Bitcoin inheritance planning
By Imok Team ·
Bitcoin inheritance planning is the process of making sure your family can find and recover your self-custodied coins if you die or are incapacitated — without exposing your keys to anyone while you are alive. Unlike every other asset you own, bitcoin has no bank, no support desk, and no court-ordered recovery path. If the knowledge of how to access your coins dies with you, the coins are effectively gone. This guide covers why bitcoin is uniquely unforgiving, the failure modes of naive plans, how the main inheritance options compare, and a layered setup that works for most holders.
Why bitcoin is uniquely unforgiving
Self-custodied bitcoin has no recovery mechanism at all: lose your seed phrase — the 12 or 24 BIP-39 words, optionally protected by an additional “25th word” passphrase — and the coins are gone forever. There is no password reset, no identity verification process, and no support desk to call. The blockchain does not know or care who you were.
This is not a theoretical risk. An estimated one-fifth of all bitcoin may already be lost or stranded, much of it through lost keys, according to analysis commonly cited from Chainalysis. Behind that number are families who knew the coins existed and could do nothing about it.
Every other asset in your estate has a human layer that can be petitioned. Banks have probate processes. Brokerages have transfer-on-death procedures. Even a neglected safe deposit box eventually gets drilled open by court order. Bitcoin deliberately removes that layer — which means the entire burden of Imok falls on you, in advance, while you are alive.
The five failure modes of naive plans
Most informal bitcoin inheritance plans fail in one of five predictable ways. Recognizing yours on this list is the first step toward fixing it.
1. The seed in a drawer no one knows about. The backup exists — stamped in steel, even — but your family does not know it exists, or where. After your death they sort your belongings, find nothing obviously labeled “bitcoin,” and the plate gets donated to a thrift store inside a box of old notebooks. A perfect backup that no one can find is functionally identical to no backup.
2. The seed handed to a lawyer unencrypted. You gave your attorney a sealed envelope containing the actual seed words. Now a single person — or anyone who breaches their office — can drain your wallet today, while you are alive, from anywhere on earth. You have traded the risk of loss for the risk of theft, and you may never know which employee or contractor saw the envelope.
3. Telling your spouse verbally. “The words are in the garage safe, and the wallet is called BlueWallet.” Human memory under grief is unreliable, and verbal instructions cannot carry the detail a recovery actually needs: which wallet, which derivation path, whether there is a passphrase, what to do first. Six months after the funeral, the fragments your spouse remembers do not add up to a recovery.
4. Exchange-only custody. Keeping everything on a custodial exchange does give your family a claims process — but it requires death certificates, court documents, and months of back-and-forth, and it defeats the entire point of self-custody while you are alive. You are exposed to exchange hacks, freezes, and insolvency in exchange for a probate path. For many holders that trade is unacceptable.
5. Over-engineered multisig your heirs cannot operate. A 2-of-3 multisig with keys distributed among family members is genuinely robust against theft and single-point loss. It is also genuinely likely that your non-technical widow, standing at a laptop in 2031, cannot coordinate two signing devices, three key locations, and a wallet coordinator she has never heard of. Security that your heirs cannot execute is not inheritance security.
The pattern across all five: the failure is rarely cryptographic. It is almost always a knowledge transfer failure — the right information not reaching the right person at the right time.
Bitcoin inheritance options compared
There are five mainstream approaches. None is perfect; they differ in who can actually recover the coins, how exposed you are while alive, and what they cost.
| Approach | Heirs can actually recover? | Security while alive | Complexity | Cost |
|---|---|---|---|---|
| Dead man’s switch with knowledge transfer | Yes — instructions delivered automatically to one chosen person | Excellent — packet is encrypted, keys stay in your physical custody | Low — write instructions once, check in periodically | Free (Imok early access) |
| Multisig 2-of-3 | Maybe — robust design, but heirs must execute a technical ceremony | Excellent — no single key spends | High — setup and heir training both demanding | Hardware + time; some providers charge |
| Collaborative custody (Casa, Unchained) | Yes — guided inheritance flows exist | Very good — provider holds one key, never all | Medium — provider guides heirs through recovery | Paid subscription, ongoing |
| Custodial exchange next-of-kin | Eventually — months of documents and legal process | Poor — you carry exchange counterparty risk | Low for you, high for your executor | Free, at the cost of self-custody |
| Letter in a safe deposit box | Maybe — works until it goes stale or the box is missed | Good — physical access required, unless the seed itself is inside | Low to set up, high to maintain | Box rental, plus manual updates |
A few things stand out. The approaches with the best heir outcomes either cost money forever (collaborative custody) or demand technical execution from grieving non-experts (multisig). The cheap approaches (safe deposit box letters) silently rot: you change wallets, move house, add a passphrase, and the letter becomes a confident guide to the wrong answer. And any approach that puts the raw seed in someone else’s hands trades loss risk for theft risk.
