h hoge.gg
Subscribe
BTC$67,432.18+2.34%ETH$3,521.44+1.08%SOL$178.62-0.62%BNB$612.30+0.41%XRP$0.6234-0.18%ADA$0.4521+3.12%DOGE$0.1623+1.86%AVAX$38.71-1.24%LINK$17.84+0.92%HOGE$0.00004120+4.21%
BTC$67,432.18+2.34%ETH$3,521.44+1.08%SOL$178.62-0.62%BNB$612.30+0.41%XRP$0.6234-0.18%ADA$0.4521+3.12%DOGE$0.1623+1.86%AVAX$38.71-1.24%LINK$17.84+0.92%HOGE$0.00004120+4.21%
● Security & Exploits

Wrench Attacks in 2026: CertiK Maps Crypto’s $124M Physical Threat

CertiK's Intel3D team verified 52 physical coercion attacks on crypto holders in the first half of 2026, with $124.1 million in losses. Here is what the wrench-attack surge means for self-custody.

Bitcoin spent the first Friday of September 2026 holding above $81,000, steady ahead of the August jobs report and the run of macro dates that will shape the fourth quarter. For most holders, the number on the screen is the whole story. For a growing minority, the more urgent number is the one attached to their front door: their home address, and whether a stranger with a weapon knows it.

On July 22, 2026, the blockchain security firm CertiK published the first-half edition of its Intel3D Wrench Attacks Report, the running tally its threat-intelligence unit keeps of physical coercion against crypto holders. The findings were blunt. CertiK verified 52 such attacks in the first six months of the year, up from 39 in the same period of 2025, and put the estimated financial exposure at $124.1 million. That is not a rounding error on the roughly $1.3 billion the same firm attributes to on-chain theft over the same window; it is a different category of risk entirely, one that no smart-contract audit can close.

CertiK built its brand grading code. Its Skynet dashboards and Hack3d loss reports made it the industry’s most-quoted scorekeeper for exploits, rug pulls, and bridge hacks. The Intel3D report is the same firm turning its attention to a threat that has nothing to do with Solidity: the crowbar, the zip tie, and the demand to open your wallet now. This piece walks through what the data says, why France became the center of it, how attackers find their targets, what corporations are spending to protect their executives, and what actually reduces the risk for everyone else, with an honest look at what does not.

What a wrench attack actually is

The term comes from a 2009 xkcd comic. A cartoon researcher boasts that no computer could ever crack his encryption; the punchline is a second figure explaining the cheaper plan, hitting him with a $5 wrench until he gives up the password. The joke aged into jargon. A “wrench attack,” or physical coercion attack, is any incident in which someone uses violence, intimidation, or a credible threat to force a victim to transfer digital assets, surrender private keys, unlock a device, reveal credentials, or pressure a third party into doing the same.

The logic is uncomfortable but simple. Self-custody was designed to remove trusted intermediaries. There is no bank to freeze the account, no chargeback, no fraud department to call. Those same properties, celebrated as censorship resistance, become a liability the moment a person with physical access to you wants your keys. A well-secured cold wallet defeats a remote hacker precisely because the keys never touch the internet. It does nothing to stop an attacker standing in your kitchen who can compel you to sign a transaction that is, on-chain, indistinguishable from one you made willingly. Once the funds move, they are gone; there is no negotiation to reverse a transfer made at knifepoint.

That inversion is what makes the trend so hard to engineer away. Every improvement in digital security, whether hardware wallets, passphrases, or multisig, raises the cost of hacking someone and, at the margin, pushes the most determined criminals toward the one attack surface that has never been hardened: the owner.

The numbers behind CertiK’s H1 2026 ledger

The headline figures describe an acceleration, not a drift.

MetricH1 2025H1 2026Change
Verified incidents3952+33%
Estimated exposure~$10.5M$124.1M~12x
Average per incident~$270,000$2.39M~9x
Home invasions120+19 cases
Kidnappings1216+4 cases
Torture / murder4 / 14 / 1steady
Source: CertiK Intel3D H1 2026 Wrench Attacks Report, as reported by crypto.news and GlobeNewswire.

