What happened
QuadrigaCX was, at the time, Canada's largest cryptocurrency exchange. Founded in 2013 by Gerald Cotten and Michael Patryn, it grew through the 2017 crypto bull run into a household name in Canadian fintech. By late 2018 the platform served roughly 115,000 users and held customer balances totaling around CAD $215 million in cash and digital assets.
On December 9, 2018, Cotten died unexpectedly in Jaipur, India, at age 30, reportedly from complications of Crohn's disease. He was on his honeymoon. The death certificate was issued days later. His widow, Jennifer Robertson, filed a sworn affidavit with the Nova Scotia Supreme Court the following month explaining what came next.
Cotten had been QuadrigaCX's sole director, sole officer, and the only person with access to the exchange's cold wallets. Robertson's affidavit stated that his laptop — which he carried everywhere and which held the keys to customer funds — was encrypted, and that she did not know the password. No one did.
"The laptop computer from which Gerry carried out the Companies' business is encrypted and I do not know the password or recovery key. Despite repeated and diligent searches, I have not been able to find them written down anywhere."
Ernst & Young was appointed monitor in February 2019. The cold wallets were eventually located and analyzed — and most of them were empty, with the last meaningful outflows occurring well before Cotten's death. Subsequent investigation by the Ontario Securities Commission concluded in 2020 that QuadrigaCX had been operating as a Ponzi-style fraud, and that Cotten had been spending customer funds on personal expenses and trading losses for years.
That fraud is its own story. But strip it away, and the original public-facing crisis still stands on its own merits as a custody failure: an exchange holding nine figures of customer assets had architected itself so that a single human being's death made those assets unreachable. Even in the universe where the wallets had been full, no one alive on December 10, 2018 could have opened them.
Where it went wrong
Three structural failures compounded into the disaster:
- Sole custody. One person — the founder — held every cold wallet key. There was no co-signer, no shared trustee, no escrow. When he died, the keys died with him.
- No succession protocol. There was no documented plan for what should happen if Cotten became incapacitated. No envelope at a lawyer's office. No shares with a co-trustee. No instructions written down. Robertson, as next of kin, was left to physically hunt through papers and devices.
- Encrypted laptop, single password. Even the recovery path — Cotten's personal computer — required a single password held in a single human head. The encryption was strong, the password was unrecoverable, and no key escrow existed.
Any one of those failures alone could have been recovered from. The combination guaranteed that the death of one person would lock everyone else out forever.
The lesson generalizes
QuadrigaCX is dramatic because of the dollar figure and the criminal context. But the underlying pattern — one person, one password, one device — is the same pattern that quietly destroys family inheritances every week. A father who held the family bitcoin on a Trezor and never told anyone about it. A founder who managed the corporate AWS root account and never set up a break-glass account. A solo developer whose GitHub MFA seed lived on a phone they took into the ocean.
The asset class doesn't matter. The architecture does.
No single person — not even you — should be the only path to your secrets.
Deadman Secrets is built around a simple cryptographic guarantee: your vault is locked by a key that is split into three pieces using Shamir's Secret Sharing. Any two pieces can reconstruct the key. No single piece reveals anything.
- One piece lives with you — derived from your passphrase on your own device. We never see it.
- One piece is sealed inside a tamper-proof hardware enclave on our side — verified by AWS hardware attestation. It is only released when your deadman conditions actually trigger.
- One piece is sealed for a beneficiary you name — your spouse, your lawyer, your business partner, your kid. We hold it encrypted to that specific person's identity, useless to anyone else, and we deliver it to them only when your deadman trigger fires.
- Pair the keys with a playbook. A seed phrase is useless to someone who’s never touched a wallet. Our ready-made “Access the crypto wallet” template gives your beneficiary an ordered, plain-language guide — which wallet, how to restore it, what to do first — with the recovery material attached exactly where it’s needed.
If Cotten had used a scheme like this, his widow plus the hardware enclave could have reconstructed the vault key without ever needing his laptop password. Customer funds — if they had still existed — would have been recoverable on day one. The cryptography would have outlived him on purpose.
"But I'm not running an exchange"
Most people reading this aren't holding nine-figure custody balances. That's not the point. The point is that the size of the loss is just a function of the size of what you hold. The mechanism that produced the QuadrigaCX disaster — one human being holding all the keys to their own digital life — is the default mechanism almost everyone is using today.
Your hardware wallet seed. Your password manager master password. The PDF of your will. The Apple ID that unlocks every device you own. The 2FA seeds that gate every bank account. The Stripe account that pays your contractors. If you can't think of two people who could recover any of these tomorrow if you didn't wake up, you have built the same architecture QuadrigaCX did. Just smaller.
What good custody looks like
A working succession plan has three properties:
- No single point of failure. No single person, device, or password can be the only path. Threshold cryptography or split-knowledge is non-negotiable for anything irreplaceable.
- Triggered, not opportunistic. Beneficiaries should not be able to claim access just because they want to. There must be a verifiable signal — a missed check-in, a death certificate, a defined waiting period — that gates the release.
- Operator can't override. The company storing the encrypted data must not be able to read it, and must not be able to unilaterally release it. If the operator can be compelled, hacked, or bribed into producing plaintext, the scheme has failed before it starts.
The QuadrigaCX story is so painful precisely because every one of those properties was missing. Cotten was the operator, the custodian, and the single point of failure all at once. The point of modern threshold custody is that no role should be allowed to collapse into one human like that.
Where we are today
The Ontario Securities Commission's 2020 report formally documented the fraud, and Netflix released a documentary, Trust No One: The Hunt for the Crypto King, in 2022. Most customer claims have been processed through bankruptcy proceedings, but only a small fraction of original balances has ever been returned.
The case quietly changed industry practice. Most reputable exchanges today use multi-party computation or multi-signature wallets for cold storage, with no single human able to sign a withdrawal alone. That is the institutional version of what Deadman Secrets makes available to individuals: cryptographic guarantees that survive the death of any one participant.
Build a real succession plan today.
It takes ten minutes. Your secrets stay locked on your device. Your beneficiaries are notified automatically — but only when the deadman conditions you defined actually trigger. Even we can't read them.
Start for Free