TLDR
- David Schwartz designed a distributed control framework for Bitcoin cold storage and estate planning.
- The system requires two hardware wallets initialized with identical 24-word recovery phrases and matching PINs.
- Family members receive the physical devices while separate trusted contacts hold the PIN code.
- Access to funds requires cooperation between at least two parties from different groups.
- Recent Coldcard security issues sparked renewed discussion about hardware wallet safety and seed phrase protection.
XRP Ledger co-creator David Schwartz has introduced a Bitcoin storage plan following recent Coldcard security incidents that raised questions about hardware wallet protection. His framework distributes control among family members and trusted contacts, preventing unauthorized access during the owner’s life while enabling smooth estate transfer.
The design relies on hardware devices, one unified seed phrase, and a separately distributed PIN. Schwartz described the arrangement as resembling a “nuclear briefcase” since individual parties cannot unlock assets independently.
Coldcard Security Incident Sparks Storage Strategy Discussion
The Coldcard security incident allegedly stemmed from a firmware vulnerability that generated predictable seed phrases. Attackers subsequently compromised over 4,500 addresses and extracted 1,367 BTC, worth approximately $89 million.
The incident prompted some users to reconsider paper wallets. Paper-based records eliminate remote attack vectors but remain vulnerable to fire, theft, moisture exposure, and unintentional destruction.
Schwartz Distributes Authority Among Multiple Parties
Schwartz proposed configuring two additional hardware wallets with identical 24-word recovery phrases. The owner would apply the same PIN across both devices and maintain the primary wallet separately.
Each additional device would transfer to a different family member. Two separate trusted contacts would receive the PIN, while remaining unaware of device locations and recovery phrase details.
Bitcoin Estate Transfer Through Multi-Party Verification
Within this framework, family members cannot transfer Bitcoin without the PIN. The contacts holding the PIN cannot access assets because they lack physical devices. This distribution prevents unilateral action by any single participant.
Following the owner’s passing, contacts would share the PIN with family members. Heirs could then activate the devices and retrieve the Bitcoin without depending on exchanges, legal intermediaries, or online platforms.
Schwartz referenced the SecuX W20 as an appropriate device. The model provides hardware-based storage and enables users to maintain private keys offline from internet-connected systems.
The approach emphasizes minimizing theft exposure, device malfunction, and estate transfer complications. It also prevents concentrating complete control with one family member, contact, or physical record.
The Coldcard security incident has renewed attention toward wallet protection. Schwartz’s framework provides a layered system founded on distributed responsibility, physical isolation, and access protocols.





