CertiK Reports Crypto 'Wrench Attacks' Surge in H1 2026 as Home Invasions Rise Sharply
Key Takeaways
- •CertiK verified 52 crypto wrench attacks worldwide in the first half of 2026, a 33.3% increase from 39 incidents during the same period in 2025.
- •Home invasions became the most common attack method, rising from a single reported case in H1 2025 to 20 cases in H1 2026.
- •Estimated financial exposure from these attacks reached approximately $124.1 million in the first half of 2026, up from $10.5 million a year earlier.
- •France accounted for 33 of the 52 globally verified incidents, and French Interior Minister Laurent Nuñez reported 77 crypto-linked kidnappings, extortion, or attempted extortion cases in H1 2026 alone.
- •CertiK recommended multisignature or MPC arrangements, withdrawal delays, spending limits, and geographically separated signers to reduce the effectiveness of physical coercion in forcing unauthorized transfers.

Crypto "wrench" attacks—incidents in which victims are physically coerced or harmed to force the surrender of digital assets—rose sharply during the first half of 2026, according to a new report from blockchain security firm CertiK.
CertiK verified 52 wrench attacks worldwide in H1 2026, representing a 33.3% increase from the 39 incidents recorded during the same period in 2025. Home invasions became the most common method of attack, surging to 20 publicly reported cases compared with just one a year earlier. Kidnappings also increased to 16 from 12, while robberies declined from five incidents to one.
The estimated financial exposure tied to these attacks reached approximately $124.1 million, a substantial increase from $10.5 million in H1 2025. CertiK noted that this figure is broader than confirmed stolen funds and may include ransom demands, transfers made under duress, assets that were subsequently frozen or recovered, and unsuccessful ransom attempts.
A Shift Toward Physical Coercion
CertiK attributes the escalation to a growing willingness among criminals to circumvent digital security measures by applying direct physical pressure on victims and their families. The sharp increase in home invasions is the most prominent indicator of this shift, as an attack vector that previously appeared rarely in CertiK's dataset became the leading tactic in the first half of 2026.
For users who rely on self-custody, the report carries a significant implication: conventional security guidance centered on safeguarding private keys and account credentials may prove inadequate when attackers seek to gain control through physical force rather than technical exploitation. That distinction matters because many cryptocurrency transfers, once authorized and broadcast, can be difficult to reverse without rapid intervention from exchanges, investigators, or other counterparties able to freeze or trace funds.
France Accounts for the Majority of Verified Cases
The geographic distribution of incidents was highly concentrated. CertiK reported that Europe accounted for 39 of the 52 verified incidents, with France alone responsible for 33—nearly two-thirds of the global total.
CertiK noted that its methodology was narrower than that used by French authorities. The firm counted only publicly reported incidents it could independently verify, meaning the French government's own figures could be higher if they draw on a broader set of cases.
On July 2, French Interior Minister Laurent Nuñez stated that authorities had recorded 77 crypto-linked kidnappings, extortion cases, or attempted extortion cases during the first half of 2026, compared with 45 across the entirety of 2025. CertiK suggested that France's prominent crypto ecosystem may contribute to the pattern, noting that data breaches and information flows can link individuals' identities and home addresses to perceived cryptocurrency holdings.
Government Response and Enforcement
French authorities have responded to the increase with targeted enforcement and prevention initiatives. Nuñez announced that officials launched a dedicated prevention platform and a rapid-alert system designed for cryptocurrency holders and professionals. He also reported that emergency measures have led to 200 arrests.
The French response underscores that the issue is not limited to wallet software or blockchain monitoring. When attackers target people at home or in transit, prevention also depends on coordination between crypto businesses, law enforcement, and potential victims who may need a way to report threats before funds are moved.
CertiK's Wallet-Design Recommendations
CertiK's recommendations center on introducing friction into the transfer process so that attackers cannot quickly convert coercion into irreversible transactions. The firm argued that physical coercion can undermine the assumptions behind many self-custody practices, particularly when a victim can be compelled to authorize transfers on the spot.
To reduce the speed at which funds can be moved under pressure, CertiK recommended the following technical and operational controls:
- Multisignature or multiparty computation (MPC) arrangements, ensuring no single threatened individual can unilaterally authorize transfers.
- Withdrawal delays that slow down transfers after an authorization is initiated.
- Spending limits that cap the financial impact of any single coerced transaction.
- Geographically separated signers, so attackers cannot simultaneously pressure all parties required to move funds.
These measures are designed to erode the attacker's advantage by introducing requirements for multiple approvals or creating time windows during which victims may be able to seek assistance. They also reflect a broader security principle: custody setups built only around secrecy can be vulnerable when a victim is forced to disclose or use credentials, while systems requiring time, distance, or multiple independent approvals can reduce the value of immediate coercion.
Escalation From Remote to Physical Attack Vectors
The steep increase in home invasions points to a broader trend: attackers are increasingly shifting from remote scams and online account compromise toward scenarios in which the victim's immediate physical compliance is the central vulnerability. This shift also helps explain why wrench incidents produce a wide range of outcomes—from completed transfers under duress to cases where assets are later recovered or ransom demands fail.
As regulators and law enforcement refine their responses, a key question is whether defensive practices will keep pace, particularly in regions where incidents are concentrated. Both public reporting and independently verified datasets will be worth monitoring for whether the escalation pattern persists into the second half of 2026.