TLDR
Violent wrench attacks that force crypto holders to hand over funds have increased sharply in 2026, and the typical haul per attack is now much larger.
- CertiK reports 52 verified wrench attacks in H1 2026, up from 39 a year earlier, with exposure jumping from 10.5 million dollars to 124.1 million dollars.
- Europe, especially France, is most affected, while home invasions linked to wrench attacks rose from one case in H1 2025 to 20 in H1 2026.
- The best defenses focus on custody design and personal security, including multi party approvals, withdrawal delays, transaction limits, and reducing public signals about large holdings.
Deep Dive
1. Scale Of The Surge
According to CertiKs H1 2026 Wrench Attacks Report, there were 52 verified wrench attacks worldwide in the first half of 2026, compared with 39 in the first half of 2025, a rise of roughly one third. Financial exposure in these incidents jumped from about 10.5 million dollars to 124.1 million dollars, an 11.8 times increase, with the average haul per attack rising from about 270,000 dollars to 2.39 million dollars.
CertiK stresses that these figures cover publicly verified cases and reported losses or ransom demands, not total criminal profit, and that underreporting likely means the real scale is higher. This framing is highlighted in both the original report and summaries such as the CoinsKid community recap of the H1 2026 Wrench Attacks Report.
The number of attacks is rising, but the more worrying change is that attackers are going after much larger balances per incident.
2. Who Is Being Targeted
The surge is heavily concentrated in Western Europe. CertiK reports 39 of the 52 global cases in Europe, with France alone accounting for 33 attacks, making it the most affected country in the dataset. A related CryptoSlate analysis notes that crypto linked home invasions increased from one verified case in H1 2025 to 20 in H1 2026, roughly a 20 times jump.
Attackers often profile victims using a mix of leaked databases, tax and compliance records, exchange data, public on chain activity, social media, real estate information, and phone intelligence. Relatives and business associates can be targeted as proxies, since the real objective is control over private keys or signing authority.
The attack surface is no longer just your wallet software, it is your entire personal footprint that hints at wealth and access.
3. Practical Risk Reductions
CertiKs recommendations focus on making a single coerced person unable to move all funds. Key ideas include multisignature or multiparty computation, geographically distributed signers, withdrawal delays, hard transaction limits, allowlists, and staged vaults where only a small hot balance is directly spendable.
For individuals and small firms, this translates to simple patterns such as separating long term savings from day to day spending, using multi party custody for larger treasuries, and avoiding public signals that reveal large holdings or easy physical access. Wallet and exchange providers can help by offering configurable limits and duress aware controls, but operational discipline still matters.
Treat physical coercion as a design scenario. Aim for a setup where even under threat you cannot move more than a small fraction of your assets.
Conclusion
Wrench attacks are shifting crypto security thinking from purely technical defenses to protecting people and processes. The data shows fewer but much larger incidents, concentrated where crypto adoption and transparency are high. As more value moves on chain, the most resilient holders will be those who design custody and personal habits assuming that someone might one day try to force them to sign.
