Recommended Free Tools
For a Java application, use a maintained Bitcoin library such as bitcoinj to generate and encode addresses instead of implementing Bitcoin’s cryptography and address formats yourself. The example below uses bitcoinj 0.17.1 and testnet. It creates a standalone key and derives legacy and native SegWit addresses; it is a learning example, not a recoverable production wallet. For real funds, use a properly backed-up hierarchical deterministic (HD) wallet and never log its secret material.
What a Bitcoin address represents
A Bitcoin address is a human-readable encoding of a payment destination. It is not a wallet, does not contain funds, and does not reveal the private key needed to spend funds sent to it. A simplified key-based flow is:
Secure randomness → private key → public key → hash or witness program → network-specific address
That shorthand does not describe every address type. Legacy P2PKH addresses encode a hash of a public key, while script-based outputs encode script-related data. Taproot addresses encode a tweaked output key. A wallet manages keys and the information needed to find and spend funds; an extended key can derive a hierarchy of related keys, while a seed or mnemonic can be used to restore that hierarchy when the wallet standard and settings match.
#1 Best Overall
- BITCOIN EXCLUSIVE, PHONE VERIFICATION: Bitkey is designed from the ground up exclusively for bitcoin — a dedicated hardware wallet for secure bitcoin storage. Approve transactions with a tap using your phone and NFC. No device screen is required.
- SELF-CUSTODY, NO EXCHANGE OR CUSTODIAN REQUIRED: You hold two of the three keys in the Bitkey system – one on your phone and one on your Bitkey device. The third is stored on Bitkey’s server and cannot move your bitcoin on its own.
- NO SEED PHRASE: Set up and use Bitkey without creating or storing a seed phrase.
- 2-of-3 MULTISIG: Three keys are stored separately across your phone, Bitkey device, and Bitkey’s server. Any two keys are required to move your bitcoin.
- BUILT-IN RECOVERY: Encrypted backup and recovery tools can help you regain access if you lose your phone or Bitkey device. You can also designate a Recovery Contact.
Choose an address type
For a conventional new single-key receiving flow, native SegWit P2WPKH is a sensible starting point if the recipient’s wallet supports it. Choose another format when compatibility or a specific wallet policy requires it.
| Type | Mainnet form | Testnet form | When to use it |
|---|---|---|---|
| Legacy P2PKH | Usually starts with 1 |
Often starts with m or n |
Older software requires it. |
| Nested SegWit P2SH-P2WPKH | Usually starts with 3 |
Often starts with 2 |
Compatibility with software that does not accept native SegWit. |
| Native SegWit P2WPKH | Starts with bc1q |
Starts with tb1q |
General-purpose single-key receiving with modern wallets. |
| Taproot P2TR | Starts with bc1p |
Starts with tb1p |
When the full application and wallet ecosystem support Taproot. |
Prefixes are a quick clue, not a complete validation method. The receiving software must support the address type, and the address must belong to the intended network. Bech32 is used for native SegWit version 0; Bech32m is used for SegWit version 1 and later, including Taproot. See BIP173 and BIP350.
Why use bitcoinj
Address generation involves more than formatting a string. Correct implementations must handle secp256k1 key generation and public-key serialization, hashes, checksums, network parameters, and the rules for each address format. Taproot adds key tweaking; HD wallets add derivation rules. A defect can create an address that looks plausible but does not represent the payment destination you intended.
bitcoinj is a Java Bitcoin library with address, wallet, protocol, and cryptographic abstractions. It is provided without a warranty, so pin and review the dependency, test your integration, and conduct an appropriate security review. For projects that implement encodings or derivation themselves, use standards and their test vectors rather than relying on a hand-written example; the BIP repository indexes the relevant specifications.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Set up the Java project
The example pins bitcoinj 0.17.1, the artifact version visible in the cited Maven Central listing. Check the listing and release notes before deploying, since versions can change. The artifact declares its dependencies, so avoid adding arbitrary cryptography-provider versions without a specific compatibility reason.
