A Steel Plate in the Safe
Families who can't recover a holder's bitcoin often find the hardware and never find the map. What a recoverable Bitcoin inheritance looks like from the family's side, and why multisig alone doesn't supply it.
The scene below is a composite, assembled to show the shape of a common failure. It is not one family's story.
A long-time bitcoin holder dies. The family knew there was "some bitcoin." Some of them suspected it was a lot. None of them knew where it was, or what to do.
After the funeral, the surviving spouse opens the home office. There is a hardware wallet in the desk drawer and a second one still in its box. There is a steel plate in the safe, etched with twenty-four words. There are sticky notes with strings of letters and numbers. There is a USB drive labelled "Sparrow backup." There is a notebook of what look like passwords, half of them crossed out.
None of it means anything to the spouse, who has heard the words "seed phrase" and "private key" and could not say whether they are the same thing. The lawyer handling the estate knows real estate and probate. The lawyer does not know bitcoin.
The family does what families do. They search online. They post in forums. They answer messages from people who call themselves bitcoin recovery experts, and most of those messages are scams. The few honest helpers can't say much without seeing the objects, because no two recoveries look the same.
Six months later, nothing has been recovered. The family is no longer sure there is anything to recover, or whether the holder sold it years ago. The steel plate sits in the safe. The hardware wallet sits in the drawer. The funds, if they exist, sit on the blockchain where nobody can move them.
This is the failure families should fear most: not an exchange hack or a stolen seed, but the ordinary, irreversible one. A holder who never wrote down a recoverable plan, and a family that learned about the bitcoin only after the holder was gone.
Nobody knows how often it happens, because the coins don't announce themselves. Chainalysis estimated in 2017 that 2.8 to 3.8 million bitcoin may already be permanently lost, but that range includes Satoshi's coins and cannot separate forgotten passwords from holders who died without a plan.
The instinct that makes it worse
When most holders think about inheritance, they think about secrecy.
"I don't want my brother to know how much I have."
"My kids aren't ready to know about this yet."
"If my spouse knew the seed phrase, that would defeat the point of self-custody."
These instincts are not wrong. Bitcoin's value to its owner depends on the owner controlling access, and sharing access is, in a real sense, sharing ownership. Holders who have been doing this for a decade are right to be cautious.
The trouble starts when secrecy is the only instinct. A holder who optimizes purely for "nobody can take this from me while I'm alive" ends up with a system nobody can recover after they're gone. The property that defends against theft is the same property that defeats inheritance.
The fix is to add a second instinct alongside the first. The privacy instinct says: don't put the seed phrase in someone else's hands. The recoverability instinct says: put the map to the seed phrase in someone else's hands. The seed gives access. The map gives only the knowledge that a process exists and where it starts.
A well-designed inheritance plan never requires handing a seed phrase to a family member. It also never requires a family member to know what a seed phrase is.
What the family should find
The clearest way to describe a plan is from the family's side: what they encounter, in order, on the day they need to act.
First, they know a document exists. They don't know its contents. They know its location: a sealed envelope in a place they can reach without a court order. That might be a home safe whose combination a trusted person knows, a safe deposit box they co-own, or an attorney holding it with the will.
Second, they open it and can read it. It is written in plain language and assumes no technical knowledge. Roughly: "If you are reading this, I am no longer able to act. This explains how to recover the bitcoin I held. You don't need to be technical. You will need to bring certain objects together. Here is the list, here is the order, and here is the person to call."
Third, it points to physical objects that work only in combination. No single object is the wallet. No single person on the list can recover it alone. Object A is in one place, known to one person; object B is in another, known to someone else; recovery needs both, or two of three. One person being unavailable doesn't break the recovery. One object being lost doesn't break it either.
Fourth, it names a technical helper. A friend who is comfortable with bitcoin, or a paid specialist, who can be called once the objects are gathered to walk the family through the restoration. The helper holds none of the objects and can't recover the funds without the family. The family can't finish without the helper.
