BTC.TedLee.ca • Bitcoin Education

Bitcoin Estate & Recovery Guide

How to make Bitcoin recoverable by the right people after illness, incapacity, or death—without leaving a single piece of paper that lets a thief take it today.

Version 2 • Generic educational guide • Updated August 11, 2026
The central problem

Bitcoin has no “forgot password” desk

Bitcoin ownership is controlled by private keys. A will can say who should inherit Bitcoin, but it cannot by itself move the coins. If the heirs cannot locate and correctly use the keys and wallet information, the Bitcoin may be permanently inaccessible. If they can find everything too easily, a thief may be able to steal it before the estate is settled.

Never put seed words, passphrases, PINs, or complete private keys in a will

Wills are often copied, shared with lawyers and executors, and may become part of public probate records. A seed phrase is not an account number—it is the master key. Anybody with it can spend the Bitcoin immediately.

1. Inventory
2. Protect
3. Document
4. Test
5. Review
A Bitcoin estate plan joins legal authority, recovery knowledge, and separate key accessBitcoinrecoverableLegal authoritywill • executor • POARecovery knowledgemap • instructions • testSeparate key access

What this guide is—and is not

This is a Bitcoin-only educational framework for self-custody. It is not legal, tax, investment, security, or estate-planning advice. Work with a BC/Canadian estates lawyer and a competent Bitcoin recovery professional where appropriate. Do not send your seed words, wallet file, private keys, or photos of backups to anyone who offers “recovery help.”

After death or incapacity

What should happen—and in what order

Bitcoin does not disappear because a holder has died. The danger is hurried action, loss of records, or scammers exploiting the family. This staged timeline gives an executor a safe order of work. Legal authority and local probate requirements are separate questions that a qualified estates lawyer must address.

First daySecure the home, devices, paper records, and safe locations. Locate the non-secret estate letter. Do not plug in wallet devices or search for “recovery help.”
First weekConfirm executor authority, notify the lawyer, inventory the holdings, and contact the named technical helper using independently verified details.
Verification stageUse the wallet map to recreate a watch-only view. Compare known addresses and balances. Confirm every signer, descriptor, passphrase process, and device path.
Only then move fundsAfter authority and recovery are confirmed, make a small test transaction. Move significant funds only to a newly verified wallet controlled by the beneficiaries or estate.

Incapacity is not the same as death

For incapacity, the owner is still alive. A power of attorney should be reviewed by a BC estates lawyer to make sure it clearly covers digital assets and the intended limits on access. Do not treat a temporary illness as permission for informal key sharing.

Build the plan before it is needed

Four things an estate plan must preserve

1. Authority

Who is legally entitled to act? Your will, executor appointment, power of attorney, and family instructions should agree.

2. Location

Where are the devices, backups, metal plates, passphrase hints, wallet records, and safe-deposit boxes?

3. Knowledge

What wallet is it, what network is it, and how does the intended person safely rebuild it without guessing?

4. Access

Can the intended people obtain the required number of independent signing keys without one person having every secret?

Use two separate documents

Estate letter (non-secret): kept with your estate documents. It tells the executor that Bitcoin exists, identifies the trusted helper(s), states where the recovery packet is held, and gives a current date. It contains no seed words, passphrases, PINs, full xpubs, or private keys.

Recovery packet (secret / controlled access): kept offline in a secure place. It contains the technical wallet map, the locations of separate key backups, device instructions, and a recovery test record. Split its contents so no single casual finder can spend the coins.

Make a plain-language inventory

Record enough to identify each holding, but do not record secrets in the same place. Include: wallet nickname; Bitcoin-only or other asset; approximate balance range (not necessarily an exact number); whether it is single-signature or multisig; software used; device models; network (mainnet or testnet); and the date last checked.

Avoid one point of failure

Single-signature, 2-of-3, and 3-of-5

A single-signature wallet needs one private key to spend. That is simple, but one lost seed, one compromised backup, or one unavailable person can become a crisis. Multisig requires a threshold of separate keys: for example, 2-of-3 means any two of three independent signers must approve a spend.

