Crypto Wrench Attacks Expose $124.1 Million in H1 2026

Home invasions overtake other attack methods as France becomes the global center
TL;DR
- CertiK verified 52 physical attacks against crypto holders during the first half of 2026.
- Recorded financial exposure reached $124.1 million as residential invasions became the leading attack method.
- France accounted for 33 verified incidents, while authorities reported a broader domestic total of 77 cases.
Trade smarter on Jupiter, Solana’s leading DEX built for fast execution and deep liquidity.
Swap tokens at competitive rates, route across multiple liquidity sources automatically, and access perpetuals, DCA, and advanced trading tools — all in one place!
CertiK verified 52 wrench attacks worldwide during the first six months of 2026, as criminals increasingly used home invasions, kidnappings and physical coercion to force cryptocurrency transfers or obtain wallet credentials. The blockchain security firm said recorded financial exposure reached about $124.1 million during the period, while France accounted for nearly two-thirds of the verified incidents.
CertiK released its Intel3D H1 2026 Wrench Attacks Report on July 22, 2026. The firm defines a wrench attack as an incident involving physical violence, kidnapping, confinement, threats or another form of coercion used to compel a victim to transfer cryptocurrency, reveal wallet information or pay a ransom. CertiK summarized the change in criminal tactics with the statement, “Crypto crime has gone physical.”
Verified incidents increased 33.3% from 39 during the corresponding period of 2025. CertiK previously recorded 72 cases across all of 2025, a 75% increase from 2024. The latest six-month total equaled about 72% of the previous full-year count and represented an average of roughly 8.7 verified attacks per month, compared with six per month during 2025.
CertiK’s public summary rounded the exposure total to $124.2 million. The firm said recorded financial exposure does not represent only cryptocurrency confirmed as permanently stolen. The calculation may include completed transfers, ransom demands, failed demands, frozen funds, recovered assets and other amounts connected to an incident, making it a measure of value exposed or demanded rather than a net-loss total.
Home invasions accounted for approximately 41% of verified incidents and became the largest individual attack category. CertiK called the increase the “defining shift” of the period, as criminals targeted victims inside their residences rather than relying primarily on robberies or remote compromise. The attacks placed victims’ relatives, personal information, routines and homes within the security perimeter criminals sought to penetrate.
The change also allowed attackers to bypass technical controls by coercing the person authorized to approve a transaction. A hardware wallet can prevent remote access, but it does not stop an owner from being forced to unlock it. A concealed seed phrase faces the same weakness when a victim or family member is threatened.
CertiK said the verified figures likely understate the scale of the problem because victims may avoid public reporting over fears of retaliation, additional targeting, reputational damage, exposure of their wealth or danger to relatives.
We’ve launched the all-new COIN360 Perp DEX, built for traders who move fast!
Trade 130+ assets with up to 100× leverage, enjoy instant order placement and low-slippage swaps, and earn USDC passive yield while climbing the leaderboard. Your trades deserve more than speed — they deserve mastery.
France accounts for most verified attacks
Europe recorded 39 of the worldwide cases, or about 75% of the verified total. France alone accounted for 33, equivalent to approximately 64% globally and about 85% of the European count. The rest of the world recorded 19 verified incidents.
CertiK linked France’s concentration partly to its large and visible cryptocurrency community, which creates identifiable targets among founders, executives and investors. The firm also pointed to personal information exposed through breaches involving France Travail and ANTS, as well as commercially or publicly available records that could connect identities and residential addresses with actual or perceived crypto wealth.
Criminal groups increasingly combine leaked databases, exchange-related information and blockchain activity into detailed “target packages,” according to CertiK. Transparent transaction histories can expose estimated holdings when a wallet is linked to a real person, helping attackers assess potential ransom value before planning an operation.
CertiK described a layered criminal structure in which organizers purchase personal data, choose targets and coordinate logistics while remaining separated from the people carrying out the physical attack. Young operators may be recruited through messaging applications and treated as disposable participants responsible for surveillance, abductions, residential intrusions or intimidation.
The security firm’s narrower French total differs from the broader count used by national authorities because the methodologies cover different sets of incidents. CertiK included publicly reported cases it could independently verify, while French authorities counted crypto-linked kidnappings, extortion attempts and completed extortion cases more broadly.
French Interior Minister Laurent Nunez said on July 2, 2026, that authorities had recorded 77 such cases during the first half of the year. That surpassed the 45 recorded throughout 2025 by 32 cases, an increase of roughly 71% before the second half of the year began.
Authorities’ response reflected the growing use of relatives as leverage. Attackers have targeted spouses, parents and other family members even when those individuals did not directly control the cryptocurrency sought by the criminals.
One of the most prominent cases occurred in January 2025, when Ledger co-founder David Balland and his wife were kidnapped in France. The kidnappers severed one of Balland’s fingers while attempting to secure a multimillion-euro ransom. Police later freed the couple.
French authorities arrested six people, including one minor, in February 2026 after a magistrate and her mother were abducted during an attempted crypto-ransom operation. The case showed that targeting extended beyond public crypto executives to people selected because of perceived financial access or family connections.
Two teenagers were charged in another case after allegedly trying to abduct the wife of The Sandbox co-founder Sébastien Borget outside Paris. The attackers reportedly carried a fake handgun and restraints. Neighbors intervened, causing the group to flee before completing the abduction.
CertiK recommends custody controls that withstand coercion
CertiK recommended security structures that prevent one threatened person from releasing an entire balance. The measures included multisignature arrangements requiring several approvals, multiparty computation systems that distribute the signing process and withdrawal delays that create time to stop suspicious transfers.
The firm also advised spending and withdrawal limits, geographically separated signers and family duress protocols. Physical separation can prevent attackers controlling one residence from obtaining every authorization needed for a transfer, while coded warnings or predetermined emergency procedures can help trusted contacts identify instructions issued under coercion.
The findings place personal-data protection, residential security, custody architecture and family preparedness alongside conventional cybersecurity. CertiK’s data showed that attack frequency, financial exposure and residential targeting all rose during the same period, while the difference between independently verified cases and the broader French government total indicated that public reporting captured only part of the activity.
This article has been refined and enhanced by ChatGPT.