The dead man’s switch row solves a different slice of the problem than the others: it does not custody anything. It guarantees that the knowledge — where the backups are, how to restore them, what to watch out for — reaches exactly one person, automatically, at the moment it is needed and not a day earlier. That is why it composes well with the other rows rather than competing with them. You can run multisig and document the recovery ceremony in a packet. You can use collaborative custody and leave your heir the account details and provider contact steps.
The recommended layered setup for most holders
For the typical self-custody holder, a layered plan beats any single mechanism. Each layer covers the failure mode of the one below it.
Layer 1: Metal seed plates in two separate locations. Paper burns and floods; steel and titanium do not. Stamp or engrave your seed words onto metal plates and store them in two geographically separated, physically secure spots — a home safe and a relative’s safe, for example. If you use a 25th-word passphrase, store it separately from the seed so that neither location alone can spend.
Layer 2: A handover packet delivered by a dead man’s switch. The packet contains the locations of your plates and step-by-step recovery instructions — not the seed words themselves. Imok encrypts the packet in your browser with AES-256-GCM before upload; the server stores only ciphertext and the passphrase never leaves your device. If you stop checking in, the system escalates through five days of email reminders and a one-time notice to your trusted contact, then releases the packet to your chosen successor as a one-time reveal link. How it works in detail.
Layer 3: The packet passphrase through a separate channel. Because the packet is encrypted, your successor also needs the passphrase — and it must travel independently of the packet. Options: a sealed envelope with your attorney, a note stored with their own important documents, or simply memorized. If the passphrase rides along with the packet, the encryption protects nothing.
Layer 4: A will that mentions the asset exists. Your will should state that you hold bitcoin and name who inherits it — without including the seed or the passphrase. Legal ownership and technical access are separate problems, and both need solving. For large holdings, an estate attorney can structure the transfer properly; Imok is not a legal document and is not estate, tax, or legal advice.
Why not put the seed words themselves in the packet? Because whoever ends up holding the reveal link plus the passphrase gets plaintext. A seed phrase in plaintext is instant, remote, irreversible theft — anyone on earth who reads it can drain the wallet in minutes. A location, by contrast, still requires someone to physically show up, which limits the threat to people who can reach your actual safes. The packet is a map, not the treasure.
What to write in the packet
Write the packet for a smart adult who has never used bitcoin. A good checklist:
- Plate locations. Exact, physical, unambiguous: “basement safe, behind the false back panel; combination is in the envelope with our attorney.” Both locations, plus a note about which holds what.
- Wallet type. What wallet software you used (e.g., Sparrow, BlueWallet, Coldcard) so the heir restores into something compatible. If you use anything nonstandard — a custom derivation path, a multisig, a passphrase — note it plainly, because a standard restore of a nonstandard wallet shows an empty balance and panic.
- A step-by-step restore guide. Written for a non-technical spouse: which app to download (from the official site only), which option to choose (“restore from seed words”), how the words are entered, how long syncing takes, and what a successful restore looks like.
- Scam warnings. Grieving heirs holding unknown crypto are prime targets. State clearly: anyone who contacts you offering “recovery services” is a scammer; never type the seed words into a website; never share them with anyone, including people claiming to be from wallet companies or exchanges.
- Calm instructions. “Don’t rush. The coins are not going anywhere — they have been on the blockchain the whole time and will stay there. Don’t tell anyone online that you have inherited bitcoin. Take weeks if you need them.”
If you are unsure what level of operational detail a handover document needs in general, what to put in a business handover document covers the same writing discipline from the business side.
