HackMyIP
← Back to News
2026-07-24 The Record

Wrench Attacks on Crypto Holders Surge 33% in First Half of 2026

Threat IntelPrivacyAuthentication

Cryptocurrency holders are increasingly being targeted through physical-world coercion rather than purely digital exploits, according to a new report from blockchain security auditor CertiK. The company documented 52 so-called wrench attacks worldwide through June 2026, marking a 33 percent year-over-year increase from the 39 incidents recorded during the same period in 2025. CertiK defines the term as physical coercion incidents in which adversaries use violence, intimidation, or credible threats to compel victims to transfer digital assets, surrender private keys, unlock wallets, reveal credentials, or pressure third parties into compliance. The crimes span home invasions, kidnappings, and in rare cases, murder.

The financial toll has escalated sharply alongside the volume of incidents. Reported losses reached approximately $124 million in the first half of 2026, compared with just $10.5 million during the first half of 2025. CertiK cautioned that the figures should be viewed as an indicator of the overall scale of wrench attacks rather than realized criminal profits, since some totals include assets that were frozen before transfer. Notable cases referenced in the report include the April kidnapping of a French mother and child, a 2025 home invasion in Minnesota, and a 2024 Connecticut incident involving a carjacked Lamborghini. The report also warned that attackers frequently target proxy victims such as spouses, children, employees, and assistants, who often have weaker operational security than the primary wallet holder. Crypto users who store sensitive credentials locally can audit their exposure with a password strength checker and run a broader privacy checkup to identify weak points in their personal security posture.

Researchers attribute the trend to the growing popularity of self-custody, where users hold their own private keys in offline hardware wallets or paper backups rather than relying on a centralized exchange. Independent researcher Lukasz Olejnik noted in January that under self-custody there is no intermediary to halt, reverse, or flag a suspicious transaction, leaving victims entirely on their own. Security firms and law enforcement have been sounding the alarm for months: TRM Labs published its own analysis on the phenomenon last March, and the British trade association CryptoUK hosted a law enforcement webinar on the topic in December. Those concerned about digital exposure that could help attackers map their targets can also run a DNS leak test to verify their traffic is not revealing identifying information to potential adversaries.

Source: The Record →

Related Tools

Check whether this kind of story affects you — free, no signup:

Password Checker →Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

Password security basics →Two-factor authentication explained →How to create a strong password →