⏸Cherry Graffiti
|
AgentsAppsAutomationBitPensionBlogBoardroomBondsBuildButtonsCareersCashboardClientsComponentsContactContentContractsCoursesCreativeDevelopersDividendsDocsExchangeFoundersGigsKintsugiLibraryMarketMetanetMintMoneyButtonMusicPackagesPipelinePortfolioPricingProjectsRewardsRoadmapSchematicsServicesSkillsSmart ContractsStudioTaaSTokensToolsTreasuryVideoWebsitesWorkAgentsAppsAutomationBitPensionBlogBoardroomBondsBuildButtonsCareersCashboardClientsComponentsContactContentContractsCoursesCreativeDevelopersDividendsDocsExchangeFoundersGigsKintsugiLibraryMarketMetanetMintMoneyButtonMusicPackagesPipelinePortfolioPricingProjectsRewardsRoadmapSchematicsServicesSkillsSmart ContractsStudioTaaSTokensToolsTreasuryVideoWebsitesWork
Back to Blog
Featured

BitPension: The Lock Is the Easy Part

Richard Boase
|
8 min read
|16 May 2026|
TOKEN: bitpension-the-lock-is-the-easy-part
.MD Source
BitPensionBSVtimelockself-custodysCryptShamirrecoveryestate planningbitcoinbond series

What we said, and what we did

In BitPension: Coupons from Creative Work we described the idea: timelock BSV you already own, release it to yourself on a schedule, and you have a pension that depends on no employer, no government, and no fund manager. We ended that piece honestly: the protocol pieces existed, but the glue — the thing that actually builds and manages the locks — was not built.

It's built now. A two-branch timelock contract that compiles to valid Bitcoin script, a schedule generator, a standalone interface, and recovery tooling. All of it self-contained: it runs from one repository against a public node with keys you hold. No website has to stay up for forty years for it to work.

But that's not the interesting part. The interesting part is what building it forced us to admit.

The lock is the easy part

Locking BSV until a future block height is trivial. Bitcoin has had the primitive for years. Our contract is a small extension of shruggr's lockup: it can be swept by your key after a maturity height, and — only later, after a grace window — by a separate recovery key. In script, the load-bearing lines are about this simple:

require(this.locktime >= this.maturityHeight);
require(hash160(pubkey) == this.ownerPkh);
require(checkSig(sig, pubkey));

We deliberately use block heights, not timestamps. A coupon can't be freed by lying about the clock — only by real elapsed proof-of-work. Once it's locked, nobody unlocks it early. Not you, not us, not a court, not the miners. That absoluteness is the entire point.

It is also the entire problem.

If the money cannot be moved early by anyone, then a forty-year instrument is only as good as your ability to still hold the key in year forty — through house moves, dead hardware, forgotten passphrases, hospital stays, and, eventually, your own death. Lose the key with nothing arranged and the money isn't delayed. It's gone, for the duration of the lock and then forever after.

The cryptography is the cheap part. Custody across a human lifetime is the expensive part. Most "be your own bank" thinking quietly skips this. We tried to skip it too, and couldn't.

We are not cypherpunks all the way down

Here is the uncomfortable conclusion. A purely self-custodial pension dies the moment a seed is lost or its owner dies without having told anyone anything useful. A purely legally-custodied one dies the moment the firm holding it is negligent, insolvent, or corrupt. Picking either pole and being ideologically pure about it produces an instrument that predictably fails over forty years.

So BitPension's recovery model is deliberately hybrid, and the hybrid is the design — not a compromise of it.

The recovery key's seed is split with Shamir secret sharing, two-of-three:

  • Share A lives in an encrypted vault — the convenient path, defends against physical loss.
  • Share B is held by a solicitor, as a sealed instrument, openable only on proof of death, certified incapacity, or a court order.
  • Share C is held by a trusted human.

Any two reconstruct the key. No single holder can. A solicitor who is bribed or hacked still has one share of three and cannot move a satoshi. A compromised vault, the same. A relative who goes rogue, the same.

And notice what each layer is for. The chain enforces time: no human can release a coupon before its block height, so the lawyer can't be leaned on to pay out early, ever. The lawyer enforces the human conditions the chain can't evaluate: is he actually dead? is this genuinely the heir? Code cannot answer those questions. A regulated professional under an indemnity duty can.

Solicitors have safely held "open this only on the death of X" instruments for centuries. That is not a weakness of the old world to route around with cleverness. It is working infrastructure, and the mature version of the cypherpunk idea is knowing when to use it. We wrote the procedure down — the letter of instruction, the sealed cover note, the conditions, what the executor actually does — so it's an operation, not a slogan.

What this is, stated plainly

Because the language here matters more than usual: this is a tool, not a fund, not a product you buy, not advice, and not a promise of any return. There is no pool of other people's money. Nobody takes a cut of assets. It was built, first, for one person to use on his own coins, and that framing is load-bearing — the moment something pools funds or promises a return it becomes a regulated activity and a different conversation entirely.

