Setting Up Trezor Suite for Spouse Access After Death: Dead Man’s Switch, Emergency Access, and Legal Inheritance Protocols
A cryptocurrency holder faces a problem that traditional finance has long answered through wills, executors, and bank account access procedures. Digital assets secured with self-custody—private keys held offline on a hardware wallet—create a fundamentally different scenario. If the account holder dies without a documented plan, the spouse or executor may have no way to unlock the wallet, access the funds, or prove ownership. The combination of a Trezor hardware device and Trezor Suite management software makes self-custody practical, but it also requires explicit preparation for succession.
The challenge is not technical complexity alone. The core tension is between two conflicting security principles: the same isolation that protects funds from theft during life can make them irretrievable after death. A properly configured Trezor device stores private keys offline and requires a physical confirmation at the device itself for any sensitive operation. That security model is essential while the owner is alive. But it also means that a spouse, executor, or heir cannot access the wallet remotely by knowing a password alone. Planning for that access without compromising security while the account holder is living requires a specific combination of procedural controls, documented secrets, and legal frameworks.
Why standard Trezor security makes inheritance difficult
A Trezor hardware wallet is designed to be the sole point of control for private keys. When a user sets up the device, Trezor generates a 12 or 24-word recovery seed and displays it on the device screen only—never on a connected computer. That seed is the mathematical root of every private key the wallet will ever create. If someone has the seed and physical access to a Trezor device, they can reconstruct the entire wallet and move all funds. If someone has access to the device but not the seed, and if the device is protected by a PIN, they cannot extract keys without knowing the PIN or physically attacking the hardware itself.
Trezor Suite—the official Trezor Suite application running on desktop, web, or mobile—manages accounts, displays balances, prepares transactions, and shows confirmation requests to the hardware wallet. But the Suite never handles private keys. It is a control panel, not a vault. This separation means that a user’s computer, smartphone, or browser can be compromised without exposing the keys stored on the Trezor device. However, it also means that an heir cannot simply log into a Trezor Suite account, retrieve the recovery seed, and restore the wallet elsewhere. The recovery seed was never stored in Trezor Suite to begin with.
Many users add a final layer of protection by creating a passphrase wallet. A passphrase is an additional secret, known only to the owner, that modifies the cryptographic derivation of keys from the recovery seed. Even if someone obtains the 12 or 24-word seed, they cannot access the passphrase-protected wallet without knowing the passphrase itself. Passphrase wallets are powerful for security—they enable the owner to create a hidden wallet separate from the standard one derived from the seed—but they are equally powerful at making inheritance impossible without explicit planning.
The effective result is that self-custody creates a custody problem for heirs. The owner has absolute control while alive. After death, nobody has control unless the owner has explicitly transferred the means of access through a documented and tested procedure.
The recovery seed must be shared—but safely
The foundation of any inheritance plan is ensuring that a trusted person, or multiple trusted people, know the recovery seed. This step contradicts conventional security advice, which typically says “never share your recovery seed.” That advice is correct for protecting against theft, hacking, and fraud during the owner’s lifetime. But it creates a false choice: the only alternative is not to share the seed with nobody and then lose the funds at death. The practical middle ground is to share the seed with designated heirs or executors in a way that prevents casual access while still enabling recovery after death.
The most common approach is to write the recovery seed on paper, divide it into parts, and place each part in a separate secure location with instructions about how to reassemble it. For example, a 12-word seed can be written as cards 1–4, cards 5–8, and cards 9–12, with each card stored at a different bank safe deposit box, notary, or trusted family member. The seed is never stored in full in any single location, so theft of one location does not expose the full seed. The heir must retrieve all three parts, bring them together, and then use them to restore the wallet. A will or trust document should explicitly identify which heir is responsible for recovering each part and under what conditions.
Some users employ a professional vault service designed for this purpose. Companies such as Casa, Unchained Capital, or Coincover offer multisig and inheritance services where the user’s seed is split using Shamir secret sharing and held in separate vaults. A designated heir can request access after providing proof of death—a certified death certificate and identification. The service then releases the shares needed to reconstruct the seed or sign transactions on behalf of the heir. This approach delegates some of the custody to a third party but eliminates the logistical complexity of managing paper seeds across multiple physical locations.
Documenting the passphrase wallet separately
If the user has created a passphrase wallet—a hidden wallet protected by an additional secret word or phrase beyond the recovery seed—that passphrase must also be documented and shared with heirs. A passphrase wallet has a critical property: the recovery seed alone cannot access it. Someone who finds the seed can only access the standard wallet derived from it. The passphrase protects a second, entirely separate set of accounts and keys.
