VERSE PRESS

Crypto News, Global First.

Physical Attacks on Crypto Holders Hit 52 Incidents in 2026, With Value Targeted Up More Than Tenfold

Security firm CertiK reported on July 22 that verified "wrench attacks" on cryptocurrency holders have reached 52 incidents so far in 2026, with the total value targeted rising more than tenfold compared to the same period last year.

|

Security firm CertiK reported on July 22 that verified "wrench attacks" on cryptocurrency holders have reached 52 incidents so far in 2026, with the total value targeted rising more than tenfold compared to the same period last year. The figures confirm an acceleration in a category of crime that uses physical violence, kidnapping, or extortion to force victims to hand over digital assets. The human cost behind those numbers is concrete: Yong Wang, a Chinese entrepreneur, was found dead in Istanbul in January 2026 with his wallets drained, in what CertiK documented as the first verified crypto-related homicide of 2026. In the United States, Nancy Guthrie, an 84-year-old mother of a journalist, was kidnapped and held for a $6 million Bitcoin ransom. In the United Kingdom, a trader known publicly as "Sillytuna" was forced to transfer approximately $24 million under duress.

The term "wrench attack" is named after a comic strip depicting low-tech coercion, and security professionals use it to describe a simple principle: attackers bypass wallet encryption and private-key security entirely by threatening or harming the person who controls the assets. CertiK has identified what it calls "the technical paradox" at the heart of this trend: protocol and wallet security keeps improving, while the human layer remains vulnerable to brute force.

Numbers Are Getting Worse

CertiK's earlier May 2026 report counted 34 confirmed incidents in the January to April window alone, a 41% increase over the 24 attacks recorded in the same period of 2025. Losses in that four-month span reached approximately $101 million. The full-year 2025 tally stood at 72 to 81 confirmed attacks with total losses estimated between $41 million and $52 million. Put plainly, the first four months of 2026 already produced nearly double the total losses recorded across all of 2025.

The jump in losses relative to incident count in 2026 reflects what CertiK describes as "a structured, transnational criminal enterprise" rather than opportunistic street crime.

Ari Redbord, Global Head of Policy at TRM Labs, a blockchain analytics firm, offered a blunt assessment to DL News: "We'll continue to see [the numbers] of wrench attacks go up." He attributed the trend to law enforcement's structural difficulty in addressing these crimes and to the growing global pool of crypto holders who represent new targets.

France Has Become the Epicenter

Europe accounted for 82% of all attacks in the first four months of 2026, with 28 of 34 incidents occurring there. France alone recorded 24 attacks in that period, roughly one every two and a half days, surpassing the country's full-year 2025 total of 20. CertiK cited several reinforcing factors: France hosts major crypto companies including Ledger, Paymium, and Binance France; the local community has a documented culture of publicly displaying wealth online and voluntary identity exposure; and data breaches have handed criminal networks detailed targeting information.

One breach involved Waltio, a tax compliance firm, in January 2026. A separate case involved a French tax official identified in court documents as Ghalia C., who was accused of accessing government records on crypto taxpayers through the DGFiP tax administration system and selling that data to criminal networks.

These incidents illustrate how regulatory reporting requirements, which are expanding under European frameworks such as DAC8, MiCA, and TRACFIN registers, can concentrate sensitive financial data in ways that create secondary security risks for individual holders.

Attack methods have also grown more systematic. CertiK documented assault teams of three to five people, consisting of males aged 16 to 50, recruited via Telegram and Snapchat and compensated with thousands of dollars per operation. Orchestrators often operate from outside the target country, with known hubs in Morocco, Dubai, and Eastern Europe.

More than half of French incidents involved a family member as either the direct victim or as leverage against the crypto holder, with spouses, children, and elderly parents targeted in both roles.

France's PNACO law enforcement unit indicted 88 suspects across 12 investigations on April 25, 2026, with 75 of those suspects held in pre-trial detention and more than 10 minors among the accused.

Regional Risk Is Not Confined to Europe

Asia recorded a sharp drop in reported attacks, falling from 25 incidents in early 2025 to just 2 in the comparable 2026 period. North America also declined, from 9 to 3. The reasons for these drops remain unclear from available data; the declines may reflect genuine crime reduction, reporting lag, enforcement gains, or a geographic migration of criminal activity toward Europe rather than a true reduction in global risk.

In Pakistan, a case emerged in July 2026 involving an alleged kidnapping in Lahore connected to demands for crypto passwords and $100,000 in ransom. The accused is reportedly a relative of Deputy Prime Minister Ishaq Dar. Source accounts of this incident contain conflicting descriptions of the victim, and the full facts have not been independently reconciled. The political sensitivity of the case drew unusual attention to a region where such incidents rarely surface in formal data sets.

India has seen its own escalation. A Gujarat court convicted 14 people to life imprisonment for kidnapping businessman Shailesh Bhatt and forcing him to surrender cryptocurrency wallet access.

Chainalysis ranked India among the top 10 countries globally by average value stolen per victim in the first half of 2025, with losses exceeding $50,000 per incident on average. That ranking covers physical crypto crime broadly and may not be limited to wrench attacks specifically.

South Africa presents a different kind of exposure. With 19.6% of the population holding crypto, the third-highest ownership rate globally according to Tangem, and a high baseline rate of violent crime, the country presents conditions that analysts characterize as a plausible future hotspot for physical crypto theft, even though such incidents do not yet appear prominently in CertiK's datasets.

What Holders Can Do

CertiK's primary recommendation is straightforward: holders should limit the publicly available information that connects their identity, location, or routine to their crypto holdings.

For developers building exchanges or peer-to-peer platforms across South Asia and Africa, the firm's findings carry a practical implication: user financial data should be treated as a physical security liability, not only a compliance requirement. Wallet features such as multisignature authorization and time-delayed transfers can also reduce the risk that a single coerced session results in total loss.

Institutional-grade insurance covering wrench attacks, including products from Lloyd's of London, exists but remains inaccessible to retail users in South Asia and Africa. Security professionals have described this as an unaddressed product gap in markets where exposure is rising.

CertiK projected earlier this year that the full-year 2026 total could reach approximately 130 incidents and several hundred million dollars in losses if the trend holds. With 52 incidents already recorded by July, that estimate may prove conservative.