Bitcoin has no “forgot password” desk
Bitcoin ownership is controlled by private keys. A will can say who should inherit Bitcoin, but it cannot by itself move the coins. If the heirs cannot locate and correctly use the keys and wallet information, the Bitcoin may be permanently inaccessible. If they can find everything too easily, a thief may be able to steal it before the estate is settled.
Never put seed words, passphrases, PINs, or complete private keys in a will
Wills are often copied, shared with lawyers and executors, and may become part of public probate records. A seed phrase is not an account number—it is the master key. Anybody with it can spend the Bitcoin immediately.
What this guide is—and is not
This is a Bitcoin-only educational framework for self-custody. It is not legal, tax, investment, security, or estate-planning advice. Work with a BC/Canadian estates lawyer and a competent Bitcoin recovery professional where appropriate. Do not send your seed words, wallet file, private keys, or photos of backups to anyone who offers “recovery help.”
What should happen—and in what order
Bitcoin does not disappear because a holder has died. The danger is hurried action, loss of records, or scammers exploiting the family. This staged timeline gives an executor a safe order of work. Legal authority and local probate requirements are separate questions that a qualified estates lawyer must address.
Incapacity is not the same as death
For incapacity, the owner is still alive. A power of attorney should be reviewed by a BC estates lawyer to make sure it clearly covers digital assets and the intended limits on access. Do not treat a temporary illness as permission for informal key sharing.
Four things an estate plan must preserve
1. Authority
Who is legally entitled to act? Your will, executor appointment, power of attorney, and family instructions should agree.
2. Location
Where are the devices, backups, metal plates, passphrase hints, wallet records, and safe-deposit boxes?
3. Knowledge
What wallet is it, what network is it, and how does the intended person safely rebuild it without guessing?
4. Access
Can the intended people obtain the required number of independent signing keys without one person having every secret?
Use two separate documents
Estate letter (non-secret): kept with your estate documents. It tells the executor that Bitcoin exists, identifies the trusted helper(s), states where the recovery packet is held, and gives a current date. It contains no seed words, passphrases, PINs, full xpubs, or private keys.
Recovery packet (secret / controlled access): kept offline in a secure place. It contains the technical wallet map, the locations of separate key backups, device instructions, and a recovery test record. Split its contents so no single casual finder can spend the coins.
Make a plain-language inventory
Record enough to identify each holding, but do not record secrets in the same place. Include: wallet nickname; Bitcoin-only or other asset; approximate balance range (not necessarily an exact number); whether it is single-signature or multisig; software used; device models; network (mainnet or testnet); and the date last checked.
Single-signature, 2-of-3, and 3-of-5
A single-signature wallet needs one private key to spend. That is simple, but one lost seed, one compromised backup, or one unavailable person can become a crisis. Multisig requires a threshold of separate keys: for example, 2-of-3 means any two of three independent signers must approve a spend.
| Design | Strength | Main weakness | Typical use |
|---|---|---|---|
| Single signature | Simple to understand and restore | One seed is both the single theft target and single loss point | Modest holdings or a carefully protected simple plan |
| 2-of-3 multisig | One lost key does not destroy access; one stolen key cannot spend alone | Requires careful configuration backup and recovery practice | Often the practical estate-planning balance for significant personal Bitcoin |
| 3-of-5 multisig | Greater resilience across more people/locations | More signers, more confusion, more maintenance, greater estate complexity | Large holdings or a well-organized family/team with ongoing support |
| Collaborative custody | A service or trusted collaborator may hold one key or manage a defined recovery process; it can make inheritance easier to coordinate. | You must understand its legal terms, fees, identity checks, availability, privacy, and what happens if the company or relationship changes. | People who want a recovery partner but still wish to limit any one party’s unilateral control. |
Multisig is not “three copies of one seed”
Three cards, devices, or backups restored from the same seed are still one signing key. They provide physical redundancy only. In particular, multiple Tangem cards carrying copies of the same wallet are backups, not a 2-of-3 or 3-of-3 multisig arrangement.