Keeping the plan current
A stale plan can be worse than none, because it sends your heir confidently in the wrong direction. Three habits keep it alive:
Update after every wallet change. New wallet, new seed, new passphrase arrangement, plate moved to a new location — any of these means editing the packet the same week, not “soon.” Because the packet is encrypted in your browser, updating it means re-encrypting and re-uploading, which also forces you to re-read what your heir will actually receive.
Do an annual review. Once a year, walk the plan end to end as if you were your own heir. Are the locations still accurate? Does your successor still live where you think they live? Is your trusted contact still the right person? Is the attorney still practicing?
Test the check-in rhythm. Your dead man’s switch only works if the check-in habit survives your real life. Use the first few months to confirm the cadence fits — and to learn what the reminder emails look like, so a genuine reminder never gets ignored as spam. The details of the escalation sequence are covered in what happens to your bitcoin when you die.
Common objections
”Isn’t a dead man’s switch overkill for my stack?” Consider what the switch replaces: a conversation your family will try to reconstruct from memory, or an envelope that someone must remember to open at the right time. The mechanism is simple — check in periodically, and instructions deliver themselves if you stop. The overhead is a few seconds a week. Compared to the value even a modest bitcoin holding represents to your family, overkill is not the right frame; the question is whether any automated guarantee exists, or none.
”What about false triggers? I travel, I get busy, I go off-grid.” This is what the escalation ladder is for. A missed check-in in Imok does not release anything: it starts five days of email reminders. If those go unanswered, your trusted contact is notified once — and that notice deliberately does not mention the packet, so it reveals nothing about your setup. Only after all of that does the packet release, as a one-time link that expires in 30 days or on first use. Any check-in during the entire window resets you to active. A two-week silent retreat is a non-event.
”Why not just use a password manager’s emergency access?” Emergency access features share live credentials with a designated person after a waiting period — useful for accounts, but a poor fit for bitcoin. Your seed should not live in a password manager at all, the waiting-period model grants standing access rather than delivering instructions, and the feature assumes your heir knows what to do with access once granted. See zero-knowledge encryption explained simply for why delivering encrypted instructions beats sharing live secrets.
”My holdings are small. Is this worth doing now?” Small stacks have a way of not staying small, and the plan you build at today’s value is the plan that protects tomorrow’s. The setup cost is an afternoon: stamp the plates, write the packet, hand over the passphrase, mention the asset in your will. It is free during early access, and the habit of keeping it current is worth more than the initial setup.
Bitcoin inheritance planning is not morbid and it is not optional. It is the price of the thing you chose when you chose self-custody: there is no one else to call, so the call has to be placed in advance. Build the layers, write the map, and let the switch carry it when you cannot.
Free while in early access. Set up in under 15 minutes.
Frequently asked questions
Should I put my seed phrase in the handover packet?
No. Whoever holds the reveal link plus the packet passphrase gets plaintext, and a seed phrase in plaintext means instant remote theft from anywhere in the world. Put the physical locations of your seed backups in the packet instead — a location still requires someone to show up in person, which is a far stronger security posture. See how Imok works for bitcoiners.
Is a dead man's switch legally enough for bitcoin inheritance?
No — it is an operational tool, not a legal document. It complements a will or trust rather than replacing one: the will establishes legal ownership, the switch delivers the practical recovery instructions. For significant holdings, consult an estate attorney so the legal transfer is as clean as the technical one.
What if my spouse is not technical at all?
That is exactly who the packet should be written for. Include a beginner-level, step-by-step restore guide: which wallet app to download, what to click, what the seed words look like, and what mistakes to avoid. Write it as if the reader has never touched bitcoin — because they may not have.
Can Imok see my bitcoin instructions?
No. Your packet is encrypted in your browser with AES-256-GCM before it is uploaded, and the passphrase never leaves your device. The server stores only ciphertext, so there is nothing for Imok — or anyone who breaches it — to read. Details are on the security page.
What happens if I just forget to check in?
Nothing irreversible. A missed check-in starts five days of email reminders, then a one-time notice to your trusted contact, and only after that does the packet release. Any check-in during that window resets everything back to active — a holiday or a busy week never triggers delivery.
Protect your one-person business
Imok delivers your encrypted handover packet automatically if you ever stop checking in.