Crypto wrench attacks, the industry term for stealing digital assets through physical threats, rose 33% year over year in the first half of 2026, according to a new report from blockchain security audit firm CertiK.
CertiK said it identified 52 such incidents worldwide through June, compared with 39 in the same period in 2025. The company said it used public information and other verified sources for the count.
The shift is ugly and low-tech: instead of trying to break a wallet’s cryptography, attackers put pressure on the person who can unlock it. CertiK defines a wrench attack as an incident in which criminals use violence, intimidation or credible threats to force someone to transfer crypto, hand over private keys, unlock a wallet, disclose credentials or make someone else comply.
What are crypto wrench attacks?
A crypto wrench attack is an in-person coercion attack against a crypto holder or someone close to them. The name comes from the old security joke that encryption can be bypassed with a wrench if the attacker can force the owner to unlock the system.
CertiK said the cases it tracks often resemble familiar violent crimes, including home invasions and kidnappings. In rare cases, the company said, they include murder. The crypto part is the payout mechanism: the victim is pushed to move digital assets or reveal the information needed to move them.
The firm warned that its tally likely misses some incidents. Victims may not report attacks to police, and some cases do not become public until investigations are finished.
The reported financial scale also jumped. CertiK said losses tied to wrench attacks reached $124 million so far this year, compared with $10.5 million in the first half of 2025. The company cautioned that this figure should be read as a measure of the financial scope of the incidents, rather than a clean estimate of criminal profits, because it may include assets that were frozen.
Attackers are targeting families and associates
CertiK said attackers do not need to reach the main crypto holder if they can pressure someone nearby, such as a spouse, parent, child, employee, driver, assistant or close friend. The report said those “proxy victims” may have weaker security habits, more predictable routines and less training than the intended target.
Recent examples cited by CertiK include the April kidnapping of a mother and child in France, a 2025 home invasion in Minnesota and a 2024 Connecticut case involving a carjacked Lamborghini. The Minnesota case was described by the Justice Department as an armed cryptocurrency kidnapping case, while the Connecticut prosecution involved a cryptocurrency robbery scheme.
Other security and industry groups have been warning about the same pattern. Blockchain analysis firm TRM Labs published research on wrench attacks and crypto-related violent crime in March, and the British trade group CryptoUK held a webinar with law enforcement on the issue in December.
Security researcher Lukasz Olejnik wrote in January that the risk is tied in part to self-custody, where users keep their own cryptocurrency keys, such as in an offline wallet at home. In that setup, there may be no bank-like intermediary able to delay, halt or reverse a transaction after coercion begins.
That is the blunt edge of self-custody. The holder controls the asset directly, which is the selling point. CertiK’s report shows why criminals may treat that same direct control as an invitation to skip malware and show up at the door.
This story draws on original reporting from The Record.