Self-custody works because only the holder of a key can move the assets. That is a security property in life and a disposal problem in death, and it is the one part of holding digital assets that cannot be fixed after the fact by anybody, at any price.
A key held only by you means nobody can take your holdings. It also means nobody can find them. There is no institution to write to, no account to claim, no process by which a family member proves entitlement and receives a balance. The keys either exist somewhere findable or the assets are gone, and there is no third state.
That is not a flaw in the design; it is the design working exactly as intended. But the design was built to solve the problem of a third party seizing or losing your assets, and it was not built to solve the problem of you not being there. The second problem is yours to solve, and the tools for it are procedural rather than technical.
The scale of the unsolved version is worth stating. A meaningful proportion of the total supply of the oldest digital assets is considered permanently unreachable, and while some of that is lost keys during life, some of it is holders who died without leaving anything findable behind. That outcome is common, and it is entirely preventable.
There is no institution to write to and no account to claim. The keys are findable or the assets are gone, and there is no third state.
The problem is harder than it appears because it has two failure modes that pull in opposite directions. The first is that nobody can find or use the keys after your death, and the holdings are lost. The second is that somebody can find and use them while you are alive, and the holdings are stolen.
Every naive solution fails one of the two. Writing the recovery phrase down and telling a family member where it is solves the first and creates the second. Telling nobody anything solves the second and guarantees the first. Any plan that does not consciously address both is solving half the problem while feeling like it solved all of it.
The framing that helps is to think in terms of a condition rather than a secret: the access should become available when a specific thing is true, and not before. Everything below is a way of implementing that condition with different trade-offs between complexity and robustness.
Three components, and most plans have only the first. An inventory: what exists, where, and roughly how much, so that the person handling your affairs knows there is something to look for. Without it, holdings can be lost simply because nobody knew to ask, which is the most avoidable failure of all.
Access instructions: how to reach each thing, written for somebody who does not know what any of it is. Not a recovery phrase in an envelope, but the procedure, in ordinary language, assuming no familiarity with the vocabulary. The person who executes this may be a lawyer or a spouse with no technical background, and the instructions have to work for them.
And the legal layer: whatever your jurisdiction requires for the assets to pass to the people you intend. That part is genuinely jurisdiction-specific, it interacts with succession law that differs enormously between countries, and it is the part where a qualified professional in your own jurisdiction is not optional advice but the actual requirement.
The single most useful structural idea is to separate what exists from how to reach it. An inventory containing no secrets can be stored with your other important documents, shared with the person handling your affairs, and updated whenever something changes, all without any security risk at all.
The access material, which is the dangerous part, can then be handled separately and with much stronger protection, because it does not need to be readable or updatable in the same way. The inventory tells the executor that something exists and where the access procedure lives; the access procedure is protected by whichever mechanism you chose.
This separation also solves a practical problem that pure secret-splitting does not. Holdings change over time, venues change, wallets get replaced, and a plan that requires reconstructing a secret every time anything changes will not be maintained. An inventory that can be updated freely, pointing at an access mechanism that rarely changes, will be.
The classic mechanism is to divide the access material into parts, distributed so that a defined number of them together can reconstruct it and any smaller number reveals nothing. Split into five with three required, no two people can collude to reach it, and losing two parts does not lose the holdings.
The mathematics of this is well established and the implementations are widely available. The difficulty is entirely human: the holders must keep their parts for years without losing them, must not know enough to be worth attacking individually, must be findable when needed, and must be told clearly what to do when the time comes without being told enough to act early.
The most common failure is not cryptographic but organisational: parts distributed to people who moved, forgot, threw them away during a house move, or died first. A split that is never rehearsed is a split whose failure you will never discover, and the discovery happens at the worst possible time to the people least equipped to deal with it.
A multi-signature arrangement can serve the same purpose more elegantly, because it never reconstructs a single secret at all. Assets held under an arrangement requiring two of three signatures can be structured so that you hold one, a trusted person holds another, and a third sits with a professional or in a secured location.
During your life you can transact with your own key plus one other, and after your death the other two can act together without you. Nobody ever holds enough alone, no secret is ever reassembled into a single vulnerable object, and the arrangement is visible on the chain rather than depending on a document nobody may find.
The cost is complexity: setting it up correctly requires care, the participants need to understand their role, and recovering from the loss of any one part requires a procedure that must itself be documented. It is the strongest structure available and it is genuinely more work, and it suits substantial holdings better than modest ones.
