HEX private key → every format, address and WIF
The master calculator: paste one 64-digit HEX private key and get every representation of that number (decimal, 256-bit binary, Base64, ASCII), both WIF strings, both public-key serializations, the secp256k1 point, both hash160 values and all five mainnet address types — plus their testnet equivalents.
Enter a value above and press Convert. Not sure what to type? Press “Use example” to load the sample from the placeholder.
What this page computes
This is the master calculator of the tool set. You give it one 256-bit integer — the
private key k — and it returns every standard representation of that integer, both Wallet
Import Format strings, both public-key serializations, the elliptic-curve point behind them, both
hash160 commitments and ten addresses (five mainnet, five testnet).
Everything here is a pure function of k: no seed, no password, no server state, no network
call. Anyone who types the same 64 hex digits gets byte-identical results, forever.
1. The private key: one number, many spellings
A private key is not a file, a string or a blob of random bytes. It is an integer — a scalar — distinguished from other keys only by its value. How you write that value down is a representation:
| Representation | For the demo key | Why it exists |
|---|---|---|
| Hexadecimal (64 digits) | 0824c314…07a171ca |
Two digits per byte, so byte boundaries are visible. What explorers print. |
| Decimal (76 digits) | 3683455675…608394 |
What a human means by "a number"; good for range checks. |
| Binary (256 bits) | 00001000 00100100 11000011 … |
One character per bit — the only form where bit decisions are visible. |
| Base64 (44 characters) | CCTDFHcrLChZyIlHE5Cja/ZuU6HKFkL5bw8skwehcco= |
The same 32 raw bytes as text, for wallet dumps. Not a WIF. |
| WIF (51 or 52 characters) | KwVYL77Lcs1ckM39NvGjrtfKhU4KKdR2iB9Wq2FSMN6rbGK5tVqG |
Base58Check of 0x80 ‖ k ‖ [0x01] — what you paste into a wallet, with a network byte and a compression flag the hex key lacks. |
| ASCII view | \x08$\xc3\x14w+,(Y\xc8\x89… |
What the bytes look like if forced through a text file: almost all unprintable. |
Hex and decimal name the same number, so converting between them is lossless. Base64 and WIF add a second ingredient — raw bytes, or bytes plus version byte and checksum — so they are not "just another base".
2. Why 256 bits, and why k cannot be 0 or n
secp256k1 lives over a 256-bit prime field, and the group generated by G is cyclic of order
n. Three hard boundaries follow:
k = 0gives0 · G, the point at infinity: no coordinates, nothing to serialize. Every validator rejects it.k ≥ nwraps:n · G = ∞, so(n+1) · G = G. A 32-byte value equal ton + 1looks normal and behaves like the key1.- The largest 32-byte value,
2256 − 1, is also invalid — it exceedsn.
| Boundary | Hex | Decimal |
|---|---|---|
| Smallest valid key | 0000…0001 | 1 |
| Largest valid key (n−1) | fffffffffffffffffffffffffffffffebaaedce6af48a03bbfd25e8cd0364140 | 115792089237316195423570985008687907852837564279074904382605163141518161494336 |
| Curve order n (invalid) | fffffffffffffffffffffffffffffffebaaedce6af48a03bbfd25e8cd0364141 | 115792089237316195423570985008687907852837564279074904382605163141518161494337 |
| 2256 − 1 (invalid) | ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff | 115792089237316195423570985008687907853269984665640564039457584007913129639935 |
The gap between the last two rows is 432420386565659656852420866394968145598 — nothing
observable marks it, which is why nobody notices until a validator throws.
Since n − 1 ≡ −1 (mod n), keys 1 and n − 1 give G
and −G, which share an x coordinate — so their Taproot addresses coincide
(bc1pmfr3p9j00pfxjh0zmgp99y8zftmd3s5pmedqhyptwy6lm87hf5sspknck9) while their P2PKH addresses
differ, because P2PKH hashes the y-parity prefix.
