Wrench attacks jump 20-fold; $124M exposure in H1 2026

Crypto home invasions rose from one in H1 2025 to 20 in H1 2026, with CertiK logging about $124.1 million in combined losses and ransom demands.

CertiK reported that crypto-related home invasions, often called wrench attacks, rose from one incident in the first half of 2025 to 20 in the first half of 2026. The security firm published its H1 2026 update on July 23 and recorded about $124.1 million in combined losses and ransom demands tied to publicly verifiable cases.

Across all attack types in the update, CertiK counted 52 verified incidents in H1 2026, up from 39 in the same period a year earlier. The $124.1 million figure combines documented losses and ransom demands from publicly verifiable cases and does not represent confirmed criminal profit or the total number of attacks. By comparison, the firm logged roughly $10.5 million in exposure in H1 2025.

Wrench attacks involve criminals threatening a wallet holder or someone close to them until the target reveals recovery material, unlocks a device, or approves a transaction. CertiK noted that hardware wallets and offline seed phrases can be bypassed when a person is under duress because a coerced individual may still provide the means to move funds immediately.

To limit the risk that a single person can release large sums, the report recommends splitting control of assets. Suggested measures include multisignature setups or multiparty computation with geographically distributed signers so no single person can approve a full transfer. The update also highlights withdrawal delays, transaction caps, allowlists, staged vaults and an independent emergency freeze that can stop transfers without requiring the threatened person to resist.

Wallet providers and custodial firms can support these fixes by offering configurable limits, delayed withdrawals and controls that detect duress. The report advises firms to map every person who can move funds, approve transactions or reset access and then separate those roles behind approval thresholds to add time and limit what attackers can obtain.

CertiK’s analysis shows attackers often assemble detailed profiles to find targets. The report lists leaked databases, tax and compliance records, exchange customer data, public wallet activity, social profiles, real-estate records and phone intelligence as sources criminals can combine to identify a holder’s address, relatives, routines and estimated wealth. The update notes that relatives and associates can provide shorter paths to those who control funds.

Geographically, the visible dataset showed most cases in Europe, with 39 of the recorded incidents and 33 specifically tied to France. The report identified potential trends to watch in the second half of 2026, including geographic shifts, wider use of proxies to reach targets and growth in criminal markets for identity data, while saying the scale and timing of those developments remain uncertain.

The report frames the rise in physical-coercion incidents as a problem for custody design and for limiting the data trail that can lead attackers to a holder’s door.

Content on BlockPort is provided for informational purposes only and does not constitute financial guidance.
We strive to ensure the accuracy and relevance of the information we share, but we do not guarantee that all content is complete, error-free, or up to date. BlockPort disclaims any liability for losses, mistakes, or actions taken based on the material found on this site.
Always conduct your own research before making financial decisions and consider consulting with a licensed advisor.
For further details, please review our Terms of Use, Privacy Policy, and Disclaimer.

Articles by this author

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.