained a crypto custody license from BaFin, under the supervision of the European Central Bank, and launched crypto trading and custody for institutional clients in February 2025 (CoinDesk, February 24, 2025). In custody of this kind, the bank controls the private keys for its clients.
Sources
- Marek Palatinus, Pavol Rusnak, Aaron Voisine, Sean Bowe: BIP-39: Mnemonic code for generating deterministic keys, assigned September 10, 2013
- Pieter Wuille: BIP-32: Hierarchical Deterministic Wallets, assigned February 11, 2012
- ethereum.org: Ethereum accounts, updated August 6, 2026
- ethereum.org: Ethereum wallets, updated February 24, 2026
- Trezor: Trezor hardware wallets and their advantages, retrieved September 29, 2026
- European Banking Authority and European Securities and Markets Authority: Joint Report: Recent developments in crypto-assets (Article 142 of MiCAR), January 13, 2025
- European Union: Regulation (EU) 2023/1114 on markets in crypto-assets, May 31, 2023
- European Commission: Delegated Regulation (EU) 2024/1774 on ICT risk management tools, methods, processes and policies, March 13, 2024
- BaFin: Merkblatt: Hinweise zu den Kryptowerte-Dienstleistungen nach MiCAR, January 3, 2025
- FINMA: FINMA publishes guidance on staking services, with Guidance 08/2023, December 20, 2023
- CoinDesk: DekaBank Rolls Out Crypto Trading, Custody Services for Institutions: Bloomberg, February 24, 2025
About Finance Loop: private keys and seed phrases
Finance Loop connects the people at banks and custodians who manage keys, backups and recovery with the auditors and compliance staff who review them. DekaBank in Frankfurt obtained a crypto custody license from BaFin and started crypto trading and custody for institutional clients in February 2025.
Finance Loop was a partner of the Forum für Digitale Vermögenswerte on February 26, 2026, a German-language forum for banks, family offices and asset managers. The forum deals with custody, tokenization and regulation as they are put into practice.