Multisig claims —
no single heir moves funds alone.
Your heirs collectively unlock the vault. Pick any threshold from 2-of-2 up to 10-of-10. Per-share basis points sum to 10,000. Contract enforces it all.
The safest inheritance architecture is the one where no single person can cash out unilaterally. HeirVault uses Ethereum-style M-of-N multisig for heir claims, with heir-specific commit-reveal protection against frontrunning.
Sign, commit, wait through the chain-specific reveal buffer, execute, then pull. Every step is auditable by every heir, every guardian, and you.
Key features
Any M-of-N you want
2-of-3, 3-of-5, 5-of-7 — configure at vault creation. Up to 10 heirs per vault. Thresholds enforced by the contract, not by trust.
Basis-point precision
Heir shares sum to exactly 10,000 bps (100%). Split 33.33% / 33.33% / 33.34%, or 50% / 30% / 20%, or any distribution you want.
Commit-reveal anti-frontrun
EVM vaults enforce a 20-minute commit-reveal delay and use a 21-minute operational wait in the app. Tron and Solana use their own next-block or next-slot reveal rules.
Pull-based withdrawal
Each heir pulls their share after execution. Claim execution snapshots assets, then withdrawals happen through separate heir transactions.
The flow
- 01
Heirs initiate
Any heir can call initiateClaim after the owner's deadline passes. The claim enters a signature-collection phase.
- 02
Heirs sign
Each heir submits their claim signature through the chain-specific claim flow until the M threshold is reached.
- 03
Commit
An heir calls commitExecuteClaim(claimId). EVM waits through the 20-minute contract delay; the app waits about 21 minutes for safety.
- 04
Execute
After the reveal buffer, the committing heir calls executeClaim(claimId). Snapshot-based withdrawal entitlements are locked in.
- 05
Pull
Each heir calls withdraw to pull their share — pull-based, reentrancy-proof. Take stablecoins, ETH, NFTs, whatever's in the vault.
Questions
Frequently asked
How do I choose M-of-N for my family?
Rule of thumb: 2-of-3 for most families (lose one heir, still inherit). 3-of-5 for family offices with independent oversight. 2-of-2 if your heirs live together. The contract supports up to 10 heirs with any threshold where M <= N.
What is commit-reveal and why wait?
Commit-reveal is a two-step execute: an heir calls commitExecuteClaim(claimId), waits through the reveal buffer, then calls executeClaim(claimId). EVM enforces a 20-minute timestamp delay, and the app uses a 21-minute operational wait to avoid boundary failures. Tron and Solana use their own block/slot reveal rules.
Can heirs claim individually?
Each heir pulls their own share after the claim is executed. But initiating and signing the claim requires the full M-of-N threshold. This prevents any single heir from dragging others into an unwanted distribution.
What happens if a signer is unavailable?
As long as you meet the threshold, you're fine. With 2-of-3, even one unavailable heir doesn't block inheritance. Design the threshold for the worst realistic case: illness, travel, lost keys.
Can heirs change shares later?
No — heir shares are fixed at vault creation (sum to 10,000 basis points). The owner can adjust before any claim is initiated, but heirs themselves never reshuffle.
No single heir. No single point of failure.
Set up your heir multisig in the vault wizard. Any M-of-N, any share distribution. Testnet is free.
Create a multisig vault