Quantus mainnet · Inheritance desk · 100% client-side
The vault your grandchildren open
Quantus was built for the long haul — post-quantum signatures from the genesis block, an 80-year emission tail. Your custody plan should last as long as the chain. This desk splits your secret with real Shamir's Secret Sharing, helps you write a beneficiary plan a non-crypto person can follow, and prints the letter your heirs will actually need. Nothing here moves funds; your secrets never leave this browser.
Why inheritance planning is the missing wallet feature
Every chain ships key generation. Almost none ship a plan for what happens when the key holder is gone. The graveyard is expensive:
of all bitcoin is believed permanently lost — mostly lost keys and dead owners with no plan. An old Chainalysis estimate (2017), still widely cited because nothing about human nature has changed.
reportedly became inaccessible when QuadrigaCX's founder died in 2019 as the sole holder of the exchange's keys. One person, one secret, zero plan — customer funds locked.
of emission tail and quantum-safe signatures from genesis: this chain is engineered to outlive its first holders. ML-DSA-65 secret keys are 4,032 bytes per FIPS 204 — kilobytes, not 32 bytes. Your backup medium and your succession plan both matter more here.
What this desk does
- Splits any text secret (seed phrase, checkphrase, instructions) into n shares where any t recover it — real GF(2⁸) Shamir math, in your browser.
- Structures your plan: who gets what, where each piece lives, how it's accessed.
- Drafts a printable letter of instruction your heirs can follow without being crypto-native.
- Compares the real custody methods available on Quantus today — with honest costs and trade-offs.
What it doesn't do
- Move funds, sign anything, or touch the chain — it can't. There is no wallet here.
- Provide legal advice. Crypto inheritance law varies by jurisdiction; talk to an attorney.
- Offer an on-chain dead-man switch — no such pallet exists on Quantus today. Anyone selling you one is selling fiction.
- Store or transmit your secrets. Everything lives in this page's memory and your browser's localStorage.
Shamir Lab — split a secret, recover it, trust the math
Shamir's Secret Sharing (1979) splits a secret into n shares so that any t of them reconstruct it — and any t−1 reveal nothing, information-theoretically. No single location ever holds your whole secret. The implementation below works over GF(2⁸) and every vector it produces is cross-checked against an independent Python implementation (tests/vectors/shamir-vectors.json).
Split a secret
Threshold can't exceed the share count — pick any t ≤ n. Common setups: 2-of-3 (spouse + lawyer + safe), 3-of-5 (family quorum).
Recover from shares
The tamper demo flips one hex character in the first share, then recovers — watch the output turn to garbage. That's why share integrity matters: store shares where they can't be silently altered.
Rules that keep this safe
- Generate shares on an offline machine. Never photograph, screenshot, or cloud-sync a share.
- One share per location: home safe, bank box, lawyer, trusted heir — never two in the same drawer.
- Anyone holding t shares owns the secret. Choose holders you'd trust with the money directly.
- Test recovery once with a small amount before trusting the setup with everything.
- This page never sends anything anywhere — but your printer, clipboard history, and disk might. Plan for that.
Your plan — who, what, where
A plan in your head helps no one. Write it down here; it saves to this browser's localStorage only, and feeds the printable letter in the next tab.
Beneficiaries
| Name | Relationship | Share % | Contact | Notes |
|---|
Where things are (the register your heirs will actually read)
| Item | Location | How to access |
|---|
Examples: "Share #1 of seed — bank safe-deposit box #412, First National"; "Hardware wallet — bedroom safe, PIN in sealed envelope with lawyer". Never write the secret itself here — only where it is and how to reach it.
If you go quiet (dead-man arrangement)
Quantus has no on-chain dead-man or timelock pallet — every workable design is off-chain procedure. Pick the shape of yours:
Legacy readiness score
Owner & backup
Autosaves to this browser as you type. Export keeps an offline copy — store it like you'd store the plan itself.
The letter — what your heirs actually read
A letter a non-crypto person can follow, generated from your plan. Print it, sign it, store it with your will — never email it, photograph it, or keep it on a phone.
Fill in the Plan tab, then generate. The letter pulls your beneficiaries, holdings register, and dead-man arrangement automatically.
