Quantus mainnet · Inheritance desk · 100% client-side

The vault your grandchildren open

Quantus was built for the long haul — post-quantum signatures from the genesis block, an 80-year emission tail. Your custody plan should last as long as the chain. This desk splits your secret with real Shamir's Secret Sharing, helps you write a beneficiary plan a non-crypto person can follow, and prints the letter your heirs will actually need. Nothing here moves funds; your secrets never leave this browser.

Splitting mathShamir over GF(2⁸) · t-of-n
Cross-checked45 vectors vs independent Python impl
Your planlocalStorage only · never synced
Moves funds?Never · planning desk only
Cost to usefree · no chain fees

Why inheritance planning is the missing wallet feature

Every chain ships key generation. Almost none ship a plan for what happens when the key holder is gone. The graveyard is expensive:

Lost keys, estimated
~20%

of all bitcoin is believed permanently lost — mostly lost keys and dead owners with no plan. An old Chainalysis estimate (2017), still widely cited because nothing about human nature has changed.

The Quadriga lesson
~C$190M

reportedly became inaccessible when QuadrigaCX's founder died in 2019 as the sole holder of the exchange's keys. One person, one secret, zero plan — customer funds locked.

The Quantus angle
80yrs

of emission tail and quantum-safe signatures from genesis: this chain is engineered to outlive its first holders. ML-DSA-65 secret keys are 4,032 bytes per FIPS 204 — kilobytes, not 32 bytes. Your backup medium and your succession plan both matter more here.

What this desk does

  • Splits any text secret (seed phrase, checkphrase, instructions) into n shares where any t recover it — real GF(2⁸) Shamir math, in your browser.
  • Structures your plan: who gets what, where each piece lives, how it's accessed.
  • Drafts a printable letter of instruction your heirs can follow without being crypto-native.
  • Compares the real custody methods available on Quantus today — with honest costs and trade-offs.

What it doesn't do

  • Move funds, sign anything, or touch the chain — it can't. There is no wallet here.
  • Provide legal advice. Crypto inheritance law varies by jurisdiction; talk to an attorney.
  • Offer an on-chain dead-man switch — no such pallet exists on Quantus today. Anyone selling you one is selling fiction.
  • Store or transmit your secrets. Everything lives in this page's memory and your browser's localStorage.
The one rule: a plan nobody can find is the same as no plan. At least one trusted person must know this plan exists and where the letter lives — without holding enough pieces to steal it alone.

Shamir Lab — split a secret, recover it, trust the math

Shamir's Secret Sharing (1979) splits a secret into n shares so that any t of them reconstruct it — and any t−1 reveal nothing, information-theoretically. No single location ever holds your whole secret. The implementation below works over GF(2⁸) and every vector it produces is cross-checked against an independent Python implementation (tests/vectors/shamir-vectors.json).

Split a secret

 

Threshold can't exceed the share count — pick any t ≤ n. Common setups: 2-of-3 (spouse + lawyer + safe), 3-of-5 (family quorum).

Recover from shares

The tamper demo flips one hex character in the first share, then recovers — watch the output turn to garbage. That's why share integrity matters: store shares where they can't be silently altered.

Rules that keep this safe

  • Generate shares on an offline machine. Never photograph, screenshot, or cloud-sync a share.
  • One share per location: home safe, bank box, lawyer, trusted heir — never two in the same drawer.
  • Anyone holding t shares owns the secret. Choose holders you'd trust with the money directly.
  • Test recovery once with a small amount before trusting the setup with everything.
  • This page never sends anything anywhere — but your printer, clipboard history, and disk might. Plan for that.

Your plan — who, what, where

A plan in your head helps no one. Write it down here; it saves to this browser's localStorage only, and feeds the printable letter in the next tab.

Beneficiaries

NameRelationshipShare %ContactNotes

Where things are (the register your heirs will actually read)

ItemLocationHow to access

Examples: "Share #1 of seed — bank safe-deposit box #412, First National"; "Hardware wallet — bedroom safe, PIN in sealed envelope with lawyer". Never write the secret itself here — only where it is and how to reach it.

If you go quiet (dead-man arrangement)

Quantus has no on-chain dead-man or timelock pallet — every workable design is off-chain procedure. Pick the shape of yours:

Legacy readiness score

0%Exposed

Owner & backup

 

Autosaves to this browser as you type. Export keeps an offline copy — store it like you'd store the plan itself.

