Skip to main content

Overview

DynamicEvmWalletClient::export_private_key returns the wallet’s raw 32-byte EVM private key as 0x-prefixed hex. The MPC export ceremony returns an xpriv; the SDK then derives the final private key at the wallet’s BIP-44 path.
Once exported, the raw private key bypasses MPC — any holder of the key can sign without your server’s involvement. Treat it as a one-way operation. Only use it for migration or disaster recovery, and rotate / abandon the wallet afterward.

Prerequisites

Export the Key

Verifying the exported key

The exported key should derive the same address as wallet_properties.account_address. With alloy:

Best Practices

  • Treat exports as a one-way operation — don’t use the same wallet through MPC after exporting; rotate to a fresh wallet.
  • Never log the key — redact it from all logs and error messages.
  • Zero memory after usezeroize::Zeroize the String once you’ve forwarded it to its destination.
  • Transport over TLS only — never send the key over an unencrypted channel.
Last modified on May 19, 2026