Methods — every honest way to pass QTC on
No method is perfect. Pick with open eyes; many holders combine two.
| Method | How it works | Strengths | Weaknesses | Cost on Quantus |
|---|---|---|---|---|
| Shamir sharesthis lab | Secret split into n shares; any t recover it. Shares live with different people/places. | No single point of failure; works with any wallet; no chain interaction needed. | Lose too many shares and it's locked forever; shares must be guarded like keys; printer/clipboard hygiene matters. | Free |
| Multisig vaultpallet 19 | On-chain m-of-n account; heirs hold signer keys. Built on Quantus's custom multisig pallet (index 19). | Enforced by the chain; no single key can move funds; heirs transact normally once set up. | Heirs must be able to sign on-chain; setup mistakes are on-chain mistakes; pallet is new. | 0.03 QTC burned to create; 0.01 QTC reserved per proposal (refunded); ~0.05 QTC per proposal burned — per the MultiSig Vault desk, read from Quantus-Network/chain |
| Paper / steel backupsimplest | Seed written down (steel for fire), stored in a safe. Heirs get the location via your letter. | Simple; no software; no fees. | Single point of failure — fire, theft, or one curious visitor ends it. Paper degrades; ML-DSA seeds are long. | Free (+ safe / steel plate) |
| Lawyer-held instructionslegal process | Attorney holds your letter (not keys) with written release conditions; probate handles the rest. | Professional custody; fits existing estate process. | Legal fees; the lawyer must understand crypto custody; slower than direct handoff. | Attorney fees |
| Exchange beneficiarynot available | Some exchanges let you name a beneficiary for custodial balances. | — | No exchange lists QTC yet (NEAR Intents announced as first venue; no listing date as of Sept 30, 2026) — nothing to evaluate. | N/A |
| "Dead-man smart contract"doesn't exist | An on-chain contract that releases funds if you stop checking in. | — | No timelock or dead-man pallet exists in the Quantus runtime. Anyone selling you one is selling fiction. Use off-chain procedure (Plan tab). | — |
Combinations that work well
- Shamir 2-of-3 + letter: spouse holds share 1, lawyer holds share 2, bank box holds share 3. Letter explains the quorum.
- Multisig 2-of-3 + Shamir backup: daily custody in multisig; a Shamir-split paper backup of one signer key in deep storage.
- Steel + lawyer: seed on steel in a safe; lawyer holds the safe's location and the letter. Simplest credible setup.
Quantus-specific notes
- Verify every heir receiving address with its five-word human checkphrase before it goes in the plan — one poisoned address in a will is catastrophic. See the SafeSend Lab.
- Generate keys on the Key Forge and print its paper card — the card plus a Shamir split is a complete backup story.
- Reversible transfers (SafeSend) are sender-cancelable payments, not a dead-man switch — don't confuse the two.
- Keep the plan's existence known and its contents compartmentalized.
Scope — read before trusting any of this
Honest limits
- Not legal or financial advice. Inheritance law, probate, and crypto tax treatment vary by jurisdiction and change. Talk to a licensed attorney before finalizing anything.
- Not a wallet. This desk never holds keys, never signs, never broadcasts. It plans; your wallet and the chain do the rest.
- Client-side only. Your plan autosaves to this browser's localStorage. Clear your browser data without an export and it's gone. Browsers are not vaults — export and print.
- Shamir is mathematics, not magic. It protects against loss and single-point theft; it does not protect against t colluding holders, coercion, or you splitting the secret on a compromised machine.
How the math was checked
- GF(2⁸) field axioms tested exhaustively in Node (all 255 non-zero inverses, distributivity samples).
- 45 known-answer vectors generated by an independent Python implementation (tests/gen-vectors.py) — the JS combine() recovers every one.
- Deterministic round-trips across share counts 2–16 and thresholds 2–n; tamper and too-few-shares cases covered.
- Real-browser QA in headless Chromium: split → recover → tamper demo → plan → letter → print sheet, zero console errors.
- Source is on GitHub — read js/shamir.js before trusting it with anything real.
Attribution
Built by @kshot9000 · Shamir's Secret Sharing: Adi Shamir, 1979 · Field arithmetic: the AES field GF(2⁸).