Blockchain security firm CertiK said in its Intel3D report released on July 23 that 52 verified crypto wrench attacks were recorded globally in the first half of 2026, up 33.3% from 39 in the same period of 2025. The report shows a simultaneous rise in incident volume and financial exposure, with home invasions replacing kidnappings as the most common attack type.
Key figures from the first half of 2026
CertiK’s report lays out several headline metrics for the period:
- Total attacks: 52, versus 39 in H1 2025, up 33.3%
- Home invasions: 20, versus 1 a year earlier
- Kidnappings: 16, versus 12, up 33%
- Robberies: 1, versus 5 in H1 2025
- Financial exposure: about $124 million, versus $10.5 million, up 11.8x
- Europe: 39 cases, or 75% of the global total
- France: 33 cases, equal to 63% of the global total and 85% of Europe’s count
CertiK said the financial exposure figure does not only refer to confirmed stolen assets. It also includes ransom demands, funds victims were forced to transfer, frozen and recovered assets, and failed extortion attempts. The firm said net realized losses may be lower, but the scale of exposure still shows a sharp increase in the expected payoff that criminal groups attach to crypto-related targets.
Home invasions moved ahead of kidnappings
The clearest structural change in the report is the rise of home invasions. What had been a marginal category in the first half of 2025, with just one case, climbed to 20 incidents in the first six months of 2026, making it the leading form of wrench attack. Kidnappings also increased, from 12 to 16, but no longer accounted for the largest share.
CertiK said the shift points to a tactical adjustment by criminal groups. According to the report, home invasions are easier to execute than kidnappings because they do not require prolonged surveillance, a detention site, or hostage management. They still achieve the same core objective: using physical coercion to bypass digital security. Attackers target victims at home and force holders or family members to surrender private keys or login credentials.
Street robberies moved in the opposite direction, falling from five cases to one. CertiK said that may suggest criminals have recognized that stealing a hardware wallet or a phone in public does not guarantee access to funds. If a device is password-protected or assets are held in a multisig setup, the odds of success are lower than forcing a victim to authorize transfers at home.
Europe dominated the map, with France far ahead
Geographically, the incidents were heavily concentrated in Europe. CertiK counted 39 cases on the continent, representing 75% of the 52 global incidents. France alone accounted for 33 cases, or 63% of the world total and 85% of Europe’s count.
French Interior Minister Laurent Nuñez said on July 2 that authorities recorded 77 crypto-related kidnappings, extortion cases, or attempted extortion incidents in the first half of 2026, well above the 45 cases logged in all of 2025. Nuñez said emergency response measures resulted in around 200 arrests.
CertiK said its own methodology is stricter than the official French tally, as it only counts publicly reported cases that can be independently verified. That is why its count for France stands at 33, while the French figure of 77 also includes incidents that were not independently verified under CertiK’s criteria.
The report suggests France’s heavy concentration may be tied to a relatively transparent crypto ecosystem. CertiK said data breaches can link identity and home address information to perceived crypto wealth, making holders easier to target. It also pointed to France’s regulatory framework for crypto assets, including the PSAN registration regime, saying that while it has helped attract legitimate businesses, it may also allow criminal groups to identify potential victims through public information.
Financial exposure rose much faster than case count
Another major signal in the report is the jump in financial exposure from $10.5 million in the first half of 2025 to about $124 million in the same period this year, an 11.8x increase. That rate far exceeded the 33.3% rise in the number of cases.
Based on the figures in the report, average exposure per case rose from roughly $270,000 to about $2.4 million, an increase of nearly ninefold. CertiK said this points to several developments:
- Much larger amounts tied to individual incidents
- A shift in targeting from smaller holders toward high-net-worth individuals and mid-sized institutions
- Higher ransom expectations overall
The article also references an Immunefi report covering the same period, which said total losses from crypto hacking in the first half of 2026 came in below $1 billion. In absolute terms, wrench-attack exposure remains smaller than digital hacking losses, but CertiK said the growth curve is much steeper, showing that physical intrusion is becoming an important complementary route for crypto crime.
From digital intrusion to physical coercion
CertiK argues that the deeper trend is a change in where attackers apply pressure. As digital protections such as multisig, cold wallets, and hardware security modules become more mature, criminal groups are increasingly targeting what the report describes as the weakest link in the chain: the human holder.
The report does not frame this as a decline in conventional hacking. It notes that Immunefi reported a record number of hacking incidents in the first half of 2026. Instead, CertiK describes a two-track approach. One track focuses on technical vulnerabilities at DeFi protocols, cross-chain bridges, and centralized exchanges. The other centers on home invasions, kidnappings, and extortion aimed directly at holders, using violence to bypass every technical layer at once.
Under that model, simply strengthening cold-storage practices or avoiding carrying large sums is no longer enough to address physical threats. The report’s point is that a victim can still be forced to participate in asset transfers even if the key material is not immediately at hand.
Asia in view: Singapore as an example, Taiwan as a risk case
Although CertiK’s data was concentrated in Europe, especially France, the report said Asia is not outside the risk zone. It singled out Singapore as an example in warning self-custody holders about a newer form of physical threat.
CertiK said crypto wealth in Asia is highly concentrated and identified Singapore, Hong Kong, and Dubai as three hubs. Combined with the high cost of private security in some places, that concentration could make high-net-worth holders more attractive targets.
For Taiwan, the report said the market is not currently listed as a hotspot in its statistics, but it flagged several risk factors:
- Exchange KYC data leaks. CertiK said data breaches are a primary way criminals identify targets, and noted that Taiwan has one of the world’s highest densities of cryptocurrency exchanges, making leakage of identity and asset information a serious concern.
- Overexposure on social media. CertiK said it has tracked criminals using platforms such as X, Telegram, and Discord to identify users who publicly flaunt crypto holdings.
- Links between property records and crypto ownership. The report said that if land registry data, tax information, and exchange reporting data are cross-referenced, individuals with sizable crypto holdings could be indirectly identified.
How CertiK says holders can respond
CertiK said the rise of coercive physical attacks requires a broader view of self-custody. In the report’s framing, it is no longer only a matter of cryptography and private-key management, but also one of personal safety and operational design.
- Use multisig or MPC setups so that one coerced signer cannot immediately release all assets
- Set time-locks and daily withdrawal limits to create time for freezes or recovery efforts
- Distribute signers across different countries or cities so attackers cannot force all approvals in one place
- Establish a duress password or a predefined action sequence that alerts co-signers, freezes assets, or triggers a preset transfer plan
- Strengthen physical home security with cameras, connected alarms, reinforced doors, and a lower-profile lifestyle
In its conclusion, CertiK said the financial incentive behind wrench attacks is likely to rise as crypto asset market value grows and adoption broadens. The report sums up the shift as a move from protecting private keys to protecting the people who hold them. It also said the issue extends beyond technology to legal treatment of forced transfers of digital assets, insurance products covering violent crypto theft, and community education on participating in the market without exposing one’s holdings.