DesignStrengthMain weaknessTypical use
Single signatureSimple to understand and restoreOne seed is both the single theft target and single loss pointModest holdings or a carefully protected simple plan
2-of-3 multisigOne lost key does not destroy access; one stolen key cannot spend aloneRequires careful configuration backup and recovery practiceOften the practical estate-planning balance for significant personal Bitcoin
3-of-5 multisigGreater resilience across more people/locationsMore signers, more confusion, more maintenance, greater estate complexityLarge holdings or a well-organized family/team with ongoing support
Collaborative custodyA service or trusted collaborator may hold one key or manage a defined recovery process; it can make inheritance easier to coordinate.You must understand its legal terms, fees, identity checks, availability, privacy, and what happens if the company or relationship changes.People who want a recovery partner but still wish to limit any one party’s unilateral control.

Multisig is not “three copies of one seed”

Three cards, devices, or backups restored from the same seed are still one signing key. They provide physical redundancy only. In particular, multiple Tangem cards carrying copies of the same wallet are backups, not a 2-of-3 or 3-of-3 multisig arrangement.

What “independent signers” means

A useful estate pattern

For many families with life-changing Bitcoin, a properly documented 2-of-3 native SegWit multisig can be a sensible balance: one signer/backup under the owner’s control, one separately secured for the spouse or trusted family member, and one in a controlled third location. The exact locations and people must fit the family, legal plan, and ability to use the system—not a generic diagram.

Collaborative custody is not the same as giving up all custody

In a collaborative arrangement, the owner may keep one or more signing keys while a specialist service, lawyer, or trusted person has a limited role—such as holding one key in a 2-of-3 arrangement or checking legal documents before co-signing. That can reduce the chance that a bereaved family is left alone with unfamiliar technology. It also introduces counterparty risk. Before using any service, have it explain in writing: who can sign, what evidence it requires after death or incapacity, how heirs contact it, fees, privacy, what happens if it closes, and how the family exits the arrangement. Do not rely on a marketing page as the estate plan.

Two of three independent keys are needed to spend from a Bitcoin multisignature walletOwner keyindependent seedFamily keyindependent seedThird keyseparate location2 of 3to spend
Cards are not automatically co-signers

Why Tangem and Ballet cards are not a 2-of-3 multisig wallet

A Bitcoin multisig wallet is not defined by the number of cards or devices you own. It is defined by the Bitcoin spending rule recorded in the wallet: for example, “two signatures from these three different public keys are required.” Each participating product also has to support that exact wallet policy and safely make its own signature.

Tangem cards

A set of Tangem cards commonly acts as copies/backups for one wallet key. If the cards carry the same wallet, any one card that can authorize a spend is a convenient backup for the others—not an independent second or third signature.

Even where a seed phrase is used or imported, cloning or restoring that seed to several cards remains one key. Tangem cards should not be counted as separate members of a 2-of-3 arrangement unless the precise model, firmware, and coordinator software explicitly support the required Bitcoin multisig policy and each card has a different key.

Ballet cards

Ballet-style physical wallets are designed primarily as simple, single-key Bitcoin wallets. A private key is secured under a tamper-evident covering; the card is not normally a programmable hardware signer that participates in a Sparrow PSBT multisig workflow.

Owning three loaded Ballet cards means owning three separate single-signature wallets—or three physical backups only if they represent the same key—not one 2-of-3 wallet. Do not uncover, type, or photograph a private key to force it into a multisig setup. That weakens security and can make estate recovery worse.

“Three cards” can mean three very different things

What you haveWhat it really isMultisig?
Three Tangem cards for the same walletThree ways to access the same single keyNo
Three Ballet cards, each funded separatelyThree separate single-signature walletsNo
Three supported hardware signers, each with a different seed, configured in one 2-of-3 walletOne wallet with three independent public keys and a two-signature spending ruleYes

That does not mean a Tangem or Ballet card is useless. They may be appropriate for a smaller single-signature holding, a spending wallet, or physical redundancy. The point is accuracy: they should not be presented to family as “multisig protection” when a single card or one private key can spend the Bitcoin.

