Skip to main content
Loading …
AS Albert Schaper
  • 01Home
  • 02About
  • 03Expertise
  • 04Projects
  • 05Contact
  • 06Insights
  • 07Tools
AS

Albert Schaper

01Home 02About 03Expertise 04Projects 05Contact 06Insights 07Tools

AI · Finance · Entrepreneur

Home / Insights / How a Wallet Actually Works: Seeds, Derivation Paths, and 5 Self-Custody Mistakes
Insights

How a Wallet Actually Works: Seeds, Derivation Paths, and 5 Self-Custody Mistakes

Seed phrase, private key, address: three terms that keep getting confused. How 256 bits of randomness become a Bitcoin, Ethereum, and Solana wallet, which derivation paths apply — and the five self-custody mistakes that cost real money.

17 September 2026 · 6 min read CryptoWeb3 Auf Deutsch lesen Share on LinkedInShare on X
Contents
  • Step 1: Entropy becomes words (BIP39)
  • Step 2: Words become a master key (BIP32)
  • Step 3: The path decides the address (BIP44 and friends)
  • 5 mistakes that cost real money
  • Why this matters right now
  • Try it — safely

Most explanations of crypto wallets stop where it gets interesting: "keep your seed phrase safe." What happens in between — how randomness becomes words, words become keys, and keys become addresses — stays a black box. Yet understanding exactly that is the precondition for self-custody worthy of the name.

This article opens the black box. To try it hands-on, there is a companion tool: the Wallet Generator, which creates Bitcoin, Ethereum, and Solana wallets 100% client-side in your browser — following the three steps below.

Step 1: Entropy becomes words (BIP39)

Everything starts with 256 bits of true randomness — in the browser via window.crypto.getRandomValues(), a cryptographically secure OS-level source. 256 bits mean 2²⁵⁶ possible combinations — a number on the order of all atoms in the observable universe. Brute force is not an option.

BIP39 translates these random bits into 24 English words from a fixed 2,048-word list. The last word carries a checksum: mistype a word during recovery and validation fails instead of silently opening the wrong wallet. That is precisely why a paper backup works — error-detecting, human-readable, no computer needed to read it.

Rule of thumb: the seed phrase is the master key. Whoever holds it controls every derived account — on every chain, forever.

Step 2: Words become a master key (BIP32)

A key-derivation function (PBKDF2, 2,048 rounds) turns the seed phrase into a 512-bit seed. From it, BIP32 builds a hierarchical tree: one master key with arbitrarily many child keys — deterministically. Same words, same tree, in every compatible wallet on earth.

That is why you can import the same 24 words into Sparrow, MetaMask, or Phantom and recover your accounts everywhere. There is no server, no account, no "forgot password." The math is the account.

Optionally there is a 25th word: an additional BIP39 passphrase that enters seed derivation and produces completely different addresses — without the exact passphrase, those wallets are lost forever. Distinct from that is the zpub (the Bitcoin account's watch-only key, e.g. for tax tools): it can derive addresses but spend nothing — yet it reveals the full payment history and belongs only with trustworthy services.

Step 3: The path decides the address (BIP44 and friends)

The derivation path selects which branch of the tree serves which chain. The m / purpose' / coin' / account' / change / index convention looks cryptic but is just addressing — like folder paths on a disk:

Chain Path Address format Curve
Bitcoin m/84'/0'/0'/0/0 Native SegWit (bc1…) secp256k1
Ethereum m/44'/60'/0'/0/0 Hex (0x…) secp256k1
Solana m/44'/501'/0'/0' Base58 ed25519

Bitcoin uses purpose 84 (SegWit) here; Ethereum and Solana use the classic purpose 44 with their registered coin numbers (60 and 501). The Wallet Generator uses exactly these paths — which is why its addresses import cleanly into standard wallets.

The final step — private key to address — is one-way math: elliptic-curve multiplication yields the public key, hashing yields the address. The reverse is infeasible. The address may be public (it is even shown as a QR code in the generator). The private key and the seed: never.

