Blocky saysPublic-key cryptography gives each user a key pair: a public key to share, a private key to keep.
Asymmetric crypto (RSA, and the elliptic-curve schemes blockchains use — ECDSA on secp256k1, Ed25519) generates a linked pair. The private key signs and must stay secret; the public key (and addresses derived from it) can be shared. Whoever holds the private key controls the funds — there is no password reset. This is why key custody is everything.
Power-ups you unlock
Key pair: public (share) + private (secret)
Blockchains use ECDSA / Ed25519 (elliptic curve)
Address derives from the public key
Hold the private key = control the funds
Double-Spend Dan attacks — common mistakes
Exposing or losing the private key
Thinking there’s a recovery/reset option
Confusing the address with the private key
Boss battleExplain why "not your keys, not your coins" follows from public-key crypto.
Example code
<!doctype html><html><head><meta charset="utf-8"></head>
<body style="background:#06040d;color:#e6e0ff;font-family:monospace;padding:20px"><pre>private key → signs (keep secret, no reset)
public key → verifies / derives your address
control = whoever holds the private key</pre></body></html>