
Crypto security is no longer only about preventing hackers from reaching a private key. In a growing number of publicly documented cases, criminals are bypassing the software and targeting the person authorised to move the assets.
Key Takeaways
- CertiK verified 52 physical coercion incidents in H1 2026, including 20 home invasions.
- The rise from one home invasion to 20 is striking, but the tiny and incomplete baseline makes a 20-fold framing misleading.
- Recorded financial exposure reached $124.1 million, although a small number of exceptionally large cases skewed the total.
- France generated most publicly verified incidents, but stronger official tracking may partly explain its dominance.
Crypto-related home invasions increased from one publicly reported case in the first half of 2025 to 20 during the same period in 2026, according to the CertiK Intel3D H1 2026 Wrench Attacks report.
CertiK verified 52 physical coercion incidents worldwide, up from 39 a year earlier. Kidnappings increased from 12 to 16, while recorded financial exposure rose from approximately $10.5 million to $124.1 million.
| Measure | H1 2025 | H1 2026 |
|---|---|---|
| Verified wrench attacks | 39 | 52 |
| Home invasions | 1 | 20 |
| Kidnappings | 12 | 16 |
| Recorded financial exposure | $10.53 million | $124.18 million |
| Incidents in Europe | 14 | 39 |
| Incidents in France | 10 | 33 |
The table deliberately excludes an average exposure per incident. Dividing the total by 52 would produce approximately $2.39 million, but the available evidence does not show that this amount resembles the typical case.
From One Home Invasion to 20, but Not a Clean 20-Fold Signal
A wrench attack uses violence, intimidation or a credible threat to force someone to transfer crypto, disclose credentials, unlock a device or pressure another person into complying.
Home invasions represented approximately 38.5% of CertiK’s verified H1 2026 incidents, moving from a marginal category in the previous comparison period to one of the dataset’s dominant attack types.
The increase does not appear to result from CertiK inventing or substantially broadening the home-invasion category. The company states that it retained the general taxonomy established in its 2025 report, adding only “Forced Crypto Transfer” as a clearer label for immediate transfers conducted under threat outside the broader context of a kidnapping, ransom or home invasion.
That finding strengthens the case that the visible threat pattern changed. It does not establish that home invasions became exactly 20 times more common across the entire crypto market.
The one-case H1 2025 baseline is too small and too dependent on visibility to support that level of precision. CertiK only includes incidents it can verify through sources such as police statements, court documents, victim testimony, on-chain evidence or corroborated reporting.
Victims may remain silent because of fear, privacy concerns or an active investigation. Police may also record a case as robbery, assault or kidnapping without publicly identifying its crypto connection. The figures therefore measure the visible and independently verifiable part of the problem, not every incident that occurred.
A Second Dataset Supports the Scale, Not the Exact Total
Jameson Lopp’s public database of physical crypto attacks provides a useful independent comparison. Lopp is the co-founder and chief security officer of Bitcoin custody company Casa and has maintained the log for years.
The database contained 46 entries dated between January 4 and June 29, 2026. That is broadly consistent with CertiK’s finding that physical attacks were no longer isolated events during the period.
The totals should not be combined or treated as competing measurements. Lopp’s log includes attempted attacks, mistaken targeting and scenarios that may fall outside CertiK’s narrower dominant-category methodology. One entry, for example, involved attackers who expected cryptocurrency but found that the victim did not hold any.
Both datasets also state or demonstrate that they are incomplete. Their agreement is strongest at the directional level: publicly documented physical attacks were occurring repeatedly across several countries, with an especially dense cluster in France.
The $124.1 Million Total Was Driven by Outliers
Verified incidents increased by 33.3% year on year, while recorded financial exposure rose by approximately 1,079%. That divergence is more informative than the average obtained by dividing one number by the other.
It suggests that a small number of very large cases drove a disproportionate share of the financial increase.
