Key Highlights
- CertiK recorded 52 verified crypto wrench attacks during H1 2026, up 33% year-over-year.
- Recorded financial exposure reached $124.1 million, nearly 12 times higher than H1 2025.
- Home invasions jumped from one case to 20, overtaking kidnappings as the most common attack method.
Crypto-related crime is increasingly shifting away from technical exploits toward physical coercion, with criminals targeting individuals rather than blockchain protocols or smart contracts.
According to CertiK’s newly released H1 2026 Wrench Attacks Report published on Wednesday, verified physical attacks against cryptocurrency holders rose sharply during the first six months of the year, with 52 publicly documented incidents and more than $124 million in recorded financial exposure.
“H1 2026 confirms that wrench attacks are no longer a fringe phenomenon or an edge-case risk for cryptocurrency holders,” CertiK wrote.
The report defines a wrench attack as any incident in which victims are physically coerced through kidnappings, home invasions, armed robberies, or assault into surrendering cryptocurrency, private keys, or wallet credentials.
While the number of incidents increased by 33%, recorded financial exposure rose from $10.5 million in H1 2025 to $124.1 million this year. CertiK cautioned that the figures reflect only publicly verified cases, meaning the actual scale of the problem is likely much larger.
Why hackers are turning their attention to crypto holders
The report reflects a broader shift already visible across the crypto industry.
Earlier this month, Web3 lost $1.31 billion during H1 2026, with wallet compromises overtaking smart contract exploits as the largest source of losses for the first time. Rather than exploiting blockchain code, attackers are targeting the weakest link in the ecosystem, the user.
CertiK argues that physical coercion has become part of that evolution. Hardware wallets, cold storage, and offline seed phrases offer little protection when victims are forced to unlock wallets themselves.
“It is not enough to tell holders to use hardware wallets and keep seed phrases offline,” the report states.
Instead, the firm recommends multi-signature custody, withdrawal delays, geographically separated recovery systems, and emergency response plans designed to withstand physical coercion.
Why France is seeing a surge in crypto-related attacks
The report also highlights an increasingly concentrated geographic pattern.
Europe accounted for 39 of the 52 verified attacks, with France alone recording 33 incidents, nearly two-thirds of all publicly documented cases worldwide.
That finding mirrors recent action taken by French authorities.
Earlier this month, France unveiled a nationwide crypto security strategy after Interior Minister Laurent Nuñez disclosed 77 crypto-related kidnappings and extortion cases during the first half of 2026.
The initiative includes closer cooperation between law enforcement and the country’s crypto industry to dismantle organized criminal networks targeting digital asset investors. According to CertiK, France’s large crypto ecosystem, combined with repeated personal data breaches and organized crime activity, has made the country particularly attractive to attackers.
Home invasions replace kidnappings
Perhaps the most notable change in the report is how criminals are targeting victims. Home invasions increased from just one publicly reported incident in H1 2025 to 20 cases in H1 2026, making them the most common form of crypto-related physical attack.
Kidnappings also remained high, increasing from 12 to 16 incidents, while cases involving torture and murder continued to appear. Rather than waiting for victims to travel or arranging elaborate kidnappings, attackers are increasingly entering homes where hardware wallets, recovery phrases, and family members can all become leverage.
How attackers target crypto holders
CertiK says these crimes rarely begin with physical violence. Instead, attackers spend weeks or even months building detailed profiles of potential victims using leaked databases, tax records, exchange information, blockchain activity, conference attendance, and social media.
The report also warns that insider access has become an increasingly valuable source of intelligence.
Instead of simply tracking wallet balances, organized groups now seek customer databases, identity records, and exchange information that can be combined with publicly available blockchain data to identify high-value targets. Reducing personal exposure, CertiK argues, has become as important as protecting private keys.
Crypto continues growing despite rising physical risks
The surge in physical attacks comes even as institutional adoption continues accelerating.
A recent Bitwise report found that tokenization, crypto equities, institutional adoption, and blockchain application revenue all continued expanding during the first half of 2026 despite weaker cryptocurrency prices.
That growing adoption, however, also creates larger targets.
As more capital flows into digital assets, the industry’s security challenge is no longer confined to cyberspace.
CertiK concludes that protecting crypto holdings now requires thinking beyond smart contract audits and wallet security. Operational security, family preparedness, executive protection, and minimizing personal data exposure are becoming just as critical as securing blockchain infrastructure itself.
Also Read: Kalshi Debuts Midterms Hub for Tracking 2026 U.S. Election Markets
