Self-custody means the risk stays with you.
Most HNW holders set up a hardware wallet years ago and haven't touched the security architecture since. Exchange accounts run on SMS 2FA. Seed phrases live in a note on iCloud. One well-crafted email and it's gone — no recourse, no insurance, no customer service.
The losses aren't dramatic. They follow the same four patterns. Most are preventable — which is why they're so frustrating after the fact.
A fake MetaMask update. A Ledger "security alert" that harvests the seed. A spoofed Coinbase email that redirects to a login page designed to capture your 2FA code in real time. These campaigns are targeted — they know you hold crypto before they send the first message. The technical sophistication keeps increasing. A six-digit 2FA code intercepted mid-transit is gone before you know it happened.
Photographed recovery sheets. Seeds stored in a password manager that syncs to the cloud. Screenshots in iCloud backup. A note sent via email "just in case." The seed phrase is the wallet — whoever has it, has the funds. Most people treat it like a password. It isn't. A password can be changed. A compromised seed cannot be invalidated without moving every coin to a new wallet first.
Not your keys, not your coins. FTX was not the first and will not be the last. Exchange insolvency, regulatory seizure, or outright fraud can freeze withdrawals before you can act. Holders who kept significant balances on centralized exchanges for convenience discovered that convenience was the risk. The mitigation isn't complicated — it requires actually moving to cold storage and maintaining it.
You die holding a Ledger, a seed phrase on paper in a drawer, and no documentation your executor can use. The wallet balance is irrecoverable. Your estate attorney cannot help. No court order unlocks self-custody. Your spouse inherits the device but not the knowledge to use it. This isn't a scenario — it's the current state of most estate plans that include crypto holdings. Nobody built the technical layer.
One-time setup. Verified. Documented. Tested before we call it done. Every component is chosen for your holdings size, not off a generic checklist.
We configure your hardware wallet from scratch or audit an existing device — firmware verified, PIN set to spec, passphrase layer enabled for high-value wallets. Seed phrase goes on a metal backup (Cryptosteel or equivalent), not paper. Physical storage location is documented and verified with your estate plan. Recovery is tested on a dummy wallet before we sign off on the real configuration. If you don't have a hardware wallet, we specify and source one.
For holdings above a defined threshold, single-key wallets introduce unacceptable risk — one compromised key, one lost device, one bad actor with access to your safe. Multisig requires M-of-N keys to authorize any transaction. We set the threshold based on your holdings and structure the key distribution: one key with you, one in a documented offline location, one held in trust by your designated co-signer or estate attorney. No single party can move funds alone. No single point of failure can drain the wallet.
Long-term holdings are separated from operational wallets used for DeFi, NFTs, or active trading. Air-gapped cold storage for the core position. A separate hot wallet with limited balance for anything that requires frequent interaction. This contains the blast radius — a compromised hot wallet loses spending money, not the full position. Wallet addresses are documented and labeled. Estate plan references the cold storage address explicitly.
SMS 2FA is not security — it's SIM-swap exposure with extra steps. Every exchange account gets a hardware security key (YubiKey) as the primary 2FA method and an authenticator app as backup — no SMS codes, no email codes. Exchange API keys used for portfolio tracking are scoped to read-only. Withdrawal whitelists are enabled where supported. Accounts that don't support hardware keys are flagged and minimized. Your exchange exposure is inventoried so you know exactly what lives where.
Every recovery document — seed phrase backup, hardware wallet location, PIN protocol, multisig key distribution — goes in a physical safe. Not the cloud. Not your password manager. Not a photograph on your phone. We document exactly what goes in, in what format, at what location. Your estate attorney gets a sealed inventory referencing the safe location. We verify the safe is rated appropriately (fire, flood, theft) for what it holds.
Your executor needs to know three things: what exists, where it is, and what to do. We produce a structured Crypto Asset Schedule — wallet addresses, custody method, access procedure, co-signers if multisig — formatted for estate attorneys and appended to your existing trust or will. This is the technical annex your attorney can't write because they don't have the technical context. We do. The document is updated when your holdings structure changes, not just at the annual review.
Setup is a one-time event. Monitoring is continuous. Here's what Amir is watching on your behalf — and what triggers an alert.
The problem with crypto inheritance isn't the law — it's the logistics. Here's the exact protocol we use to ensure your holdings are accessible after you're gone, without ever creating a single point of failure while you're alive.
Crypto custody is one component of a complete digital estate plan. If you also need your executor to access cloud accounts, 2FA tokens, business SaaS, and domain portfolios — that's the full Estate Protection service →. The crypto protocol documented here is built into that service and connected to every other piece of your digital estate.
Not a checklist from a blog post. Not a setup guide from the hardware wallet manufacturer. A single person who designs the architecture for your specific holdings, sets it up correctly, and stays on top of it. Request an assessment — we'll tell you exactly what's exposed and what it takes to close the gap.
Crypto security is included in Family Guard and Estate Protection tiers →