Yes, and it is the arrangement most likely to produce a fiduciary problem. A trustee personally holding a device concentrates trust assets behind one object, one person, and one memorized passphrase, with no third party able to attest to any of it. Where the instrument permits delegation to a qualified custodian, that is usually the more defensible choice.
Part of our guide: Digital Asset Custody.
The short version
- Nothing prohibits it. The question is whether it meets the prudent trustee standard in your circumstances.
- The instrument must authorize holding digital assets and, ideally, delegating custody. Silence is not permission.
- A device in a trustee’s personal possession creates commingling risk by appearance, even where the trustee is scrupulous.
- The failure mode is access loss, not theft: a passphrase in one person’s memory defeats the device the trust legally owns.
- If a trustee does hold one, the compensating controls are a written custody policy, a co-signer, and a rehearsed successor path.
What makes it defensible or not
Authority. The instrument has to permit holding digital assets, and holding key material is a further step some documents do not contemplate. A trustee holding a device under an instrument that never mentions any of it is acting outside their authority before performance is discussed.
Proportionality. A modest holding in a device with a documented recovery plan is a different proposition from a family’s principal asset behind one hardware wallet in a trustee’s desk drawer.
Whether delegation was available. If the instrument permits delegating custody to an institution and the trustee chose personal custody anyway, that choice needs a written reason. Absent one, hindsight supplies a bad reason.
Separation. The device must be identifiably trust property, held separately from the trustee’s own assets, with records showing which is which.
The failure this actually produces
Not theft. Access loss.
A hardware wallet protected by a passphrase held only in the trustee’s memory is a single point of failure that survives no adverse event. If that trustee dies, is incapacitated, or is simply unreachable, the trust owns assets nobody can move, and the loss is permanent.
The federal case that makes the point cleanest involved a seized device rather than a trust: the government lawfully held the hardware and could not open it, because the passphrase was elsewhere. Possession of the object conferred nothing. Read as a fiduciary scenario, a successor trustee inheriting a drawer with a device and no passphrase is in exactly that position.
This is squarely within a trustee’s control, which is what makes it a liability question. A court reviewing a total loss caused by an administrative choice is on very different ground than one reviewing a price decline.
The appearance problem
Even a careful trustee holding a device personally creates an evidentiary weakness. There is no third party who can attest that the assets are trust property. The proof is whatever the trustee wrote.
Compare a custody account opened in the trust’s name: a regulated institution performed checks and recorded the trust as the account holder, and that record exists independently of the trustee. It is evidence a fiduciary cannot manufacture for themselves, and it is the strongest available answer if beneficiaries later dispute what was held or on whose behalf.
If a trustee does hold one
Sometimes there is no practical alternative: the instrument forbids delegation, or no custodian will take the asset. Then the compensating controls matter.
A written custody policy covering where the device lives, who has access, how it is backed up, and what the recovery path is.
No memorized-only secrets. Any passphrase must exist somewhere a successor can reach without the trustee.
A co-signer or a multi-signature arrangement, so the trust is not one person away from inaccessible.
A rehearsed successor path, tested with a real transaction by the person who would have to perform it.
Records that identify the device as trust property, with the assets on it inventoried and dated.
Beneficiary awareness, in writing, that this is the arrangement and why.
What I actually see
Family trustees take this on without recognizing that the role carries personal liability, and they apply the same habits they use for their own holdings. Those habits are usually built for one person who knows everything, which is precisely the wrong design for a fiduciary who might not be available.
Corporate trustees have generally worked this out and respond by declining the asset or requiring a named custodian. That looks conservative and is a rational answer to a standard nobody has settled.
The question I would put to any trustee holding a device: if you were unavailable tomorrow, could the successor trustee move these assets using only what exists today, without asking you anything? If the answer is no, the arrangement has an unmanaged risk that dwarfs anything in the market.
Where this goes wrong
The trustee is the single point of failure and the records cannot demonstrate otherwise.
The specific failures: a passphrase held only in memory. A device in a home safe a successor cannot open without a court order. No written record identifying the device as trust property, so an estate cannot tell trustee assets from trust assets. Delegation permitted by the instrument and never considered. And a successor trustee who was never told the device exists.
The decision rule
- Read the instrument for authority to hold digital assets and to delegate custody.
- If delegation is permitted, prefer a qualified custodian, and record the reasoning either way.
- If holding personally, write the custody policy first.
- Never allow a memorized-only secret.
- Add a co-signer so the trust is not one person away from frozen.
- Rehearse the successor path with the successor, using a real transaction.
- Record the device as trust property, inventoried and dated.
Where this sits
This is where trustee duties meet custody practice. Trustee liability is the exposure being managed. Whether the trust can hold the assets is the authority question underneath. Key succession is the specific plan a hardware-wallet arrangement needs. Qualified custody vs self-custody is the same trade without the fiduciary overlay.
A trustee holding a device has taken on the hardest version of the custody problem, with personal liability attached and a beneficiary who can ask questions later.
Sources
- Wyoming Uniform Trust Code, Wyo. Stat. Ann. Title 4, Chapter 10 (Wyoming Legislature)
- Uniform Prudent Investor Act (Uniform Law Commission)
- Uniform Fiduciary Access to Digital Assets Act
- Wyoming digital asset statutes, Wyo. Stat. Ann. §§ 34-29-101 to 34-29-102
- NIST, Special Publication 800-57, Recommendation for key management
- 17 CFR 275.206(4)-2, Custody of funds or securities of clients by investment advisers
Related
- Can a trustee be liable for crypto losses?
- Can a trust hold Bitcoin, Ethereum, or other digital assets?
- Private key succession planning
- Qualified custody vs self-custody for crypto wealth
- How to build a crypto custody policy
- Crypto trust structures
Last updated: 3 August 2026.
This article is general education, not legal, tax, or investment advice. Fiduciary obligations depend on your instrument, your jurisdiction, and your facts. Talk to a qualified estate attorney about your own situation.
