Where does a crypto address come from?
An address looks like line noise. It is actually the end of a short, strictly one-way pipeline, and knowing the three steps explains several things that otherwise seem arbitrary.
Step 1: the private key is a random number
On the curve Bitcoin and Ethereum both use — secp256k1 — a private key is any integer from 1 up to just under n ≈ 1.158 × 10⁷⁷. That is it. There is no generation ceremony; a valid key is a 256-bit random number in range.
This is why the quality of the randomness is the whole of the security. Which matters more than it sounds — see the warning below.
Step 2: the public key is derived by curve multiplication
The public key is computed as private key × G, where G is a fixed point on the curve agreed by everyone. The multiplication is repeated point addition on an elliptic curve.
Forwards, this takes microseconds. Backwards — recovering the private key from the public key — is the discrete logarithm problem, which has no known efficient solution. That asymmetry is what lets you publish one and keep the other.
Step 3: the address is a hash of the public key
Addresses are shortened, checksummed encodings of the public key, and the two big chains do it differently:
- Bitcoin: SHA-256 of the public key, then RIPEMD-160 of that result, giving 160 bits. Encoded as Base58Check for legacy addresses beginning
1, or Bech32 for native SegWit addresses beginningbc1. - Ethereum: Keccak-256 of the 64-byte uncompressed public key; take the last 20 bytes; prefix
0x.
Hashing again shortens the address and adds a second one-way step between the public world and the key.
Why you can publish an address safely
Work the size. 2²⁵⁶ ≈ 1.16 × 10⁷⁷. Estimates put the number of atoms in the observable universe near 10⁸⁰. Guessing a specific private key is not a computing problem to be solved with a bigger budget; the search space is a physical absurdity.
But that guarantee depends entirely on the key being random. So-called brain wallets, where a key was derived from a memorable human-chosen phrase, were systematically emptied — often within seconds of funding — because the search space collapsed from 10⁷⁷ to the size of a wordlist that attackers had already precomputed. The mathematics is only as strong as the entropy fed into it, which is exactly what the next lesson is about.
One address, many chains
Every EVM-compatible chain uses Ethereum's address format, so the same key produces the same address across dozens of networks. This is convenient and is also the mechanism behind the "wrong network" losses in Unit 2: the address is valid everywhere, and the assets land on whichever chain you actually broadcast to.
Ethereum addresses also carry an optional checksum (EIP-55) encoded in the pattern of upper- and lower-case letters, which catches typos — but only in software that bothers to verify it.
Try it now
- On a block explorer, compare a Bitcoin
bc1...address with an Ethereum0x...address. Different lengths, different alphabets, different derivation — and no way to convert one into the other. - Take any Ethereum address and note the mixed upper- and lower-case letters. That pattern is data, not styling: it is the EIP-55 checksum.
- Read the price of one unit of ether off the chart below, then reflect that the only thing standing between that value and anyone else is a randomly chosen number nobody can guess. Provided it really was randomly chosen.