A third family of approaches makes access conditional on time rather than on people. Various mechanisms allow access to open after a period during which you have not signalled that you are still there, whether through a service, through a contract, or through a lawyer holding instructions to open a sealed item after a period of confirmed non-contact.
The attraction is that they require no ongoing trust in another person's discretion. The weakness is that they require ongoing action from you, indefinitely, and any mechanism that fails if you forget to press a button for a few months has introduced a new way for things to go wrong that did not exist before.
Where they work best is in combination rather than alone: a time condition governing when a professional is instructed to act, rather than a fully automated release of funds. The human step provides judgement that a timer cannot, particularly around the question of whether the triggering condition is actually true.
Assets held on a platform rather than under your own keys follow a completely different path, and it is closer to a conventional financial account. There is an institution, there is a process, and the estate of a deceased account holder can generally make a claim supported by the documentation that jurisdiction requires.
That is genuinely simpler and it is one of the honest advantages of custodial holding, particularly for people whose heirs have no technical background. The trade-off is the ordinary custodial one, which is covered elsewhere, and neither side of it is obviously right for everybody.
What it does mean practically is that the inventory matters even more for platform holdings, because they are recoverable but only if someone knows they exist. An account nobody knows about is not claimed by anybody, and platform holdings that nobody knows to look for are as effectively lost as a burned recovery phrase.
Platform holdings are recoverable through a process. They are not recoverable by an heir who never knew the account existed.
The step that separates plans that work from plans that exist is rehearsal, and almost nobody does it. Take the person who will handle your affairs, give them the instructions as written, and have them attempt to recover a small holding without your help. Watch where they get stuck.
The results are consistently humbling. Instructions that seemed complete assume vocabulary the reader does not have, reference a device they cannot find, or require a step you do without thinking and never wrote down. Every one of those is a total failure in the real event, because the real event has no you to ask.
Rehearsing also has a secondary benefit that people underestimate: it forces the conversation. Many plans fail because the person who was supposed to act did not know they had been designated, did not take it seriously, or did not understand that time might matter. A rehearsal makes all three of those visible while they are still fixable.
Write the inventory first, today, containing no secrets: what exists, roughly how much, where the access procedure is documented, and who to contact. That one document eliminates the single most common failure, which is nobody knowing there was anything to look for, and it carries no risk at all because it contains nothing usable.
Then choose an access mechanism proportionate to the size of what you hold. Modest holdings do not justify a multi-signature arrangement with professional participants; substantial holdings do not deserve a phrase in a drawer. And then speak to a qualified professional in your own jurisdiction about the legal layer, because succession law is where the general advice in an article stops being useful.
Finally, put a date in the calendar to review it annually. Holdings change, people change, devices are replaced, and a plan written once and never revisited describes a situation that stopped being true years ago. The review takes twenty minutes and it is the difference between a plan and a document.
Nothing automatic. There is no institution to write to and no account to claim: the keys either exist somewhere findable or the assets are unreachable permanently. A meaningful proportion of the oldest assets is considered lost, and some of that is holders who died leaving nothing findable.
Because it has two failure modes pulling opposite ways. Nobody can access the keys after your death and the holdings are lost; or somebody can access them during your life and they are stolen. Every naive solution fixes one and creates the other.
Three things: an inventory of what exists and where, access instructions written for somebody with no technical background, and whatever your jurisdiction's succession law requires. Most plans have only the first, and many have only the second in an unsafe form.
Not as your only plan, because it solves the death problem by creating a theft problem. Better structures make access conditional: split the secret across several people so that a defined number together can act, or use a multi-signature arrangement where no single party ever holds enough.
The access material is divided into parts so that a defined number together reconstruct it and fewer reveal nothing. Split into five with three required, no two can collude and losing two parts loses nothing. The failures are organisational: people move, forget, or discard their part.
It is the strongest structure because no single secret is ever reassembled. Two of three signatures lets you transact in life with one other party, and lets the other two act together after your death. The cost is genuine complexity and it suits substantial holdings better than modest ones.
Yes, and that is an honest advantage of custodial holding. There is an institution and a process, and an estate can generally claim with the documentation the jurisdiction requires. But an account nobody knows about is never claimed, so the inventory matters even more.
Rehearsal. Give your instructions to the person who will act and have them recover a small holding without your help. Instructions that seemed complete routinely assume vocabulary they lack or a step you do without thinking. Every one of those is total failure in the real event.