104 · The long haul · lesson 4 of 5
Building a Recovery Kit — the document your family can actually follow
One short, plain-language document ties the whole plan together: what you have, where the pieces are, and what to do. Then you rehearse it with a real person, and wrap it in the legal authority to act.
The previous lesson showed why Bitcoin gets lost at inheritance: it isn’t findable, and it isn’t followable. This one is the fix, in three parts — write the Kit, rehearse it, and wrap it in the right legal container.
None of it is technical work. It is writing, testing, and filing. It is also the part almost everyone skips, which is exactly why it’s worth the afternoon.
Build a Recovery Kit — the one document that ties it together
The heart of your plan is a plain-language Recovery Kit: a short document you write for your family and store with your estate papers. It doesn't need to be technical. It needs to answer, in order, "what is this, where are the pieces, and what do I do?"
Here's what to put in it:
- That Bitcoin exists — and a rough sense of how much, so your family takes it seriously.
- Which wallet app to use, by name, with a note on where to download it.
- The wallet fingerprint (XFP) — a short code, like
7A3F2C10, that the wallet shows to identify which wallet these keys belong to. It helps confirm your heir is rebuilding the right one. - The derivation path — a short technical string (something like
m/84'/0'/0') that tells the app how to find your coins inside the seed phrase. Most modern wallets use a standard path, but writing yours down removes all guesswork. - The descriptor — for multisig, include the full descriptor text (the file that describes how your keys form the wallet). This is essential; without it, recovery can fail even with every key in hand.
- Where each backup lives — the exact location of each seed-phrase backup, each hardware wallet (the small physical device that stores a key), and, if you use one, the passphrase backup. Be specific enough that someone who doesn't live with you can walk in and find it.
- The date you last tested it — so your family knows the plan is current, not a decade stale.
- Who to call for help — the name and contact for your attorney, your collaborative-custody partner if you have one, and any trusted technical helper.
The one thing you never put in the Recovery Kit: the actual seed-phrase words or the passphrase itself. The Kit is a map to your backups, not a copy of them. Anyone who reads the Kit alone should learn how the recovery works, but should still need to physically reach your separately-stored backups to move a single satoshi. Keep the words on their metal backups, in their own secure spots; keep the Kit pointing to them.
One more test: hand the draft to a friend who knows nothing about Bitcoin and ask them to explain what they'd do. Wherever they get confused, rewrite it. You're writing for them, not for yourself.
What people do instead — and where each one breaks
A Kit is more work than the alternatives, and the alternatives are what almost everybody actually does. They are worth walking through, because each one fails at a moment nobody will be around to correct it:
- Telling one person, out loud. The most common plan there is. It survives exactly as long as their memory of a conversation they did not know was important, and it gives them no way to check whether they have remembered it right.
- Putting the seed words in the will. A will becomes a public document when it goes through probate, so this publishes your keys to anyone who asks for a copy. It also freezes them: a will you update every few years is a poor home for something you might change next month.
- Handing the seed to an heir now. This does work, and it also hands them your Bitcoin today — along with the job of keeping a secret they did not ask for, in a house you cannot inspect. It is a real option for some families and it should be a decision rather than a shortcut.
- A dead-man's-switch service that emails your secrets if you stop checking in. It means a company holds your keys, subject to their outages, their acquisition, their breach, and a false positive while you are on holiday. Everything this guide says about custody applies, plus a timer.
- Splitting the words between two heirs so neither can act alone. Now your Bitcoin depends on two people co-operating at the worst moment of their lives. Families that get on today are not reliably families that get on during a probate. If you want that property, multisig gives it to you with rules instead of goodwill.
- Leaving nothing, and assuming they will work it out. They will find a metal plate and a device with no name on it. This is not a hypothetical failure mode — it is the single largest category of permanently lost Bitcoin.
What the Kit does that none of them do is separate the two secrets. Where things are, and how to use them, is information your family needs and an attacker cannot spend. Keeping those apart is what lets you be generous with one and ruthless with the other.
Rehearse it — a plan you never tested is a guess
Documentation that has never been used is the quiet failure that catches almost everyone. The fix is a rehearsal: while you're alive and well, you walk a trusted person through the whole thing as a dry run.
