Crypto “wrench” attacks—incidents where victims are coerced or harmed to obtain access to their digital assets—accelerated sharply in the first half of 2026, according to new analysis from blockchain security firm CertiK.
CertiK verified 52 wrench attacks worldwide in H1 2026, up 33.3% from 39 incidents during the same period in 2025. Home invasions emerged as the most frequent method, climbing to 20 publicly reported cases versus 1 a year earlier. The same report also found that kidnappings increased to 16 from 12, while robberies fell from five incidents to just one.
Key takeaways
- Wrench attacks rose to 52 verified incidents in H1 2026, up 33.3% year-on-year from 39 in H1 2025, according to CertiK.
- Home invasions surged to 20 cases, up from 1 a year earlier, becoming the dominant attack pattern.
- Kidnappings increased to 16 (from 12), while robberies dropped to 1 (from 5).
- Estimated financial exposure reached about $124.1 million, up from $10.5 million in H1 2025, though the figure includes more than confirmed theft.
- France accounted for 33 of 52 incidents, with Europe totaling 39, highlighting a major geographic concentration.
A shift toward physical coercion
CertiK’s report attributes part of the trend to a growing willingness by criminals to bypass purely digital defenses through direct physical pressure on victims and their families. The dramatic rise in home invasions is the clearest signal of that change: attacks that once appeared rarely in the dataset became the leading tactic during the first half of 2026.
CertiK also emphasized that its “financial exposure” number is broader than simple theft totals. The company reported that the recorded financial exposure linked to wrench attacks reached approximately $124.1 million, compared with $10.5 million a year earlier. CertiK clarified that the estimate is not restricted to confirmed stolen funds and may include ransom demands, transfers by victims, assets that were frozen or recovered, and even failed ransom attempts.
For investors and users who rely on self-custody, the implication is straightforward: traditional security guidance focused on protecting keys and accounts may not be sufficient when attackers aim to obtain control through coercion.
France dominates the verified caseload
Geographically, the report shows a concentrated pattern. CertiK said Europe accounted for 39 of the 52 verified incidents, with France alone responsible for 33—nearly two-thirds of the global total.
CertiK noted that it used a narrower methodology than French authorities. In particular, CertiK counted only publicly reported incidents that it could independently verify. That distinction matters for interpretation: the French government’s totals could be higher because they may rely on a wider set of cases than CertiK’s verification criteria.
On July 2, French Interior Minister Laurent Nuñez said authorities had recorded 77 crypto-linked kidnappings, extortion cases, or attempted extortion cases during the first half of 2026, up from 45 in the entirety of 2025. CertiK pointed to the possibility that France’s more visible crypto ecosystem contributes to the pattern, citing how data breaches and information flows can connect identities and home addresses with perceived crypto wealth.
Policy and wallet-design countermeasures
French officials have responded to the uptick with targeted enforcement and prevention efforts. In response to the threat, Nuñez said French authorities launched a dedicated prevention platform and a rapid-alert system for crypto holders and professionals. He also said emergency measures have resulted in 200 arrests.
CertiK’s recommendations, meanwhile, focus on making it harder for attackers to quickly convert coercion into irreversible transfers. The firm argued that physical coercion can undermine assumptions behind many “hold your own keys” practices, especially if a victim can be forced to act immediately.
To reduce the speed at which funds can be moved under pressure, CertiK recommended several technical and operational controls, including:
- Multisignature or multiparty computation arrangements so no single threatened party can unilaterally authorize transfers.
- Withdrawal delays to slow down transfers after authorizations are initiated.
- Spending limits to cap the impact of any coerced transaction.
- Geographically separated signers, so attackers cannot simultaneously pressure all parties needed to move funds.
These measures are designed to change the attacker’s advantage: instead of forcing victims to act immediately, they introduce friction, require multiple approvals, or create time windows that may allow victims to seek help.
Why the jump in home invasions matters
The sharp increase in home invasions suggests attackers are increasingly moving from remote scams or online compromise to scenarios where the victim’s immediate physical compliance becomes the key vulnerability. That trend also helps explain why “wrench” incidents can carry such a wide range of outcomes—ranging from transfers under duress to situations where assets are later recovered or ransom demands fail.
As regulators and law enforcement refine their response, the next test will be whether defensive practices keep pace across borders—particularly in regions where incidents are concentrated. Users should pay close attention to whether both public reporting and independently verified datasets continue to show the same pattern of escalation in the second half of 2026.