Two things stand out. First, the money. Total estimated exposure jumped from roughly $10.5 million in the first half of 2025 to $124.1 million, close to a twelvefold increase that Decrypt summarized as losses up twelve times in six months, while the average recorded loss per incident rose from about $270,000 to $2.39 million, almost nine times higher. The count went up by a third; the damage went up by an order of magnitude. Second, the method. Home invasions climbed from a single verified case a year earlier to 20, making forced entry the most common attack type CertiK recorded in the period, per its reported breakdown.

The quarter-by-quarter split is easy to miss and worth pausing on. CertiK logged 35 incidents in the first quarter of 2026 against 22 in the first quarter of 2025, then 17 in the second quarter of 2026, the same as the second quarter of 2025. In other words, the entire year-over-year surge landed in the first three months, and the second quarter reverted to the prior year’s pace. Whether that reflects a genuine cooling, a lag in verification, or the effect of a spring crackdown in France is the open question the back half of this piece returns to.

Fewer targets, bigger hauls

CertiK’s own framing for the shift is that attackers are pursuing “fewer, higher-value targets” rather than chasing volume, a phrase drawn from its report summary. The average-loss figure is the tell. A ninefold jump in the take per incident, against only a one-third rise in incident count, is the signature of planning: surveillance, target selection, and an expectation of a payout large enough to justify the risk of a violent felony.

The category mix supports that read. Home invasions (from 1 to 20) and kidnappings (from 12 to 16) both rose, while torture (4) and murder (1) held steady. These are not opportunistic muggings. A home invasion requires knowing where the target lives; a kidnapping requires knowing who around them can pay. Both imply reconnaissance, and reconnaissance implies that the attacker believed, before acting, that the victim held enough to be worth it.

Ari Redbord, global head of policy and government affairs at TRM Labs, has been tracking the same curve. “2025 was a record year for wrench attacks,” he told The Block, adding that “the true number is likely significantly higher” than any public tally because many victims never come forward. Under-reporting is the standing caveat over every figure in this article: a coerced transfer can look, to everyone but the victim, like an ordinary send.

Why France became the epicenter

The most striking finding is geographic. Of the 52 verified incidents, 39, about three quarters, occurred in Europe, and 33, some 63.5% of the global total, occurred in France alone. The United States recorded four, with Sweden and the United Kingdom two each. For a phenomenon usually imagined as a global problem, the first half of 2026 was, overwhelmingly, a French one.

CertiK links the concentration to two factors: a visible, high-profile crypto ecosystem, and a run of major data breaches, including incidents at French government services, that pushed personal information into circulation. France is home to Ledger, one of the world’s largest hardware-wallet makers, and to a dense cluster of founders, funds, and conference circuits. Visibility, in this reading, is exposure.

The spring of 2025 made the trend a national story. In January, David Balland, a co-founder of Ledger, was abducted from his home in central France; his captors demanded a ransom of about 100 BTC (worth roughly $10 million at the time) from a fellow co-founder and mutilated one of Balland’s hands before an elite gendarmerie unit, the GIGN, freed him and his partner. In May, four masked men attempted to seize the daughter and grandson of Pierre Noizat, chief executive of the exchange Paymium, in broad daylight in Paris, and were foiled by bystanders. Days later, the French interior minister, Bruno Retailleau, convened crypto executives for a confidential meeting and agreed on measures including police briefings, priority alert access, and home-security assessments for sector figures. By June, French authorities had made more than 20 arrests tied to the kidnapping networks.

That enforcement response is the most plausible explanation for the second-quarter dip in CertiK’s data. It also frames the deterrence question in a way that on-chain security never allows: physical crime responds to policing. There is no squad car you can send after a reentrancy bug.

The cases that defined the trend

Aggregate numbers understate how specific these attacks are. A short list of verified incidents from 2025 and 2026 shows the range of methods and the fact that no jurisdiction is immune.

