Will & Key

Self-custody inheritance · Base

Your crypto
should outlive
you.

Crypto can become permanently inaccessible when the only signing key is lost. Will & Key is a self-custody vault with a dead man's switch: deposit, name your heir, and check in on a schedule you choose. If you ever go silent, your heir can claim on chain, with no custodian and no one holding your seed phrase.

Version 2, live on Base since 28 September 2026. It contains the contract fixes from a preliminary audit of version 1 by AI auditing agents, run at our request and not independent. A few findings were kept by design; the security page lists them as known limits. Version 2 itself has not had an independent third-party audit: only AI agents of the same kind that wrote it have reviewed it. Treat it as new software: start with an amount you could afford to lose.

Diagram of the vault mechanism: owner key, inactivity timer, challenge window, heir An engraved dial. The owner's key stands at its centre. A gold arc around the dial measures the inactivity period, a hatched segment at the bottom marks the challenge window, and a dotted chain leads from the dial to the heir's seal. Callouts A to D label each part. CHECK-IN CLAIM FINALIZE FIG. 1 A · OWNER KEY B · INACTIVITY PERIOD C · CHALLENGE WINDOW D · HEIR WILL & KEY — NON-UPGRADEABLE

How it works

1

Lock

Create a vault with ETH on Base or one of four listed tokens: USDC, WETH, cbBTC or EURC. The list is fixed in the contract and refuses every other token. Name your heir's wallet address, pick your check-in schedule (7 days to 10 years), and set a challenge window (we suggest 14 days or more). Your keys, your coins — the contract is open source and non-upgradable.

2

Check in

One cheap transaction resets your timer, up to your horizon. One click refreshes every vault you own, and names each one it could not refresh and why (a claim pending, or the horizon reached). Miss a check-in because life happened? Nothing fires instantly — your heir must wait out your inactivity period, and then a challenge window in which you can still stop the claim: with a veto before your horizon, and past it by extending the horizon or withdrawing everything. Will & Key sends no alerts of any kind: nobody will notify you if your timer expires or a claim is filed, so open the app on your own schedule.

3

They inherit

If you truly go silent, your heir claims with their own wallet. Once the challenge window has run, anyone can finalize and the funds are credited to them. Until a finalize transaction is mined your key can still cancel, so heirs should finalize promptly. No court, no customer support, no company that needs to still exist.

The trust model, stated honestly

ScenarioWhat happens
You lose your wallet The vault expires on schedule and your heir can claim. This is the designed recovery path. An optional paper-seed check-in chain (advanced, with no app support) can keep the vault alive while you coordinate, but a check-in is safe only if it is mined strictly before the deadline (from then on your heir can claim first), and whoever holds the seed can postpone your heir's claim.
Your wallet is stolen A stolen owner key is a stolen vault. Will & Key defends against absence and loss, not against a compromised key — nothing self-custodial can.
Your heir loses their wallet While you're alive: change the heir address in one transaction. Keeping it current is part of owning a vault. After you're gone, a lost heir key leaves the vault stuck for good.
Nobody is watching Will & Key sends no alerts of any kind. Nobody will notify you if your timer expires or a claim is filed, your wallet will not show a claim, and nobody notifies your heir either.
We disappear Nothing changes. The contract keeps running without us. Claims can always be finalized by anyone, and if our fee address is unset at the moment a claim settles, no fee is taken.
We turn evil We can pause new vault creation, cut the fee at once, raise it only after 30 days of public notice on chain and within the limits below, change the fee recipient, sweep value sent to the contract outside any vault, and hand administration to a new address (in two steps). We cannot add a token, take a wei from any vault or payout beyond the settlement fee, block a withdrawal, block a claim, or raise any vault's fee above the rate in force when it was created. Those are facts of the bytecode, not promises.
A token issuer acts All vaults in one token share one balance at the vault contract. USDC and EURC (issued by Circle) and cbBTC (issued by Coinbase) are upgradeable tokens whose issuers can pause transfers, blocklist an address or change the token's code, so one action could freeze that token for every vault at once. Claims still settle on schedule; payouts wait until the freeze lifts, and a wipe would be a loss the contract cannot prevent. ETH and WETH have no issuer with these powers.

Fees you can verify

  • 0.5% when an inheritance settles. That is the only fee. Deposits, check-ins, and your own withdrawals are always free.
  • Hard-capped at 1% in the bytecode. No admin, present or future, can ever take more.
  • Locked twice. Your vault's fee can never exceed the rate in force when your creation transaction is mined. Starting a claim then locks the lower of that ceiling and the rate in force at that moment, and nothing can take that claim's fee higher. A later cut helps your heir only if it is still in force when the claim settles.
  • 30 days' notice for any raise. A higher rate takes effect only 30 days after it is announced on chain, and so does switching fees back on after the fee recipient was removed. Cuts apply at once.
  • Enforced by the contract. If no fee recipient is in force when a claim settles, no fee is taken. Every rule here is in the open-source contract, not in our app. The exact rules.

