Crypto

Keys and wallets: what you actually own

Tiziano Brunno · 31 August 2026 · 9 min

Hi trader,

for more than a year I kept my crypto on an exchange and I was convinced I owned it.

I did not.

I had a number on a screen, which is a different thing, and I only realised it when I tried to work out what happens to that number if the company showing it to me shuts down.

This is the lesson that explained it to me. It is the second in the series, and if you missed the first one, what a blockchain is, read that first: here I take for granted that the ledger is made of rows and not of coins.

Ok, vamos.

The question nobody asks

If there are no coins on the ledger, only rows, and the rows are written by the network, then what exactly do you own?

Not an object. Not a file. Not a token inside an app.

You own the ability to sign. Meaning the ability to prove to the network that those rows can be moved by you and by nobody else.

That ability is a secret number, and it is called a private key.

What is inside a wallet

Here is the first misunderstanding to clear out, and the name itself does not help: wallet means wallet, but there is no money inside it.

There are keys.

The mechanism runs one way, and this is the beautiful part. From the private key you derive the public key. From the public key you derive the address, the one you give to other people so they can send you things.

Every arrow works in one direction only. From the address you do not get back to the key, and it is not a question of how clever you are: with today’s computers the age of the universe would not be enough.

Four step chain starting from the twelve seed words and leading to the private key, then the public key and finally the address, with arrows running one way only and a warning that there is no going back, plus the note that the coins are not in the wallet but on the ledger
From the twelve word phrase you derive the private keys, from each of those the public key, and from that the address. The arrows run one way only: there is no going back. The coins are not inside the wallet, they are on the ledger.

So when you say “I moved my bitcoin into the wallet” you are saying something imprecise. The bitcoin did not move anywhere: they are still rows on the ledger. What changed is which key can move them.

The twelve words

Now the part that really counts.

When you open a new wallet, the first thing it makes you do is write down twelve words (sometimes twenty four). It is called the seed, or recovery phrase.

Those words are not a reminder of your password. They are the wallet.

From those twelve words the software derives, with a calculation that is always the same, all of your private keys. All of them. The ones you have now and the ones you will generate in two years.

Which means something very practical: the phone is irrelevant. If it gets stolen, you get another one, you type in the twelve words and you find everything exactly as it was. But if you lose the words and the phone breaks, there is no “I forgot my password” button. There is nobody to call. It is over, full stop.

One detail that shows how well designed this is: the words come from a fixed list of 2,048, and the last one is not free, it carries a check code calculated from the previous ones. Twelve words are worth 128 bits of real randomness, a number with thirty nine digits of possible combinations.

Guessing it is not hard. It is out of the question.

Get one thing into your head though: the words have to be generated by the device, not by your brain. The check on the last word rejects almost every invented phrase, but not all of them, and that is not the point anyway. A phrase thought up by a human being is guessable, because our imagination is far poorer than randomness, and over the years the people who tried it found their wallets emptied.

Two clarifications that are worth real money.

The first. Some wallets let you add a passphrase to the twelve words, an extra word of your own, what some people call the twenty fifth word. If you use it, the twelve words on their own no longer open anything, so it has to be kept as carefully as the rest. And be careful, because if you get it wrong it does not say “error”: it opens an empty wallet, which is the best possible way to give yourself a heart attack.

The second. If you restore your words into a different app from the one you started with and you see zero, almost always you have lost nothing: it is the app looking at a different branch of the same tree of keys. Before you panic, try again in the app you started from.

“Not your keys, not your coins”

You will hear this repeated like a prayer. Now you have what you need to understand it, and it takes two lines.

When you buy on an exchange, the keys are theirs. The number you see in your account area is not a row on the ledger: it is a row in the exchange’s database, saying how much they owe you.

You do not own bitcoin. You own a claim against a company.

As long as that company works, the two things look identical, which is why nobody thinks about it. The day it stops working, it turns out they were not identical at all.

I am not telling you exchanges are evil: you go through them to buy, it is normal, I use them too. The problem is not buying there. It is leaving there what you cannot afford to lose.

The three ways people lose everything

There are not a hundred of them. There are three, and they all look like a custody mistake, not a market one.

The three cards of the ways people lose everything: losing the seed, giving it away to whoever asks, and trusting a third party that goes down. For each one how it really happens, how to avoid it, and the blunt consequence
The three ways people lose everything, side by side: you lose the seed, you give the seed away, you trust a third party that goes down. For each one, what actually happens and the rule that avoids it.

One. You lose it. You never wrote it down, or you wrote it on a scrap of paper that got wet, or it lived in a phone note that died with the phone. No recovery possible. It is the stupidest way and also the most common.

Two. You give it away. And here you carve one rule into your head, and it holds forever: nobody legitimate will ever ask you for your seed. Not support, not a site that needs to “validate” your wallet, not a helpful person messaging you, not an app you have to unlock. Nobody. If somebody asks you for it, that person is robbing you, with no exceptions and no special cases.

Three. You trust a third party. The crypto sits on an exchange, or on a platform promising yield, and that one goes down. You did not lose your keys: you never had them.

There is a fourth way, subtler, which is signing without reading and authorising a contract to drain your wallet. We will cover it in the lesson on scams, because it deserves its own space.

What you do from tomorrow morning

Four things, in order, and the third one is the one almost nobody does.

Write the seed on paper. Not a photo, not the cloud, not your phone notes, not a message to yourself. Paper, somewhere that survives a distracted version of you.

And get clear on what you have just created: that piece of paper works like cash. Whoever finds it does not have to guess a password and does not have to break anything, they type in the words and take everything in two minutes, from anywhere in the world. So “somewhere safe” means actually safe, not the top drawer of your desk.

Do not tell it to anybody and do not type it anywhere, other than into the wallet itself when you are restoring.

Test the restore before you put anything serious in there. Put in pocket change, delete the app, install it again, restore with the words and see whether you find everything. It is the only way to know you wrote them down correctly, and finding out afterwards is too late.

If the amount starts to matter, get a dedicated device. The kind where the key never leaves the object and you confirm operations with a physical button. The right question is not “how much does it cost” but “how much am I keeping on it”.

On this one a hard rule though: buy it only from the manufacturer’s site. Never used, never from a marketplace, never from some guy online because it was cheaper. A tampered device arrives with the seed already written down by somebody else, and you pour your money onto it convinced you are safe. It is a scam that exists and that works.

Where we go next time

If the exchange’s keys are its own, then it is time to understand properly what an exchange is, how it really works and what happens if it fails. That is next week’s lesson, and anybody who lived through certain stories already knows why it matters.

A wallet does not hold coins. It holds the ability to sign, and either you have it or somebody else has it in your place.

tradingblog.itPosta su X

Let me close with the thing that sorted my head out on this subject.

In trading we spend our days worrying about market risk: the stop, the size, the drawdown. Then somebody keeps everything on an exchange and never thinks about it, because that risk does not flash on the screen.

But it is a risk like any other, and it has one nasty feature: it does not make you lose a percentage.

It makes you lose everything, all at once.

Suerte Amigo!

Tiziano Brunno

Tradingblog

Want to put your market reading to the test?

Compete and challenge other traders inside an Arena in a demo environment, with no real capital at risk. Discover the Performance Arena Events by The Thunder Trader.

Discover The Thunder Trader →


Disclaimer: purely informational and educational content. It does not constitute financial advice or an invitation to trade. Trading involves the risk of capital loss.

← Torna al blog
© 2026 tradingblog.it — Tiziano BrunnoContenuti a scopo informativo e didattico, NON consulenza finanziaria. Il trading comporta un rischio elevato di perdita del capitale.