Physical coercion against cryptocurrency holders increased sharply in the first half of 2026, according to security firm CertiK, which recorded 52 verified “wrench attacks” worldwide during the period. The company said that was 33.3% higher than a year earlier, while estimated financial exposure rose to about $124.1 million.

What CertiK counts as a wrench attack

CertiK uses the term “wrench attack” for incidents in which violence, intimidation, or a credible threat is used to force a victim to hand over digital assets, private keys, or access to a wallet. Unlike software exploits, these attacks target the holder directly rather than a technical system, making them a distinct risk for people with visible crypto wealth.

The firm said the $124.1 million total reflects exposure rather than confirmed losses alone. The figure includes ransom demands, payments made by victims, and assets that may later have been frozen or recovered. CertiK noted that some of the money counted in the total was not ultimately lost.

Europe and France dominated the cases

According to the data, Europe accounted for 39 of the 52 incidents logged in the first six months of the year. France alone represented 33 cases, making it the single biggest national concentration in the dataset.

CertiK’s figures point to a marked shift in how these attacks are being carried out. Home invasions rose to 20 in H1 2026 from just one in the same period of 2025, suggesting that attackers are increasingly identifying and approaching targets at home. Kidnappings also increased, rising from 12 to 16 year over year.

The report recorded four torture cases in H1 2026. It also said there was one murder associated with a crypto coercion event in both the current and prior-year periods.

Exposure per incident rose sharply

Beyond the increase in case numbers, the estimated financial scale of these incidents also changed significantly. CertiK said average exposure per attack climbed from around $270,000 in H1 2025 to roughly $2.39 million in H1 2026.

That jump does not necessarily mean attackers successfully extracted those sums in each case. CertiK stressed that its exposure metric is broader than stolen funds and is intended to capture the financial scale of threats and demands surrounding these events.

The company also cautioned that the reported totals likely understate the real picture because many cases may go unreported.

First-half pace suggests a higher annual tally

If the first-half rate were simply extended through the rest of the year, the total would come to around 100 incidents in 2026, according to a basic extrapolation from the available data. CertiK said this should not be treated as a forecast.

The firm’s recommendations focused on reducing the link between a person’s identity and their crypto holdings, limiting public information that connects names or locations to wallet ownership, and structuring custody so that no single person can transfer significant assets under duress. It also advised separating wallets, signing tools, and recovery information, alongside improving home security and emergency planning.

The figures add to a growing focus on personal security risks tied to digital asset ownership, especially where holdings can be linked to identifiable individuals. CertiK’s data suggests that, at least in the first half of 2026, the threat became more concentrated in Europe and more likely to involve intrusions at victims’ homes.

Source: Cryptopolitan