The coordinator is not the key

How Sparrow Wallet works with Bitcoin multisig

Sparrow Wallet is desktop Bitcoin wallet software. In a hardware-wallet multisig setup, Sparrow is normally the coordinator: it stores the wallet’s public configuration, displays balances and addresses, builds a proposed transaction, and gathers the required signatures from the independent hardware signers. The hardware devices keep their private keys and approve the transaction on their own screens.

Sparrow creates transaction
Signer A verifies & signs
Signer B verifies & signs
Sparrow combines signatures
Bitcoin network confirms

Example: 2-of-3 using Sparrow

  1. Set up three independent compatible hardware signers, each with a different seed phrase.
  2. In Sparrow, create an air-gapped or hardware-wallet multisig wallet using the three public keystores/xpubs and the chosen 2-of-3 policy.
  3. Verify the multisig receiving address on the hardware signers before depositing meaningful funds.
  4. When spending, Sparrow creates a PSBT (Partially Signed Bitcoin Transaction). It can be passed to each signer by USB, SD card, or QR code, depending on the devices.
  5. Each signer shows the amount and destination address for human verification, then adds one signature without releasing its seed.
  6. After any two valid signatures are returned, Sparrow combines them and broadcasts the finished transaction—either directly through a trusted node or by exporting it for broadcast.

Sparrow does not replace the recovery map

The Sparrow wallet file on one computer is not enough for estate recovery, and it should not be the only copy of the wallet configuration. Keep an offline backup of the descriptor or exported multisig configuration, plus the threshold, fingerprints, derivation information, signer labels, and the location of each separate seed. An heir can then rebuild the same wallet in compatible software even if the original computer or Sparrow installation is gone.

Important operating discipline

  • Use Sparrow as a watch-only coordinator whenever possible; do not type multiple hardware-wallet seeds into the desktop computer.
  • Verify every receiving address on the hardware signers, not only on the computer screen.
  • Before signing, read the address and amount on each hardware signer’s own trusted display.
  • Keep a small test transaction in the estate plan so family can rehearse the process safely.
The information most often forgotten

Preserve the full wallet map

With a simple wallet, the seed phrase may be enough to derive addresses. With multisig, seed phrases alone may not reliably tell an heir which combination of keys, derivation path, script type, and wallet policy was used. The software may need the wallet descriptor or equivalent configuration before it can find and spend the Bitcoin correctly.

The recovery map should record

  • Wallet name and the coordinator software used (for example, the exact wallet application).
  • Whether the wallet is single signature, 2-of-3, 3-of-5, or another threshold.
  • Address/script type and derivation path.
  • Each signer’s master fingerprint and extended public key (xpub/zpub/etc.) or the exported wallet descriptor/configuration file, stored as appropriate.
  • The device model and firmware/application information that was used at setup.
  • Where each separately secured seed backup and device can be found—without putting all the secrets on one sheet.
  • Whether a BIP-39 passphrase (“25th word”) is used, and a separate method by which the authorized person can locate it.
  • A list of receiving addresses or a watch-only wallet so the estate can confirm it has rebuilt the correct wallet before spending.

A passphrase adds both protection and permanent-loss risk

A BIP-39 passphrase is not a password reset feature. A different spelling, capital letter, space, or punctuation produces a different wallet. If you use one, the succession plan must make it recoverable by the correct person without writing it beside the seed phrase.

Store data in layers

LayerCan containMust not contain
Estate letterThat Bitcoin exists; executor contact; recovery-packet location; datesAny seed, PIN, passphrase, or private key
Wallet mapWallet policy; fingerprints; public configuration; device/software instructionsAll seed phrases and passphrase together
Seed backupOne seed phrase or signer backup; signer label kept discreetOther signers’ seeds; matching passphrase beside it
Passphrase recordA separately protected passphrase or controlled access methodThe matching full seed phrase
A careful recovery process

How an authorized family should recover Bitcoin

This is a generic safety sequence, not instructions to enter a seed into any particular website or phone app. Use the actual wallet map and original manufacturer documentation. If the estate cannot identify the wallet type or its sources, stop before entering any secret and obtain independent, in-person technical guidance.