Rank #2
- Unparalleled Security: Protect your assets NDA-free EAL 6+ Secure Element, offering robust defense and complete transparency
- Simple & Secure Interface: Manage your digital assets easily with a clear OLED screen for secure on-device confirmations
- Supports 1000s of Coins & Tokens: Securely handle thousands of assets, including Bitcoin, Ethereum, and more, all in one wallet
- Effortless Asset Management: Monitor and transact seamlessly with Trezor Suite, our intuitive desktop and mobile app
- Enhanced Backup Solution: Rest assured with Multi-share Backup, eliminating single points of failure for secure cold wallet recovery
Maven
<dependency>
<groupId>org.bitcoinj</groupId>
<artifactId>bitcoinj-core</artifactId>
<version>0.17.1</version>
</dependency>
Gradle
dependencies {
implementation("org.bitcoinj:bitcoinj-core:0.17.1")
}
JDK requirements depend on the module and use case: the project documents Java 8+ support for its base and core modules, Java 17+ for several tools and examples, and Java 25+ for its JavaFX wallet template. Check the project documentation for the requirements that apply to your chosen version and module; a build requirement is not automatically the same as a runtime requirement.
Generate testnet addresses from a random key
This version-qualified example generates a fresh key with bitcoinj’s secure randomness, then derives one legacy and one native SegWit address. It deliberately uses testnet. Keep the private-key print statement out of real applications; it is included only to make the secret-versus-address distinction visible.
import org.bitcoinj.base.BitcoinNetwork;
import org.bitcoinj.base.LegacyAddress;
import org.bitcoinj.base.SegwitAddress;
import org.bitcoinj.crypto.ECKey;
public class GenerateBitcoinAddresses {
public static void main(String[] args) {
BitcoinNetwork network = BitcoinNetwork.TESTNET;
ECKey key = new ECKey();
LegacyAddress legacyAddress = LegacyAddress.fromKey(network, key);
SegwitAddress nativeSegwitAddress = SegwitAddress.fromKey(network, key);
System.out.println("Legacy address: " + legacyAddress);
System.out.println("Native SegWit address: " + nativeSegwitAddress);
// Demonstration only: never log or expose this in a real application.
System.out.println("Private key: " + key.getPrivateKeyAsHex());
}
}
The printed address strings should have testnet forms, not mainnet forms. Exact package names and API signatures are version-sensitive: bitcoinj 0.17 introduced package and API changes, so compile against the pinned release and consult its release notes if adapting older code. The example creates two encodings for the same key; it does not create a wallet with seed-based recovery, address rotation, or backup.
Use mainnet only by deliberate choice
When an application is ready to handle real payments, choose BitcoinNetwork.MAINNET explicitly and verify that the surrounding wallet, payment flow, and address validation all use mainnet. Keep test fixtures and testnet funds separate from production workflows. Testnet addresses are not mainnet destinations, and changing network parameters is not a way to convert one address into another. bitcoinj’s getting-started guide covers network-aware address use and recommends testnet or regtest for development.
Use an HD wallet for production
A standalone random key gives you a key and its corresponding addresses, but not the recovery and address-management features most production applications need. An HD wallet derives a tree of keys from a seed, enabling repeatable address sequences, change addresses, and wallet recovery. bitcoinj describes deterministic keys and receiving-address behavior in its wallet documentation.