It's simple. Hand them the Recovery Kit — nothing else, just what they'd actually discover someday. Then watch them try to:
- find each backup and device using only the Kit's directions,
- install the right app and load the wallet as watch-only first — a mode that lets them see the balance and confirm they've got the right wallet without touching the secret keys, which is a safe way to check they're on track,
- and then move a tiny test amount to prove the full recovery works end to end.
Your job during the rehearsal is to stay quiet and only answer when the Kit is unclear — because every question they ask is a gap in your instructions. Fix each gap on the spot. Then do this again after big life changes (a new heir, a move, a change to your setup) and otherwise every few years, so the plan doesn't drift out of date.
This one habit is what separates plans that work from plans that don't. Test it now, while you can still fix what breaks.
Wrap it in the right legal container
Your Recovery Kit handles the how. A legal document handles the authority — who is officially allowed to act, and when. The common wrapper for Bitcoin is a revocable living trust: a legal arrangement you control while alive and can change anytime, that names who takes over and gives them the authority to carry out your plan.
The trust doesn't usually hold the Bitcoin directly. Instead it holds the instructions and names a trustee — often a family attorney experienced with digital assets — who has the authority to coordinate the recovery, work with your collaborative-custody partner if you have one, and act as a neutral party if family members disagree. A well-chosen wrapper also lets you keep the Recovery Kit sealed until it's actually needed, which resolves the tension between "findable by my family" and "not findable by a burglar." Name a backup trustee too, in case your first choice can't serve.
A quick, honest caveat: this is not legal advice. Estate law varies by where you live, and ordinary do-it-yourself wills often handle Bitcoin poorly. For anything beyond a small amount, sit down with an estate attorney — ideally one who has handled digital assets before.
And you don't have to assemble all of this alone. Dedicated Bitcoin-inheritance tools and services now exist specifically to help you build, store, and test a plan like this — a reasonable option if you'd rather have expert structure than start from a blank page.
Never write the actual seed words or the passphrase into the Recovery Kit. The Kit is a map to your backups, not a copy of them. Someone who reads the Kit alone should understand exactly how the recovery works and still need to physically reach your separately-stored backups to move a single satoshi.
- I wrote a plain-language Recovery Kit listing the wallet app, fingerprint (XFP), derivation path, descriptor for multisig, and where every backup and device lives — but never the seed words or passphrase themselves.
- A non-technical friend read the draft and could explain what they would do; I rewrote everywhere they got stuck.
- I have done a full rehearsal: a trusted person found the pieces and moved a test amount using only the Kit, and I fixed every gap they hit.
- The Kit is stored with my estate papers, wrapped in a will or revocable living trust, with a trustee and a backup trustee named — reviewed with an attorney.
- I dated the plan when last tested, and I re-test it after big life changes and otherwise every few years.
Check yourself
2 questions on what this lesson just covered. Nothing is scored, recorded or saved — it isn’t sent anywhere and it’s gone when you close the tab.
1Your heirs find a metal plate with your seed words on it and load them into a wallet app. It shows an empty wallet. What is the most likely explanation?
This is the most common way Bitcoin is lost to death, and it is why the passphrase deserves its own line in your plan. A passphrase opens a separate, hidden wallet; the seed words on their own open a different one, which looks entirely normal while being empty. The family concludes there was nothing there and stops looking. If you use one, it has to be backed up and inheritable, stored somewhere the seed is not, and your instructions must state plainly that it exists — the fact of it, never the passphrase itself. "It is only in my head" is not a plan.
2Your multisig is solid: three keys, three locations, and your heirs know exactly where each one is. What is still missing?
For multisig the keys are not enough. Your heirs also need the descriptor: a short configuration file saying which keys make up the wallet and the technical settings that go with them. Without it, even somebody holding every key can struggle to rebuild the wallet, because no software can work out from keys alone what wallet they belong to. It holds no private keys and cannot spend anything, so it is safe to include in your written instructions — and it has to be. The wider point: for inheritance the problem is almost never security, it is findability. A rock-solid wallet with no instructions is worse than a simple wallet with good ones.
✓ Last verified: July 29, 2026