Fifth, it says what not to do. Don't photograph the contents. Don't type them into a computer except as the named helper instructs. Don't show them to anyone outside the list. Don't panic if the first attempt doesn't match; there is a troubleshooting page at the back.
That is the whole structure. It isn't exotic and it isn't technically demanding. It is written down, and the people who will need it know it exists.
It doesn't exist by default because writing it forces the holder to admit something uncomfortable: they will not always be the one operating the wallet. The plan is partly a confrontation with mortality, and holders avoid the confrontation by avoiding the plan. The wallet keeps working, and the day it matters stays a future problem until it isn't.
Multisig is part of the answer
In Bitcoin circles, the standard answer to inheritance risk is multisig: a wallet that needs several keys to spend instead of one.
It is a real improvement. A 2-of-3 wallet with keys held by you, your spouse and a third party (a lawyer, a collaborative-custody company or a trusted friend) means no single loss breaks the recovery. If you die, your spouse and the third party can still sign. If your spouse dies first, you and the third party can.
I didn't always think this way. For years I was convinced that holding every key yourself was the only serious way to hold bitcoin. I changed my mind, and I now believe a well-designed multisig, with one key held by an accountable institution, is the stronger setup for most families.
But multisig doesn't remove the need for the map, for two reasons.
First, it adds steps a non-technical family can't navigate alone. The plan still has to exist, still has to be written down, and still has to point the family to objects and a helper. Multisig changes the recipe; it doesn't remove the need for one.
Second, it's a setup decision that has to be made before it's needed. A holder who has been on a single key for ten years may never get around to migrating. The same procrastination that prevents writing the plan prevents the better architecture. By the time the family needs the multisig, it's too late to set it up.
Inheritance is a documentation problem before it is a wallet problem. Whatever architecture sits underneath, the family needs a written plan they can act on.
Three ways a plan fails
It was started but never finished. The holder bought a guide, got to step two and stalled. What exists is a half-written document somewhere, which can be worse than nothing, because it gives the family a misleading map.
It was finished but never shared. The holder wrote everything down, and the document is excellent. It's in a folder on a laptop nobody else knows about. The family inherits the laptop, but it's encrypted, and the password lived in a password manager whose master password died with the holder.
It was shared but never tested. The holder told the spouse where the document was. Five years passed. The document moved. The spouse doesn't remember exactly where, and asking now feels morbid.
The fix for all three is the same: the plan isn't done until you have rehearsed the family receiving it. Not the contents, just the act of finding the document. Once a year, on a fixed date, tell your designated person where it is. Ask them to describe the location back to you. Write the date in the document. Re-seal it if anything has changed. Thirty minutes a year.
The conversation
No plan substitutes for one conversation, with the person who will be primarily responsible for acting on it.
The conversation isn't about bitcoin. It's about you not being there. It goes roughly like this:
"I want to tell you about something I've set up. There is a document, and it's in [location]. If something happens to me, if I'm incapacitated or I die, it explains what to do. You don't need to do anything now. You only need to know it exists. The contents are sealed. There's a name in it of someone to call, and they'll help you. You don't need to learn anything about bitcoin today. I'm telling you because the plan isn't complete until you know it exists."
It is an awkward conversation. A family that has heard it once has somewhere to start. A family that hasn't starts by guessing.
Where to start
Pick a date this month. Block thirty minutes. Write the first draft of the recovery letter, the one the person acting in your place will read.
You don't have to get it right the first time. The first draft is the hard one. The second is editing. The tenth, years from now, is the annual review.
If your family opened the safe tomorrow, what would they find first: the steel plate, or the letter that explains it?
The keys protect your bitcoin from everyone else. Only the map protects it from your absence.
Sources
- Fortune, 25 November 2017, reporting Chainalysis's estimate of 2.78 to 3.79 million BTC lost.
Disclosure: I am one of the advisers at The Bitcoin Adviser, which offers collaborative multisig custody. This essay does not recommend any provider.