Planning for a hardware wallet means planning for the recovery material, because the device itself is a replaceable convenience and the recovery words are the asset. Families reliably protect the wrong object: the wallet goes in the safe and the seed backup ends up in a desk drawer. The other thing worth knowing early is that the law which helps fiduciaries reach online accounts does almost nothing here, and for a structural reason most people never learn.
Part of our guide: Digital Asset Custody.
The short version
- The device is replaceable. The recovery material is not. Protect accordingly.
- A hardware wallet wipes itself after enough wrong PIN attempts, so a helpful heir can end access in an hour.
- A passphrase creates a hidden wallet. Heirs who recover the words alone see an empty balance and stop looking.
- Digital asset access law works through custodians, and self-custody has none. No statute reaches your device.
- Document the device’s existence, the location of its recovery material, and who holds authority. Never the words themselves.
Why the law does not help here
The Revised Uniform Fiduciary Access to Digital Assets Act, adopted in most states, is the mechanism that lets a personal representative or trustee obtain access to online accounts. Its entire machinery runs through one defined party. Nevada’s enactment is representative:
“‘Custodian’ means a person that carries, maintains, processes, receives or stores a digital asset of a user”
(NRS 722.090).
A hardware wallet in your desk has no custodian. There is no company to serve with letters testamentary, no compliance department to review a trust instrument, and no disclosure obligation for anyone to satisfy. The statute that solves the email problem and the exchange problem has no application to the drawer.
That is the structural reason self-custody puts the entire burden on private planning. For custodied assets, the law provides a path. Here, whatever you write down is the path.
The two mechanics that destroy access
The PIN counter. Hardware wallets erase their stored key material after a set number of incorrect PIN entries. The design is correct and protects a stolen device. It also means an heir working through birthdays and anniversaries can permanently wipe a device holding a substantial position, in an afternoon, while trying to help. The device can be restored from the recovery words. Without them, the wipe is the end.
The passphrase. Many wallets support an additional word or phrase on top of the recovery seed, creating a separate hidden wallet. Recover the seed alone and you get a real, functioning, empty wallet. Nothing indicates anything is missing. This is the failure that looks like success, and it is the one I would flag hardest to any family using the feature. If you use a passphrase, it has to be recorded wherever the words are recorded, and its existence has to be stated plainly in the instructions.
What has to be documented
That the device exists at all. Manufacturer, model, and where it lives. A fiduciary who never learns of a device cannot administer it.
Where the recovery material is, described by location and access procedure. Never reproduced.
Whether a passphrase is in use, stated explicitly, with where it is recorded.
How many devices there are. Multiple devices are common and partially documented sets are worse than none, because a fiduciary who finds one concludes the search is finished.
What is actually on it, approximately. The estate needs to know whether it is looking for a test wallet or the family’s largest holding.
Who has legal authority, and the location of the documents that grant it.
The first call. Name a specific person, so the family has an alternative to experimenting.
None of that belongs in the will, which can become a public record. It belongs in the private letter of instruction, with authority granted separately in the estate documents.
What I actually see
The device is treated as the valuable object. It sits in a safe, sometimes in a safe deposit box, while the paper backup of the recovery words is in a drawer or a filing cabinet. The security effort went to the replaceable item.
The second pattern is the undocumented second device. An old wallet from an earlier setup, still holding a position, that nobody remembers and no instruction mentions. Families find one device, restore it, see a balance, and stop. Devices should be inventoried, including retired ones, and any device that is genuinely empty should be recorded as empty so nobody wonders later.
The third is the plan that assumes technical competence. Written by someone fluent, for readers who are not, using terms they have never encountered under circumstances where nobody is calm. Instructions that begin “restore from your seed” assume knowledge the reader does not have.
The exercise worth doing once: set up a device with a small amount, write the instructions, hand them to the person who would inherit, and have them recover it without help. Every place they stall is a defect in the plan, and finding those defects with fifty dollars at stake is considerably better than finding them later.
Where this goes wrong
The owner plans for theft and never plans for absence.
The specific failures: a seed backup stored in the same building as the device, so one event takes both. A passphrase that exists only in the owner’s memory. A PIN nobody else knows, on a device that wipes. Recovery words written into a will. Instructions that assume the reader knows what a wallet is. An undocumented second device. And a device whose location is known while its recovery material is not, which leaves the family with a paperweight they cannot open.
The decision rule
- Inventory every device, including retired ones, and record what each holds.
- Separate the device from the recovery material, in locations that fail independently.
- Record the passphrase wherever the words are recorded, and state that one exists.
- Write instructions for a non-technical reader, in order, starting with what to avoid.
- Name the first call, so nobody improvises with the device.
- Grant authority in the estate documents and keep the operational detail out of them.
- Test the recovery once with a small amount and the person who would actually do it.
- Review annually, and after any new device, firmware change, or move.
Where this sits
The device is one piece of a larger arrangement. Seed phrase storage covers the material that actually matters. Private key succession planning covers the access design. Custody covers the alternative of holding some of the position where an institution already has a fiduciary process.
That alternative is worth pricing honestly rather than dismissing. A qualified custodian replaces this entire design problem with an onboarding procedure that already exists, at the cost of a fee and a counterparty. Many families end up with both: an institutional core that a fiduciary can reach through normal channels, and a self-custodied portion with a documented plan around it. Deciding that split deliberately, with the estate attorney and whoever handles the custody arrangement in the same conversation, is worth more than optimizing either half alone.
Sources
- Nevada Revised Statutes Chapter 722, Fiduciary Access to Digital Assets (Nevada Legislature)
- Michigan Fiduciary Access to Digital Assets Act, Act 59 of 2016
- Revised Uniform Fiduciary Access to Digital Assets Act (Uniform Law Commission)
- NIST Special Publication 800-57 Part 1 Rev. 5, Recommendation for Key Management (National Institute of Standards and Technology)
- Wyoming digital asset statutes, Wyo. Stat. Ann. §§ 34-29-101 to 34-29-103
- IRS, Digital assets
Related
- Seed phrase storage for estate planning
- What to do if heirs find a hardware wallet
- Private key succession planning
- Can a trustee hold a hardware wallet?
- What is a digital asset letter of instruction?
- Crypto estate planning
Last updated: 3 August 2026.
This article is general education, not legal, tax, or investment advice. Digital asset access law varies by state. Talk to a qualified estate attorney about your own situation.
