← All articles

What is a wallet address and who sees it

Published: September 29, 2026

A wallet address is the string you give someone so they can send you coins. It is safe to hand out in one specific sense — nobody can spend your money just by knowing it — and it is not private in any sense at all. Anyone who has your address can look up your balance, every payment you have ever received and every payment you have made from it, for as long as the chain exists. Both of those facts are true at once, and most explanations stop after the first one.

This page covers what the address is, where to find yours, what a stranger learns the moment you send it to them, and what you can still do about it afterwards. We run notrace.exchange, a mixing service, so the last two sections are about where a service like ours does and does not help.

A wallet address: safe to share because nobody can spend from it, not private because anyone who has it reads your balance and every payment

What a wallet address actually is

Every wallet is built on a pair: a private key that signs payments, and a public key derived from it. The address is derived from the public key in turn, by a one-way hash. That direction matters. The key produces the address, the address cannot produce the key, and the whole security of the arrangement rests on that being a one-way street.

On Ethereum the recipe is written down plainly in the developer documentation: an account address is made by "taking the last 20 bytes of the Keccak-256 hash of the public key and adding 0x to the beginning". That is why every Ethereum address is 42 characters long — the 0x plus 40 hexadecimal digits.

Bitcoin has several formats, added at different times, and you can tell them apart by how they start. Addresses beginning with 1 are the original pay-to-public-key-hash type. Those beginning with 3 are pay-to-script-hash. Those beginning with bc1 are the newer bech32 format. All three are ordinary Bitcoin addresses; a wallet that understands the format will pay any of them.

Two practical consequences follow from this, and both cost people money regularly.

  • An address belongs to one chain. The same ticker often lives on several networks, and each has its own address format. Sending to an address that belongs to a different chain than the one you selected is one of the most common ways to lose a transfer permanently, because there is usually nobody who can reverse it.
  • The address is not a password. There is nothing to protect about it in the theft sense. What needs protecting is the private key or the recovery phrase behind it, and no legitimate service will ever ask you for those.

Where do I find my wallet address?

In a self-custody wallet, it is behind the button marked Receive. In an account on a service, it is on the deposit screen, and there it usually belongs to the service rather than to you — which is a distinction worth keeping in mind, because it means the service can see everything that arrives there.

Most modern wallets will hand you a fresh address every time you ask, and keep the old ones working. That is not a quirk. It is the single most useful privacy habit available to an ordinary user, and the reason is in the next two sections.

Is it safe to give out a wallet address?

Against theft, yes. Someone holding your address cannot sign anything, cannot move a coin, and cannot do anything to your balance at all. Whoever you hand it to is only being given the ability to pay you.

Against being watched, no — and this is where the usual answer stops too early. A public ledger is a permanent, searchable, public record. From one address a stranger can pull up, in a few seconds and with no special tools:

  • the balance, right now;
  • every payment ever received, with amounts and timestamps;
  • every payment ever sent from it, and the addresses on the other end;
  • the pattern — how often you transact, in what sizes, at what hours of the day, and therefore roughly where in the world you probably sleep.

That last one is worth sitting with. You have not told them anything. They looked up one string you typed into a chat window.

There is also a much more ordinary problem with reusing one address, and the Bitcoin Wiki spells it out for merchants: if everyone pays you at the same address, then "a malicious agent Bob could see that same transaction and send you an email claiming that he paid". When the address is shared, you lose the ability to tell who actually sent what.

What a stranger can work out on top of that

Reading one address is only the first step. The techniques that turn a set of addresses into a person are well developed and are used routinely by analysis firms and law enforcement — is Bitcoin traceable goes through them properly, but the short version matters here.

Addresses get grouped. If a single payment spends coins from several of your addresses at once, that is taken as evidence they all belong to one owner, and they get merged into one profile. Do that a few times and a stranger is no longer looking at an address; they are looking at your wallet.

Then the profile gets a name attached, usually not on the chain at all. It happens when one of those addresses touches a service that knows who you are, when you post an address publicly, or when you send it to someone who keeps records.

And an address you published is a hook other people can use. Tiny unexplained amounts arriving at your address are sometimes exactly that — a dusting attack, where the dust is sent specifically so that spending it will link your addresses together for whoever sent it. The defence is simply not to spend it.

A new address for every payment, and what it still does not fix

The standard advice is the right advice. The Bitcoin Wiki puts it as plainly as anyone: "people have many different Bitcoin invoice addresses and for privacy and security reasons a unique invoice should be used for each transaction."

But it is worth knowing the limit of that habit, because it is often oversold. A fresh address per payment stops the laziest kind of watching — it does not stop the grouping described above. The moment you make a payment that draws on coins sitting at two of your fresh addresses, those two are linked anyway. Change works against you in the same way: pay 0.3 from an input of 1, and the remaining 0.7 comes back to an address of yours that is now tied to the payment you just made.

This is why techniques exist that go further, and why they involve other people. A CoinJoin builds one transaction with many participants and equal outputs, so that the link between a particular input and a particular output stops being readable. A mixing service does something related by a different route, and the two words for it — tumbler and mixer — mean the same thing.

When the address is already public

Some addresses cannot be kept quiet. A donation address on a website, an address in a forum signature, one you gave a client on an invoice, one printed in a contract — those are public for good, and no habit adopted afterwards will retract them. The realistic question is not how to undo it but what happens next.

Two things are worth being clear about.

What is already on the chain stays there. No service, ours included, can remove or rewrite a transaction that has been recorded. Anyone telling you otherwise is selling something that does not exist.

What can change is what happens after that point. If coins move on in a way that does not draw a straight line from the published address to where they end up, then the published address stops being a live feed and becomes a historical record. That is the whole of what a mixing service does, and it is worth stating in those narrow terms rather than the usual ones.

Where we stand

notrace.exchange is a custodial service: while a payout waits, the funds are held by us, and section 8 of the terms says so rather than implying otherwise. What the service does with an address you give it:

  • the payout leaves as two transfers to two addresses you name, each with its own delay; on 29 September 2026 each delay could be set from zero to 6 hours, and a transfer leaves no earlier than the delay you chose;
  • the payout can be in the same coin or in another one — taking it in another coin is what changes the asset and the amount, because the same coin keeps both;
  • each order comes with a letter signed with our PGP key, naming what you send, the least you will receive, both addresses and both delays;
  • our fee on 29 September 2026 was 0.5% and it is the only thing we add to the quote; the current figure is on the FAQ page.

The honest limit is the one above: this changes what a watcher can follow forward from a known address. It does nothing about the history already written, and it is not a reason to publish an address you would rather keep quiet.

Where to start

If you only take one habit from this page, take the fresh-address one — it costs nothing and it is the default in most wallets already. If you want to understand how a chain gets read in the first place, is Bitcoin traceable covers the methods and the cases where they were used. If an address of yours is already public and you want the payout split across addresses and time, the bitcoin mixer page opens the form with its current minimum, and the checks in how to choose a bitcoin mixer apply to us as much as to anyone else.

Share: