The QuadrigaCX incident was later found to involve allegations of fraud — does that mean this case actually has nothing to do with "self-custody inheritance risk," and was simply a straightforward fraud case?
This is a complexity worth confronting honestly: subsequent investigations (including a report from the Ontario Securities Commission) did find that some of Quadriga's cold wallets were actually empty, and that Cotten had been misappropriating customer funds over an extended period, using fabricated trades to keep the books balanced — signs suggesting this incident likely involved a genuine fraud component, not simply an unfortunate accident. But that doesn't mean the core issue of self-custody inheritance risk disappears as a result. Even setting the fraud component aside entirely, the QuadrigaCX case still genuinely demonstrates the structural weakness of an entire system's private keys being concentrated in a single person's hands with no backup mechanism whatsoever — and if that person dies, even in a scenario where they genuinely did hold customer assets, the result is the same permanent inaccessibility.
This is exactly why this article also cites the case of Stefan Thomas — his situation involves no fraud allegations whatsoever; it's purely a case of a forgotten password locking assets away permanently, which demonstrates the risk of self-custody having no backup mechanism in a much cleaner way, without needing to lean on a case like QuadrigaCX that carries fraud controversy attached to it. Looking at both cases together helps a reader separate two questions that frequently get conflated — fraud risk and purely technical inheritance risk — and understand each on its own terms.
If self-custody's core value proposition is "depending on no third party," is there any way to solve the inheritance problem without introducing one?
The industry has developed several technical approaches attempting to balance these two goals, though none of them is flawless. One approach extends multisig architecture: splitting a Private Key into multiple parts, giving each to a different person or storage location, and setting a threshold — requiring a certain number of the parts to reconstruct full access. That way, even if one keyholder dies or becomes unreachable, as long as enough of the remaining shares are still available, the assets remain accessible. The cost of this approach is that once you actually need to gather the threshold number of shares to access anything, everyday convenience drops accordingly — you're trading some of the "depends on no one" purity for recoverability at inheritance time.
Another approach is a dead man's switch type of service: designed so that if you don't periodically confirm you're still alive within a fixed window, the system automatically triggers, releasing pre-encrypted, stored information to a designated person. The advantage of this kind of service is that it doesn't require handing sensitive information to anyone while you're still alive; the drawback is that the service itself is still a form of third party — you're still placing some degree of trust in that provider's reliability and continued existence. If the provider itself fails or shuts down operations, that could actually create a new risk of its own. This is exactly why "zero third party, and a perfect solution to inheritance" remains, under current technical conditions, a core paradox with no truly perfect answer — every solution involves a trade-off between the two goals rather than fully satisfying both at once.
Beyond multisig and dead man's switch type technical solutions, is there a simpler, lower-barrier approach an ordinary household can take in practice?
For ordinary users whose asset scale doesn't warrant a complex technical solution like multisig, a commonly recommended approach in the industry is "information layering": keeping basic inventory information — what assets exist, roughly how much, which platform or type of wallet they're on — entirely separate from the actual Seed Phrase or Private Key that unlocks them. The former can be written directly into a formal will or handed to a law firm, because even if that document leaks, simply knowing how much you have isn't enough to actually access it. The latter needs to be handled with more caution — for example, split into two or three parts stored at different physical locations (part in a home safe, part in a bank safety deposit box), with the instruction document only stating where to look, rather than writing the complete content directly into the same document.
Another frequently overlooked, yet extremely low-cost step, is actually walking through the entire process with your designated executor or heir while you're still around — not just writing steps down on paper, but genuinely using a small test amount to have them follow your instructions and carry out the process themselves, confirming the whole thing actually works end to end. Most inheritance planning failures aren't cases where no instructions were left at all — they're cases where the instructions had a small gap (missing a two-factor device required by a particular platform, or missing the master password for a password manager needed at a certain step). This kind of detail-level gap is only reliably caught through an actual Dry Run.
The amount of crypto I currently hold isn't particularly large — is this level of inheritance planning really necessary to start on now?
The answer to this follows similar logic to what's been discussed in earlier articles: what genuinely determines whether planning is worth it isn't purely the absolute dollar amount of the asset — it's how much real impact or regret it would cause your family if that asset genuinely vanished forever. Most of the 115,000-plus victims in the QuadrigaCX case weren't wealthy whales — they were ordinary people who'd put a portion of their savings into crypto. Stefan Thomas's case also serves as a reminder that asset value can shift dramatically over time — the amount of Bitcoin he originally deposited is now, years later, worth over $200 million. Nobody can accurately predict whether an asset you currently consider "not a large amount" might, someday, become a sum that matters a great deal to your family.
