CASABLANCA, July 24, 2026
Crypto holders faced 52 verified physical-coercion attacks in the first half of 2026, exposing about $124.18 million in reported value, CertiK said, as Bitcoin traded near $64,100 after a month in which its price ranged from roughly $58,551 to $66,507.
The security firm’s H1 report documented a 33.3% rise in cases from 39 a year earlier and an 11.8-fold jump in recorded exposure from about $10.53 million. The figures are not a tally of confirmed criminal proceeds: CertiK said they can include ransom demands, transfers, frozen or recovered assets, failed demands and public loss estimates.
Europe accounted for 39 of the 52 verified cases, or 75%, while France alone accounted for 33. The concentration gives the report a sharper search and reader-safety angle than a broad cybercrime total, while its methodology limits the count to publicly reported incidents that CertiK could independently verify.
Bitcoin moved from about $60,909 on June 25 to $64,109 on July 24, according to CoinGecko historical data, a gain of roughly 5.3%. The price touched about $58,551 on July 1 and $66,507 on July 22, illustrating the large, visible holdings that can make known owners attractive targets without establishing a causal link to any individual attack.
CertiK defines a wrench attack as a physical-coercion event in which attackers use violence, intimidation or credible threats to make someone transfer assets, unlock a wallet or disclose credentials. In its report, the firm said its visible dataset is only part of the problem because victims may fear retaliation, reputational damage or a lack of effective response if they report an incident.
The shift changes the practical meaning of crypto security. Hardware wallets and offline recovery material can reduce remote theft, but they do not create a complete defense when the authorized signer is threatened in person. The report does not prove a single cause for the rise, but it points to an expanding risk surface that includes identity data, public visibility and who can move funds under pressure.
Bitcoin
BTCCertiK Records 52 Crypto Wrench Attacks in H1
CertiK said the first-quarter acceleration drove the full-half result. It recorded 35 cases in the first three months of 2026, compared with 22 in the same period of 2025, then recorded 17 cases in the second quarter, matching the prior-year quarter.
The figures are intended as a documented baseline, not a forecast. CertiK said a straight-line annualization would suggest about 100 incidents for 2026, but it cautioned that the first half had two distinct periods and that reporting delays can change later counts.
Recorded exposure rose to $124,180,400 from $10,532,242, CertiK said. That lifted average recorded exposure per case to about $2.39 million from roughly $270,000. It is a material distinction from a conventional hack-loss table: a ransom demand, a payment, an amount frozen by authorities and a stolen asset can all be part of the total, without each being the same thing.
The firm’s separate Hack3D report put total Web3 losses at about $1.32 billion across 344 incidents in H1. Wrench attacks therefore remain a smaller part of the broader loss count, but their mechanism is different: attackers aim at the person who can authorize a valid transaction instead of breaking a protocol’s code.
Daily Crypto Briefs covered that distinction after two Texas brothers pleaded guilty in an $8 million crypto kidnapping case. A blockchain transfer may leave an investigative trail, but the transaction can still be technically valid when a victim is forced to sign it.
France Accounts for 33 of the Verified Cases
France represented 63.5% of CertiK’s global dataset and 84.6% of the Europe total. The report counted 33 verified French cases in H1, compared with 10 a year earlier; it separately noted that French police data may show more incidents because official reporting and CertiK’s narrower public-verification method do not measure exactly the same set of events.
Home invasions were the report’s clearest tactical change. CertiK recorded 20 in H1 2026, up from one a year before. Kidnappings rose to 16 from 12, while the firm recorded four torture cases and one murder in each half-year. Those classifications describe the dominant form of coercion reported in each case, rather than the full legal disposition of every investigation.
CertiK did not attribute the French concentration to one factor. It cited the country’s visible crypto ecosystem, the availability of administrative and identity data, and more extensive public reporting as possible reasons that cases appear more often in the verifiable record. The report says those conditions can be combined with social-media profiles, public wallet activity and other information to identify targets.
The same data-risk premise has appeared in other parts of the industry. Daily Crypto Briefs’ coverage of the Ledger-linked Global-e data breach noted that contact details can make phishing more convincing; in a physical-threat setting, exposed names, addresses and routines can be more consequential still.
Home Invasions Put Custody Controls Under Scrutiny
The report’s core operational point is that a single-signature wallet can be fragile under duress. Cold storage protects against many online attacks, but a device and recovery material held in one residence may be accessible if a holder is compelled to unlock or search for them.
CertiK recommends reducing unnecessary disclosure of wallet details, travel routines and home information; separating routine spending wallets from long-term reserves; and using time delays, allowlists, transaction thresholds or multi-party signing where appropriate. Those are risk-reduction measures, not guarantees, and users should weigh them against their own legal, custody and recovery requirements.
The report also describes proxy targeting, in which an attacker pressures a family member, employee or associate rather than the main holder. That makes the security question broader than the private key alone, particularly for founders who retain unilateral control over treasury wallets, administrative permissions or emergency access.
For self-custody users, the distinction is useful when considering product claims. Daily Crypto Briefs’ look at a physical attack on older wallet hardware concerned a different vector, but both cases show why a device is a control layer rather than a complete security plan.
The Crypto Fear and Greed Index read 28, classified as Fear, on July 24. The market-wide measure does not track physical crime, but it provides context as Bitcoin remained below its July 22 high.
Fear & Greed Index
July 24, 2026The next evidence to watch is whether later law-enforcement disclosures or CertiK updates change the verified total, and whether companies with high-value signers adopt controls that leave no one person able to move significant funds immediately. CertiK’s report establishes a documented increase in reported physical coercion; it does not establish that every holder faces the same level of risk or that the H1 pace will continue.
Stay up to date
Get the latest crypto insights delivered to your inbox
Primary sources and further reading
| Source | Title |
|---|---|
| | CertiK: Intel3D H1 2026 Wrench Attacks report |
| | CertiK: Hack3D H1 2026 report |
| | CertiK: official website and brand asset |
| | CoinGecko: Bitcoin historical price data |
| | Alternative.me: Crypto Fear and Greed Index |
Fact-checked by: Daily Crypto Briefs Fact-Check Desk
Related Articles
Frequently Asked Questions
What is a crypto wrench attack?
CertiK defines a wrench attack as physical coercion, violence or credible threats used to force a person to transfer digital assets, unlock a wallet, reveal credentials or pressure someone else into compliance.
How many crypto wrench attacks did CertiK record in H1 2026?
CertiK recorded 52 verified, publicly reported incidents worldwide in the first half of 2026, compared with 39 in the same period a year earlier.
How much crypto exposure did CertiK record from wrench attacks?
CertiK put recorded exposure at approximately $124.18 million. It cautioned that this includes reported demands, transferred assets, frozen or recovered funds and estimates, so it is not a measure of confirmed criminal profit alone.
Why did France feature so prominently in CertiK's report?
CertiK recorded 33 verified incidents in France, or 63.5% of its global dataset. The firm said reporting visibility, a large crypto ecosystem and data-exposure risks may all contribute, but its data does not establish a single cause.
Can a hardware wallet stop physical crypto coercion?
A hardware wallet can reduce online key theft, but it cannot by itself stop someone from being forced to unlock a device or authorize a transaction. CertiK recommends layered controls such as separated signing authority and withdrawal friction for significant holdings.



