A friend’s father died last spring. Cancer, quick, the kind of thing that gives a family about six weeks to say everything they meant to say and then a year to deal with everything they said they’d deal with later.
Later came. My friend and his mother went through the house. They found the hardware wallet in a desk drawer, still in its box, still with the little plastic film over the screen. They knew it held bitcoin. They had watched his father talk about it at dinner, the way a man talks about a boat he’s proud of. What they could not find were the twenty-four words. Not on paper. Not in a password manager. Not in the email drafts folder where he kept everything else.
So here is where it stands. The coins are still there. Still on the chain. Still worth real money. Still, in every sense that matters to that family, gone.

The blockchain does not know you died.
It just knows nobody is moving the coins.
Chainalysis puts the number at roughly 2.78 million to 3.79 million BTC likely lost or permanently unrecoverable. That is between 17% and 23% of all the bitcoin ever mined. I want to be careful here, because I’ve seen this figure quoted as if it were a headcount. It isn’t. It’s a modelled range, a best-effort estimate over a supply of about 19.8 to 20.05 million coins. Nobody has a list.
But the estimated causes are the part that should sit with you. Forgotten seed phrases. Destroyed backups. And — right there in the list — people dying without any inheritance plan for the words.
One in five. Maybe. Lost forever, not because the encryption broke, not because someone was clever, but because the one thing that stood between a living person and the money became a thing nobody left behind. I think about that family’s hardware wallet every time I read the number.
Here is the part that took me a while to actually feel, and not just understand.
A bank account is not really yours. It’s a promise. There’s a company holding a database with a number next to your name, and if you die, the bank doesn’t get to keep it just because you’re not around to click a button. There’s a process. A teller, a probate court, an executor, a branch manager who has done this before and has a form for exactly this. The system is built on other people who can act on your behalf.
A seed phrase is not that. A seed phrase is not a password. It is the money.
That sentence sounds dramatic, so let me be plain about the mechanics. BIP39 is deterministic. Twelve or twenty-four words get run through a standard algorithm and come out the other side as a master private key. Every address you own is derived from that key. No company holds a copy. No server has your “account.” There is no forgot-password flow because there is no password to forget — there is only a mathematical object, and either you have it or you don’t. Ask yourself what a support agent could possibly do for you. There is no such thing as a support agent for a number. Whoever holds the words controls the coins, full stop. That’s not a policy choice anyone can reverse. It’s the entire point of the thing.
So the words are everything. Which means there are exactly two ways to lose your crypto, and they pull in opposite directions.
The first is losing the words. That’s the drawer, the dead backup, the father in the box.
The second is leaking the words. And this one is sneakier, because the people who fall for it are often careful people.
On January 10 of this year, a holder handed his twelve words to someone posing as Trezor support and lost about $282 million — $139 million in bitcoin and $153 million in litecoin. A tracing firm called ZeroShadow managed to freeze roughly $700,000 of it, and they did it within twenty minutes. Twenty minutes, and $700k out of $282 million. The rest walked.
Read that again and notice what did not happen. Nobody broke elliptic-curve cryptography. Nobody brute-forced anything. A person was talked into typing the words into the wrong place. That’s it. That’s the whole attack.
Now here’s the uncomfortable part about “leaking,” the part I didn’t appreciate at first. Trust doesn’t leak all at once. It leaks in pieces.
A twelve-word BIP39 phrase carries about 128 bits of entropy. If you tried to brute-force that at a billion guesses per second, you’d be looking at something on the order of 10^22 years. The universe is about 1.4 × 10^10 years old. So guessing the whole thing is not the risk. Stop worrying about that.
But suppose seven of your twelve words leak. Say someone photographs half your backup, or you reuse a set of words across two things and one of them is compromised. Seven known words collapses the remaining search space to under a year. Ten known words drops it to milliseconds. Security does not degrade in a straight line. It falls off a cliff. There is a point past which the math simply stops protecting you, and you don’t get a warning before you cross it.
One small mercy, and I’ll take it: BIP39 has a checksum built in. Write one word down wrong and the wallet will usually tell you the phrase is invalid rather than quietly opening a different, empty wallet. That feature exists to catch typos. It does not exist to save you from a person on the phone who is being very helpful and very patient.
The danger is never the math. It is exposure.
This is not a hypothetical for me. I hold coins. I have thought about the drawer, and I have thought about the phone call, and I have decided I’m not going to be the father in that story. So here is what I actually do. Not what you should do — what I do.
- 1) I wrote a letter that lets someone find it, not just read it. This is the one most people skip. I didn’t write the words into a document and call it a plan, because a single document with the seed in it is just a leak waiting to happen. The letter says where things are, what the wallet is, and how to get to the next step. Findability and secrecy are two different problems, and I keep them separate.
- 2) I gave someone the ability to find it without giving them the ability to spend it. For me that meant a sealed instruction held with a lawyer, plus a structure where no single person can move the funds alone. A split or multisig arrangement does the same job if you don’t want a lawyer in the loop. The goal is simple: the person helping my family should be able to hand them a path, not a private key.
- 3) I keep it current. This is the part everyone underestimates. I rotated the plan when I changed wallets. I updated it when a device died and I moved to a new one. A plan written two years ago and never touched is often worse than no plan, because it points at something that no longer exists. The words spelled out to a wallet you stopped using are a locked door with the wrong key.
None of this is clever. That’s rather the point. The crypto doesn’t fail because of the math or the code — it fails because nobody planned for the day the holder stops being able to act.
One honest limit, and I mean it. I am not a lawyer. Inheritance and probate law varies by country and by state, and the right structure depends entirely on where you live and who your family is. A sealed instruction, a multisig, a trust — those words mean different things in different places, and getting it wrong can be worse than doing nothing. Talk to someone who actually knows your jurisdiction. Nothing I’ve written here is legal advice.
But the underlying thing is not legal. It’s simpler than that.
Your keys only mean something as long as somebody alive can find them and use them. The chain will keep the record forever. It is not cruel about it. It has no opinion about you at all. Which is exactly why this is on you, and on me, and not on any of the institutions we’re used to leaning on when things go wrong.
(The End)







[…] Related reading: Uptober Is a Base Rate, Not a Law · The Blockchain Won’t Know You Died […]