Self-custody’s greatest strength is its estate-planning nightmare: no company can recover your keys — including for your family, after you’re gone. Exchanges have death-certificate processes; wallets have mathematics. Every year, real fortunes are permanently lost not to thieves but to grief plus a missing plan. This guide is the plan — and it’s universal: nothing here depends on any particular token, chain, or protocol.
What Three Shortcuts Cost
- A Seed Phrase in a will becomes readable by others. In many jurisdictions a will becomes a public court record during probate — and even where it doesn’t, it passes through hands you don’t control; the master key ends up in a document built to be read by others.
- A seed pre-shared with heirs “just in case” takes on their security. Their phone photos, their cloud notes, their password habits: a seed known by two people has double the attack surface and none of the accountability.
- “They’ll figure it out” leaves heirs a riddle. A hardware wallet in a drawer is a riddle; grieving people rarely solve riddles — they hire “recovery services,” many of which are scams aimed exactly at them.
The Letter-of-Instruction Pattern
The core design: instructions that are worthless to a thief but sufficient for an heir.
- Write a sealed letter that explains — in plain language for a non-crypto reader — what exists (types of assets, not amounts), where the metal backup lives (location description, not the words on it), what device is involved, whether a passphrase wallet exists and where any sealed record of it is kept (a location, never the words — without the passphrase, heirs restore only the standard wallet; see the passphrase plan below), and who to ask for competent help (a named, vetted person or firm — not “Google it”).
- The letter contains no secrets. Anyone reading it learns there is a backup and where to look with lawful access — which an executor has and a burglar doesn’t. The seed itself never appears in any document.
- Store it with your estate documents — the lawyer’s copy, the safe copy. Update it when locations change; date every revision.
Stronger: Shamir Shares Across Heirs
If your hardware wallet supports Shamir backup (SLIP-39), split the recovery into shares — say 2-of-3: one to the heir, one to the lawyer or executor, one in the safe. As long as the three shares sit in three different places and hands, no single person or burglary can reconstruct the wallet, and no single loss destroys it — an heir who lives where the safe is, or can open it, already holds two of the three. Two shares only ever meet at the moment of legitimate recovery. Keep the scheme executable: the letter of instruction explains which shares exist, where, and how many are needed — because a Shamir setup nobody understands is just a more elaborate way to lose everything.
Shares usually come with a new wallet. A wallet already backed by 12 or 24 words cannot be re-split, so moving to Shamir means creating the new wallet and moving funds into it — the backup guide has the procedure. On Trezor the one exception is a 20-word single-share backup made in June 2024 or later: it upgrades to shares in place, and the original single-share backup still restores the same wallet on its own, so until that backup is destroyed one find of it reaches the whole wallet. Some positions do not follow a move freely: a native HEX stake cannot move at all, a HEX Stake Instance (HSI) moves only as an NFT once tokenized, a delegated HSI comes free only by retiring the HTTs minted against it, and an ACTR vault deposit withdrawn inside its 90-day lock burns part of itself. Whatever stays behind stays under the old seed, so the old seed’s backup stays in the plan, and in the letter, until the last position is out.
The Passphrase Needs Its Own Plan
If the wallet uses a passphrase (an extra word or phrase, on top of the Seed Phrase or shares, that opens a hidden wallet), the Seed Phrase or the shares alone restore only the standard wallet — the decoy — and whatever sits behind the passphrase stays out of reach. Nothing warns the heir: every passphrase opens a valid wallet with no error message, so a restored standard wallet looks complete. A passphrase that exists only in one head is lost with that head, and the hidden wallet with it — no seed, device or company can restore it. The letter of instruction can record that a passphrase wallet exists and where any sealed record of it is kept — a location, never the words — so the heir knows the standard wallet is not the whole estate. Setup and the practice unlock are in the backup guide.
Locked Positions Need Their Own Paragraph
Staked and time-locked assets (HEX stakes, delegated HSIs, vault deposits) don’t move on demand — they have end dates, grace windows, and penalty rules. The letter should say so in one honest line: “Some assets unlock on future dates; do not rush, do not pay anyone who promises early access, and consult the named helper before touching anything.” Rushed heirs plus lockups is exactly the scenario penalty rules punish. HTTs are different: they are ordinary tokens that can be sent or traded on any day, and each HTT redeems 1:1 for HEX from its maturity day onward, a right with no deadline (the grace window belongs to the backing stakes, not the holder).
The Practice Run
A plan that’s never been rehearsed is a hope. Once: walk your intended heir (or the named helper) through recovering a test wallet with a few dollars on it — set up on a spare device with the same scheme as the real one (test shares or words, plus a test passphrase if the real wallet uses one) — using only the letter’s instructions and the test backups, start to finish. An hour of mild awkwardness converts your entire plan from theory to muscle memory — and surfaces every wrong assumption while you’re alive to fix it.
Keep It Current
Reread the letter yearly (tax season pairs well — see record-keeping). The letter has a living sibling: the personal runbook you keep for yourself — same no-secrets design, built in the backup guide. Locations change, holdings change, helpers move away, wallets get migrated. An outdated plan can be worse than none — it sends people confidently to the wrong place.
Everything on this page is universal — send anyone the link — pointing people to the source beats forwarding copies (a file passed around is exactly what this site warns about; the link stays canonical and current). For the curious: this site documents Actuator.Finance on PulseChain — the one-page version is How It Works, and Start Here picks your path.
