Blockchain & Digital Assets / Bitcoin Transaction

What you will do: Run nine steps: generate the source key, extract its public key, create the source address, generate a recipient key and address, format the transaction, visualize the message, sign it and verify the signature.

Worked example: Format a 0.5 BTC transfer with a 0.0001 BTC fee between the two generated addresses, sign it with secp256k1 ECDSA, and Verify Signature reports VALID against the sender's public key.

Runtime and privacy: The cryptographic exercise runs in this browser. Review the site privacy terms before entering sensitive material; use synthetic inputs for learning and evaluation.

Browse all Crypto Lab tools · Learn with Digital Assets

For your role

Developer / Engineer
Walk the nine steps from Generate Source Key: the secp256k1 key is created inside the softhsmv3 token, and each step explains the transaction structure being built and signed.
Researcher / Academic
The Shor's Algorithm note on the first step is the threat model; follow the steps to see which values in a transaction expose the public key and when.

Initializing SoftHSM…

C_Initialize → C_InitToken → C_OpenSession → C_Login

Educational demo — keys and transactions generated here are not for production use.

STEP 1 OF 9

1. Generate Source Key

Generate a key pair for the sender inside SoftHSMv3 (PKCS#11 via WebAssembly). The private key is a 256-bit scalar (32 bytes) generated by the HSM's internal CSPRNG and never leaves the token. Note: breaks secp256k1 — this algorithm will require migration when a cryptographically relevant quantum computer (CRQC) arrives.

Private Key
secp256k1 curve
Public Key
Compressed (33 bytes)
SHA-256
First hash
RIPEMD-160
Second hash
Base58Check
With checksum
Address
1... (P2PKH)
// Generate secp256k1 key pair inside the SoftHSMv3 token
const { pubHandle, privHandle } = hsm_generateECKeyPair(
  module, hSession,
  'secp256k1',
  false,   // extractable = false — private key stays in HSM
  'sign'   // usage: CKA_SIGN on private, CKA_VERIFY on public
)
TERMINAL OUTPUT
Click Execute to run this step.

Try it

In Generate Source Key, where does the secp256k1 private key live?

Next step

Turn it into a plan: Deployment Playbook

This tool practises the Digital Assets module, phase 5 (Pilots & Migration); Deployment Playbook produces a deliverable of that phase.

Next in Blockchain & Digital Assets