secp256k1 — Private Key → Public Key

Statistics 2026–2027 · educational cryptography experiment. Scalar multiplication Q = kG is a one-way function under the discrete-log assumption — it is not a cryptographic hash function. This page demonstrates the algorithm itself, then tests that claim statistically.

Test keys only. Never paste a real wallet private key here. Use the Random button or small values like 13. All computation runs locally in your browser; nothing is uploaded.

1 · Private key → public key



k (decimal)
–
k (hex)
–
public x
–
public y
–
on curve?
–
timing
–
library cross-check
–

Curve: y² = x³ + 7 over p = 2²⁵⁶ − 2³² − 977, standard generator G, group order n = 0xFFFFFFFF…4141. Multiplication means elliptic-curve scalar multiplication, not ordinary multiplication.

2 · The algorithm: binary double-and-add

–

–

–

Step through the real computation (bit by bit)

All steps at once

bit ivalueactionR after step (x, abbreviated)

2b · Toy-curve animation (honest finite-field picture)

–

A smooth textbook curve would be a lie here: secp256k1 lives over a finite field, so its “points” are scattered discrete dots. This toy curve is small enough to draw every valid point.

–

3 · Ethereum connection: public key → address

k  ─secp256k1→  Q=(x,y)  ─Keccak-256→  last 20 bytes  →  address
uncompressed pubkey
–
Keccak-256
–
address (EIP-55)
–

Two different operations: elliptic-curve scalar multiplication produces the public key; hashing (Keccak-256) produces the address. Conflating them is exactly the mistake §5 warns about.

4 · Statistical exploration

Base point:

Alternate base points are experimental only: H = aG means kH = (ka)G, a relabelling inside the same cyclic group — not a new kind of function. The standard Ethereum computation always uses G.

idle

A · Coordinate distribution (x/p and y/p, 20 bins)

x histogram

y histogram

B · Bit distribution (% ones per bit position; green line = 50%)

–

C · Linear correlation (Pearson — detects only linear association)

k vs x (normalized)

k vs y (normalized)

–

D · One-bit input change → Hamming distance of x (avalanche-LIKE, not a hash property)

–

E · Neighbouring keys: (k+1)G = kG + G exactly

–

Report summary (copy into your write-up, with N and method)

–

5 · What the experiments do — and do not — prove

PropertyECC k → kGCryptographic hash
DeterministicYesYes
Easy forwardYesYes
Hard to invertYes — ECDLP assumptionYes — preimage resistance by design
Arbitrary-length inputNo (scalar < n)Normally yes
CollisionsNone for distinct valid k (bijection onto subgroup)Must exist; finding them must be infeasible
AvalancheEmpirically avalanche-like; not a claimed propertyCommonly desired, designed-in
Algebraic structureStrong: (k+1)G = kG + GIdeally hidden

Balanced histograms, ~50% bit frequencies and ≈0 Pearson correlation are sanity checks, not security proofs. Security of k → kG rests on the difficulty of the elliptic-curve discrete logarithm problem — a different assumption from hash-function design. “Output changes completely” does not make scalar multiplication a hash: the coordinates may look pseudorandom while the group relation stays exact.