What “independent signers” means
- Each signer has its own independently generated seed phrase.
- Use different manufacturers or codebases where practical, so one device or software failure is less likely to affect every key.
- Create and store each seed separately; never enter every seed into one computer or phone.
- Store devices and seed backups in different secure locations.
- Do not let one person casually hold all signing devices, all seed backups, and all passphrases.
A useful estate pattern
For many families with life-changing Bitcoin, a properly documented 2-of-3 native SegWit multisig can be a sensible balance: one signer/backup under the owner’s control, one separately secured for the spouse or trusted family member, and one in a controlled third location. The exact locations and people must fit the family, legal plan, and ability to use the system—not a generic diagram.
Collaborative custody is not the same as giving up all custody
In a collaborative arrangement, the owner may keep one or more signing keys while a specialist service, lawyer, or trusted person has a limited role—such as holding one key in a 2-of-3 arrangement or checking legal documents before co-signing. That can reduce the chance that a bereaved family is left alone with unfamiliar technology. It also introduces counterparty risk. Before using any service, have it explain in writing: who can sign, what evidence it requires after death or incapacity, how heirs contact it, fees, privacy, what happens if it closes, and how the family exits the arrangement. Do not rely on a marketing page as the estate plan.
Why Tangem and Ballet cards are not a 2-of-3 multisig wallet
A Bitcoin multisig wallet is not defined by the number of cards or devices you own. It is defined by the Bitcoin spending rule recorded in the wallet: for example, “two signatures from these three different public keys are required.” Each participating product also has to support that exact wallet policy and safely make its own signature.
Tangem cards
A set of Tangem cards commonly acts as copies/backups for one wallet key. If the cards carry the same wallet, any one card that can authorize a spend is a convenient backup for the others—not an independent second or third signature.
Even where a seed phrase is used or imported, cloning or restoring that seed to several cards remains one key. Tangem cards should not be counted as separate members of a 2-of-3 arrangement unless the precise model, firmware, and coordinator software explicitly support the required Bitcoin multisig policy and each card has a different key.
Ballet cards
Ballet-style physical wallets are designed primarily as simple, single-key Bitcoin wallets. A private key is secured under a tamper-evident covering; the card is not normally a programmable hardware signer that participates in a Sparrow PSBT multisig workflow.
Owning three loaded Ballet cards means owning three separate single-signature wallets—or three physical backups only if they represent the same key—not one 2-of-3 wallet. Do not uncover, type, or photograph a private key to force it into a multisig setup. That weakens security and can make estate recovery worse.
“Three cards” can mean three very different things
| What you have | What it really is | Multisig? |
|---|---|---|
| Three Tangem cards for the same wallet | Three ways to access the same single key | No |
| Three Ballet cards, each funded separately | Three separate single-signature wallets | No |
| Three supported hardware signers, each with a different seed, configured in one 2-of-3 wallet | One wallet with three independent public keys and a two-signature spending rule | Yes |
That does not mean a Tangem or Ballet card is useless. They may be appropriate for a smaller single-signature holding, a spending wallet, or physical redundancy. The point is accuracy: they should not be presented to family as “multisig protection” when a single card or one private key can spend the Bitcoin.
How Sparrow Wallet works with Bitcoin multisig
Sparrow Wallet is desktop Bitcoin wallet software. In a hardware-wallet multisig setup, Sparrow is normally the coordinator: it stores the wallet’s public configuration, displays balances and addresses, builds a proposed transaction, and gathers the required signatures from the independent hardware signers. The hardware devices keep their private keys and approve the transaction on their own screens.
Example: 2-of-3 using Sparrow
- Set up three independent compatible hardware signers, each with a different seed phrase.
- In Sparrow, create an air-gapped or hardware-wallet multisig wallet using the three public keystores/xpubs and the chosen 2-of-3 policy.
