I guess the risk of Bitpay getting hacked is only a risk if they also store my private key somewhere. Im not talking about Bitpay the website, im talking about Bitpay the wallet which you download to your phone or computer.
Correct.
I dont know if Bitpay stores this info on their server or something.
I don't think they do. That said, hackers are clever. Its a possibility that someone can expose your key. Let's say, since you are self declared noobish, someone discovers this wallet is with bitpay. They could send a convincing email, that gets you to transfer your funds to a different wallet, since it was exposed (I won't get into how they would convince you so you don't get all confused).
If you moved them in the scenario I painted in my OP, you'd know for sure this was a scammer. If not, you might actually do what they say.
But if i understand it correctly, the wallet info is stored on your device. And if this is correct and is the case with Bitpay, then the only risk is your phone/computer getting compromised.
This is correct, including the example above for alternative risk exposures like knowing your wallet is associated with BitPay.
But say you export your key, and then format the computer, wipe everything from the hard drive, then that risk is no more. Right?
Similar to the above response, correct. That aspect is no more at risk. Still, the knowledge that your wallet is/was associated with BItPay is still a risk- you'd potentially be more averse to expose yourself, if someone used this information in the above example, but still remains a risk.
Reading about crypto in the last couple of days, i find that talk about "security" often overshadows simple answers to simple questions.
It definitely can. Security discussions are often conducted through
first principles thinking (from deep understanding to surface level functioning). Most folks are used to
first function thinking (the reverse surface level functioning to deep understanding). Your replies show you are understanding this from first function thinking. The people replying to you are often giving you first principle replies. The reason for such depth is to ensure you understand you can do what you are inquiring about no problem without assuming you can do something else with equal success (The same end result: your funds safe & still in your control- in your crypto bank account).
Otherwise, you may assume moving private keys = feeless movement of crypto, which can get you into trouble (i.e. losing your funds) when someone asks for it to initiate a feeless transaction & you send them your password (which your private key is). That would be made obvious, among many other dangerous assumptions, by clarifying what the private key, wallets, & interfaces are & how they function. Moving Private keys moves the wallet to the interface you decide, as you showed later in your replies.
Simple questions don't always come from clear understanding. And in this space, most folks (sharing the information) know that can cost you your funds quickly.
Like take this thread for example, the title i gave it:
"Moving bitcoin with private keys to avoid fees?"
The answer is (if im understanding correctly) that yes this is possible.
You have 2.123456 BTC on Bitpay, you export private key, you import it in Exodus, and now you have 2.12345 BTC on Exodus. Absolutely.
As the above section covered that, the summary is: For the one specific use case described (changing the interface you use to access your crypto), & others exactly like it, yes.
In crypto.
- You have a public key (email) and a private key (password). Anyone who has the password (private key) has access to your account (wallet) and can spend your money.
You never "export" or "import" your coins. When you enter your password (private key) in any website/app, you login into that account (wallet). So basically "import" = login. It's like opening your PayPal account.
Your friend is correct. If a website has your password (private key), they can login to your account (wallet). If a hacker breaks the website, the hacker can use all the accounts (wallets).
Your private key never changes. You can't change your password (private key). You can create another account (wallet).
--
EDIT: worth mentioning that some websites or apps automatically create multiple accounts (wallets) for you.
I double down on what's shared here. Your private key is all you need to login to your wallet, no public key necessary. That's the critical difference between crypto & a (insert bank) account login.
So the address/private key is the actual account/wallet/cryptos.
The wallet - Exodus Bitpay etc - isn't really important, but if they have your private key, they can pretty much take your cryptos. If anyone has them they can take your cryptos.
Your reply came in as I typed this. This is it. Obviously they made that clear they don't operate with your keys, & legit operators of wallet interfaces will confirm this with you.
So I'm not sure if what you said only happens for Bitcoin specifically, but at least this one time for Cardano everything remained the same.
Not every wallet interface creates new public (facing) keys to receive your crypto. Some do it by default, some don't find it necessary. Whether a wallet interface does this or not is a matter of optional crypto security built in to the interface. But this isn't really the thread dedicated to that aspect.