CaseWhen and whereMethodOutcome
David Balland, Ledger co-founderJan 2025, central FranceHome abduction; ~100 BTC (~$10M) ransom; hand mutilatedFreed by GIGN; suspects arrested
Pierre Noizat family, Paymium CEOMay 2025, ParisAttempted daylight abduction of his daughter and grandson by four masked menFoiled by bystanders; arrests followed
SoHo townhouse torture caseMay 2025, New York CityVictim lured and held for weeks; tortured for a Bitcoin passwordVictim escaped; two charged, pleaded not guilty
Ransom-by-proxy kidnappingMay 2025, FranceFather of a crypto entrepreneur abducted; finger severedRescued; 20+ arrests across linked networks
Sources: France 24, CoinDesk, CBS News.

The New York case is the American counterpoint to France’s cluster. Prosecutors allege that two investors, John Woeltz and William Duplessie, lured a 28-year-old Italian man to an eight-bedroom townhouse in SoHo in May 2025 and held him there, demanding the password to his Bitcoin; the victim escaped after offering to retrieve it from a laptop, and both defendants have pleaded not guilty. The details are grim, and they are the point: the target was not a protocol or an exchange, but a single person and the secret in his head.

Jameson Lopp, co-founder of the custody firm Casa, has catalogued this history longer than anyone. His open-source list of physical Bitcoin attacks now runs to more than 100 documented incidents over the past decade, and his tally identifies 2025 as the worst year on record, with roughly 70 attacks against about 41 in 2024. CertiK counts verified incidents under a stricter standard, which is why its number (52 for the first half of 2026) sits below Lopp’s broader figure. The two datasets diverge on method, not on direction.

The record also refuses to stay in any one country. Lopp’s archive spans dozens of jurisdictions, from the United States and France to Turkey, the United Arab Emirates, and points across Asia and Latin America, and it includes low-profile holders as well as founders. Perceived wealth is enough: several victims were targeted not because they were rich but because an attacker believed they were, sometimes on the strength of a single post. That is the uncomfortable implication of a coercion-driven threat model. You do not have to actually hold a fortune to be treated as though you do.

How attackers build a target list

The recurring question after each case is the same: how did they know? CertiK’s answer is that a large share of victims, in effect, told them. In roughly 43% of first-half incidents where investigators could reconstruct the pre-attack reconnaissance, the victim had publicly signaled wealth: posting about holdings, showing off a hardware wallet, discussing portfolio performance, or attending events where they were photographed. Nick Bax, a researcher affiliated with the Security Alliance (SEAL), has attributed much of the wave to “poor privacy” and to people “flexing their net worth in group chats.”

Public blockchains sharpen the problem in a way traditional wealth does not. A bank balance is private; an on-chain balance is visible to anyone once a wallet is tied to a name, which turns a single successful doxxing into a precise, real-time estimate of how much a victim is worth. Chain-analysis skills built to trace criminals can be pointed the other way, and a market of data brokers already sells the linkage between wallets, exchange accounts, and physical identities. Where a mugger once had to guess at a target’s wealth, an attacker profiling a crypto holder can often read it off a block explorer.

The other half of the pipeline is data that leaks whether or not you post. Ledger itself is the cautionary tale. A 2020 breach of its e-commerce database exposed the names, phone numbers, and home addresses of more than 270,000 customers, information later dumped publicly and used for phishing, extortion letters, and, in some cases, physical threats. In January 2026, a breach at Ledger’s e-commerce processor produced a fresh wave of physical letters, personalized with recipients’ names, exact addresses, and device models, impersonating a security notice from the company’s own chief technology officer. CertiK ties France’s concentration in part to breaches at government services, which widen the pool of linkable identity data still further.

This is where physical risk meets the debate over identity. The same know-your-customer and anti-money-laundering rules that require exchanges and custodians to collect names, addresses, and document scans also create databases whose compromise can be dangerous. A honeypot built for compliance is a honeypot all the same. None of this argues against KYC on its own terms, but it does mean that every mandated data store is also a mapped set of potential targets, and the security of that store is now a physical-safety matter, not only a privacy one.