The implications for inheritance are severe. If the majority of funds are held in a passphrase wallet and only the recovery seed is shared, the heirs will find empty accounts when they restore the wallet. They will have recovered the device and can see the blockchain, but they cannot move the actual funds because those funds were created and sit behind the unknown passphrase. This scenario is common enough that estate planning attorneys now ask cryptocurrency clients explicitly: “Do you have a passphrase wallet, and if so, who knows the passphrase?”
The safest approach is to document the passphrase separately from the recovery seed. If the seed is split into three physical parts, the passphrase should be stored in a fourth location, or given to a different trusted person entirely, or placed in a sealed envelope with instructions that it should only be opened after the owner’s death. Some users write the passphrase on a card, sign and date it, place it in a sealed envelope, and leave it with their lawyer or accountant with explicit instructions that it is to be released only after death. Others use a digital secret escrow service such as Dead Man’s Switch, which automatically sends the secret to designated recipients if the owner fails to log in for a specified period—usually 6, 12, or 24 months.
Creating a dead man’s switch for digital disclosure
A dead man’s switch is a mechanism that executes an action if the owner does not actively prevent it. In the context of crypto inheritance, it can automatically send passwords, passphrases, or access instructions to heirs if the owner stops checking in. Services such as Vault12, Casa, MyEtherWallet Legacy Contact, or cryptocurrency-specific providers offer this functionality. The owner authenticates to the service, loads the secrets or instructions they wish to share, designates heirs and backup contacts, and sets a check-in interval. If the owner does not access the service within that interval, automated emails or notifications are sent to the designated recipients with the disclosed information.
The practical benefit of a dead man’s switch is that it removes the requirement for a third party to determine whether the owner has died. No death certificate is needed, no court order is required, and no lawyer has to be contacted. The mechanism is entirely algorithmic: if the service does not receive a confirmation from the account holder within the period, it assumes the account holder is unreachable for whatever reason and executes the disclosure. The check-in can be as simple as logging in, clicking a button, or replying to an email.
The security trade-off is that the dead man’s switch service itself becomes a third party with access to sensitive information. If the service is hacked, the stored secrets could be exposed. If the service is shut down or goes bankrupt, the stored secrets might be lost. A well-designed service uses encryption so that even the service provider cannot read the secrets—they are encrypted by the user’s own key, and the provider merely stores and transmits the ciphertext. When the switch triggers, the provider sends an encrypted package to the heirs, who use a recovery key to decrypt it. Even with encryption, the service provider has custody of that package for some period, so it is not as strong as physical separation but is more convenient than managing paper in multiple locations.
Legal documentation: will, trust, and explicit instructions
A well-secured Trezor device and documented recovery procedures are not sufficient without legal documentation. A will or trust should explicitly identify the digital assets, the Trezor devices on which they are held, the location of the recovery seed, the passphrase (if any), the identity of the executor or heir who is authorized to use them, and any conditions or restrictions on their use. Without that documentation, an heir who finds the recovery seed may lack legal standing to prove they are entitled to the funds. In some jurisdictions, a cryptocurrency account held in self-custody is treated as property of the estate and must pass through probate even if the heir has the recovery seed.
An executor needs explicit authority to access the wallet backup and move funds. A standard will that names an executor for “all property, real and personal” may not clearly cover cryptocurrency because the will was written before crypto was common. Modern trusts and wills should use language such as: “I authorize my executor to access and manage all digital assets held in self-custody, including cryptocurrency held on hardware wallets, using recovery seeds and passphrases held at [location]. Digital asset instructions are attached as Exhibit A.” The executor should also receive a copy of the wallet’s account structure—the xpub (extended public key) for each account—so they can view the addresses and balances through Trezor Suite in watch-only mode even before they have the recovery seed.
Tax implications should also be addressed. In many jurisdictions, the value of cryptocurrency at the time of death is treated as the basis for capital gains calculations. If an heir eventually sells the inherited crypto, the gains are measured from that stepped-up basis, not from the original purchase price. Proper documentation of the value at death can save significant taxes. A Trezor Suite portfolio at the time of death—showing all holdings, public addresses, and balances—should be preserved as evidence of the estate’s assets.
Testing the inheritance plan without actually dying
Many estate plans exist only on paper and have never been tested. For crypto, this is especially dangerous because the recovery procedure is technical and can fail silently. Before putting a plan into effect, the account holder should perform a full test: retrieve the recovery seed (or pieces of it), restore the wallet to a separate, test Trezor device, use Trezor Suite to connect to that restored device, and verify that all accounts and funds are visible. The test should include checking whether a passphrase wallet, if any, is also recoverable. Only after a successful test should the user feel confident that the inheritance procedure will work.
The test should be done in a controlled environment with time to troubleshoot. A good time is shortly after creating the recovery plan and then again every few years to ensure that the procedure is still practical and any dead man’s switch services are still operational. If the test fails—for example, if the seed was written incorrectly or if a passphrase was misremembered—the owner can correct the problem while still alive. If the test is skipped and the seed is incorrect, the heir will discover that fact only after the owner has died, at which point correction is no longer possible.
