Crypto home invasions surge 20-fold in H1 2026, CertiK reports $124M losses

Editorial illustration for: Crypto home invasions surge 20-fold in first half of 2026, CertiK reports $124 million exposure

In brief

  • CertiK tracked 1 crypto home invasion in H1 2025; H1 2026 surged to 52 verified incidents
  • Wrench-attack losses jumped 11.8-fold to $124.1 million from $10.5 million year-over-year
  • Europe and France account for 39 and 33 cases respectively, showing geographic concentration
  • Attackers profile targets using leaked databases, tax records, and public wallet activity
  • Multisignature wallets with distributed signers and withdrawal delays provide strongest defense

The surge in physical-coercion attacks

CertiK tracked just one crypto-related home invasion in the first half of 2025. A year later, the tally had surged 20-fold. In H1 2026, the security firm counted 52 verified incidents, up 33.3% from 39 a year earlier.

The financial toll has accelerated even faster. CertiK recorded roughly $124.1 million in exposure from losses and ransom demands in H1 2026, compared with about $10.5 million in H1 2025—an 11.8-fold increase. The numbers reflect exposure rather than confirmed criminal profit; some ransom demands go unpaid, and victims may recover funds. Still, the scale signals a new risk vector for holders of significant crypto wealth.

Geographic concentration and attacker profiling

Europe accounted for 39 wrench-attack cases and France for 33 in CertiK's H1 2026 dataset, showing a clear geographic concentration. Attackers don't choose targets randomly. CertiK says attackers can combine leaked databases, tax or compliance records, exchange customer data, and public wallet activity to profile potential targets before striking.

A hardware wallet or offline seed phrase alone won't stop a motivated attacker. When a holder is forced to unlock a wallet or reveal recovery material under duress, even the most secure self-custody setup becomes vulnerable.

Defense strategies

"Physical-coercion crimes, often called wrench attacks, bypass digital defenses by threatening a holder or relative until someone surrenders access or moves funds." — CertiK security report

CertiK recommends layered defenses. The first layer is structural: multisignature or multiparty computation with geographically distributed signers ensures no person at the scene can approve the full transfer. The second layer adds time and limits through withdrawal delays, transaction caps, allowlists, and staged vaults. Together, these measures raise the friction and coordination cost of a successful attack.

Wallet security must now protect people under duress and shrink the data trail leading attackers to their doors. For holders of material wealth, that means rethinking both the technical architecture of their custody and the operational security of their privacy.

Frequently asked questions

What is a wrench attack in crypto?

A wrench attack is a physical-coercion crime where attackers threaten a holder or relative until someone surrenders access to crypto funds or reveals recovery material. It bypasses digital security by targeting the person rather than the technology.

How do attackers find crypto holders to target?

Attackers combine leaked databases, tax records, exchange customer data, and public wallet activity to profile potential targets. This allows them to identify individuals likely to hold significant crypto wealth before attempting a physical attack.

How can crypto holders defend against wrench attacks?

CertiK recommends multisignature wallets with geographically distributed signers to prevent any single person from approving transfers. Additional layers include withdrawal delays, transaction caps, allowlists, and staged vaults to increase the time and coordination required for a successful attack.