CertiK, a blockchain security firm, said on Wednesday that 52 confirmed physical attacks on crypto holders occurred in the first half of 2026. The amount of money at risk was ~$124.1 million, up from $10.5 million the previous year.
Nowadays, there is a much more common and much more expensive threat to anyone with a known identity who has real crypto.
There were 52 confirmed incidents, a 33.3% increase year over year from the 39 cases in H1 2025. CertiK defines a wrench attack as any form of violence, intimidation, or credible threat used to force someone to transfer digital assets, provide private keys, or unlock a wallet.
The tactic is an βestablished threat vector for cryptocurrency holders,β CertiK said. It works on even strong digital security because it attacks the person, not the software.
France drives Europeβs wrench attack wave
Of the 52 confirmed incidents, 39 were in Europe. France alone was home to 33 of them, according to CertiK. Europe was already highlighted as the riskiest region for crypto holders in CertiKβs 2025 wrench-attack report.
Increasingly, victims are being confronted in their own homes by attackers. CertiK reported that the number of crypto-related home invasions soared from one publicly reported case in H1 2025 to 20 in H1 2026. Kidnappings also increased, from 12 to 16.
Elsewhere, there was little movement. There were four cases of torture, as in the year before. Each period had one murder in association with a crypto coercion event.
The rise was attributed to home invasions. The attackers are now finding out where the targets live instead of waiting to catch them somewhere else.
$124 million exposure figure isnβt stolen crypto
The ~$124.1 million number is an estimated exposure, not a confirmed theft. It includes ransom demands, money victims paid, and assets later frozen by authorities or providers. Some of this money was never lost.
The average recorded exposure per incident rose from ~$270,000 in H1 2025 to ~$2.39 million in H1 2026. CertiK says its totals understate the true picture. Attack victims often donβt report them because theyβre afraid of getting hurt, being taxed, or having their reputations hurt.
The half-year total obscures two different phases. The increase was led by Q1 2026, with 35 incidents compared to 22 in Q1 2025. January saw 15 cases compared to 9 a year ago, March had 13 compared to 7, and April shot up to 8 from 2. Then May and June were down below 2025. CertiK attributes that to a combination of better holder security, reporting delays, and law-enforcement pressure. Q2 2026 ended with 17 incidents, the same as Q2 2025.
Extrapolating the first half in a straight line would indicate about 100 incidents for the entire year. CertiK warns that this is not a prediction, especially given the differences between the two quarters.
Cryptopolitan reported this month that 63% of the 164,538 traders active in Robinhood Chainβs top memecoins were underwater. Wrench attacks target a different profile. Holders whose money and location are sufficiently obvious that it is worth the trouble to coerce.
CertiKβs advice is to break the link between a personβs public identity and their holdings. It proposes limiting data that links a name, location, or daily pattern of a holder to ownership of a crypto. Significant assets should be stored so that no one person can move them on demand.
Crypto holders should keep their wallets, signing tools, and recovery data separate. The company also says that people should make their homes secure, talk to their family about what to do in an emergency, and avoid using sensitive accounts on any devices they take with them when they travel.
If you're reading this, youβre already ahead. Stay there with our newsletter.


















English (US)