3. From number to point: the public key
Multiplying G by k gives a point P = (X, Y) on
y² = x³ + 7 (mod p): the public key. A point has two coordinates, so it serializes in more than
one way — and the choice changes every address that follows.
| Form | Layout | Length | Demo value |
|---|---|---|---|
| Uncompressed | 04 ‖ X ‖ Y | 65 bytes (130 hex) | 04ff812e26…32b424ae |
| Compressed, even Y | 02 ‖ X | 33 bytes (66 hex) | 02ff812e26116a9aa140abe629e7f8a38401653caf925119def59ed3758c67ee80 |
| Compressed, odd Y | 03 ‖ X | 33 bytes (66 hex) | not this key — its Y is even |
| x-only (BIP340) | X | 32 bytes (64 hex) | ff812e26116a9aa140abe629e7f8a38401653caf925119def59ed3758c67ee80 |
Compression is lossless: Y² = X³ + 7 has two solutions, Y and p − Y,
always of opposite parity, so one bit — the 02/03 prefix — picks between them.
Recovery is closed-form because p ≡ 3 (mod 4):
Y = (X³ + 7)(p+1)/4 mod p, negated when the parity does not match.
4. WIF: the same key with a network tag and a checksum
WIF (Wallet Import Format) is Base58Check over a small payload:
compressed: 0x80 ‖ k(32 bytes) ‖ 0x01 → 34-byte payload → 52 characters
uncompressed: 0x80 ‖ k(32 bytes) → 33-byte payload → 51 characters
| Property | Compressed WIF | Uncompressed WIF |
|---|---|---|
| Demo value | KwVYL77Lcs1ckM39NvGjrtfKhU4KKdR2iB9Wq2FSMN6rbGK5tVqG | 5HssbguBnjbaUVZCsH9YuzUG7T4vYQf51iiodi4izdVy6aVNekU |
| Payload (hex) | 800824c314…07a171ca01 | 800824c314…07a171ca |
| Payload length | 34 bytes | 33 bytes |
| Checksum (hex) | 3a0a0417 | b6f3d7f5 |
| First character | K or L | 5 |
| Address it implies | the compressed set | the uncompressed set |
A private key does not "know" whether it is compressed; the 01 suffix decides which public
key encoding the wallet hashes, and therefore which address it looks at. Import a compressed WIF while your
coins sit at the uncompressed address (16kR3eiswUY6tmGnxZhwQmW6LAvTLGWG2G here) and the wallet
reports a zero balance.
5. hash160: the 20-byte commitment
The intermediate values for the demo key, so nothing is hidden:
| Input | SHA-256 (32 bytes) | RIPEMD-160 = hash160 (20 bytes) |
|---|---|---|
compressed pubkey 02ff812e…ee80 |
067eb00a0b9864633b020eef374476142daba913c5481ad6a4741cc8ab702617 |
21f57b6debcfc5b67182dfb4af1641f0a8189012 |
uncompressed pubkey 04ff812e…24ae |
30c812bb6ef97f95538e2423f944d056d0cefc28021113de143e56d2c9d11900 |
3f0e966dc089c611a9c1d03bd4f69ea53b0223f9 |
Two reasons are usually given: it shortens the address, and it hides the public key behind a hash for any address that has never spent — which matters because the public key is what a quantum computer running Shor's algorithm could attack directly. The trade-off is a 160-bit commitment, far weaker against collisions than the curve itself, though a collision alone does not let anyone spend your coins.
6. One key, five addresses
All five come from the same private key, but they commit to different bytes and are spendable by different scripts.
| Badge | Type | scriptPubKey | Size | Encoding | Demo address |
|---|---|---|---|---|---|
| C | P2PKH compressed | OP_DUP OP_HASH160 <h160(pub_c)> OP_EQUALVERIFY OP_CHECKSIG |
25 B | Base58Check 0x00 |
146ZNjH7XTXnMd1ofe3z7CL2i8WM7N2UqT |
| U | P2PKH uncompressed | same script, but h160(pub_u) |
25 B | Base58Check 0x00 |
16kR3eiswUY6tmGnxZhwQmW6LAvTLGWG2G |
| S | P2SH-P2WPKH | OP_HASH160 <h160(0x0014‖h160(pub_c))> OP_EQUAL |
23 B | Base58Check 0x05 |
3DZT76KyKyc5zkzvLugP8umgt4RPY4XPQw |
| W | P2WPKH | OP_0 <20-byte witness program = h160(pub_c)> |
22 B | Bech32, witness v0 | bc1qy86hkm0telzmvuvzm76279jp7z5p3yqjnaerk6 |
| T | P2TR (key path) | OP_1 <32-byte x-only output key> |
34 B | Bech32m, witness v1 | bc1pmsrhxnvmj8tjxxu9wj69ntvwvhvr28qufyc26tshz3rjj777tx3sh54u63 |
- C and U share one script type. Witness programs accept only compressed keys, so modern wallets derive C; U survives because coins paid to it before 2012 must stay spendable.