- Verify the multisig receiving address on the hardware signers before depositing meaningful funds.
- When spending, Sparrow creates a PSBT (Partially Signed Bitcoin Transaction). It can be passed to each signer by USB, SD card, or QR code, depending on the devices.
- Each signer shows the amount and destination address for human verification, then adds one signature without releasing its seed.
- After any two valid signatures are returned, Sparrow combines them and broadcasts the finished transaction—either directly through a trusted node or by exporting it for broadcast.
Sparrow does not replace the recovery map
The Sparrow wallet file on one computer is not enough for estate recovery, and it should not be the only copy of the wallet configuration. Keep an offline backup of the descriptor or exported multisig configuration, plus the threshold, fingerprints, derivation information, signer labels, and the location of each separate seed. An heir can then rebuild the same wallet in compatible software even if the original computer or Sparrow installation is gone.
Important operating discipline
- Use Sparrow as a watch-only coordinator whenever possible; do not type multiple hardware-wallet seeds into the desktop computer.
- Verify every receiving address on the hardware signers, not only on the computer screen.
- Before signing, read the address and amount on each hardware signer’s own trusted display.
- Keep a small test transaction in the estate plan so family can rehearse the process safely.
Preserve the full wallet map
With a simple wallet, the seed phrase may be enough to derive addresses. With multisig, seed phrases alone may not reliably tell an heir which combination of keys, derivation path, script type, and wallet policy was used. The software may need the wallet descriptor or equivalent configuration before it can find and spend the Bitcoin correctly.
The recovery map should record
- Wallet name and the coordinator software used (for example, the exact wallet application).
- Whether the wallet is single signature, 2-of-3, 3-of-5, or another threshold.
- Address/script type and derivation path.
- Each signer’s master fingerprint and extended public key (xpub/zpub/etc.) or the exported wallet descriptor/configuration file, stored as appropriate.
- The device model and firmware/application information that was used at setup.
- Where each separately secured seed backup and device can be found—without putting all the secrets on one sheet.
- Whether a BIP-39 passphrase (“25th word”) is used, and a separate method by which the authorized person can locate it.
- A list of receiving addresses or a watch-only wallet so the estate can confirm it has rebuilt the correct wallet before spending.
A passphrase adds both protection and permanent-loss risk
A BIP-39 passphrase is not a password reset feature. A different spelling, capital letter, space, or punctuation produces a different wallet. If you use one, the succession plan must make it recoverable by the correct person without writing it beside the seed phrase.
Store data in layers
| Layer | Can contain | Must not contain |
|---|---|---|
| Estate letter | That Bitcoin exists; executor contact; recovery-packet location; dates | Any seed, PIN, passphrase, or private key |
| Wallet map | Wallet policy; fingerprints; public configuration; device/software instructions | All seed phrases and passphrase together |
| Seed backup | One seed phrase or signer backup; signer label kept discreet | Other signers’ seeds; matching passphrase beside it |
| Passphrase record | A separately protected passphrase or controlled access method | The matching full seed phrase |
How an authorized family should recover Bitcoin
This is a generic safety sequence, not instructions to enter a seed into any particular website or phone app. Use the actual wallet map and original manufacturer documentation. If the estate cannot identify the wallet type or its sources, stop before entering any secret and obtain independent, in-person technical guidance.
- Establish authority and secure the materials. The executor works with the estate lawyer. Collect the estate letter, wallet map, and the separately stored materials. Record where each item came from; do not photograph recovery words.
- Identify the exact wallet. Determine whether it is a single-signature wallet, a multisig wallet, a collaborative arrangement, or exchange custody. Check mainnet/testnet, wallet software, the signing policy, and whether a BIP-39 passphrase or descriptor is in use.
- Rebuild visibility first. Use public information—the descriptor, extended public keys, or a known watch-only wallet—to view the expected addresses and balance. This verifies that the map points to the right wallet without using every secret.
