Wrench attacks: crypto home invasions rise 20-fold; $124M exposed

CertiK found crypto-related home invasions climbed from 1 in H1 2025 to 20 in H1 2026, with roughly $124.1 million in recorded losses and ransom demands in H1 2026.

Security firm CertiK reported that crypto-related home invasions increased from one incident in the first half of 2025 to 20 in the first half of 2026, and that those publicly verifiable cases produced about $124.1 million in recorded losses and ransom demands. The figure reflects exposure from confirmed public cases, not verified criminal profit or the total number of attacks.

In its H1 2026 security report, published July 23, CertiK counted 52 verified incidents across all attack types, up from 39 in H1 2025, a 33.3% increase. The firm recorded roughly $124.1 million in financial exposure for H1 2026 compared with about $10.5 million in recorded exposure for H1 2025.

The report highlights a rise in physical-coercion crimes, commonly called wrench attacks, in which attackers threaten a holder or a family member to force the surrender of wallet access or the authorization of transactions. Under duress a private key, seed phrase or wallet authorization can be revealed or used, allowing transfers that bypass digital security controls.

Geographically, the visible record in CertiK’s dataset was concentrated in Europe, which accounted for 39 of the verified incidents. France alone accounted for 33 of those cases. The firm noted limits to what can be inferred from publicly available cases and did not assign reasons for the concentration.

To limit the risk that a single coerced person can move large sums, the report recommends removing unilateral authority over significant funds. Suggested measures include multisignature arrangements or multiparty computation with signers in separate locations so no individual at the scene can approve a full transfer. The report also recommends withdrawal delays, transaction caps, allowlists and staged vaults to introduce time and limits that can block immediate theft, and an independent emergency freeze that can stop a transfer without requiring the coerced person to resist.

CertiK urges wallet providers and firms to support those custody architectures through configurable limits, delayed withdrawals and controls that recognize duress. Organizations are advised to map every role that can move funds, approve transactions or reset access, and then separate those roles behind approval thresholds so a single person cannot unilaterally empty an account.

The report says attackers are using identity profiling to locate and pressure holders. It details how criminals can combine leaked databases, tax and compliance records, exchange customer data, public wallet activity, social media, property records and phone intelligence to build profiles of an owner’s address, routines and estimated wealth. Relatives and associates can provide attackers a shorter path to a wallet controller, increasing risk for a wider circle beyond the account holder.

CertiK notes the scale of profiling and proxy targeting is unclear in the public record. The firm flagged potential developments for the second half of 2026, including geographic shifts in attacks, more proxy targeting through associates and growth in illegal markets for identity data, without assigning probabilities. The report recommends custody designs that make it difficult for attackers to complete demands and that reduce the personal data trails that can lead attackers to a holder’s door.

Articles by this author