Crypto home invasions jump 20x as wrench-attack exposure hits $124 million

CertiK tracked just one crypto-related home invasion in the first half of 2025. A year later, its publicly verifiable tally had surged 20-fold.

Physical-coercion crimes, often called wrench attacks, bypass digital defenses by threatening a holder or relative until someone surrenders access or moves funds. The change turns a crime statistic into a custody-design problem: a secure key is not enough if one frightened person can release all the value immediately.

- Advertisement -

In CertiK’s H1 2026 wrench-attack report, released July 23, across all attack types, the security firm counted 52 verified incidents, up 33.3% from 39 a year earlier. It recorded roughly $124.1 million in financial exposure from losses and ransom demands, compared with about $10.5 million in H1 2025, an 11.8-fold increase.

Related Reading

IRL crypto threats: Physical “wrench attacks” have led to over $100 million in losses since January alone

Wrench attacks are forcing exchanges and holders to rethink protection as criminals target the people behind private keys.

Read More:  Trump’s financial disclosure puts $1B crypto payday at center of CLARITY Act vote

May 11, 2026 · Oluwapelumi Adejumo

Within the dataset, Europe accounted for 39 cases and France for 33, a clear concentration in the visible record.

Related Reading

France’s crypto kidnapping surge exposes the personal data trail behind wrench attacks

France’s response shows why visible crypto wealth now demands offline threat planning, data controls, and faster law-enforcement coordination.

Jul 2, 2026 · Liam ‘Akiba’ Wright

Custody has to survive coercion

A hardware wallet or offline seed phrase can still be bypassed as a sole safeguard when a holder is forced to unlock a wallet, reveal recovery material, or authorize a transaction. The first priority is therefore to eliminate unilateral authority over significant funds.

CertiK recommends multisignature or multiparty computation with geographically distributed signers so no person at the scene can approve the full transfer. The second layer adds time and limits through withdrawal delays, transaction caps, allowlists, and staged vaults. An independent emergency freeze is another way to stop a transfer without asking the person under threat to resist.

Read More:  Bitcoin faces a 90-minute Fed shock as CPI and Warsh testimony collide today

Wallet providers can support that architecture with configurable limits, delayed withdrawals, and duress-aware controls, while firms should map everyone who can move funds, approve transactions, or reset access, and then separate those roles behind approval thresholds.

The safeguards turn an attacker’s demand into a dead end, buying time while approval limits keep the bulk of the funds locked away.

CryptoSlate Daily Brief

Daily signals, zero noise.

Market-moving headlines and context delivered every morning in one tight read.