  1. Establish authority and secure the materials. The executor works with the estate lawyer. Collect the estate letter, wallet map, and the separately stored materials. Record where each item came from; do not photograph recovery words.
  2. Identify the exact wallet. Determine whether it is a single-signature wallet, a multisig wallet, a collaborative arrangement, or exchange custody. Check mainnet/testnet, wallet software, the signing policy, and whether a BIP-39 passphrase or descriptor is in use.
  3. Rebuild visibility first. Use public information—the descriptor, extended public keys, or a known watch-only wallet—to view the expected addresses and balance. This verifies that the map points to the right wallet without using every secret.
  4. Choose a clean destination wallet. Before any spend, prepare a newly created wallet for the estate or beneficiaries, with its own verified backup plan. Do not reuse the old wallet after secrets have been gathered.
  5. Make a small test transaction. Independently verify the destination address on a trusted signer display. Sign only the small test amount. Confirm it arrives and that every action has been documented.
  6. Complete the transfer deliberately. After the test succeeds and authority is confirmed, transfer the balance in a way that suits the estate’s legal and security plan. Preserve transaction records and the fair-market-value evidence needed for tax advice.

Never import a valuable seed casually

Do not type estate seed words into a website, browser extension, unfamiliar mobile app, email form, remote-access screen, or a computer somebody else controls. Do not disclose a seed phrase to a lawyer, accountant, “support worker,” or recovery company merely to prove the estate owns Bitcoin. Legitimate professionals can advise without possessing the secrets.

People before hardware

Give family a safe path, not a treasure hunt

The best plan is understandable under stress. Choose one primary executor and one technically capable Bitcoin helper, then decide what each should learn and what each should be able to access. The helper should not become the sole controller of the coins.

  1. Explain what exists. Tell the executor and intended heir that Bitcoin exists and that there is a recovery plan. Do not surprise them after death.
  2. Choose roles. Separate legal authority, family beneficiary, and technical helper where that reduces risk. Confirm your lawyer’s advice on incapacity and estate administration.
  3. Teach the warning signs. No legitimate recovery requires a seed phrase by email, text, website form, phone call, remote-access session, or social-media message.
  4. Practice a controlled recovery. Rebuild a test wallet or small-value wallet with the people who will need to act. Do not practise by exposing the main wallet’s seeds to unnecessary devices.
  5. Leave time for verification. Estate recovery should be slow and deliberate. First recreate a watch-only view, verify known addresses and balances, and only then prepare a small test spend.

Do not rush because someone says funds are in danger

After a death or incapacity, scammers may impersonate exchanges, wallet companies, lawyers, government agencies, or “blockchain recovery specialists.” Pause. Use phone numbers and websites independently obtained—not links or phone numbers sent in a message. Discuss the plan in person or by a verified channel.

For an executor who is not technical

Leave a one-page first-action sheet: “Do not move Bitcoin. Do not disclose recovery words. Contact [named trusted person] using the number in the estate letter. Locate the sealed recovery packet and lawyer’s documents. Verify authority. Read instructions before connecting any device.” Keep the technical instructions in the recovery packet, not in the will.

A backup untested is only a hope

Test recovery without taking unnecessary risks

Hardware fails, handwriting fades, businesses change, and people forget. A periodic test turns an assumption into evidence. Use a small separate test wallet where possible, or rebuild the main wallet only in an offline, controlled setting with the minimum people required.

Annual review

  • Devices power on and PINs work.
  • Seed plates/paper backups are intact and legible.
  • Safe, safe-deposit, or storage access still works.
  • Executors and contacts are current.
  • Wallet software can still import the descriptor/configuration.

After every major change

  • Record new wallet policy or signer replacement.
  • Update the non-secret estate letter date.
  • Confirm old backups no longer expose active funds.
  • Test a small receive and spend from the new wallet.
  • Verify the watch-only balance and known receiving addresses.