- S is a wrapper: the 22-byte
0x0014 ‖ h160redeemScript, hashed into a3…address so old wallets could pay into SegWit. - W is the modern default for single-key wallets: the address is the witness program, so the scriptPubKey and the fee are the smallest of the first four.
- T is a different construction. The x-only internal key is tweaked with
TapTweak(demo tweakbae9168523281e7f9e91d897a8d23f7ae6fe66d61854019dcb8abb5185e8fa4d, output keydc07734d9b91d7231b8574b459ad8e65d8351c1c4930ad2e171447297bde59a3). Taproot never hashes the key down to 20 bytes, so a hash160 tool cannot produce it.
7. Checksums: protection from a typo
| Family | Checksum | Demo evidence |
|---|---|---|
Base58Check (1…, 3…, 5…, K…) |
4 bytes appended before encoding: first 4 bytes of SHA256(SHA256(payload)) |
P2PKH payload 0021f57b6d…a8189012 → checksum cbd7667e; P2SH → acbfef44 |
Bech32 / Bech32m (bc1q…, bc1p…) |
6 characters from a BCH-style polymod; v0 = bech32, v1+ = bech32m | bc1qy86hkm0telzmvuvzm76279jp7z5p3yqjnaerk6 decodes to 32 data words y86hkm0telzmvuvzm76279jp7z5p3yqj; the Taproot one to 52 words ending …777tx3s |
Base58Check detects errors but cannot correct them. Bech32 also forbids mixed case and caps length at 90 characters, so typos surface.
8. Testnet: same key, different prefixes
| Item | Mainnet | Testnet |
|---|---|---|
| Version bytes | P2PKH 0x00, P2SH 0x05, WIF 0x80, hrp bc | P2PKH 0x6f, P2SH 0xc4, WIF 0xef, hrp tb |
| P2PKH (compressed) | 146ZNjH7XTXnMd1ofe3z7CL2i8WM7N2UqT | micWfnN6LUy38jVRPD2Mw7YMa873zjixGw |
| P2PKH (uncompressed) | 16kR3eiswUY6tmGnxZhwQmW6LAvTLGWG2G | mmGNLhorkVyMfskQg8gKEgiRCAXAGnxeBv |
| P2SH-P2WPKH | 3DZT76KyKyc5zkzvLugP8umgt4RPY4XPQw | 2N57fAqFzwS7SCYdU23JFkrkx6QdZKurmpU |
| P2WPKH | bc1qy86hkm0telzmvuvzm76279jp7z5p3yqjnaerk6 | tb1qy86hkm0telzmvuvzm76279jp7z5p3yqjemzsdf |
| P2TR | bc1pmsrhxnvmj8tjxxu9wj69ntvwvhvr28qufyc26tshz3rjj777tx3sh54u63 | tb1pmsrhxnvmj8tjxxu9wj69ntvwvhvr28qufyc26tshz3rjj777tx3squrnq7 |
| WIF (compressed) | KwVYL77Lcs1ckM39NvGjrtfKhU4KKdR2iB9Wq2FSMN6rbGK5tVqG | cMrXo27C3vhsunWQmL5sEDAPKhMiz5WinDHywShwrUkrr1RkCJ4i |
| WIF (uncompressed) | 5HssbguBnjbaUVZCsH9YuzUG7T4vYQf51iiodi4izdVy6aVNekU | 91eWBRijNxfiSZ4VVd3Tnb2Dm7RdhaCGMfakiLRELNF1saLqhym |
146ZNjH7… and micWfnN6… commit to the same 20-byte hash160; only the version byte
differs. Treat the prefix as part of the payment instruction, not as decoration.