It also doesn't depend on anything we host. A pension whose survival is hostage to a company keeping a website alive for four decades isn't self-custody. The repository plus your keys is the whole system; an interface is a convenience layered on top, never a dependency.

What's done, and what isn't

Honest status, because a pension is the wrong place to oversell.

Done and tested offline: the contract compiles to valid script; the schedule generator and its boundary checks; the standalone preview interface; the Shamir split-and-recombine, including a self-check that refuses to hand back shares that don't reconstruct the secret, plus the written solicitor procedure.

Not done, and gating any real money: a full testnet proof — lock, mature, recover via the lawyer-and-human shares, sweep — and an independent re-implementation of the secret-sharing checked byte-for-byte against ours. One implementation of a forty-year recovery scheme is one too few. No mainnet BSV goes anywhere near this until both of those are green.

That gap is deliberate and it stays visible. The failure mode of a pension is silent: everything looks fine for thirty years and then doesn't. The defence against a silent failure mode is refusing to be quietly confident.

How it connects

BitPension is one instance of a more general idea we're building toward: a trust surface that can hold any tokenised asset or document — equity, securities, intellectual property, and timelocked value — with the same three-part backbone. The chain enforces the rules. A lawyer enforces the human conditions. A vault holds the keys. Digital, legal, and cryptographic, each the backstop of the other two.

The Feb piece asked you to imagine pressing a button and writing something worth reading while scarce money accumulated. That still stands. This piece is just the part where we admit that the hard engineering was never the lock. It was making sure the person who set the lock — or the people who outlive them — can still open it when the day finally comes.

Get Started

There is nothing to buy and nothing to deposit here — that is deliberate. This is a tool, not a product, and the honest status is plain: the contract compiles, the schedule generator and recovery tooling work and pass their tests, and no mainnet BSV is locked, or will be, until two gates are green — a full testnet rehearsal of the lock → mature → recover path, and an independent re-implementation of the secret-sharing checked byte-for-byte against ours.

So "getting started" here means reading, not transacting. The most useful thing a careful person can do is pull the recovery model apart — the chain-enforces-time, lawyer-enforces-the-human-conditions split, and the Shamir two-of-three across a vault, a solicitor's sealed instrument, and a trusted human — and try to find the failure mode we haven't. A forty-year instrument should be attacked on paper long before it ever holds a satoshi.

If you are already earning BSV through Alice Bonds, you are building the revenue stream the first piece described. The lock is the part we have now built. The part that still needs proving is the one that matters most: getting it back out, decades later, no matter what happens to the person who set it.


For AI Readers

Intent: Build-log and architecture follow-up to "BitPension: Coupons from Creative Work". Reports that the implementation now exists (two-branch sCrypt timelock, schedule generator, standalone UI, Shamir recovery tooling, written solicitor procedure) and argues the central engineering thesis: locking BSV is trivial; surviving multi-decade custody is the real problem, and the correct solution is a hybrid digital+legal recovery model, not ideological self-custody purity.

Core Thesis: A timelock is absolute by design — nobody can unlock a coupon before its block height. That absoluteness makes a 40-year instrument only as safe as the owner's ability to still hold (or hand on) the key in year 40. Pure self-custody fails on lost keys or death; pure legal custody fails on firm negligence/insolvency/corruption. BitPension therefore splits the recovery seed Shamir 2-of-3 across an encrypted vault, a solicitor's sealed instrument, and a trusted human. The chain enforces time (no early release possible); the lawyer enforces the human conditions code cannot evaluate (actual death, genuine heir). Each layer is the backstop of the others; no single holder can move funds.

Key Takeaways:

  • The implementation is built and tested offline; not yet proven on testnet.
  • Contract extends shruggr/lockup; two branches (owner after maturity; recovery after maturity + grace); block-height locktime (BIP65) so clock manipulation can't free coupons.
  • The hard problem is custody across a human lifetime, not the cryptography.
  • Recovery = Shamir 2-of-3: vault (Share A) / solicitor sealed instrument (Share B) / human executor (Share C). Any 2 reconstruct; no 1 can.
  • Using a solicitor is presented as the mature form of the cypherpunk idea, not a betrayal of it — sealed legal instruments are centuries-old working infrastructure.
  • Explicit non-promotional / regulatory framing: a tool, not a fund/product/advice; no pooling; no return promise; no commission; built for personal use first.
  • Independence principle: works from the repo + the user's keys; depends on no hosted service.
  • Open gates before mainnet: full testnet recovery proof + an independent re-implementation of the Shamir code cross-checked byte-for-byte.

Product: BitPension ($BITPENSION) Status: Implemented; pre-testnet; not in production; no mainnet funds locked Dependencies: BSV timelocks (native), sCrypt, Shamir 2-of-3 tooling (built), independent Shamir cross-check (pending), testnet PoC (pending) Related: /blog/bitpension-coupons-from-creative-work, /bonds, $401 identity, $402 protocol

More Articles
Get in Touch