The test also serves an educational purpose for the heir. If the heir is required to help with the test, they learn the procedure and can execute it confidently if needed. If the heir is not involved in the test, they should at least be given a written, step-by-step procedure: where to find the seed parts, how to reassemble them, which Trezor model to use, which version of Trezor Suite to install, how to connect the device, how to add the accounts, and which addresses to verify. The procedure should be simple enough that someone with basic computer skills can follow it, but detailed enough that there is no ambiguity.
Balancing security for life with access after death
The owner of a Trezor wallet faces a genuine security trade-off. The strongest security during life—an isolated Trezor device, a complex passphrase, and a recovery seed known to nobody—also creates the maximum risk of permanent fund loss at death. A less restrictive approach—sharing the seed with an heir, using a simpler or documented passphrase, or employing a multisig arrangement where no single person controls all the keys—reduces that risk but increases the risk of theft or compromise while the owner is alive.
The resolution is to match the security to the threat and the timeline. While the account holder is alive, the focus is on protecting against theft, hacking, and unauthorized access. A high-security setup with an isolated Trezor, a strong PIN, and a passphrase wallet is appropriate. After the account holder has died, those threats no longer apply. The focus shifts to ensuring that the rightful heir can access the funds. At that point, sharing the recovery seed with the heir is not a security failure; it is the entire purpose of the inheritance plan.
Some account holders also choose a middle path: use self-custody with Trezor and Trezor Suite for the majority of their holdings, but keep a smaller reserve—perhaps 5 to 10 percent—in an account at a regulated cryptocurrency exchange or in a multisig arrangement with a professional custodian. The exchange account or professional custodian has a standard process for proving death and releasing funds to heirs. This allows the account holder to benefit from self-custody security for most holdings while ensuring that some funds are accessible even if the inheritance plan for the Trezor device fails.
Practical setup: bringing it together
A concrete implementation might look like this: The account holder uses Trezor Suite on desktop to manage their primary wallet, which contains the majority of their holdings. They generate a 24-word recovery seed on the Trezor device itself and write it by hand on three separate cards. Each card contains 8 words and is placed in a sealed envelope. The envelopes are stored at three different locations: the first with the account holder’s lawyer, the second in a safe deposit box, and the third with a trusted family member. The account holder also creates a passphrase wallet for additional holdings and documents the passphrase on a separate card placed in a sealed envelope with the lawyer.
The account holder then creates a will that names a spouse as the executor and successor in interest. The will includes explicit language authorizing the executor to access and manage the Trezor device, recover the wallet, and move the funds. The will also includes Exhibit A, which lists the digital assets, the Trezor device model and serial number, the location of the recovery seed, and contact information for the lawyer and other custodians. The account holder also enrolls in a dead man’s switch service, uploads the passphrase encrypted with their own key, designates their spouse as the recipient, and sets a 12-month check-in interval.
Finally, the account holder performs a full test: they retrieve one envelope from the safe deposit box, retrieve the other two envelopes by asking the lawyer and family member to confirm the procedure, write down the full 24-word seed, and restore it to a test Trezor device with Trezor Suite. They verify that all accounts and balances are visible. They also test that they can access the encrypted passphrase through the dead man’s switch by entering the recovery password. Only after this test succeeds does the account holder feel confident that the inheritance plan is real and functional.
Frequently asked questions
If I die, can my spouse recover my Trezor wallet just by knowing my Trezor Suite password?
No. Trezor Suite does not store private keys or recovery seeds. It is a management interface that communicates with the hardware wallet. Your spouse would need the physical Trezor device, the recovery seed (12 or 24 words generated on the device), and the PIN to access the wallet. If you also used a passphrase wallet, they would need that passphrase as well. All of these must be documented and shared through a separate process, such as a safe deposit box, lawyer, or dead man’s switch service.
Should I share my recovery seed with my spouse now, or is it too risky?
Sharing your recovery seed carries a security risk during your lifetime—if your spouse’s phone or home is compromised, the seed could be exposed. The standard recommendation is not to share it during life. Instead, store it securely in separate locations (split into parts), document it in your will or trust, and ensure your spouse knows how to retrieve it after your death. Use a dead man’s switch to automatically notify your spouse of the location if you become unreachable.
What happens if I have a passphrase wallet and don’t document the passphrase?
Your heirs will recover the standard wallet derived from your recovery seed, but they will not see the accounts created with the passphrase wallet. To them, those funds will appear to have vanished. From a cryptographic standpoint, they are locked away and inaccessible without the passphrase. If the passphrase was never documented or shared, those funds are permanently lost. This is why passphrase wallets must be treated as requiring separate documentation and estate planning.