It started with a knock on the door. A man in Paris who had quietly accumulated over $2 million in Bitcoin over the past five years — never posting about it, never mentioning it at work — answered his front door on a Tuesday evening in April and met four strangers who already knew exactly what he held and where he kept his hardware wallet. By the time his neighbors called the police, the attackers were gone, and so was everything he had built. They had not broken a single line of code.
This is the new face of crypto crime — and it is not happening on the blockchain. It is happening at front doors, in parking garages, and in suburban kitchens across Europe and beyond. As digital security has grown more sophisticated and harder to crack, criminals have pivoted to the one vulnerability that no cryptographic algorithm can fix: the human beings who hold the keys. The strategy even has a name, borrowed from a dark corner of internet security culture: the wrench attack. Why spend months trying to break a hardware wallet when you can simply threaten the person holding it?
A landmark mid-year report from blockchain security firm CertiK, corroborated by data from Chainalysis, revealed that wrench attacks have reached a scale the industry can no longer treat as a footnote. The numbers are alarming, and they are getting worse.
The Numbers: $124 Million in Six Months
CertiK’s H1 2026 physical security report documented 52 verified wrench attacks between January and June — a 33% increase over the 39 incidents recorded in the same period a year earlier. But the headline figure is not the incident count. It is the financial damage: $124.1 million in total financial exposure during those six months alone. In the first half of 2025, that figure was $10.5 million. The jump — nearly twelve-fold in a single year — reflects both the growing sophistication of attackers and the rising price of the assets they are targeting.
The average loss per incident tells its own story. In H1 2025, the average successful wrench attack netted attackers around $269,000. In H1 2026, that figure climbed to approximately $2.4 million per incident — nearly nine times higher. Attackers are not swinging randomly. They are conducting extensive reconnaissance, identifying high-value targets, and striking with precision.
Chainalysis, which tracks both on-chain and real-world crypto crime, estimates that roughly $30 million in funds was actually extracted and moved in successful attacks — a figure that excludes frozen assets, ransom payments under negotiation, and cases that have not yet been made public. The firm notes that only 26% of theft attempts in 2026 succeeded, down from 49% in 2025, suggesting that awareness and better security practices are having some effect. The other side of that coin: the attacks that do succeed are far larger than before.
France at the Center of a Growing Crisis
If wrench attacks have a current epicenter, it is France. Of the 52 verified incidents in H1 2026, 33 occurred in France — roughly 63.5% of global cases. French authorities have been considerably more forthcoming with data than other jurisdictions; they reported 77 crypto-related kidnappings and extortion cases in the first half of the year alone, suggesting that the publicly verified count significantly undercounts the actual problem.
Researchers have traced France’s outsized exposure to a 2024 data breach involving compromised records from French financial and tax authorities. The stolen dossiers reportedly included names, home addresses, asset holdings, phone numbers, and tax filings for thousands of wealthy crypto holders. That dataset, or data derived from it, appears to have been circulating in criminal networks ever since, enabling the kind of targeted, intelligence-driven attacks that have made France so dangerous for crypto holders. The breach did not just expose individuals — it created a shopping list that organized crime groups have been working through methodically.
The problem has risen to a level that French Interior Minister Bruno Retailleau addressed directly in a June press conference, calling for new measures to protect crypto holders and pledging enhanced coordination with exchanges to identify and secure high-risk individuals. Several prominent French crypto influencers and founders — individuals who had built their profiles on social media around their holdings — have since deleted accounts and relocated.
How the Attacks Work: A New Criminal Playbook
The evolution of wrench attacks mirrors the broader professionalization of organized cybercrime — except that the weapon of choice here is intimidation rather than malware. CertiK’s report identified three distinct tiers of perpetrators, ranging from opportunistic criminals to sophisticated organized networks with cartel and extremist financing connections.
At the tactical level, the most significant shift in H1 2026 was the surge in home invasions. This attack vector went from a single verified case in the first half of 2025 to 20 cases in H1 2026. Kidnappings rose from 12 to 16 incidents over the same period. One homicide linked to a crypto-motivated attack was also documented. The preference for home invasions reflects what security analysts call a “controlled environment” advantage: attackers can take their time, reduce the risk of witnesses, and apply sustained pressure on victims without the exposure of a street encounter.
