
CertiK recorded 52 physical attacks on crypto holders in H1 2026, with $124M in exposure. France accounted for 33 cases. Home invasions jumped 20x.
Blockchain security firm CertiK logged 52 physical attacks on cryptocurrency holders in the first half of 2026, with an estimated $124.1 million in exposure, up from $10.5 million a year earlier, the company said Wednesday. The number of confirmed incidents rose 33.3% year over year from 39 in H1 2025.
CertiK defines a wrench attack as violence, intimidation, or a credible threat used to force someone to transfer digital assets, provide private keys, or unlock a wallet. The tactic is an "established threat vector for cryptocurrency holders," the company said. It works against strong digital security because it attacks the person, not the software.
Europe accounted for 39 of the 52 incidents. France alone was home to 33, according to CertiK. That region was already flagged as the riskiest for crypto holders in CertiK's 2025 report.
Home invasions tied to crypto surged from one publicly reported case in H1 2025 to 20 in H1 2026. Kidnappings rose to 16 from 12. Torture cases stayed at four, and each period recorded one murder in association with a crypto coercion event. The growth was driven by attackers now learning their targets' home addresses instead of waiting to intercept them elsewhere, CertiK said.
The $124.1 million figure is estimated exposure, not confirmed theft. It includes ransom demands, funds victims paid, and assets later frozen by authorities or providers. Some of that money was never lost. The average recorded exposure per incident climbed from about $270,000 in H1 2025 to roughly $2.39 million in H1 2026. CertiK said its totals understate the true picture; victims often do not report attacks because they fear injury, tax liability, or reputational harm.
The half-year total masks two different phases. Q1 2026 had 35 incidents compared with 22 in Q1 2025. January saw 15 cases against 9 a year earlier, and March had 13 versus 7. April shot up to 8 from 2. Then May and June fell below 2025 levels. CertiK attributed the drop to better holder security, reporting delays, and law-enforcement pressure. Q2 2026 ended with 17 incidents, the same as Q2 2025.
Extrapolating the first half in a straight line would imply about 100 incidents for the full year. CertiK warned that is not a prediction, particularly given the divergence between quarters.
Wrench attacks target holders whose money and location are sufficiently visible to make coercion worthwhile. CertiK's advice is to break the link between a person's public identity and their holdings. It recommends limiting data that ties a name, location, or daily routine to cryptocurrency ownership. Significant assets should be stored so no single person can move them on demand. Holders should keep wallets and recovery data separate, secure their homes, and discuss emergency protocols with family.
CertiK also urged avoiding sensitive accounts on any devices taken during travel.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.