Skip to content
SpendTheBits

Recovery · 8 min read

Crypto Inheritance: Social Recovery vs a Hardware Wallet for Your Family

By Jay, Founder, SpendTheBits ·

In short

Crypto inheritance fails through silence, not theft. Chainalysis estimated in 2017 that between 2.78 million and 3.79 million bitcoin were already gone for good, and most of that was lost, not stolen [1]. A hardware wallet with a paper backup makes your heirs solve a puzzle: device, PIN, words and passphrase, all at once. A lawyer holding your seed is custody by another name. Shamir-style social recovery under SLIP-0039, which SpendTheBits uses, splits the secret into verifiable shares, so no single person, including you, is a point of failure. Add a dead-man's switch and your family has a route that opens only after real silence.

3.79M BTC
the high end of Chainalysis's estimate of bitcoin lost for good, 17 to 23 percent of the supply at the timeSource: Fortune (reporting a Chainalysis study)

Most people who worry about self-custody worry about hackers. The record says the bigger danger is quieter. In 2017 Chainalysis segmented the whole bitcoin supply by age and activity and concluded that between 2.78 million and 3.79 million coins were already lost, roughly 17 to 23 percent of everything mined [1]. Those coins were not taken. Their owners forgot a password, threw out a drive, or died without telling anyone where the keys were.

This piece is about that last failure. It compares the three ways families try to solve crypto inheritance, explains why two of them recreate the problem they are meant to fix, and ends with a plan you can finish in a weekend. Where SpendTheBits comes up, it is because we built social recovery and inheritance around exactly these failure modes.

Silence loses more coins than theft

The famous lost-key stories share one shape. Stefan Thomas was paid 7,002 bitcoin in 2011 for an explainer video, kept the keys on an IronKey drive, and lost the paper with the password; the drive allows 10 guesses before it encrypts itself for good, and he has used eight [2]. Nothing was stolen. One piece of paper went missing and a fortune became unreachable.

The QuadrigaCX collapse is usually told the same way. When founder Gerald Cotten died in India in December 2018, the platform said its cold wallets were unreachable, and over 76,000 clients were owed a combined 215 million Canadian dollars [3]. The Ontario Securities Commission later found that most of the 169 million dollar shortfall came from Cotten's own fraud, not lost keys [3]. But the line that matters for families comes earlier in the same report: from 2016 onward Cotten was in sole control of a company with hundreds of thousands of clients [3]. One person knew everything. When he went silent, nobody else could act, whatever the real cause.

That is the lesson for your own house. The question is not whether your keys are safe from a thief. It is whether anyone but you can reach them, correctly, on the worst day of their life, without a phone call to you.

One hardware wallet and a sheet of paper

A hardware wallet with the seed words on paper is the default advice, and it keeps a thief out. For crypto inheritance it is a chain of single points of failure. Your heir needs the device or the words, the PIN, the passphrase if you set one, and the knowledge of where all of it is. Miss one link and the chain is broken.

The PIN alone is a trap for a grieving family. Trezor's own documentation says the Model One, Model T, Safe 3 and Safe 5 reset and erase the wallet after 16 incorrect attempts, and the Safe 7 after 10 [5]. A relative who finds the device and starts guessing birthdays is racing a counter they do not know exists. The paper backup rescues them only if they know it exists, can find it, and know whether a passphrase sits on top.

The paper itself is fragile in ways that only show up years later. Ink fades, houses flood, a spring clean throws out an envelope. Our seed phrase backup guide covers the durable-medium fixes. None of them solve the real problem: one object, held by one person, is the only door.

A lawyer with your seed is custody by another name

The second approach is to hand the seed, or a sealed copy, to an estate lawyer or a safe-deposit box. It feels responsible. It also quietly turns self-custody back into custody, with a weaker custodian than the ones you left. A law firm is not built to protect a string of words that moves money with no signature and no court order. Staff turnover, office moves and burglary are ordinary events, and any one of them exposes everything.

The bigger issue is timing. A seed in an envelope is live from the day it is written. If it leaks, the money is gone while you are alive, and you may not learn it for months. A crypto inheritance plan should give heirs nothing usable today and everything usable when needed. Envelopes cannot tell those two moments apart.

There is a narrow role for a lawyer, and it is not holding keys. It is holding instructions: that a crypto inheritance plan exists, which app it lives in, who the guardians and heirs are, and how the passphrase reaches them. That document reveals nothing on its own.

How SLIP-0039 shares change the maths

Shamir's secret sharing splits one secret into N pieces so that any M of them rebuild it, and fewer than M reveal nothing at all. SLIP-0039 is SatoshiLabs' standard for doing this with wallet seeds, published as a replacement for the single BIP-39 phrase [4]. Each share is a mnemonic of 20 or 33 words drawn from a list of exactly 1,024 words, so it can be written down and read back like a normal phrase [4].