9. Worked example, end to end
Produced by this page from the sample key
0824c314772b2c2859c889471390a36bf66e53a1ca1642f96f0f2c9307a171ca:
| Step | Value |
|---|---|
| k (hex, 32 bytes) | 0824c314772b2c2859c889471390a36bf66e53a1ca1642f96f0f2c9307a171ca |
| k (decimal) | 3683455675284633286911943861444039993120875154046227415438637967083965608394 |
| k (binary prefix) | 00001000 00100100 — 4 leading zero bits, 116 of 256 bits set |
| k (Base64) | CCTDFHcrLChZyIlHE5Cja/ZuU6HKFkL5bw8skwehcco= |
| P = k·G, X | ff812e26116a9aa140abe629e7f8a38401653caf925119def59ed3758c67ee80 |
| P = k·G, Y | 8f49cde13c7ffd64f1d730bf87a743a578eda4971ddac4a08118160732b424ae |
| Y parity | last hex digit e → even → prefix 02 |
| Compressed public key | 02ff812e26116a9aa140abe629e7f8a38401653caf925119def59ed3758c67ee80 |
| Uncompressed public key | 04ff812e26116a9aa140abe629e7f8a38401653caf925119def59ed3758c67ee808f49cde13c7ffd64f1d730bf87a743a578eda4971ddac4a08118160732b424ae |
| hash160 (compressed) | 21f57b6debcfc5b67182dfb4af1641f0a8189012 |
| hash160 (uncompressed) | 3f0e966dc089c611a9c1d03bd4f69ea53b0223f9 |
| P2SH script hash | 823333d5fd23a83661e8e47629552c4a5bfc8b6e = hash160(0014‖21f57b6d…) |
| Compressed WIF | KwVYL77Lcs1ckM39NvGjrtfKhU4KKdR2iB9Wq2FSMN6rbGK5tVqG |
| Uncompressed WIF | 5HssbguBnjbaUVZCsH9YuzUG7T4vYQf51iiodi4izdVy6aVNekU |
| Address C | 146ZNjH7XTXnMd1ofe3z7CL2i8WM7N2UqT |
| Address U | 16kR3eiswUY6tmGnxZhwQmW6LAvTLGWG2G |
| Address S | 3DZT76KyKyc5zkzvLugP8umgt4RPY4XPQw |
| Address W | bc1qy86hkm0telzmvuvzm76279jp7z5p3yqjnaerk6 |
| Address T | bc1pmsrhxnvmj8tjxxu9wj69ntvwvhvr28qufyc26tshz3rjj777tx3sh54u63 |
10. What comes next in the chain
- Decimal private key and binary private key — the same number written two other ways.
- WIF → private key — the reverse direction, including the checksum test.
- Private key → compressed public key — P = k·G explained on its own.
- hash160 → addresses and Bech32 decoding — after the hash.
11. Security notes
Even though everything here is computed server-side without logging or outbound calls, the key still travelled in a URL and through this server's memory. Never use a tool like this with a key that guards real money — real funds belong in a hardware wallet.
- Entropy, not cleverness. Keys must come from a CSPRNG, a hardware RNG or a BIP39 mnemonic; human-chosen phrases, timestamps and counters are enumerable.
- Address reuse is a privacy leak. Spending publishes the public key and links later payments to it; modern wallets derive a fresh address per payment (BIP32/44/84/86).
- Verify a printed address, not a screenshot. Clipboard-swapping malware is today's most common self-custody theft vector.
- Testnet keys are not safe to publish: the "testnet version" of a mainnet key is the same scalar.
12. Common mistakes
- Expecting one address. One key produces five mainnet and five testnet addresses; a wallet shows the type it was built for.
- Pasting a WIF where hex is expected. A
K…/5…string is Base58Check, not hex — decode it first (WIF → private key). - Dropping leading zeros.
824c314…instead of0824c314…shifts every byte by a nibble; this page left-pads short input, which hides the error. - Reading a checksum as proof of ownership. It only means the string was not garbled:
1BgGZ9tcN4rm9KBzDn7KprQz87SZ26SAMHis valid, its key is1, and it is empty. - Treating the public key as the address. The address commits to a hash of the encoded key, or to a script built from it; the conversions are one-way.
- Confusing p with n. Coordinates are modulo
p = FFFF…FC2F; keys live in[1, n−1]withn = FFFF…4141.
13. Quick reference
| Item | Value / rule |
|---|---|
| Input | Hex private key; 64 digits expected, 0x prefix, spaces and case accepted |
| Valid range | 1 … n−1, n = 0xFFFF…4141 |
| Key length | 256 bits = 32 bytes = 64 hex digits |
| Public key lengths | 33 bytes compressed, 65 uncompressed, 32 x-only |
| Addresses per key | 5 mainnet + 5 testnet |
| Address encodings | Base58Check (C, U, S) and Bech32/Bech32m (W, T) |
| Reversible? | Representations yes; address → key no (ECDLP + hashing) |
| Safe to share | Addresses and public keys yes; WIF, hex, decimal, binary no |