Required for a real-value pilot
Wallet safety policy
Protect the keys that protect the vault.
CryptoWill should remain compatible with standard Ethereum addresses. For any pilot involving real value, hardware wallets should be the default. A complete-kit option can provide a new device for the holder, every attestor and every beneficiary.
Recommended by role
Different authority, different controls.
A hardware wallet protects a key; it does not replace signer independence, careful address checks or a tested recovery plan.
Required for a real-value pilot
Professional
Use a firm-controlled hardware wallet or approved institutional signing setup. It must be independent from the holder and other attestors.Strongly recommended
Other attestors
Each signer should control a separate account and recovery process. A shared seed would weaken the intended multi-party approval.Strongly recommended for material value
Beneficiaries
The receiving address is immutable. Verify it on the device before deployment and preserve recovery access for the life of the vault.Optional pilot bundle
One new device for every participant.
The Complete Participant Hardware Kit would cover the holder, every attestor—including the professional—and every beneficiary. Depending on the vault configuration, that means 5–19 separate devices and recovery processes.
Trusted procurement
New, unopened devices
Buy directly from the manufacturer or an authorised channel and complete the manufacturer's genuine-device check.Private ownership
Participant-only setup
CryptoWill never initialises a device or sees a PIN, recovery phrase, private key or backup.Address assurance
Verify on the device
Each person confirms the complete Ethereum address on the trusted display before it enters the immutable vault.Operational readiness
Rehearse on Sepolia
Every participant completes their actual role journey with test assets before any controlled real-value pilot.Setup guide
What each signer needs.
A genuine device bought through a trusted channel, its official management software, a dedicated Ethereum account, a protected offline recovery phrase and enough ETH for transaction fees.
If a signer cannot understand the action on the trusted device display, the transaction must not proceed.
- 01
Create a fresh device seed
Initialise the device using its official software. Generate the recovery phrase on the device; never import a browser-wallet seed.
- 02
Back up offline
Record the recovery phrase offline and protect it from loss, fire, theft and unauthorised access. Never type it into CryptoWill, email, cloud storage or chat.
- 03
Create a dedicated Ethereum account
Keep CryptoWill signing separate from everyday DeFi activity. Install the current Ethereum app and keep the device, browser and wallet software updated.
- 04
Connect through a supported wallet
For the POC, connect the hardware account through MetaMask. Confirm that the address shown in CryptoWill is the hardware-controlled address—not a software account.
- 05
Rehearse on Sepolia
Run the complete role journey with test assets first: connect, approve, wait through the challenge period, terminate a separate vault and claim.
- 06
Verify every production signature
Check the network, contract, action and amount on the trusted device display. If the device cannot show understandable details, stop and do not sign.
Preferred launch candidate
Target Ledger, keep CryptoWill open.
Ledger is a strong first integration target because it already supports Ethereum accounts and works with MetaMask. CryptoWill should still accept other compatible hardware and institutional signing systems, so a user is never trapped by one manufacturer.
Collaborate on human-readable CryptoWill transaction details and Clear Signing metadata before any real-value pilot.
Explore direct fulfilment, volume pricing, co-authored education or sponsored devices for all configured people.
Later, assess Ledger's institutional products for law firms and wealth businesses that need managed signing policy.
Ledger is an integration candidate. This page does not represent an existing partnership, endorsement, device offer or production approval. CryptoWill must never initialise a participant's device or receive recovery material.
What a device cannot fix
Hardware is one layer.
- A compromised or incorrectly copied beneficiary address
- Loss of the device and every recovery copy
- Signers controlled by the same person or recovery phrase
- Signing an unreadable or malicious transaction
- A beneficiary who cannot access the address when funds release
- An unaudited smart contract or untested operating process
Proof of concept first
Rehearse the exact process with test assets.
The current CryptoWill build is unaudited Sepolia software. Do not deposit real assets. Complete the test journey with each signer before considering a controlled pilot.
Open the Sepolia console