When executive protection becomes a line item

For companies, the response has been to spend. Coinbase disclosed in its 2026 proxy statement, filed with the U.S. Securities and Exchange Commission, that it spent about $8.7 million in 2025 on the personal security of chief executive Brian Armstrong, up from roughly $6.2 million the year before, covering protection officers, secure lodging, and residential security. The contrast inside the same SEC filing is instructive: the company’s president and chief operating officer, Emilie Choi, received about $43,567 in security-related benefits over the same year, per The Block’s reading of the proxy. The gap is a rough proxy for how visibility maps to perceived risk.

Company / personReported security spendSource
Coinbase, CEO Brian Armstrong~$8.7M (2025), up from ~$6.2M (2024)SEC proxy filing
Coinbase, President Emilie Choi~$43,567 (2025)SEC proxy filing
Gemini (executive protection)~$400,000 per monthCertiK Intel3D report
MARAseveral million dollars, incl. vehicle armoringCertiK Intel3D report
Sources: Coinbase 2026 proxy (SEC), The Block, CertiK Intel3D H1 2026 report.

CertiK’s report cites other examples of the same trend, including a reported $400,000 a month spent by Gemini on executive protection and several million dollars spent by the miner MARA, part of it on vehicle armoring. Because U.S. public companies must disclose executive perquisites, the SEC filing is where much of this spending becomes visible: security that would once have been a discreet arrangement is now a reported, dollar-denominated risk indicator. It also underscores a limit of the approach. A protective detail is available to a listed-company chief executive; it is not available to the typical self-custodian who is, per CertiK’s own data, increasingly the person at the door.

The custody paradox: where exchanges hold an edge

There is an irony in the data that cuts against a decade of crypto orthodoxy. The movement’s rallying cry, that if they are not your keys they are not your coins, assumes the danger always lies with the custodian. A wrench attack inverts that assumption. An attacker who corners a self-custodian can compel an immediate, irreversible transfer of everything the victim controls, with no counterparty to slow it down. The same coercion applied to someone whose funds sit on a regulated exchange runs into friction that has nothing to do with cryptography: withdrawal limits, address allowlists with cooling-off periods, mandatory holds on transfers from new devices, and a support desk that can freeze an account when a pattern looks wrong.

None of that makes exchanges safe in the broad sense. They carry their own custody, insolvency, and hacking risks, and their identity databases are precisely the honeypots described above. But against the narrow threat of physical coercion, that friction is a feature. It is why the most careful self-custodians increasingly imitate the exchange model, splitting funds between a spending wallet with trivial balances and a deep-cold vault that no single person, coerced or not, can move in a hurry. The design goal is the one Sabbatella described: keep the fast money small and the large money slow.

That convergence, with custodial platforms adding self-custody options while self-custodians borrow custodial controls, is one of the clearer second-order effects of the wrench-attack wave. The account-abstraction tooling now reaching consumer wallets is what makes it practical for an individual to run exchange-grade rules on keys they alone hold, without a company sitting in the middle.

The threat the code cannot patch

CertiK’s Intel3D work fits a larger thesis the firm has argued all year: the losses are moving off the code. In its Hack3d report for the first half of 2026, chief executive and co-founder Ronghui Gu noted that “attackers are getting more return by going after key management, multisig governance, and operational infrastructure than by hunting for bugs in code,” a line drawn from Forbes’s coverage of the report. The wrench-attack data is the physical extreme of that same migration. When the cheapest path to the keys runs through the key holder, the quality of the smart contract is beside the point.

That reframing is disorienting for an industry that spent a decade treating security as an engineering problem. Tor Bair, chief executive of Hybrid Minds Advisory and former president of the Secret Foundation, put the ceiling plainly: “No matter how many technical precautions you take or how many factors you authenticate with, no individual is immune to human attack vectors,” adding that “there is no such thing as perfect security, only better security, and it always comes at a cost.” An audit can prove properties of a contract. It cannot prove anything about the person who controls it.

