Crypto home invasions jump 20x as wrench-attack exposure hits $124 million
CertiK recorded roughly $124.1 million in losses and ransom demands in H1 2026, a measure of exposure rather than criminal profit.
Quick Take
- CertiK logged crypto home invasions rising from 1 in H1 2025 to 20 in H1 2026, alongside $124.1 million in recorded exposure.
- The $124.1 million blends losses and ransom demands from verified public cases, not confirmed criminal profit or total attack prevalence.
- Multisig, withdrawal delays, caps, freezes and data minimization can limit what coercion and identity profiling can unlock.
CertiK tracked just one crypto-related home invasion in the first half of 2025. A year later, its publicly verifiable tally had surged 20-fold.
Physical-coercion crimes, often called wrench attacks, bypass digital defenses by threatening a holder or relative until someone surrenders access or moves funds. The change turns a crime statistic into a custody-design problem: a secure key is not enough if one frightened person can release all the value immediately.
In CertiK's H1 2026 wrench-attack report, released July 23, across all attack types, the security firm counted 52 verified incidents, up 33.3% from 39 a year earlier. It recorded roughly $124.1 million in financial exposure from losses and ransom demands, compared with about $10.5 million in H1 2025, an 11.8-fold increase.
Within the dataset, Europe accounted for 39 cases and France for 33, a clear concentration in the visible record.
Custody has to survive coercion
A hardware wallet or offline seed phrase can still be bypassed as a sole safeguard when a holder is forced to unlock a wallet, reveal recovery material, or authorize a transaction. The first priority is therefore to eliminate unilateral authority over significant funds.
CertiK recommends multisignature or multiparty computation with geographically distributed signers so no person at the scene can approve the full transfer. The second layer adds time and limits through withdrawal delays, transaction caps, allowlists, and staged vaults. An independent emergency freeze is another way to stop a transfer without asking the person under threat to resist.
Wallet providers can support that architecture with configurable limits, delayed withdrawals, and duress-aware controls, while firms should map everyone who can move funds, approve transactions, or reset access, and then separate those roles behind approval thresholds.
The safeguards turn an attacker’s demand into a dead end, buying time while approval limits keep the bulk of the funds locked away.
The same defense begins before any transaction. CertiK says attackers can combine leaked databases, tax or compliance records, exchange customer data, public wallet activity, social profiles, real-estate information and phone intelligence into profiles of a holder's identity, address, family, routines and estimated wealth.
The report leaves the scale of profiling and proxy targeting unclear. Even so, every scrap of personal data can become a trail leading attackers to a holder’s door.
Relatives and associates can offer attackers a shorter path to whoever controls the funds. Crypto companies must protect that wider circle through transaction safeguards, access monitoring and tighter limits on storing sensitive identity data.
CertiK frames geographic shifts, proxy targeting, and criminal identity-data markets as possible H2 developments without assigning odds.
Where the threat moves next remains murky. Wallet security must now protect people under duress and shrink the data trail leading attackers to their doors.