5 mistakes that cost real money

From more than a decade working with Bitcoin — in 2015 I wrote Geld 2.0, one of the first German books on the topic — and countless founder conversations, I know the failure patterns. They are rarely technical, almost always organizational:

1. Storing the seed digitally. Screenshot, cloud note, email to yourself. Every one of these paths has been drained a thousand times — often months later, via a hacked cloud account that had nothing to do with crypto. Rule: paper or steel, two separate locations.

2. Generating online for real amounts. A browser tool is ideal for learning and dust amounts. For savings: save the page via Ctrl+S, disconnect the network, generate in a fresh browser profile. Or use a hardware wallet — it keeps the key on a separate chip that never reveals it.

3. Sharing the private key instead of the address. Sounds trivial, happens constantly in "support" scams: no legitimate party — no support agent, no airdrop, no verification — ever needs your seed or private key.

4. No test transaction. Send a small amount first, verify receipt, test the backup with a real recovery on a second device — then move the rest. A backup never tested is not a backup.

5. One backup, no plan. What happens in case of fire, loss, or inheritance? Second medium in a different location, instructions your family can actually follow, multisig instead of a single key beyond a certain size.

Why this matters right now

Wallets are no longer just custody for investors. With paying AI agents — five competing payment protocols launched since May 2025, see What Actually Happens When AI Agents Start Paying for Themselves — every agent system gets a wallet. Giving an agent access to real money inherits exactly the governance risk from this article series (What an AI Agent Actually Costs): a spending cap before the first real transaction is the minimum requirement.

The same craft — seed custody, derivation paths, spending limits — applies to human and machine wallet owners alike. Difference: the agent will not complain when its key ends up in a log file.

Try it — safely

The Wallet Generator implements exactly this pipeline: entropy from getRandomValues(), BIP39 seed, BIP84/BIP44 derivation, QR codes for addresses only. All local, no backend, no tracking. For learning, for workshop demos, for dust amounts — and as a reference for how the standards fit together.

For anything beyond that, the order is: understand first (this article), then generate offline, then test — and for larger amounts or company setups, have a conversation before money moves. That is exactly what I help with: custody concepts, payment flows, and technical reviews with a finance and execution lens.


Sources:

BIP standards

  • Bitcoin BIPs: BIP39 — Mnemonic code for generating deterministic keys
  • Bitcoin BIPs: BIP32 — Hierarchical Deterministic Wallets
  • Bitcoin BIPs: BIP44 — Multi-Account Hierarchy
  • Bitcoin BIPs: BIP84 — Derivation scheme for P2WPKH based accounts
  • SLIP-0044: Registered coin types (60 = Ethereum, 501 = Solana)

More on this site

  • Bitcoin & Web3 Basics — overview
  • Wallet Generator — try it
  • Using a Hardware Wallet Right
  • What Actually Happens When AI Agents Start Paying for Themselves
  • What an AI Agent Actually Costs
  • Glossary: Seed Phrase, BIP39/32/44 & Derivation Path
More Insights
  • Crypto

    Why Anonymous Bitcoin Trading Ends in 2026 — and What Stays Private Anyway

    Binance had to halt its EU operations on July 1, 2026. The company blames postponed regulatory meetings; the Wall Street Journal points to compliance concerns instead. Four new rules kick in simultaneously in 2026. What they actually change, and what self-custody still explicitly protects.

  • Crypto

    Bitcoin & Web3 Basics: The Beginner's Learning Path

    Nine articles, one learning path: how wallets come to exist, how transactions actually work, and what matters for your own security — three modules, ~28 minutes, with a progress tracker and the matching tools to try it yourself.

  • Crypto

    How Safe Is Your Seed: 12 or 24 Words?

    12 words mean 128 bits of randomness, 24 words 256 bits — but what is that in years? Why brute force is hopeless, PBKDF2 slows attackers further, and what no word count on earth protects against.

Albert Schaper
About the author

AI expert, entrepreneur, and founder with a finance background and a focus on execution. I build companies, invest in ventures, and advise teams on putting AI to work. LinkedIn

← All Insights
AS

AI · Finance · Entrepreneur

Navigation

Home About Expertise Projects Contact Insights Tools

Projects

Best-AI.org BitAutor Geld 2.0 ASCANUS Health

© Albert Schaper. All rights reserved.

Privacy / Imprint