TLDR
CertiKs latest H1 2026 security report shows a sharp global surge in wrench attacks, violent crimes used to steal crypto under physical coercion.
- CertiK verified 52 wrench attacks in H1 2026, with about $124.1 million in exposure and a strong concentration in Europe, especially France.
- These attacks bypass digital wallet security by targeting people, often using leaked data and profiling, and are likely underreported.
- The report urges multi?party custody, withdrawal delays, and better personal security practices so a single threat cannot drain all your crypto at once.
Deep Dive
1. Scale And Geography Of The Surge
CertiKs H1 2026 wrench attacks report verifies 52 physical?coercion incidents worldwide, up from 39 in H1 2025, with recorded exposure climbing from about $10.5 million to $124.1 million in just six months. That is roughly a 12?fold increase in money at stake, and the average recorded haul per attack rose from around $270,000 to $2.39 million. Europe accounts for 39 of the 52 incidents, with France alone reporting 33 attacks, making it the most affected country in the dataset. Home invasions linked to these crimes jumped from 1 case to 20, highlighting that attackers are increasingly willing to show up at victims houses. CertiK stresses that public figures likely underestimate the true scale because many cases go unreported and criminal proceeds are not fully known. You can see these details in the firms H1 2026 wrench attacks report and in coverage of crypto home invasions jumping 20x.
Confidence: high based on multiple recent detailed reports.
2. Why Wallet Security Is Not Enough
A wrench attack ignores seed phrase storage and hardware wallets and instead forces the victim to unlock and transfer funds while under threat. CertiK notes that criminals often build profiles using leaked databases, tax and compliance records, exchange data, public wallet activity, social media, real?estate information, and phone intelligence to pick targets with visible crypto wealth. Because the attack vector is the person, not the software, standard strong password and cold wallet advice does not fully address the risk, especially for public figures or anyone whose holdings or address are easy to infer. Relatives, business partners and employees can also be targeted as proxies, so the risk extends beyond the primary holder.
3. Safeguards And Signals To Watch
CertiKs main recommendation is to design custody so that no single individual under duress can immediately move all funds. That includes multisig or multiparty setups with geographically separated signers, withdrawal delays, transaction limits, allowlists, staged vaults and emergency freezes, all aimed at turning an attackers demand into a dead end or at least slowing it. The report also urges firms to separate roles for initiating transactions, approving them and resetting access, so an attacker cannot exploit one persons permissions. At the personal level, reducing public signals of large crypto holdings, limiting identifiable on?chain footprints, and treating physical security as part of your crypto strategy are increasingly important.
crypto security is now about protecting both keys and people; if you hold meaningful size, it is worth considering multi?party custody and simple speed bumps like withdrawal delays rather than relying only on a single wallet you control alone.
Conclusion
The CertiK findings show that a growing share of crypto risk has moved from purely on?chain exploits to real?world coercion, with Europe and especially France currently bearing the brunt. For everyday users and institutions, the takeaway is that robust custody design and basic personal opsec can materially reduce the damage from a worst?case physical incident, even if they cannot eliminate the threat entirely.
