Violent attacks aimed at forcing crypto holders to hand over access credentials accelerated in the first half of 2026, according to blockchain security firm CertiK. The company recorded 52 so-called wrench attacks in the first six months of the year, a sharp increase from the same period in 2025, while the value tied to those cases climbed far more dramatically.
What CertiK recorded
CertiK said the 52 incidents logged in H1 2026 marked a 33.3% rise from the first half of last year. The firm uses the term wrench attack to describe cases in which criminals rely on violence, intimidation or confinement to force a victim to reveal private keys or passwords.
The term comes from a well-known xkcd comic and has become shorthand for physical coercion replacing technical exploitation. In CertiK’s assessment, these incidents are becoming a structural threat for people active in the digital asset sector.
Financial exposure jumps
The financial exposure linked to the attacks rose to $124.18 million in H1 2026 from about $10.5 million a year earlier, according to CertiK. The firm said this figure includes ransom demands, funds transferred by victims and assets frozen by authorities.
That means the increase was not limited to the number of incidents. The amount of money associated with them expanded much faster, underscoring how costly such crimes can become once kidnappings or threats escalate.
France dominates the tally
France accounted for 33 of the 52 incidents recorded this year, making it the main concentration point in CertiK’s data. The firm linked that pattern to the country’s prominent crypto industry presence and to recent data exposure events that may make potential victims easier to identify.
According to CertiK, France has a large and visible cryptocurrency ecosystem that includes exchanges, founders, investors, service providers and regular industry events. At the same time, it has seen major data exposure incidents affecting both private and public-sector organizations.
CertiK pointed to the compromise of France Travail and a security incident disclosed by Agence Nationale des Titres Sécurisés, or ANTS, as recent examples. It said such breaches can increase the amount of personal information available to criminals, who may combine that data with open-source intelligence and public blockchain information to select targets.
How the attacks are organized
A separate February report from the Organized Crime Information, Intelligence and Strategic Analysis Service of the Judicial Police, known as SIRASCO, said these kidnappings are often organized from abroad. According to that report, organizers coordinate with recruiters in France, who then connect them with young people with criminal records to carry out online intimidation and physical assaults.
The reported victim profile is also relatively specific. The kidnappings usually target men aged 20 to 35 who are involved in digital assets as investors, entrepreneurs or influencers.
The emerging picture suggests that the risk around digital assets is no longer limited to hacking, scams or protocol exploits. CertiK’s figures and the SIRASCO report indicate that real-world coercion is becoming a more prominent danger, particularly in France, where visible crypto activity and data exposure may be creating a deeper pool of potential targets.
Source: dailyhodl.com