Physical attacks against cryptocurrency holders reached record levels in the first half of 2026. CertiK's Intel3D unit verified 52 wrench attacks globally between January and June, a 33.3% increase over the 39 incidents logged in H1 2025. Financial exposure — encompassing confirmed losses, ransom...
"These are serious matters, and your concern is legitimate." — Laurent Nuñez, French Interior Minister
Physical attacks against cryptocurrency holders reached record levels in the first half of 2026. CertiK's Intel3D unit verified 52 wrench attacks globally between January and June, a 33.3% increase over the 39 incidents logged in H1 2025. Financial exposure — encompassing confirmed losses, ransom demands, and frozen funds — hit $124.1 million, a 11.8-fold jump from the $10.5 million recorded in the same period a year earlier. Chainalysis, tracking a slightly narrower set of 46 confirmed theft events, pegged direct losses at $30 million, with attempted extractions totaling $107 million.
France accounted for the majority of incidents. Interior Minister Laurent Nuñez confirmed 77 crypto-related kidnappings, detentions, and extortions in H1 2026, up from 45 in all of 2025. The attack frequency in France reached one incident every 2.5 days. A January 2026 breach of Waltio, a French crypto tax platform, exposed data on 50,000 users and was linked by hackers on BreachForums to at least three kidnappings that netted $17.1 million. The case illustrates how data leaks are converting digital vulnerability into physical danger — a dynamic that fundamentally challenges the custody model underlying self-sovereign crypto assets.
Two independent datasets frame the scale of the problem. The figures differ because each firm uses different verification and scoping criteria, but both point in the same direction.
CertiK Intel3D (H1 2026):
Chainalysis (H1 2026):
CertiK's higher financial figure includes ransom demands, frozen funds, and partial recoveries that Chainalysis excludes from its direct-loss tally. Both firms note that many incidents — particularly those involving private settlements or unreported ransoms — never reach public disclosure.
For context, 2025's full-year total was $58 million in direct losses according to Chainalysis. The H1 2026 pace, if sustained, would exceed that by year-end.
The composition of attacks shifted materially in H1 2026, according to CertiK data:
| Attack Type | H1 2025 | H1 2026 | Change | |---|---|---|---| | Home invasions | 1 | 20 | +1,900% | | Kidnappings | 12 | 16 | +33% | | Torture incidents | 4 | 4 | Flat | | Murder | 1 | 1 | Flat |
Home invasions became the dominant attack vector, rising from a single documented case in H1 2025 to 20 incidents in H1 2026. Chainalysis data corroborates this, showing home invasions at 37% of all 2026 incidents, up from 14% in 2025.
Kidnappings remained persistent but shifted in target profile. Chainalysis found that attacks targeting family members or acquaintances — rather than the crypto holder directly — rose to 25-30% of all incidents by early 2026, from near zero in 2021. In France, that figure exceeded 40%.
A notable recent case: two French crypto millionaires were kidnapped in London and held for 52 hours, beaten, and threatened with immolation before police rescue. The perpetrators demanded $150,000 in cryptocurrency but extracted approximately $30,000 before intervention. Five men were subsequently convicted.
In the Netherlands, a hearing on August 4 addressed charges against three men accused of kidnapping a victim in Nieuw-Vennep, driving him to a wooded area, forcing him to strip, and extracting approximately $69,000 in cryptocurrency.
France recorded 77 crypto-related kidnappings and extortions in H1 2026, according to Interior Minister Laurent Nuñez. CertiK attributed 33 of its 52 global incidents to France — 63% of the worldwide total.
The concentration is striking. By comparison, no other country recorded more than single-digit incidents in either dataset. The rate of roughly one incident every 2.5 days represents a 71% acceleration from 2025's pace of approximately 1.9 attacks per month.
Several structural factors explain France's outsized share:
1. Data exposure. The Waltio breach and a separate case involving a former tax official selling investor data (identified in French press as Ghalia C., detained in June 2025) created a pipeline from digital records to physical targeting.
2. Criminal demographics. Of 25 individuals charged in a May 2025 sweep, all were aged 16-23 and six were minors. Investigators described them as locally hired muscle, paid as little as $10,000 per operation by organizers based outside France. This low barrier to entry enables volume.
