The most common mistake among crypto holders isn't the absence of a death plan. Almost everyone who's thought about it for five minutes has some plan. The mistake is subtler: the plan requires disclosing the secret right now, to a living person who might talk, go bankrupt, divorce you, or simply turn out not to be who you thought they were twenty years on. A seed phrase written into the text of a will. A password dictated to a lawyer. A key file emailed "just in case" to a grown son. Each of these moves solves the inheritance problem — and immediately creates a lifetime problem: now someone besides you can move your assets today, with no death required.
The task actually splits into two, and most people conflate them. The first: how do you guarantee access reaches the right people after you're gone. The second: how do you make sure no one — including the people you trust most — has that access before then. Solving the first at the expense of the second isn't a solution; it's a theft on a timer. Solving both at once is the real engineering problem, and it has working answers.
Why "just tell someone" isn't a plan
The intuitive move is to pick the most trustworthy person in your life and hand them the key or password whole, with instructions to "use it when I'm gone." The problem isn't whether to trust that person. The problem is that from the moment of handoff, you no longer control what happens to the secret. Their phone can be hacked. They can be coerced — blackmail, a court order, a plain betrayal in the relationship. They can let it slip carelessly, not out of malice but because a secret is a heavy thing to carry when you never asked for it. You didn't pass on an inheritance. You passed on a risk that starts ticking immediately, not after your death.
Worse still is writing the key into a will. In most jurisdictions, a will becomes a public document during probate — read by a court, a notary, sometimes an opposing party in a family dispute. A seed phrase in that document isn't an inheritance. It's an announcement to the Duat that unclaimed funds are sitting there, read out loud before your children ever get a chance to open the wallet.
Our record: the key here is the Ren in its most literal sense — to speak it aloud is to hand over power over whatever it protects. The secret of the name is meant to be revealed only to the one who has passed judgment, and only at the moment of judgment, never before. Anything that breaks that order isn't a handoff anymore. It's a leak.
Shamir's Secret Sharing: split it so no one holds the whole
The mathematical tool for this exact problem has existed since 1979 and is called Shamir's Secret Sharing. The idea is simple: a secret — say, a seed phrase — is split into N shares such that any M of them reconstruct the original, and any M-1 give absolutely no information about it. Not "almost nothing" — literally zero. A single share holder doesn't even know what alphabet the secret is written in.
In practice it looks like this: build a 3-of-5 scheme. Five shares go to five different people or places — a lawyer, two adult children, a safe deposit box, a trusted friend in another city. Each holder can go years without understanding what's on their drive. None of them alone can do anything with your assets. Only when, after your death, three of the five come together — through a notary or an executor — does the secret reconstruct. While you're alive, you can reshuffle the shares any time you fall out with one of the holders; it's not an on-chain transaction, just an ordinary algorithm reset.
The difference from a plain multisig is that Shamir's scheme works with any secret, not just a specific protocol's cryptographic keys, and it leaves no on-chain trace that an inheritance plan is even in motion — to an outside observer, the wallet looks like an ordinary single-owner wallet.
MPC wallets: there's no whole key left to steal
A newer and even more airtight tool is the multi-party computation (MPC) wallet. Here the focus shifts: instead of a full key existing and then being cut into shares, the key never assembles as a whole — not in your hands, not anywhere. Several parties jointly compute a transaction signature, each holding only its own fragment of the underlying math, and the resulting signature is valid only when the required number of parties has agreed to produce it.
For inheritance, this delivers the same property as Shamir's scheme but built into the signing mechanics itself rather than layered on top: heirs don't receive "access to a vault," they receive the right to participate in computing a signature once the other fragment-holders confirm the triggering event. Institutional custodians like Fireblocks or Zengo build their entire business on this principle; the same approach is increasingly reaching individuals through a new generation of consumer wallets.
Timelocks and dead-man's switches: no human intermediary at all
A third layer solves what neither Shamir nor MPC solves on its own: what if all the share-holders are simultaneously unreachable, hesitant, or simply unwilling to take responsibility for assembling a quorum? This is where code replaces people. A smart contract can be set so that if the owner stops confirming activity — a regular "I'm alive," signed with the primary key — after a set period (six months, a year), recovery rights to pre-specified addresses open automatically. You remain the sole party able to move funds as long as you check in regularly; silence triggers the mechanism without anyone having to decide anything.
This removes the last real vulnerability in the whole scheme — dependence on the goodwill and promptness of living people — and replaces it with a protocol that doesn't care who's tired, estranged, or off the grid.
A legal layer that contains no secret
Share-holders and heirs still need a document — not one containing the key, but one explaining how to find and assemble it. That document is safe to leave with a notary, even to read aloud in front of witnesses: there's nothing in it worth stealing. "Five people hold one share each of a secret, here are their names, here's the condition for assembly, here's who to contact" is a map without the treasure. The treasure is protected by math, not by keeping the map a secret.
Do this today
Don't build the whole system at once — start with one decision you can make in an hour. Choose between Shamir's Secret Sharing and one of the newer MPC wallets (several now ship with usable consumer interfaces) and write down, on paper, five candidates you could trust with one share each of a secret — no names on the shares themselves, just a list for your own reference. This isn't the handoff yet. It's the first step that turns splitting the secret into a one-evening task instead of a "someday" idea.