Practical guidance

How to pass on a seed phrase without putting it in your will

A seed phrase is a bearer credential: whoever holds it controls the wallet completely, immediately, and without further proof. That makes it the hardest asset to bequeath, because every method of giving it to heirs also risks giving it to them — or to someone else — too early.

Last reviewed 6 September 2026Legatus · Digital Legacy Vault

Why a seed phrase does not belong in a will

A will can become a public record during probate, and is read by court staff, executors and potentially opposing parties long before assets are distributed. A seed phrase written into a will is therefore exposed to everyone who handles that document, any one of whom could empty the wallet without leaving a trace.

The same objection applies to any document that must be read by others to be acted on. A will should name the existence of your virtual digital assets and point to where access instructions are held. It should never contain the credential itself.

Why telling someone now is not a plan

Sharing a seed phrase with a trusted person converts a cryptographic guarantee into a social one. It works exactly as long as that relationship does, and it cannot be undone — a person who has seen a seed phrase cannot un-see it, so revoking access means moving every asset to a new wallet.

The methods that actually work

Four approaches avoid premature exposure: splitting the secret so no one person holds it, requiring multiple signatures to move funds, sealed instructions held by a professional, or an encrypted vault that releases on verified conditions. Each trades technical difficulty against how much you must trust any individual.

MethodStrengthWeakness
Shamir split across several holdersNo single holder can act aloneHeirs must understand how to reassemble it under stress
Multisig wallet (e.g. 2-of-3 keys)Enforced on-chain, no service to trustDemands real technical competence from heirs
Sealed instructions with a lawyerFamiliar, legally integratedThe lawyer, or their staff, physically hold the secret
Encrypted vault with verified releaseNo one holds anything readable in advanceDepends on the service continuing to exist
Whichever you choose, test it

The most common failure is not a broken mechanism but an untested one: instructions nobody can follow, a hardware wallet whose PIN was never recorded, a split secret where one share was lost years ago. Walk an heir through the process while you are alive, using a wallet holding a trivial amount.

What to write down, and where

Record the inventory separately from the credentials. A list of which exchanges, wallets and hardware devices exist is enormously useful to heirs and is not itself dangerous. The seed phrases and passphrases that open them belong somewhere access is conditional, not somewhere they can simply be read.

Heirs who know that a Ledger exists and which exchange accounts were held can pursue those assets even if one access route fails. Heirs who know nothing cannot begin, and assets nobody knows about are indistinguishable from assets that never existed.

How Legatus handles this specific problem

Legatus encrypts a seed phrase in the owner’s browser and wraps the vault key separately for each nominee, so no nominee holds anything readable in advance. Release requires two of three nominees to confirm independently, administrative review of a death certificate, and a 72-hour hold.

The honest limitation: this depends on Legatus continuing to exist, and two colluding nominees are the weakest point in the model. For a holding large enough that its loss would be serious, multisig with a Legatus vault holding the supporting instructions is a better arrangement than either alone.