3. Regulatory transparency. France's MiCA-aligned registration requirements mean crypto service providers maintain more extensive user records than in some other jurisdictions — records that, when breached, contain richer targeting information.
Telegram founder Pavel Durov highlighted the systemic nature of the problem in an April 2026 post: "41 kidnappings of crypto holders in France in 3.5 months of 2026. French tax officials selling crypto owners' data to criminals... More data = More victims."
The Waltio incident illustrates the causal chain from data breach to physical violence. A timeline of events:
The breached data included email addresses, year-end crypto balances, and capital gains/loss records — precisely the information needed to identify and value targets. The hacking group Shiny Hunters was linked to the attack by French newspaper Le Parisien.
A French government security bulletin subsequently warned that the breach could lead to physical threats, including impersonation by fake police officers and kidnapping attempts.
The Waltio case is not isolated. Chainalysis linked the broader rise in French incidents to an "alleged breach that exposed tax records and information on high-net-worth crypto holders." The implication: centralized data repositories of crypto ownership — whether held by tax platforms, exchanges, or government agencies — represent physical-security liabilities for the individuals they describe.
One counterintuitive finding from Chainalysis: attackers are succeeding less often, even as they attack more frequently.
| Year | Success Rate | |---|---| | 2024 | 67% | | 2025 | 49% | | H1 2026 | 26% |
Through late June 2026, only 26% of theft attempts resulted in a payment to attackers, down from 49% in 2025 and 67% in 2024. Chainalysis attributes the decline partly to the shift from targeted, intelligence-driven attacks to more opportunistic and indiscriminate operations — particularly in France, where younger, less sophisticated attackers are driving volume.
The falling success rate does not reduce the severity of the problem. A failed extortion attempt that involves kidnapping and torture remains a violent crime. And the absolute number of successful thefts is still rising: 26% of 46 incidents represents more events than 67% of a smaller 2024 base.
French authorities have escalated enforcement significantly:
Interior Minister Nuñez announced a three-pillar security strategy in a June 30 address to ADAN (Association for the Development of Digital Assets):
Whether these measures will bend the curve remains to be seen. The structural problem — that centralized data repositories identify and value potential victims — is not addressed by operational policing alone.
The wrench attack epidemic has direct implications for crypto custody architecture. A hardware wallet or offline seed phrase provides no defense when the holder is physically coerced into revealing access credentials or authorizing a transaction.
CertiK's H1 2026 report recommends:
The economic logic is straightforward. At $2.39 million in average exposure per incident, the cost of institutional custody — typically 25-75 basis points annually — represents a fraction of the expected loss. Lloyd's of London has begun offering coverage that includes wrench attacks, according to industry reports.
The trend may accelerate migration toward regulated custodians and digital asset security providers that offer multi-signature wallets, biometric access controls, insurance protection, and delayed transaction authorization. Self-custody, the ideological foundation of cryptocurrency's early years, faces a practical challenge: it concentrates both the asset and the attack surface in a single human being.
The wrench attack epidemic represents a category of risk that the cryptocurrency industry has been slow to address: the physical security of asset holders. Unlike smart contract exploits or protocol hacks, wrench attacks cannot be patched with code. They exploit the fundamental design principle of self-custody — that a single individual controls access to potentially unlimited value.
The data from H1 2026 shows the problem accelerating. France's experience, where data breaches created a direct pipeline from digital records to physical targeting, may be a preview of what other jurisdictions face as crypto ownership data becomes more widely collected under MiCA and similar regulatory frameworks.
The declining success rate of attacks offers limited comfort. The absolute number of violent incidents is rising, and the shift toward targeting family members introduces a dimension of risk that individual security measures cannot fully address. The economic value at stake — $124.1 million in exposure in six months — dwarfs the cost of institutional custody solutions.
For the crypto industry, the wrench attack problem is not primarily a security question. It is a custody-architecture question. Systems that concentrate both asset access and physical vulnerability in a single person are structurally exposed to this class of attack. The data increasingly suggests that self-custody, as currently practiced, does not scale safely with portfolio size.