Replace a compromised seed—do not merely update software

If you believe a seed was weakly generated, copied, photographed, entered into a suspect device, or exposed to an unknown party, treat it as compromised. Create a completely new wallet with new independent seed(s), verify the destination, and move the funds. A firmware update cannot make an already-exposed private key secret again.

Avoid predictable failure

Top 10 Bitcoin estate-planning mistakes

  1. Putting secret words in the will. A will gives legal instructions; a seed phrase gives immediate spending control. Keep them separate.
  2. Giving nobody notice that Bitcoin exists. A perfectly hidden backup is useless if heirs never look for it.
  3. Leaving only a hardware wallet. Devices fail, PINs are forgotten, and models disappear. The recovery material and written plan matter more.
  4. Calling copies of one seed “multisig.” Multiple cards or devices holding the same key improve availability, not the Bitcoin spending rule.
  5. Saving every multisig seed but no wallet descriptor. The heirs may not know the script type, threshold, fingerprints, or derivation details needed to find the wallet correctly.
  6. Using a BIP-39 passphrase that no authorized person can recover. A passphrase typo creates a different wallet. It must be carefully documented through a separate controlled process.
  7. Keeping recovery words in photos, email, cloud notes, or chat messages. Digital convenience creates a theft path that can outlive the owner.
  8. Choosing complex custody because it sounds impressive. A 3-of-5 setup that no family member can execute can be less safe in practice than a tested 2-of-3 or simple single-signature plan.
  9. Never testing. Recovery instructions, devices, safe access, contacts, and software all change. A plan needs an actual rehearsal.
  10. Acting under pressure after a death. Bitcoin does not expire. “Move it now” messages are a classic way scammers push families into exposing keys.
Print, discuss, and revisit

Estate-plan checklists

Owner checklist

  • I have made a Bitcoin inventory that identifies every wallet without exposing secrets.
  • My will and estate letter identify who should be contacted and who has legal authority.
  • No will, email, cloud document, phone note, or photo album contains my seed phrase or passphrase.
  • Each multisig signer has an independent seed and separate storage location.
  • I have preserved the wallet descriptor/configuration, threshold, fingerprints, derivation details, and software information.
  • I have a clear plan for any BIP-39 passphrase and have not stored it beside its seed.
  • I have tested recovery using a safe, controlled process and recorded the date.
  • I review the plan at least annually and after a device, address, signer, family, or legal change.

Executor / family first-action checklist

  • Do not share words, PINs, photographs, wallet files, or device screens with anyone.
  • Do not act on emails, texts, advertisements, or unsolicited recovery offers.
  • Locate the estate letter, confirm legal authority, and contact the named trusted helper through a verified method.
  • Find the sealed recovery map and separate key locations; do not combine materials until the written process says to do so.
  • Rebuild watch-only visibility first and compare known addresses/balance records.
  • Before moving significant Bitcoin, have the recovery reviewed independently and make a small test transaction.
  • Document each action for the estate file, but never include secret words in that file.

Printable non-secret estate worksheet

Use this with your lawyer or executor. Do not write seed phrases, passphrases, PINs, private keys, or full recovery words on this sheet.

Executor:
Technical helper:
Estate lawyer:
Date reviewed:
Wallet nickname(s):
Custody model (single-sig / 2-of-3 / other):
Non-secret recovery-map location:
Next review due:

Recovery drill record

Test wallet / harmless test amount:
People who completed the drill:
Watch-only view matched known addresses?
Date:
Small test spend successful?
Changes needed before next review:
Further reading

Sources and technical references

Disclaimer

This page is general education, prepared for BTC.TedLee.ca. It is not individualized legal, tax, estate, investment, or cybersecurity advice, and it does not endorse any wallet, device, recovery service, lawyer, or security arrangement. Bitcoin transactions are irreversible. Laws, probate rules, tax treatment, wallet software, hardware, and security practices can change. Seek qualified Canadian legal and tax advice before relying on an estate arrangement, and obtain independent technical assistance before moving substantial Bitcoin.

Security warning: Never disclose a seed phrase, private key, or passphrase to a website, app, phone caller, email sender, text message, or “support” worker. No legitimate helper needs it to give general advice.