
According to CertiK's latest Intel3D: H1 2026 Wrench Attacks Report, crypto-related wrench attacks reached 52 verified incidents in the first half of 2026, representing a 33.3% increase from 39 cases in H1 2025. The financial exposure from these attacks surged dramatically to $124.2 million, marking a 1,079% increase from approximately $10.5 million recorded in the same period last year. The report defines a wrench attack as any incident in which victims are physically coerced through kidnappings, home invasions, armed robberies, or assault into surrendering cryptocurrency, private keys, or wallet credentials. As reported by CertiK, H1 2026 confirms that wrench attacks are no longer a fringe phenomenon or an edge-case risk for cryptocurrency holders. The most significant development is that the severity per incident grew roughly 24 times faster than the frequency, with attackers targeting far better-chosen victims rather than casting a wider net, demonstrating intelligence-led selection rather than opportunism.
Europe emerged as the primary target for these physical attacks, recording 39 of the 52 verified incidents, or 75% of the global total. France alone accounted for 33 incidents, representing 63.5% of all verified cases worldwide and 84.6% of Europe's total. According to CertiK, the French National Directorate of Judicial Police recorded 41 incidents between January and March, suggesting the actual French total may be higher than the verified public dataset. The U.S. recorded four incidents, while Sweden and the UK each recorded two cases. Earlier this month, France unveiled a nationwide crypto security strategy after Interior Minister Laurent Nuñez disclosed 77 crypto-related kidnappings and extortion cases during the first half of 2026. According to CertiK, France's large crypto ecosystem, combined with repeated personal data breaches and organized crime activity, has made the country particularly attractive to attackers. The report attributes this concentration to data exposure, not market size, with the key forecasting variable being holder visibility rather than bitcoin price alone.
The most significant change occurred in attack methodology, with home invasions rising from one to 20 cases in H1 2026, accounting for approximately 41% of first-half attacks. As reported by CertiK, kidnappings increased from 12 to 16 cases, while torture remained at four cases and murder at one case. These wrench attacks rely on physical force, threats or intimidation to make victims transfer crypto, reveal private keys or unlock wallets, often bypassing digital safeguards by targeting the person controlling the assets rather than the wallet software itself. According to the report, attackers increasingly enter homes where hardware wallets, recovery phrases, and family members can all become leverage, spending weeks or even months building detailed profiles of potential victims using leaked databases, tax records, exchange information, blockchain activity, conference attendance, and social media. The report warns that insider access has become an increasingly valuable source of intelligence, with organized groups now seeking customer databases, identity records, and exchange information that can be combined with publicly available blockchain data to identify high-value targets. CertiK describes home invasions as attacking a victim's "entire security perimeter," with access vectors including doorbell impersonation as delivery workers, fake business meetings, transit interception at airports, and proxy targeting of family members.
The report highlights several significant cases that demonstrate the devastating impact of physical coercion attacks. Notable incidents include a €900,000 forced bitcoin transfer during a home invasion near Paris and a $24 million coerced transfer in the UK's Sillytuna case, both illustrating how physical coercion now bypasses on-chain security controls entirely. These cases underscore how attackers are increasingly targeting high-net-worth individuals and institutions rather than random victims, with the severity per incident growing roughly 24 times faster than the frequency. The attacks demonstrate that crypto-related crime is increasingly shifting away from technical exploits toward physical coercion, with criminals targeting individuals rather than blockchain protocols or smart contracts. According to CertiK, hardware wallets, cold storage, and offline seed phrases offer little protection when victims are forced to unlock wallets themselves.
The report reflects a broader shift visible across the crypto industry, with Web3 losing $1.31 billion during H1 2026, marking the first time that wallet compromises overtook smart contract exploits as the largest source of losses. According to CertiK, crypto-related crime is increasingly shifting away from technical exploits toward physical coercion, with criminals targeting individuals rather than blockchain protocols or smart contracts. The firm argues that hardware wallets, cold storage, and offline seed phrases offer little protection when victims are forced to unlock wallets themselves. CertiK recommends that reducing personal exposure has become as important as protecting private keys, advising multi-signature custody, withdrawal delays, geographically separated recovery systems, and emergency response plans designed to withstand physical coercion. The company has now launched operational security services to help identify exposure risks related to identity, family, residence, and travel routes, while simultaneously strengthening cooperation with international law enforcement agencies such as Interpol and Europol to provide technical support for cross-border attack investigations. The report identifies proxy escalation as a rising H2 2026 scenario, with attackers increasingly targeting family members, employees, drivers and assistants because they're easier to approach and produce stronger emotional leverage.