This is why the wrench attack belongs in a security-exploits conversation at all, even though not a line of code is broken in a single one of these cases. The asset, the incentive, and the finality are all products of the same system that on-chain exploits target. The attacker has simply chosen the one layer engineers do not control.

Duress wallets, decoys, and the limits of plausible deniability

If a determined attacker can always reach the person, the defensive question becomes whether you can design a system in which the person genuinely cannot hand over everything, even under coercion. That idea sits at the center of crypto’s newest security debate, and the tools fall into a few families.

Decoy and duress wallets rely on plausible deniability. A passphrase-protected hidden wallet lets a holder unlock a small, believable balance under threat while the main funds stay behind a different secret; wallet makers including BlueWallet, Trezor, and Nunchuk ship versions of this, and Foundation Devices has said it is testing biometric passphrase protection for a release in the third quarter of 2026. Panic wallets go further, adding duress triggers that can wipe a balance, surface a decoy, or silently call for help.

Multisignature and MPC arrangements attack the problem structurally. A 2-of-3 setup with keys in separate locations, or a policy that enforces a withdrawal delay no local threat can override, means that no single coerced signature moves the money. Pablo Sabbatella, co-founder of the security outfit Opsek, frames the goal as removing unilateral control: “design systems that do not allow you to move your long-term funds alone.” The same principle is spreading into consumer wallets through account abstraction; the smart-account standards arriving across wallets and exchanges make spending limits, guardians, and time-locked recovery configurable defaults rather than expert-only setups.

The honest caveat is that the evidence for these defenses is thin. There is very little data on how duress wallets perform in real attacks, and the cases that exist are not encouraging: in one documented incident a victim’s decoy failed to convince the assailant, and in another the victim complied immediately and was tortured for hours anyway because the attacker assumed hidden reserves existed. A defense that depends on an attacker believing you have nothing left works only until attackers learn to assume you are lying.

The unglamorous defenses that actually help

Ask the people who have studied this longest and the advice is consistent and dull: do not become a target in the first place. Jameson Lopp’s guidance, echoed across security researchers, reduces to keeping a low profile: do not broadcast holdings, do not flash hardware wallets, do not discuss portfolio size, and treat any request to change location or share personal details as hostile by default. In one survey of security professionals cited by The Block, eight in ten named a low profile as their first line of defense.

Privacy technology helps in a specific way. Tools that reduce the on-chain footprint of your wealth make you harder to profile before an attack. Bitcoin’s reusable silent-payment addresses, for example, let a holder receive funds without publishing a static address that links every payment to one identity, shrinking the trail reconnaissance depends on. Reducing what is publicly knowable about your balances is not glamorous, but it aims directly at the 43% of cases that began with a visible signal of wealth.

Behavior at events and while traveling deserves its own line. The reconnaissance CertiK describes often begins at conferences, meetups, and the hotels around them, where badges, side conversations, and social posts quietly assemble a target list. Practical habits follow: leave hardware devices at home rather than carrying them through unfamiliar cities, keep large balances off any device that travels, avoid geotagging in real time, and treat an unsolicited in-person approach about your holdings as the opening move of an attack rather than a networking accident. The people most exposed are often the most visible, which is exactly the population a public event is built to make findable.

For those holding meaningful sums, physical measures round out the picture: reinforced entry points, cameras, alarm response, and, above all, a family plan. Kidnappings and home invasions frequently target relatives rather than the holder, so a household that knows what to do, and that cannot individually move the funds, is itself a deterrent. Sabbatella’s rule bears repeating in this context: “you can’t have direct access to long-term funds.” If you cannot move it alone, neither can anyone forcing you to.

The regulatory gap: no market watchdog polices a crowbar

There is a jurisdictional hole at the center of this problem. The SEC oversees securities markets, disclosures, and the conduct of registered firms; it does not investigate assaults. A wrench attack is a matter for the FBI, the Department of Justice, and local police, and in Europe for national forces like the gendarmerie units that freed David Balland. No market regulator’s rulebook, in the United States or under Europe’s MiCA framework, reaches a crime committed with a weapon in a private home.