The letter — what your heirs actually read

A letter a non-crypto person can follow, generated from your plan. Print it, sign it, store it with your will — never email it, photograph it, or keep it on a phone.

 

Fill in the Plan tab, then generate. The letter pulls your beneficiaries, holdings register, and dead-man arrangement automatically.

Print discipline: use a printer you own, on paper that lasts. Shred misprints. A letter that says where the shares are is itself sensitive — store it sealed, separately from any share.

Methods — every honest way to pass QTC on

No method is perfect. Pick with open eyes; many holders combine two.

MethodHow it worksStrengthsWeaknessesCost on Quantus
Shamir sharesthis lab Secret split into n shares; any t recover it. Shares live with different people/places. No single point of failure; works with any wallet; no chain interaction needed. Lose too many shares and it's locked forever; shares must be guarded like keys; printer/clipboard hygiene matters. Free
Multisig vaultpallet 19 On-chain m-of-n account; heirs hold signer keys. Built on Quantus's custom multisig pallet (index 19). Enforced by the chain; no single key can move funds; heirs transact normally once set up. Heirs must be able to sign on-chain; setup mistakes are on-chain mistakes; pallet is new. 0.03 QTC burned to create; 0.01 QTC reserved per proposal (refunded); ~0.05 QTC per proposal burned — per the MultiSig Vault desk, read from Quantus-Network/chain
Paper / steel backupsimplest Seed written down (steel for fire), stored in a safe. Heirs get the location via your letter. Simple; no software; no fees. Single point of failure — fire, theft, or one curious visitor ends it. Paper degrades; ML-DSA seeds are long. Free (+ safe / steel plate)
Lawyer-held instructionslegal process Attorney holds your letter (not keys) with written release conditions; probate handles the rest. Professional custody; fits existing estate process. Legal fees; the lawyer must understand crypto custody; slower than direct handoff. Attorney fees
Exchange beneficiarynot available Some exchanges let you name a beneficiary for custodial balances. — No exchange lists QTC yet (NEAR Intents announced as first venue; no listing date as of Sept 30, 2026) — nothing to evaluate. N/A
"Dead-man smart contract"doesn't exist An on-chain contract that releases funds if you stop checking in. — No timelock or dead-man pallet exists in the Quantus runtime. Anyone selling you one is selling fiction. Use off-chain procedure (Plan tab). —

Combinations that work well

  • Shamir 2-of-3 + letter: spouse holds share 1, lawyer holds share 2, bank box holds share 3. Letter explains the quorum.
  • Multisig 2-of-3 + Shamir backup: daily custody in multisig; a Shamir-split paper backup of one signer key in deep storage.
  • Steel + lawyer: seed on steel in a safe; lawyer holds the safe's location and the letter. Simplest credible setup.

Quantus-specific notes

  • Verify every heir receiving address with its five-word human checkphrase before it goes in the plan — one poisoned address in a will is catastrophic. See the SafeSend Lab.
  • Generate keys on the Key Forge and print its paper card — the card plus a Shamir split is a complete backup story.
  • Reversible transfers (SafeSend) are sender-cancelable payments, not a dead-man switch — don't confuse the two.
  • Keep the plan's existence known and its contents compartmentalized.

Scope — read before trusting any of this

Honest limits

  • Not legal or financial advice. Inheritance law, probate, and crypto tax treatment vary by jurisdiction and change. Talk to a licensed attorney before finalizing anything.
  • Not a wallet. This desk never holds keys, never signs, never broadcasts. It plans; your wallet and the chain do the rest.
  • Client-side only. Your plan autosaves to this browser's localStorage. Clear your browser data without an export and it's gone. Browsers are not vaults — export and print.
  • Shamir is mathematics, not magic. It protects against loss and single-point theft; it does not protect against t colluding holders, coercion, or you splitting the secret on a compromised machine.

How the math was checked

  • GF(2⁸) field axioms tested exhaustively in Node (all 255 non-zero inverses, distributivity samples).
  • 45 known-answer vectors generated by an independent Python implementation (tests/gen-vectors.py) — the JS combine() recovers every one.
  • Deterministic round-trips across share counts 2–16 and thresholds 2–n; tamper and too-few-shares cases covered.
  • Real-browser QA in headless Chromium: split → recover → tamper demo → plan → letter → print sheet, zero console errors.
  • Source is on GitHub — read js/shamir.js before trusting it with anything real.

Attribution

Built by @kshot9000 · Shamir's Secret Sharing: Adi Shamir, 1979 · Field arithmetic: the AES field GF(2⁸).