Ripple CTO David Schwartz Proposes Split-Control System for Bitcoin Cold Storage and Inheritance
Key Takeaways
- •A firmware vulnerability in Coldcard wallets generated predictable seed phrases, enabling attackers to drain over 4,500 addresses and steal 1,367 BTC worth approximately $89 million.
- •Schwartz's plan designates two relatives to hold backup hardware wallets while two unrelated trusted friends each receive only the PIN, ensuring no single party can independently access the funds.
- •Upon the owner's death, the PIN-holding friends would share the code with the device-holding relatives, enabling heirs to unlock the Bitcoin without involving an exchange, attorney, or online service.
- •Schwartz cited the SecuX W20 as a suitable hardware wallet for this setup because it keeps private keys isolated from internet-connected systems.
- •Chainalysis estimates that several million BTC are already permanently inaccessible due to lost keys and holders who died without leaving recovery instructions.

A Layered Approach to Bitcoin Security
XRP Ledger co-creator and Ripple Chief Technology Officer David Schwartz has outlined a Bitcoin storage and inheritance plan that splits control across multiple trusted parties, drawing renewed attention to hardware wallet security following the Coldcard wallet hack.
Schwartz's proposal centers on dividing access between relatives and trusted friends so that no single individual can unlock the funds alone. He compared the structure to a "nuclear briefcase" — a system designed to require cooperation before anything can be accessed.
The plan addresses a gap that has grown more pressing as Bitcoin adoption widens. Unlike traditional bank accounts, which typically include beneficiary designations and probate procedures, self-custodied Bitcoin holdings have no built-in inheritance mechanism. Industry researchers, including Chainalysis, have estimated that several million BTC are already permanently inaccessible due to lost keys and deceased holders who left no recovery instructions.
Coldcard Hack Reignites Wallet Security Debate
The Coldcard wallet hack reportedly originated from a firmware vulnerability that generated predictable seed phrases. Attackers exploited the flaw to drain more than 4,500 addresses, stealing 1,367 BTC valued at approximately $89 million.
The incident prompted some users to revisit paper wallets as an alternative. While paper records are immune to remote attacks, they remain vulnerable to physical threats such as fire, theft, water damage, and accidental loss. The hack also underscored the trade-offs between convenience and security that have long shaped hardware wallet design, where single-device setups remain the norm despite known single-point-of-failure risks.
Dividing Control Across Devices and People
Schwartz recommended configuring two additional hardware wallets with the same 24-word recovery phrase used on the owner's primary device. The same PIN would be set on both backup devices, while the main wallet would remain in the owner's possession.
How do you handle inheritance? How do you handle theft/loss? Hardware wallets solve both those problems.
— David 'JoelKatz' Schwartz (@JoelKatz) August 2, 2026
Each backup device would be entrusted to a different relative. Separately, two unrelated trusted friends would each receive the PIN — but would not hold the wallets or know the recovery phrase.
The 24-word recovery phrase referenced follows the BIP39 standard, widely used across hardware wallet manufacturers to generate and restore private keys.
Inheritance Without Single-Party Access
Under Schwartz's plan, relatives holding the devices cannot move the Bitcoin without the PIN. Conversely, the friends holding the PIN cannot access the funds because they lack the physical hardware. This separation prevents any one person from acting independently.
Upon the owner's death, the friends would share the PIN with the relatives. The heirs could then unlock the devices and access the Bitcoin without relying on a cryptocurrency exchange, attorney, or online account.
Schwartz cited the SecuX W20 as a suitable hardware wallet for this setup. The device supports hardware-based key storage, keeping private keys isolated from internet-connected systems.
The strategy aims to reduce three primary risks: theft, device failure, and inheritance complications. By distributing control across multiple parties and physical objects, the plan avoids concentrating authority in any single relative, friend, or document. It also offers a simpler alternative to multi-signature setups, which require multiple separate private keys to authorize transactions but can involve greater technical complexity.
The Coldcard hack has pushed wallet security back into the spotlight. Schwartz's proposal offers a layered framework built on shared responsibility, physical separation, and conditional access — addressing both everyday protection and posthumous transfer of digital assets.