In March, the pseudonymous game developer Sillytuna reported being forced to transfer approximately $23.6 million in an Aave USDC position. The token represented USDC deposited into the Aave lending protocol.
That one incident accounted for approximately 19% of CertiK’s entire H1 exposure figure.
CertiK did not publish a median or a complete distribution showing the amount connected with every case. Without that information, the report supports the conclusion that the largest attacks became financially severe, but it cannot establish how much was involved in the typical incident.
The $124.1 million also does not represent confirmed criminal proceeds. CertiK’s figure includes disclosed losses, ransom demands, frozen or recovered funds and partially reported amounts. It excludes costs that are difficult to measure, including medical treatment, relocation, security changes, interrupted work and long-term harm to victims and their families.
The Cases Show Why Cryptography Is Not the Only Target
In another March incident, three attackers posing as police reportedly entered a couple’s home in Le Chesnay-Rocquencourt, near Paris. According to Le Parisien, the victims were threatened and compelled to transfer approximately €900,000 in bitcoin.
The attackers did not need to extract a seed phrase from encrypted hardware or exploit a software vulnerability. They needed access to the people capable of approving the transaction.
That distinction changes the relevant security question. A hardware wallet may protect a key against malware or remote theft, but it does not remove the risk created when one identifiable person can authorise the entire balance immediately.
France May Be the Largest Hotspot, or the Most Visible One
Europe accounted for 39 of CertiK’s 52 verified cases, with France alone representing 33.
France may have experienced an exceptional concentration of crypto-related violent crime. It may also be unusually capable of identifying, tracking and publicly disclosing the crypto connection.
The Gendarmerie nationale reported 77 kidnappings and unlawful confinement cases connected with the crypto sector by July 7, 2026. CertiK’s lower total uses a narrower methodology limited to cases it could independently verify, so the two figures are not directly interchangeable.
The existence of a dedicated official count gives researchers a larger pool of incidents to identify and verify. Countries that do not routinely disclose a crypto motive may appear safer in an international dataset even when similar crimes are being recorded under broader categories.
Visibility is unlikely to explain the entire concentration. France has a substantial and public crypto industry, regular industry events and a visible population of founders, investors and service providers. Personal information available through administrative systems, data breaches and open online sources may make some targets easier to identify.
France’s data regulator, the CNIL, fined France Travail after finding that attackers had accessed information including postal addresses, email addresses, telephone numbers and social security numbers.
There is no evidence connecting that breach with a particular wrench attack. It illustrates how leaked identity information can be combined with public blockchain activity, company biographies, social media posts or property information to build a more detailed target profile.
Criminals Can Build the Target Before Reaching the Door
The physical attack may take place at a home, hotel or meeting point, but preparation can begin online.
A target profile may include a home address, family relationships, employment, conference appearances, estimated holdings, wallet addresses, phone numbers, vehicles and predictable travel routines.
A portfolio screenshot therefore creates a different risk from a general market opinion. It can connect a real identity with perceived wealth. Live location posts and public travel schedules can then show when and where the person or their relatives are accessible.
The increase in home invasions is not evidence that every crypto holder faces the same threat. It shows that security assumptions built entirely around remote hacking are incomplete when the holdings are large, publicly associated with an individual and immediately movable by that person.
Our separate guide to reducing physical coercion risk for crypto holders examines the practical limits of multisignature wallets, withdrawal delays, provider-assisted custody and geographic key separation.
How this article was created: Incident figures, definitions and methodological notes were compared directly with CertiK’s H1 2026 report. CertiK’s dataset was cross-checked against Jameson Lopp’s independently maintained public log of physical crypto attacks. France-specific figures were checked against official Gendarmerie and CNIL publications, while individual incidents were checked against contemporary reporting. Sources were reviewed on July 25, 2026.
This article is for informational and security-awareness purposes only. It does not provide personalised custody, legal or physical-security advice. Anyone facing an immediate threat should prioritise personal safety and contact the competent emergency services as soon as circumstances allow.



Be the first to comment