- Choose a clean destination wallet. Before any spend, prepare a newly created wallet for the estate or beneficiaries, with its own verified backup plan. Do not reuse the old wallet after secrets have been gathered.
- Make a small test transaction. Independently verify the destination address on a trusted signer display. Sign only the small test amount. Confirm it arrives and that every action has been documented.
- Complete the transfer deliberately. After the test succeeds and authority is confirmed, transfer the balance in a way that suits the estate’s legal and security plan. Preserve transaction records and the fair-market-value evidence needed for tax advice.
Never import a valuable seed casually
Do not type estate seed words into a website, browser extension, unfamiliar mobile app, email form, remote-access screen, or a computer somebody else controls. Do not disclose a seed phrase to a lawyer, accountant, “support worker,” or recovery company merely to prove the estate owns Bitcoin. Legitimate professionals can advise without possessing the secrets.
Give family a safe path, not a treasure hunt
The best plan is understandable under stress. Choose one primary executor and one technically capable Bitcoin helper, then decide what each should learn and what each should be able to access. The helper should not become the sole controller of the coins.
- Explain what exists. Tell the executor and intended heir that Bitcoin exists and that there is a recovery plan. Do not surprise them after death.
- Choose roles. Separate legal authority, family beneficiary, and technical helper where that reduces risk. Confirm your lawyer’s advice on incapacity and estate administration.
- Teach the warning signs. No legitimate recovery requires a seed phrase by email, text, website form, phone call, remote-access session, or social-media message.
- Practice a controlled recovery. Rebuild a test wallet or small-value wallet with the people who will need to act. Do not practise by exposing the main wallet’s seeds to unnecessary devices.
- Leave time for verification. Estate recovery should be slow and deliberate. First recreate a watch-only view, verify known addresses and balances, and only then prepare a small test spend.
Do not rush because someone says funds are in danger
After a death or incapacity, scammers may impersonate exchanges, wallet companies, lawyers, government agencies, or “blockchain recovery specialists.” Pause. Use phone numbers and websites independently obtained—not links or phone numbers sent in a message. Discuss the plan in person or by a verified channel.
For an executor who is not technical
Leave a one-page first-action sheet: “Do not move Bitcoin. Do not disclose recovery words. Contact [named trusted person] using the number in the estate letter. Locate the sealed recovery packet and lawyer’s documents. Verify authority. Read instructions before connecting any device.” Keep the technical instructions in the recovery packet, not in the will.
Test recovery without taking unnecessary risks
Hardware fails, handwriting fades, businesses change, and people forget. A periodic test turns an assumption into evidence. Use a small separate test wallet where possible, or rebuild the main wallet only in an offline, controlled setting with the minimum people required.
Annual review
- Devices power on and PINs work.
- Seed plates/paper backups are intact and legible.
- Safe, safe-deposit, or storage access still works.
- Executors and contacts are current.
- Wallet software can still import the descriptor/configuration.
After every major change
- Record new wallet policy or signer replacement.
- Update the non-secret estate letter date.
- Confirm old backups no longer expose active funds.
- Test a small receive and spend from the new wallet.
- Verify the watch-only balance and known receiving addresses.
Replace a compromised seed—do not merely update software
If you believe a seed was weakly generated, copied, photographed, entered into a suspect device, or exposed to an unknown party, treat it as compromised. Create a completely new wallet with new independent seed(s), verify the destination, and move the funds. A firmware update cannot make an already-exposed private key secret again.
Top 10 Bitcoin estate-planning mistakes
- Putting secret words in the will. A will gives legal instructions; a seed phrase gives immediate spending control. Keep them separate.
- Giving nobody notice that Bitcoin exists. A perfectly hidden backup is useless if heirs never look for it.
- Leaving only a hardware wallet. Devices fail, PINs are forgotten, and models disappear. The recovery material and written plan matter more.