More disturbing still is the rise of family member targeting. In 2021, attacks on relatives — spouses, children, elderly parents — were essentially unreported. By mid-2026, Chainalysis found that 25 to 30% of global wrench attacks targeted family members rather than the crypto holder directly. In France, the figure exceeded 40%. Attacking a family member is, in many cases, more effective than attacking the holder: it creates overwhelming psychological pressure without requiring the attacker to be present when the victim accesses their wallet.
Reconnaissance is increasingly thorough and long-running. CertiK documented cases in which criminals built target profiles over weeks or months, combining blockchain analytics, leaked financial data, social media activity, and insider information purchased from exchange employees. Honeypot schemes — including fake romantic relationships used to stage assaults — have also been documented in Spain and Sweden.
The Technical Paradox: Better Locks, More Violence
There is a grim logic underneath the surge. As the crypto industry has invested billions of dollars in cryptographic security, multi-signature custody, hardware wallet protection, and smart contract audits, the cost of stealing crypto by technical means has increased dramatically. The protocols are not unbreakable, but cracking them now requires sophisticated state-level capabilities, months of work, or massive resources that most criminal organizations simply do not have.
Physical coercion is cheaper. It scales to the size of whatever the target holds. It does not require a technical background. And it has historically been underpoliced in the crypto space, because most law enforcement agencies are still primarily focused on digital-asset crime rather than its physical analogs.
CoinDesk, which covered the early arc of this trend in February, described it as the “Technical Paradox” — the phenomenon where improved digital security inadvertently increases physical risk. The better your vault, the more appealing the option of forcing you to open it. Lloyd’s of London and several specialty insurers have begun responding to this dynamic, now offering insurance products that explicitly cover wrench attack scenarios, a category that barely existed as a named product three years ago.
What This Means for You
If you hold cryptocurrency — whether a few thousand dollars or significantly more — the wrench attack trend has practical implications that go well beyond updating your wallet firmware. Here is what security professionals recommend:
- Operational silence is your first line of defense. The single most consistent thread across 2026 attack cases is that victims were identifiable — through social media, tax records, on-chain activity, or exchange data leaks. The safest crypto holders are the ones who are invisible. Do not publicly post about your holdings, do not link your real identity to on-chain addresses, and be cautious about which exchanges and wallets you connect your identity to.
- Multi-signature custody raises the cost of attack. If your funds require approvals from two or more separate devices stored in separate locations, a single coercion event cannot drain your wallet. This does not eliminate the threat, but it substantially raises the cost and complexity of any attack.
- Withdrawal delays add a critical window. Some custody solutions now support time-locked or delayed withdrawals — a setting that prevents any transfer from completing for 24 to 72 hours after initiation. That window may be the difference between a catastrophic loss and a recoverable situation.
- Prepare your family, not just your wallet. With 25–40% of attacks now targeting relatives, family preparedness has become a genuine security consideration. This does not mean alarming your family unnecessarily, but it does mean ensuring they know not to discuss your holdings and are aware of basic safety protocols.
- Consider physical security proportionate to your holdings. For high-value holders, this means thinking seriously about home security, visitor screening, and geographic privacy in ways that were once associated only with traditional high-net-worth individuals.
An Industry Reckoning
The crypto industry has spent the better part of a decade building better vaults. It has been less attentive to the question of what happens when criminals stop trying to crack them. The wrench attack surge of 2026 is not a peripheral problem. It is the direct consequence of asymmetric progress — digital defenses improving faster than the physical security frameworks designed to protect the humans who use them.
That gap is now visibly closing — but not in the way the industry would want. Criminals have adapted. Organized networks have built infrastructure to exploit it. And the data from CertiK and Chainalysis suggest that the second half of 2026 is unlikely to reverse the trend on its own.
The man in Paris who answered his door on a Tuesday evening did everything the industry told him to do digitally. His mistake — if you can call it that — was being known. In a space that was built on pseudonymity, the most dangerous vulnerability in 2026 may simply be having your real name attached to your wallet balance. That is a security problem no firmware update will fix.
Sources:
CryptoTimes — Crypto Wrench Attacks Exposed $124M in H1 2026: CertiK Report
Chainalysis — Violent Wrench Attacks Targeting Crypto Holders
CoinCodex — Crypto ‘Wrench Attacks’ Surge in 2026
CoinDesk — Crypto Crime Is Getting Violent: Wrench Attacks Jumped 75% in 2026
CryptoBriefing — Violent Crypto Attacks Surge in 2026 with $124M in Exposure, France Hit Hardest