The question that finally made me sort out my own setup was blunt. If you died tonight, could your family actually move your coins within a year, without a miracle and without hiring someone shady off a forum? For most people who self-custody, the honest answer is no. We spend enormous effort making sure nobody else can ever touch our keys, and that effort works exactly as intended when the person who dies is us. Hardware wallets, passphrases, steel plates hidden in places only we know about. All of it turns into a vault with no door the moment we are not around to explain it.
Exchange accounts are survivable. An heir with a death certificate and the right letters from a probate court can eventually get an exchange to release funds. It is slow and painful, but it happens, because there is a company on the other end with a legal department and a process. Self-custodied coins have no counterparty to appeal to. There is no reset flow, no support ticket, no court order that can compel a blockchain to do anything. Whatever plan exists has to be built by you, in advance, while you are alive and thinking clearly. And the most obvious plan, writing the seed phrase into your will, has a flaw that only shows up when it is far too late to fix.
Why the seed phrase can never go in your will
The instinct makes sense. The will is the official document about what happens when you die, so put the recovery phrase there. Except that when a will goes through probate, it typically becomes a public court record. In most jurisdictions, anyone can request a copy. Your twenty four words would sit in a courthouse file, readable by clerks, by contested relatives, by anyone who bothers to ask, and a seed phrase behaves like bearer cash. Whoever reads it first can spend it, and the chain will not check whether that person was named in the document.
There is a timing problem too. Probate takes months, often longer, and between the filing and the distribution the phrase is live. Even if only honest people ever see the will, every additional pair of eyes is another uncontrolled copy of something that moves money with no second factor. So the split I use is simple. The will says who gets the crypto assets, described generically, and points to a separate mechanism for how access actually happens. Secrets and legal documents live in different places, always. Once you accept that split, the real question becomes what the separate mechanism should be, and there are three families of answer worth taking seriously.
Three setups that work, and what breaks each one
Sealed instructions are the simplest. You write down the seed phrase, the passphrase if one exists, and step by step recovery instructions plain enough for a stressed non-technical person, then you seal the package somewhere your executor can reach after your death but strangers cannot. A home safe plus a duplicate in a second location, or a lawyer's vault. It costs almost nothing and any heir can follow it. The weakness is static exposure with no alarm. If the envelope is ever opened, photographed, or copied, nothing tells you, and the funds can be swept years later without warning. Bank safe deposit boxes add their own trap, since in many places the box is sealed when the holder dies and opening it needs the same court paperwork your heirs are still months away from getting. If you go this route, keep two geographically separate copies, check the seals on a schedule, and never label the envelope with what it contains.
Multisig with a trusted third key is what I lean toward for anything meaningful in size. A 2-of-3 wallet where you hold two keys in separate locations and a third party holds one. The third key alone can do nothing, so the lawyer, the collaborative custody service, or the technical friend holding it never has unilateral power over your funds. After your death, an heir combines the key they inherit with the third party's key and moves everything. Nobody ever holds a complete secret, so there is no envelope that quietly compromises the whole stack. The catch is operational and it is bigger than people expect. Recovering a multisig wallet takes more than the keys. You also need the wallet configuration, the descriptor or the full set of extended public keys that tells the software how the wallet is put together. People back up three seeds diligently and still lose coins because nobody kept the descriptor. Back that file up everywhere, since it is not spendable on its own. The other catch is that your heirs will need to drive wallet software under stress, which only works if someone in the plan is technical. That person does not have to be the beneficiary, and usually should not be.
Dead-man switch services sit at the far end. You check in on a schedule, and if you go quiet for long enough, the service releases a message to a designated person. The idea is sound, and the implementations make me nervous anyway. You are betting that a small company will still exist in fifteen years, that its infrastructure never gets breached, and that the trigger does not fire while you are on a long trip somewhere without signal. My rule for these is to never let the switch carry the secret itself. Let it release the location of your sealed instructions, or the name of the lawyer holding the third key, plus contact details for your technical helper. A false trigger or a breach then leaks a map instead of the money, and if the service dies quietly, your underlying mechanism still works on its own, which it needed to do anyway.
The plan I would actually run
If I were starting from zero, the sequence would look like this.
- Write an inventory letter with zero secrets in it. What exists, roughly where it lives, which wallets and which exchanges, and who to call for help. Store it with your estate documents, where it can safely become public because it contains nothing spendable. If you already track your positions across wallets and exchanges in one place, in Blockcircle or anywhere else, that asset list mostly writes itself.
- Pick one access mechanism and build it deliberately. Sealed instructions for smaller holdings, 2-of-3 multisig once the number gets serious, a dead-man switch only as a notification layer on top.
- Back up the wallet metadata along with the keys. Descriptors, extended public keys, derivation paths for anything nonstandard, and a note that a passphrase exists if one does.
- Name a technical helper and tell them they have the job. The best setup on paper fails if the person executing it is grieving, non-technical, and alone.
- Run a recovery drill once a year and after any wallet change. Pretend you are your heir, take only the materials they would actually have, and try to recover a small test amount. Every gap you find in the drill is a gap that would otherwise be found by someone who cannot ask you questions.
The failure mode I would flag hardest is the hidden passphrase. If you use a BIP39 passphrase, the so-called twenty fifth word, the bare seed opens a decoy wallet that looks empty. An heir who recovers the seed perfectly will see a zero balance, decide the crypto stories were exaggerated, and walk away from real money that was one missing word deep. Document that the passphrase exists even if you store the passphrase itself somewhere else entirely.
None of this is enjoyable to set up, and the annual drill is tedious enough that I understand why almost nobody does it. But the whole package costs roughly a weekend once and an hour a year after that, against a downside where everything you were careful about ends up permanently stranded on-chain in full public view. I would start with the inventory letter, since it forces no security decisions at all, and let the rest follow from there.