That gap has a practical consequence for victims. On-chain, an industry has grown up around after-the-fact response, from tracing firms to recovery bounties that pay hackers a percentage to return stolen funds. Those mechanisms depend on the counterparty being reachable and, in some sense, rational. A violent robber who has already moved coins through a mixer is neither. The finality that makes crypto attractive is, for the physically coerced victim, the same property that makes recovery close to impossible.

The macro backdrop does not help. With Bitcoin holding above $81,000 into a data-heavy September and the calendar of jobs prints, inflation reports, and a Federal Reserve decision all capable of moving prices, paper wealth is both larger and more visible than it was a year ago. Rising prices expand the population of people worth targeting faster than any of them can upgrade their physical security.

What the second half of 2026 will decide

CertiK’s data leaves three questions open. The first is whether the second quarter’s reversion to trend was real. If the French crackdown genuinely bent the curve, the back half of 2026 should stay closer to 2025’s pace than to the first quarter’s spike; if the dip was a reporting lag, the annual total will climb regardless.

The second is displacement. Aggressive policing in France may simply move the activity to jurisdictions with weaker enforcement and looser reporting, which would show up in CertiK’s data as a shift away from Europe rather than a fall in the global count. The geographic concentration that defined the first half of 2026 is unlikely to be permanent.

The third is the one the industry finds hardest to say out loud. Self-custody, the founding value proposition of this technology, carries a physical tail risk that scales with the price of the assets it secures. The defenses that work best, distributed control, withdrawal delays, and a low profile, all involve giving up some of the immediacy and the bragging rights that drew people to crypto in the first place. CertiK can count the attacks. Whether holders change their behavior before the count climbs again is not a question any dashboard can answer.

Frequently Asked Questions

What is a wrench attack in crypto?

A wrench attack is a physical coercion attack in which someone uses violence, intimidation, or a credible threat to force a crypto holder to transfer assets, hand over private keys, or unlock a device. The term comes from a 2009 xkcd comic making the point that it is often cheaper to beat a password out of someone than to break strong encryption. Because on-chain transfers are final and self-custodied funds have no intermediary to reverse them, a coerced transaction is very hard to undo.

How many wrench attacks happened in 2026?

CertiK’s Intel3D team verified 52 physical coercion attacks against crypto holders in the first half of 2026, up 33% from 39 in the same period of 2025, with estimated losses of $124.1 million. Independent trackers such as Jameson Lopp’s open-source list record higher totals under a broader definition, and researchers agree many incidents are never reported, so the real number is likely higher.

Why are so many wrench attacks happening in France?

France accounted for 33 of the 52 verified incidents in CertiK’s H1 2026 report, about 63.5% of the global total. CertiK attributes the concentration to France’s highly visible crypto ecosystem and to a series of data breaches, including at government services, that exposed personal information. A wave of high-profile abductions in 2025 pushed the French interior ministry to offer security support to sector figures.

Can a hardware wallet or multisig stop a wrench attack?

A hardware wallet protects against remote hacking but not against an attacker who can physically compel you, because a coerced transaction looks legitimate on-chain. Multisignature and MPC setups help more, since a policy that requires several geographically separated approvals or enforces a withdrawal delay means no single coerced signature can move the funds. Duress and decoy wallets add plausible deniability, but there is little evidence they reliably work under real coercion.

How can crypto holders reduce their risk of a physical attack?

The most consistent advice from security researchers is to keep a low profile: avoid publicizing holdings, flashing hardware wallets, or discussing portfolio size, since about 43% of victims in CertiK’s data had signaled wealth beforehand. Beyond that, use distributed custody so you cannot move long-term funds alone, add withdrawal delays, reduce your on-chain footprint with privacy tools, and, for larger holders, invest in home security and a family safety plan.

Anneke de Vries is HOGE Wire’s security desk editor.

Share 𝕏 Post Telegram