Rank #3
- Unparalleled Security: Protect your assets with EAL 6+ Secure Element, offering robust defense and complete transparency
- Simple & Secure Interface: Manage your digital assets easily with a clear OLED screen for secure on-device confirmations
- Supports 1000s of Coins & Tokens: Securely handle thousands of assets, including Bitcoin, Ethereum, and more, all in one wallet
- Effortless Asset Management: Monitor and transact seamlessly with Trezor Suite, our intuitive desktop and mobile app
- Enhanced Backup Solution: Multi-share Backup eliminates single points of failure for secure cold wallet recovery
Address derivation conventions specify both a script type and a path. The following are common first external receiving-address paths for mainnet; the final 0 is address index zero:
| Purpose | Address type | Mainnet path | Usual appearance |
|---|---|---|---|
| BIP44 | P2PKH | m/44'/0'/0'/0/0 |
1... |
| BIP49 | P2SH-P2WPKH | m/49'/0'/0'/0/0 |
3... |
| BIP84 | P2WPKH | m/84'/0'/0'/0/0 |
bc1q... |
| BIP86 | Single-key P2TR | m/86'/0'/0'/0/0 |
bc1p... |
For testnet, the conventional coin-type component is 1' rather than 0'; for example, a BIP84 path begins m/84'/1'/0'/0/0. These are standards-based conventions, not interchangeable labels. Details are in BIP44, BIP49, BIP84, and BIP86.
Free tools Windows power users keep installed
One-click scans. No signup required.
The same seed can lead to different addresses if the wallet uses a different passphrase, network, script type, derivation path, account, branch, or index. A restore using the wrong path can appear empty even when funds exist. Bitcoin Core’s wallet-management documentation discusses seeds and common derivation paths. Record the wallet’s recovery details with the seed backup, and test restoration in an isolated environment.
- Mnemonic or seed backup
- Passphrase, if one is used
- Network and script type
- Derivation path and account number
- External receiving or internal change branch, and address index
A BIP39 passphrase cannot be reset like an account password; a different passphrase derives a different wallet. Store it with the same care as other recovery secrets.
Validate an address before using it
Validation should establish that the address has valid syntax and checksum, belongs to the expected network, and uses a type supported by the receiving flow. It does not prove that the person who supplied the address controls its private key. If control must be demonstrated, use a signed challenge or another appropriate proof-of-control flow.
Rank #4
- Dual-chip architecture for maximum protection: The next-gen, fully auditable TROPIC01 chip works alongside a certified EAL6+ Secure Element—completely NDA-free—to deliver radically transparent, industry-leading defense against physical attacks.
- Quantum-ready security: Get protection against future threats with the first-ever hardware wallet designed with quantum-ready architecture.
- See every detail with confidence: Our largest high-resolution color touchscreen makes it easy to navigate your assets, review transactions and manage your coins with clarity.
- Wireless freedom with encrypted Bluetooth control: Manage, buy, swap and stake securely using Trezor Suite on desktop or mobile. Qi2-compatible wireless charging keeps your Trezor powered up. No cables required—security meets convenience.
- Works seamlessly with Android, iOS and desktop: Connect wirelessly or via USB-C to your phone or computer. Manage your crypto anywhere with our companion Trezor Suite app.
bitcoinj’s release notes document network-aware validation methods, including BitcoinNetwork.isValidAddress(Address) and checkAddress(Address). Parsing APIs can vary across releases, so use the selected version’s Javadocs. A version-specific parsing pattern for a SegWit address is:
String text = nativeSegwitAddress.toString();
try {
SegwitAddress parsed = SegwitAddress.fromString(network, text);
System.out.println("Valid address: " + parsed);
} catch (IllegalArgumentException ex) {
System.err.println("Invalid or wrong-network address: " + ex.getMessage());
}
For a payment integration, also confirm that the destination’s supported script type matches the address you intend to use. A valid checksum alone does not establish that compatibility.
Protect private keys and recovery material
Anyone with the private key or wallet recovery material may be able to spend the associated funds. An address can generally be shared to receive a payment, but reusing it can reduce privacy. Never place private keys or seed phrases in source control, ordinary logs, email, terminal history, CI output, telemetry, or error reports. Avoid converting secrets into immutable Java String objects unnecessarily, since they cannot be explicitly cleared.
- Use cryptographically secure randomness or a standards-compliant wallet seed. Never derive a private key directly from a username, timestamp, UUID, password, or other predictable input.
- Encrypt private material at rest and restrict access. For higher-risk applications, evaluate an HSM, hardware wallet, secure enclave, or dedicated key-management system.
- Back up recovery material and test restoration in an isolated environment before relying on it.
