Create a Bitcoin inheritance plan
A Bitcoin inheritance plan must let an authorized successor find and recover the wallet without giving one document, person, or location enough information to steal it. The steps below address wallet operations, not legal, tax, or estate advice.

Do not put a recovery phrase, SeedQR, BIP39 passphrase, private key, or signing quorum in an ordinary will. A probated will may become public or pass through many hands. Never direct a successor to enter a secret into a phone, computer, website, coordinator, cloud form, chat, or support ticket; recovery input belongs only on trusted hardware in a documented flow.
Separate instructions from secrets
Create two layers.
The instruction layer explains the wallet and recovery process. It may identify the wallet type, signers, fingerprints, derivation paths, descriptor, software, and neutral location labels. It should not contain enough private material to spend.
The secret layer contains recovery phrases, shares, passphrases, private keys, or devices that can sign. Store these so one event or unauthorized person cannot collect the required spending material. An authorized successor may eventually need both layers, but they should not normally be kept together.
Build a private recovery worksheet
Include:
- a neutral wallet identifier and Bitcoin network;
- singlesig or multisig and, if relevant, the threshold;
- script/address type;
- signer labels, fingerprints, derivation paths, xpubs, and complete multisig descriptor;
- key order and coordinator configuration for multisig;
- hardware models, firmware, coordinator version, and tested recovery method;
- neutral labels for device and backup locations;
- where a separate passphrase record can be found, without writing it on this sheet;
- one receiving address previously verified on hardware;
- last recovery-test date and result;
- the first authorized person or professional role to contact.
Fingerprints, xpubs, descriptors, and addresses are not signing secrets, but they reveal wallet structure and may expose transaction history. Keep the worksheet private.
Write instructions another person can follow
The first page should say:
- Do not share wallet words with anyone.
- Ignore unsolicited recovery help.
- Obtain the named hardware and software only from official sources.
- Enter recovery words and any passphrase only on trusted hardware in the documented recovery flow.
- Confirm the expected fingerprint and hardware-verified address.
- Send and spend a small test before moving the larger balance.
- Contact the named legal or technical person if the plan requires help.
Explain how many keys are needed, what restores each key, whether a passphrase exists, where the descriptor is, and how to recognize the intended wallet. Avoid shorthand such as “use the usual key.”
For a passphrase wallet, state that every exact passphrase opens a valid wallet and an empty balance may mean a typo. For multisig, state that signer phrases alone do not describe the policy; the successor needs the descriptor plus enough independent signer backups to meet the threshold.
Design storage around real hazards
Map fire, flood, theft, unauthorized family access, institutional closure, border crossing, evacuation, and inability to travel. Do not store a device beside its only recovery backup.
For 2-of-3 multisig, store any two usable signer credentials so that one disaster or one unauthorized person cannot reach both. A policy copy may be stored with each signer backup because it cannot sign alone, but use sealed or encrypted storage to reduce privacy exposure.
If using metal, confirm that the material and marking preserve complete words and order. Fire resistance does not help if characters were recorded incorrectly.
Coordinate legal and operational access
A will can identify beneficiaries, an executor, and the existence of separate recovery instructions. Ask a qualified lawyer in your jurisdiction how to handle wills, trusts, taxes, corporate holdings, safe-deposit access, and incapacity. The lawyer does not need the recovery phrase to advise you unless your independently designed custody plan intentionally assigns that person a key-holding role.
Document what happens if a named company or wallet service disappears. Physically test an alternate recovery implementation for the exact backup format and settings rather than assuming standards guarantee compatibility.
Test the handoff and review it
Use Test a Bitcoin wallet recovery with a small-value wallet and spare hardware. Have the intended successor perform a dry run using only the instructions; identify unclear terms without exposing secrets.
Review at least yearly and after a move, relationship or business change, death or incapacity of a trusted person, hardware end-of-life notice, major firmware update, provider change, or damaged storage location. Device loss or suspected secret exposure is an incident, not merely a routine review trigger: stop using the affected component and follow Verify Jade Plus and avoid wallet scams. If enough signing material is confirmed exposed to authorize a spend, migrate urgently to fresh independent keys. Record reviews and incident actions without balances or secrets.
Related security steps
Updated on: 04/08/2026
Thank you!