- Calling copies of one seed “multisig.” Multiple cards or devices holding the same key improve availability, not the Bitcoin spending rule.
- Saving every multisig seed but no wallet descriptor. The heirs may not know the script type, threshold, fingerprints, or derivation details needed to find the wallet correctly.
- Using a BIP-39 passphrase that no authorized person can recover. A passphrase typo creates a different wallet. It must be carefully documented through a separate controlled process.
- Keeping recovery words in photos, email, cloud notes, or chat messages. Digital convenience creates a theft path that can outlive the owner.
- Choosing complex custody because it sounds impressive. A 3-of-5 setup that no family member can execute can be less safe in practice than a tested 2-of-3 or simple single-signature plan.
- Never testing. Recovery instructions, devices, safe access, contacts, and software all change. A plan needs an actual rehearsal.
- Acting under pressure after a death. Bitcoin does not expire. “Move it now” messages are a classic way scammers push families into exposing keys.
Estate-plan checklists
Owner checklist
- I have made a Bitcoin inventory that identifies every wallet without exposing secrets.
- My will and estate letter identify who should be contacted and who has legal authority.
- No will, email, cloud document, phone note, or photo album contains my seed phrase or passphrase.
- Each multisig signer has an independent seed and separate storage location.
- I have preserved the wallet descriptor/configuration, threshold, fingerprints, derivation details, and software information.
- I have a clear plan for any BIP-39 passphrase and have not stored it beside its seed.
- I have tested recovery using a safe, controlled process and recorded the date.
- I review the plan at least annually and after a device, address, signer, family, or legal change.
Executor / family first-action checklist
- Do not share words, PINs, photographs, wallet files, or device screens with anyone.
- Do not act on emails, texts, advertisements, or unsolicited recovery offers.
- Locate the estate letter, confirm legal authority, and contact the named trusted helper through a verified method.
- Find the sealed recovery map and separate key locations; do not combine materials until the written process says to do so.
- Rebuild watch-only visibility first and compare known addresses/balance records.
- Before moving significant Bitcoin, have the recovery reviewed independently and make a small test transaction.
- Document each action for the estate file, but never include secret words in that file.
Printable non-secret estate worksheet
Use this with your lawyer or executor. Do not write seed phrases, passphrases, PINs, private keys, or full recovery words on this sheet.
Recovery drill record
Sources and technical references
- Bitcoin Improvement Proposal 39 (BIP-39) — mnemonic-code standard and optional passphrase details.
- Bitcoin Improvement Proposal 48 (BIP-48) — hierarchical deterministic multisig wallet derivation convention.
- Bitcoin Core release notes: watch-only and multisig support — an official Bitcoin.org technical reference.
- Sparrow Wallet documentation — wallet and PSBT/multisig features; verify current device compatibility before relying on any setup.
- Blockstream developer documentation — wallet and Bitcoin technical documentation.
- BloFin Academy: Bitcoin inheritance planning — overview of inheritance failure modes and options; independently verify any service or jurisdiction-specific claim.
- Spark Research: Bitcoin inheritance planning guide — comparative discussion of inheritance approaches, including multisig and collaborative custody.
- Ledger Academy: what happens to crypto when you die — general estate-planning considerations; product claims should always be independently assessed.
Disclaimer
This page is general education, prepared for BTC.TedLee.ca. It is not individualized legal, tax, estate, investment, or cybersecurity advice, and it does not endorse any wallet, device, recovery service, lawyer, or security arrangement. Bitcoin transactions are irreversible. Laws, probate rules, tax treatment, wallet software, hardware, and security practices can change. Seek qualified Canadian legal and tax advice before relying on an estate arrangement, and obtain independent technical assistance before moving substantial Bitcoin.
Security warning: Never disclose a seed phrase, private key, or passphrase to a website, app, phone caller, email sender, text message, or “support” worker. No legitimate helper needs it to give general advice.