A more practical way to frame it: full-scale inheritance planning — deploying multisig or a dead man's switch, for example — genuinely does require an investment of time and cost, and isn't necessarily proportionate to every asset scale. But the most basic step — leaving an instruction document telling a trusted person roughly where the asset is and who to turn to for help — costs almost nothing and requires only a little time. Rather than getting stuck on whether your holdings are large enough to justify full-scale planning, a more practical first step is simply making sure that if something happened to you tomorrow, your family would at least know this asset exists and roughly where to look for it. This bare minimum of preparation has nothing to do with the size of your holdings, yet it dramatically lowers the worst-case outcome of the asset vanishing entirely, with your family never even knowing it existed.
On December 9, 2018, Gerald Cotten — founder and CEO of QuadrigaCX, Canada's largest crypto exchange — died suddenly of complications from Crohn's disease while traveling in India, at age 30. His sudden death instantly froze roughly $190 million (about CA$250 million) in customer assets, because the private keys to the exchange's entire Cold Wallet infrastructure were known only to Cotten, stored on a fully encrypted laptop. His widow had the laptop in hand but had no idea what the password was, and even professional security experts couldn't crack it — over 115,000 users' assets vanished into limbo. On-Chain Analytics firms including Chainalysis later investigated and found that some assets claimed to be sitting in "cold wallets" simply didn't exist, and the incident eventually evolved into a complex case involving allegations of fraud. But regardless of what the full truth ultimately turns out to be, the core risk this incident exposed is real and universal: any self-custodied crypto asset, once the only person who knows the Private Key dies, gets permanently locked — and no customer service line, court order, or death certificate can open it.
A different, purer case with no fraud allegations attached is the story of programmer Stefan Thomas: in 2011, he encrypted and stored the private key to 7,002 Bitcoin (worth over $200 million at recent prices) on an IronKey hardware USB drive, then later forgot the unlock password. The drive allows only ten incorrect password attempts before permanently and irreversibly wiping all data, and Thomas has already used eight of those attempts — only two chances remain. This isn't an inheritance case — he's alive and simply locked out of his own assets — but it precisely demonstrates the same core paradox: self-custody is considered the safest way to protect crypto assets exactly because it depends on no third party, with no customer support to reset a forgotten password for you. But that same "nobody can help you" property means that the moment the person who held the key (whether through death, memory loss, or a broken device) can no longer personally access it, the asset vanishes permanently — no back door, no emergency contact, nothing that can step in. Security and inheritability pull against each other by design in the world of self-custody.
Worth noting is that most crypto asset loss doesn't stem from a hack or a scam — it comes from far more mundane causes: a holder dying without leaving any access instructions, a Seed Phrase accidentally destroyed (fire, water damage), or a Hardware Wallet failing with nobody around who knows how to recover it. One survey found nearly 90% of crypto holders worry about what happens to their assets after they die, yet only a small fraction have actually put a formal inheritance plan in place — a gap that reflects exactly how easily inheritance planning for self-custodied assets gets postponed and overlooked compared to what most people assume.
What makes this even trickier is that the moment you start planning how family can access assets after you're gone, that planning process itself creates new risk: writing out a complete seed phrase and handing it to a specific person to safeguard makes that person a potential attack target from then on. And if the heir isn't experienced with crypto and is eager to access this newfound windfall, they become even more vulnerable to falling for a scam involving someone impersonating official support to "verify identity." Instructions originally designed to protect an asset, once they land in the hands of an inexperienced heir eager to cash out, can end up doing exactly the opposite — becoming a playbook that invites the wolf in.
If you currently hold any self-custodied crypto assets, regardless of the amount, it's worth taking time to consider one question: if you suddenly couldn't operate this wallet yourself tomorrow, what would happen? The approach most commonly recommended in the industry is separating "the information needed to access assets" from "where that information physically lives" — for example, leaving only a set of instructions describing what assets exist, roughly how much, and where to go to find the actual seed phrase or private key (a sealed envelope held by a law firm, a bank safety deposit box), rather than writing the complete seed phrase somewhere easily found or easily glimpsed by someone. At the same time, designate an executor who genuinely understands basic crypto operations and is trustworthy enough, and while you're still around, actually test the full access process with a small amount of assets to confirm your heir can genuinely follow the instructions successfully — rather than only discovering a gap in the instructions after you're already gone. There's no one-size-fits-all answer here, but putting off this planning is itself a bet that a fairly non-trivial accident will simply never happen to you.