Questions people actually ask

Is this a legal will?

No. It is a technical mechanism that transfers on-chain assets, and it operates independently of probate. Estate law varies by country — for anything beyond crypto, and for tax treatment, talk to a professional. Will & Key handles the part lawyers can't: keys.

What if I'm in hospital and miss my check-in?

Nothing fires instantly. Your heir must first wait out your inactivity period, then claim, then wait a challenge window of at least 7 days. Before your horizon, you cancel the claim with Veto claim in the app, or by changing the heir, changing the check-in period, installing or disarming a check-in chain (advanced), extending the horizon or making any withdrawal. A check-in or a top-up does not cancel a claim, and neither does ordinary activity in your wallet: only transactions sent to the vault contract count. At or after your horizon, only extending the horizon (at least one check-in period ahead) or withdrawing everything stops a claim. Will & Key sends no alerts of any kind: nobody will notify you if your timer expires or a claim is filed. Choose a schedule that fits your life; most people pick 60–180 days, and a challenge window of 14 days or more leaves room for a slow network.

Can Will & Key or a hacker take my funds?

Only two people decide where a vault's funds go: you (anywhere, any time) and your heir (only through a claim, only after your timer expires and the challenge window has run). Anyone may call finalize, and after a 30-day grace anyone may push a payout, but those only move value to the address already entitled to it. The admin is a single Ledger hardware-wallet key. It can pause new vault creation, cut the global claim fee at once or raise it after 30 days' notice (never above 1%, and a vault is never charged more than its creation-time rate), change the fee recipient, transfer administration in two steps, and sweep surplus in ETH or a listed token: value above the accounted vault balances and payouts. It cannot add a token. That accounting keeps every vault balance and payout out of the admin's reach, apart from the settlement fee, and a vault can hold only ETH or one of the four listed tokens. A token's issuer can still freeze its own token whatever we do. A stolen owner key is a stolen vault.

What does my heir need to know?

More than you might think. Put these in your sealed letter or estate papers: the chain (Base) and the vault contract address below; your own public wallet address and the vault number; which of their wallet addresses you named, and that they must keep that wallet safe; the app address, willandkey.com/app; and your check-in period and horizon date, so they know roughly when they could claim. Tell them plainly that nobody will notify them when the time comes: they have to check the app themselves. Claiming costs cents on Base. They should trust only a vault whose owner address they recognise, because anyone can create a vault naming any address; they should check the payout address carefully when they start a claim, because the only way to change it is to cancel the claim and file a new one, and that is safe only before the claim becomes finalizable; and they should never type a seed phrase anywhere or accept unsolicited "recovery help". The planning checklist covers the letter.

Which chains?

Base (Ethereum L2) today. BNB Chain is planned; nothing is deployed there yet. Check-ins cost about a cent on Base, and the contract needs to outlive you by decades — Ethereum's security inheritance matters more for an inheritance product than for anything else in crypto.

Has it been audited?

Not by an outside audit firm — and we will say so plainly until that changes. Every review so far was run by AI systems of the same kind that wrote the code, so none is independent. In August 2026 an internal adversarial review of version 1 found and fixed ten defects before it was deployed (3 high, 3 medium, 4 low); the report is public. In September 2026 a preliminary audit by AI auditing agents, performed at our request, reported 47 findings in version 1, the app, the retired reminder watcher and our documentation (5 medium, 21 low, 21 informational). Version 1 could not be changed, so its contract fixes went into version 2, which five further review rounds and a pre-launch review, all by AI agents, then checked before it went live on 28 September 2026. Version 2 has not had an independent audit; a third-party audit is still pending. That is real evidence and it is not the same thing as an outside audit. An inheritance product earns trust slowly or not at all.

Where is the contract?

Base mainnet, and here are the addresses — check them yourself rather than trusting this page:
Vault (version 2, live since 28 September 2026): 0xA07b59d9249A996604A5fF482f1E564EdeE3A774
Retired vault (version 1, do not use): 0xC821849A1D74959753450409b594b23eCE7fEe2f
Retired reminder billing contract (do not pay): 0x60749aF621180de1DC05DB4f3d158D09dE979dC6
The vault contract is not upgradeable: what is deployed there is what will run forever. The security page lists the fingerprint of its code and how to check it against the source in our repository. Version 1 no longer accepts new vaults: its creation is paused on chain (transaction), and on 27 September 2026 it held no user funds. Reminder sales were switched off on the billing contract itself on 26 September 2026: the admin set its price to the maximum possible value, so every payment now reverts, and only the admin could reverse that (transaction). Do not send funds to either retired contract.