SECSOURCE-LED TOPIC GUIDE

Bitcoin security: keys and recovery

Connect key protection, Seed Phrase, recovery and Multisig. Distinguish technical control of funds, legal entitlement and custody’s operational risks.

72connected coordinates
231Source links

You authorize spending through your own keys and script conditions. Technical ability to sign does not by itself establish legal ownership. A Seed Phrase enables recovery of derived keys in a supported format. The words are not attached to a transaction or sent to the network. Recovery requires the correct words, order, format and any passphrase. Derivation paths, address types and configuration may be needed to find all funds. Multisig can distribute signatures across devices or people. The required signature threshold and available backups determine whether you depend on another party.

Leaked words can threaten many accounts; any passphrase's strength and secrecy affect the risk. Do not invent or translate the words, or send them to support or a website requesting “verification”. Assess custody arrangements against specific threats and a verified recovery procedure. Buying a device alone does not address every way funds can be lost. Linked entries have their own sources and reviews.

Primary sources

A curated path from first principles to the details that matter.

01
Security · KEYS

Self-custody

Direct control of the keys needed to spend bitcoin, with responsibility for verification, backup and recovery.

Open entryOpen source
02
Security · KEY

Private Key

A secret scalar that can authorize spending under a corresponding public key.

Open entryOpen source
03
Security · SEED

Seed Phrase

Recovery words, wallet backups, safe storage, recovery checks and the scams that steal bitcoin.

Open entryOpen source
04
Security · HW

Hardware wallet

A dedicated signer that keeps private keys away from the general-purpose host computer.

Open entryOpen source
05
Security · M-of-N

Multisignature

A spending policy that requires a threshold of several keys instead of one signature.

Open entryOpen source
06
Security · WATCH

Watch-only wallet

A watch-only wallet tracks a defined set of Bitcoin scripts and can derive addresses, detect receipts and prepare unsigned transactions without containing the private keys required to spend. Its usefulness depends on importing the complete wallet policy—not merely one visible address—and on obtaining trustworthy chain data.

Open entryOpen source

Definitions, mechanisms, people and source data connected to this field.

KEYPrivate KeySecurity · 2 §WALBitcoin walletSecurity · 3 §SEEDSeed PhraseSecurity · 5 §BIP39BIP 39Security · 14 §BIP32HD walletSecurity · 14 §M-of-NMultisignatureSecurity · 4 §COLDCold storageSecurity · 15 §HWHardware walletSecurity · 4 §WATCHWatch-only walletSecurity · 14 §UTXO+Coin controlPrivacy · 2 §CHGChange outputPrivacy · 14 §2XDouble-spendSecurity · 14 §XPUBExtended Public Key (xpub)Security · 5 §DESCOutput DescriptorSecurity · 5 §BIP174PSBTSecurity · 3 §CJCoinJoinPrivacy · 5 §PRIVBitcoin PrivacyPrivacy · 5 §PSEUDOPseudonymityPrivacy · 5 §KYCKYCPrivacy · 5 §KEYSSelf-custodySecurity · 4 §BLINDBlind signaturePrivacy · 5 §MIXMix networkPrivacy · 3 §SYBILSybil attackSecurity · 3 §ECLEclipse attackSecurity · 3 §SELFSelfish miningSecurity · 3 §MINIMiniscriptSecurity · 5 §MuSig2MuSig2Security · 2 §SCHNORRSchnorr signatureSecurity · 5 §SPSilent PaymentsPrivacy · 3 §V2P2PBIP324Privacy · 3 §P2EPPayJoinPrivacy · 2 §NEUTRINOCompact Block FiltersPrivacy · 4 §SELECTCoin SelectionSecurity · 6 §GAPGap LimitSecurity · 5 §PATHDerivation PathSecurity · 9 §BIP85BIP85Security · 4 §SLIP39SLIP-39Security · 5 §SSSShamir Secret SharingSecurity · 4 §SESecure ElementSecurity · 4 §AIRGAPAir-gapped WalletSecurity · 4 §DICEDice Roll EntropySecurity · 4 §DURESSDuress WalletSecurity · 6 §INHERITBitcoin Inheritance PlanSecurity · 7 §VAULTBitcoin VaultSecurity · 5 §DMSDead Man’s SwitchSecurity · 7 §COLLABCollaborative CustodySecurity · 7 §CHAINALChain SurveillancePrivacy · 6 §CIOHCommon-Input Ownership HeuristicPrivacy · 5 §CLUSTERAddress ClusteringPrivacy · 4 §LABELTransaction LabelingPrivacy · 3 §CASHUCashuPrivacy · 9 §BIP157/158Compact Block FiltersPrivacy · 5 §BIP370PSBT v2Security · 4 §FROSTFROSTSecurity · 4 §NEUTRINONeutrinoPrivacy · 4 §BISQBisqPrivacy · 3 §PEACHPeach BitcoinPrivacy · 3 §HCryptographic entropySecurity · 3 §BIT-HBits of entropySecurity · 2 §2^NBrute-force search spaceSecurity · 3 §RNGRandom-number generatorSecurity · 2 §CSPRNGCryptographically secure PRNGSecurity · 2 §PRNGDeterministic PRNGSecurity · 3 §TRNGHardware true random-number generatorSecurity · 2 §MIX-HEntropy mixingSecurity · 3 §SEED-GENWallet seed generationSecurity · 2 §CSBIP39 checksumSecurity · 4 §BIP39-PBIP39 passphraseSecurity · 4 §PBKDF2PBKDF2 in BIP39Security · 3 §FPWallet master fingerprintSecurity · 3 §REPROReproducible firmware buildSecurity · 4 §CK-RNGCOLDCARD RNG incident (2026)Security · 3 §
691Search all Atlas entries