Two properties matter for families. First, the shares are verifiable. Every SLIP-0039 share carries an RS1024 checksum that guarantees detection of any error affecting up to 3 words, with under a one in a billion chance of missing larger errors [4]. A guardian who copied a word wrong finds out the day they write it, not the day your family needs it. Second, the scheme has two levels, a group threshold and a member threshold inside each group, so you can require, in the standard's own example, three of five friends together with two of six family members [4].

This is the model behind guardian recovery in SpendTheBits. You choose guardians and an M-of-N threshold, the app splits the secret on your device, and each guardian receives an encrypted share. Our backend stores only ciphertext and holds no key that could open it. A recovery can be started by you or by guardians, you are notified, and you can cancel it, which is the defence against guardians colluding. If you use a passphrase, the standard supports it, and the shares alone still do not open the wallet [4].

The dead-man's switch: inheritance without handing over keys today

Social recovery answers the question of a lost phone. Crypto inheritance asks a harder one: how do heirs claim when the owner cannot take part at all? Our answer is a passive dead-man's switch. You nominate heirs and set a silence period measured in months. Ordinary use of the app counts as a check-in, so there is no ritual to remember. If the silence period passes with no activity, a claim can begin. If you are simply away, you are warned as the deadline approaches, and any activity resets the clock.

Three design choices keep this non-custodial. Nothing is moved, escrowed or restricted while the plan is dormant, so your funds and Earn positions behave as before. A claim in progress is visible to you and can be stopped, so a premature or malicious claim cannot complete quietly. And the passphrase reaches heirs out of band, never stored with the plan. The server holds ciphertext it cannot read; the heirs hold a passphrase that is useless without the claim. Neither half is money on its own.

That split is the whole point. A hardware wallet in a drawer is usable by anyone who finds it today. A seed at a lawyer's office is usable by anyone who opens the envelope. A dead-man's switch is usable by nobody today, and by the right people after real silence. The inheritance setup article walks through the screens; this section explains why they are shaped that way.

A family plan you can finish this weekend

Start with the written backup, because everything else layers on it. Write the seed on a durable medium, store it where it survives fire and water, and do not photograph it. Then decide whether you want a passphrase. If so, treat it as a second secret with its own handoff, not a note stapled to the first.

Next, pick guardians who are unlikely to fail together. Five people in one house is a lower threshold than it looks, because one flood reaches all of them. Three of five, across at least two households, is a common balance. Set social recovery up in the app, let each guardian accept their share, and write the guardian list into a plain document. Then nominate your heirs and set a silence period long enough that a hospital stay or a long trip cannot trigger it.

Finally, tell people a plan exists. That is the step families skip, and it is why silence wins. Give your executor or lawyer a one-page note: the app, the fact that guardians and heirs are configured, and how the passphrase will reach the heirs. The note reveals no secret. Review it yearly, replace any guardian you can no longer reach, and rehearse a recovery on a spare phone so the first time your family sees the flow is not the day they need it. Our security page describes what the device keeps and the server never sees; the families and long-term holders page collects the rest of the tooling.

Hold your own keys, keep the yield, skip the middleman.

SpendTheBits is a fully non-custodial wallet for 13 chains, free on iOS and Android.

Frequently asked

It protects against theft, but for inheritance it is a chain of single points of failure: the device, the PIN, the paper backup, the passphrase and the knowledge of where they are. Some Trezor models erase the wallet after 16 wrong PIN attempts, so a guessing heir can destroy what they are trying to reach [5].

SLIP-0039 is SatoshiLabs' standard for Shamir secret sharing of wallet seeds. It splits a secret into shares so that any M of N rebuild it, and every share carries a checksum that catches copying errors, so a guardian learns about a mistake when they write the share down rather than years later.

No. The server stores ciphertext only and holds no key that could decrypt it, and the passphrase is handed to heirs out of band. There is no point at which SpendTheBits could complete a claim on its own.

A claim cannot begin until the full silence period has passed with no activity in the app, and you are notified and can cancel if one starts. Normal use resets the clock, and you are warned before the deadline.

Yes, but instructions rather than keys: which app the plan lives in, that guardians and heirs are configured, and how the passphrase reaches them. That note reveals no secret on its own.

Sources

  1. 1.Exclusive: Nearly 4 Million Bitcoins Lost Forever, New Study Says · Fortune (reporting a Chainalysis study) · accessed 2026-09-02
  2. 2.This man owns $321M in bitcoin, but he can't access it because he lost his password · CBC Radio, As It Happens · accessed 2026-09-02
  3. 3.QuadrigaCX: A Review by Staff of the Ontario Securities Commission · Ontario Securities Commission · accessed 2026-09-02
  4. 4.SLIP-0039: Shamir's Secret-Sharing for Mnemonic Codes · SatoshiLabs · accessed 2026-09-02
  5. 5.PIN protection on Trezor devices · Trezor · accessed 2026-09-02

This article is educational and reflects observed data and public sources on the date shown. It is not financial, legal or tax advice. Digital assets can lose value; yields shown are observed, not promised.