- Treat any exposed key as compromised and move funds to a new, securely generated wallet.
Online key or mnemonic generators are unsuitable for real funds: the browser, extensions, device, malware, or service operator may expose the secret. Production key generation should happen in an appropriately controlled, audited environment.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Test the integration and diagnose common failures
Use testnet for interoperability testing and regtest for controlled local integration tests. Regtest is a private Bitcoin network on which blocks can be generated locally; see the bitcoinj getting-started guide. A local Bitcoin Core node can support end-to-end wallet and transaction testing.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsBest Value
- Effortlessly build your crypto portfolio via the all in one Ledger Wallet app: buy, sell, send, receive, swap, stake and more across popular blockchains. 15,000+ coins & tokens in a single dashboard. Keep a close eye on the market. Compare service providers. Track performance. Get timely alerts. Build your portfolio with confidence.
- Effortlessly build your crypto portfolio via the all in one Ledger Wallet app: buy, sell, send, receive, swap, stake and more across popular blockchains. 15,000+ coins & tokens in a single dashboard. Keep a close eye on the market. Compare service providers. Track performance. Get timely alerts. Build your portfolio with confidence.
- Enjoy Bluetooth connectivity, iOS access, and hours of battery use with this mobile-first, secure backup signer. Freedom you can depend on.
- Genuine Check: confirm your signer is authentic during setup with the Ledger Wallet app.
- Protect your signer: keep it in mint condition at all times with a bespoke Pod or Case to avoid scratches and everyday wear and tear.
Minimum test coverage
- Generate multiple random keys and verify that their derived addresses differ.
- For an HD wallet, restore the same seed with the same settings and verify identical addresses at the same indices.
- Check that mainnet and testnet encodings differ, and reject an address for the wrong network.
- Accept valid addresses and reject malformed checksums.
- Test each supported format separately, including Taproot only if the selected library version and full payment flow support it.
- Test receiving indices, later indices, and change addresses separately.
- Restore from the backup in an isolated test environment.
For custom implementations, use standards-based vectors for BIP32, BIP39, BIP44, BIP49, BIP84, BIP86, BIP173, and BIP350 where applicable. Avoid treating address-prefix checks as a substitute for checksum and network validation.
Wrong network
An address may be rejected or encoded for testnet when mainnet was expected because the application selected the wrong network. Select the intended network at derivation and parsing time; do not attempt to convert the string. Never send mainnet funds to an address generated for testing.
Lost standalone key
If a program discarded its random private key and no wallet backup exists, the address cannot be used to recover it. A blockchain explorer cannot reconstruct a private key. This is why the example is unsuitable as a complete production wallet.
Wrong format or derivation path
A payment service may reject an unsupported address type, or a restored HD wallet may show no funds if its path or script type does not match the original. Verify the network, address type, derivation path, account, branch, and index against the wallet that created the address.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Address reuse or weak key generation
Repeatedly presenting one receiving address can make payments easier to link and complicate accounting. Derive fresh receiving addresses where practical and retain an internal mapping to the relevant invoice or customer. Never substitute a password or predictable application data for wallet entropy.
Manual encoding defects
Common implementation mistakes include losing leading zero bytes in Base58Check, using the wrong network version, serializing the wrong public-key form, applying Bech32 instead of Bech32m for Taproot, or mishandling witness-version rules. Use a maintained library for production address handling and test any custom code against BIP173 and BIP350 specifications and vectors.
Quick Recap
Production readiness checklist
- Pin and review the library version; check current project release notes and dependency advisories.
- Use secure entropy and a recoverable HD-wallet design rather than an unbacked standalone key.
- Make network and script type explicit, and test compatibility with the receiving wallets and services.
- Record derivation metadata, protect and back up recovery secrets, and verify restoration.
- Do not log secrets; define access controls and key rotation or incident procedures.
- Use fresh receiving addresses where practical and preserve the mapping needed for payment reconciliation.
- Keep ownership proof separate from address syntax validation.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




