Wrench Attacks: CertiK Logs $124M Exposure in H1 2026, Up From $10.5M
CertiK data shows 52 crypto kidnapping cases in H1 2026, a 33.3% jump YoY, with France accounting for 33 incidents and rising financial exposure.

Physical coercion against crypto holders is scaling faster than the market it targets. Blockchain security firm CertiK counted 52 so-called wrench attacks in the first half of 2026, a 33.3% increase from the 39 recorded in the same period of 2025. Total financial exposure tied to these incidents jumped to $124.18 million, up from roughly $10.5 million a year earlier — a more than tenfold rise that outpaces the headcount growth by a wide margin.
The term “wrench attack” traces back to an xkcd comic and describes a low-tech but effective threat model: rather than breaching smart contracts or exchange infrastructure, attackers use violence, intimidation or confinement to force a victim to hand over private keys or passwords directly. CertiK’s exposure figure blends ransom demands, funds victims actually transferred, and assets later frozen by authorities.
France accounts for nearly two-thirds of cases
Of the 52 global incidents tracked in H1 2026, 33 occurred in France, making the country the clear epicenter of the trend. CertiK links the concentration to the country’s unusually visible crypto footprint — exchanges, founders, investors, service providers and a dense calendar of industry events — combined with a run of major data exposure incidents.
The firm specifically cites breaches at France Travail and a security incident disclosed by the Agence Nationale des Titres Sécurisés (ANTS). CertiK’s assessment is that leaked personal data from those events can be cross-referenced with open-source intelligence and public blockchain records, letting criminals build target profiles that pair identity with estimated holdings.
Organized recruitment pipeline, not lone actors
A February report from SIRASCO, the Organized Crime Information, Intelligence and Strategic Analysis Service of the French Judicial Police, describes a structured operation behind the French cases. Organizers based abroad coordinate with recruiters inside France, who in turn connect with young people who already have criminal records to carry out online intimidation and physical attacks.
This layered structure — foreign coordination, domestic recruitment, local execution — mirrors organized crime logistics more than opportunistic street crime, and helps explain why case counts have kept climbing despite increased public awareness of the tactic. Victims skew toward men aged 20 to 35 who hold a public or semi-public profile in digital assets, whether as investors, entrepreneurs or influencers, according to the data.
Why the exposure figure matters more than the headcount
For traders and on-chain researchers, the more telling number isn’t the 33.3% rise in incident count but the roughly 12x jump in dollar exposure. That gap suggests attackers are increasingly able to identify and extract from higher-value wallets rather than opportunistic, smaller targets — consistent with CertiK’s thesis that leaked identity data is being fused with public chain analytics to pre-select victims by estimated holdings.
As self-custody balances grow alongside institutional and retail adoption, wrench attacks add a real-world security dimension that sits outside the usual smart-contract and exchange-hack threat models tracked by on-chain forensics. Unlike protocol exploits, this vector cannot be patched with an audit — it depends on operational security: wallet visibility, personal data hygiene, and physical safety practices around identifiable holders.
Read more: BTC Trades $64.7K as BitMEX Wind-Down Echoes Mt. Gox, FTX Cycle Bottoms