Key Takeaways
- CertiK verified 52 physical coercion incidents in H1 2026, including 20 home invasions.
- The rise from one home invasion to 20 is striking, but the tiny and incomplete baseline makes a 20-fold framing misleading.
- Recorded financial exposure reached $124.1 million, although a small number of exceptionally large cases skewed the total.
- France generated most publicly verified incidents, but stronger official tracking may partly explain its dominance.
A new report from CertiK shows a significant rise in home invasions targeting people with cryptocurrency. While there was only one reported case in the first half of 2025, that number jumped to twenty during the same period in 2026.
CertiK identified 52 cases of people being forced or threatened in connection with cryptocurrency around the world, an increase from 39 last year. Kidnappings went up from 12 to 16 incidents, and the total amount of money at risk climbed significantly – from about $10.5 million to $124.1 million.
| Measure | H1 2025 | H1 2026 |
|---|---|---|
| Verified wrench attacks | 39 | 52 |
| Home invasions | 1 | 20 |
| Kidnappings | 12 | 16 |
| Recorded financial exposure | $10.53 million | $124.18 million |
| Incidents in Europe | 14 | 39 |
| Incidents in France | 10 | 33 |
The table doesn’t include an average cost per incident on purpose. While calculating a simple average across all cases ($2.39 million) is possible, the data suggests this number isn’t representative of what most incidents actually cost.
From One Home Invasion to 20, but Not a Clean 20-Fold Signal
A wrench attack involves using force, threats, or intimidation to make someone hand over cryptocurrency, reveal sensitive information like passwords, unlock a device, or coerce another person into doing something they wouldn’t otherwise do.
In the first half of 2026, home invasions accounted for about 38.5% of security incidents verified by CertiK. This represents a significant increase from previous periods, making it one of the most common types of attacks they observed.
The rise in reported incidents doesn’t seem to be because CertiK changed what counts as a “home invasion.” They say they used the same categories as their 2025 report, simply adding a more specific label – “Forced Crypto Transfer” – to describe situations where cryptocurrency is stolen under threat, but isn’t part of a larger kidnapping, ransom, or home invasion.
This discovery supports the idea that the way threats were seen has shifted. However, it doesn’t prove that home invasions increased by exactly 20 times throughout the entire cryptocurrency world.
The initial estimate for 2025, based on a single scenario, isn’t realistic and relies too much on having complete information to achieve the desired accuracy. CertiK only reports security incidents it can confirm with reliable evidence, like official statements from law enforcement, court records, accounts from those affected, blockchain data, or trustworthy news reports.
People affected by cryptocurrency-related crimes might not report them due to fear for their safety, wanting to keep things private, or because a police investigation is already underway. Additionally, law enforcement could classify these incidents as regular robberies, assaults, or kidnappings without revealing the link to crypto. As a result, reported numbers only show a portion of the total problem – specifically, cases that are publicly known and can be confirmed by outside sources.
A Second Dataset Supports the Scale, Not the Exact Total
A helpful resource for understanding real-world cryptocurrency theft comes from Jameson Lopp’s public database of physical attacks. Lopp, who co-founded the Bitcoin storage firm Casa and currently serves as its head of security, has been compiling this information for several years.
The database included 46 records from January 4th to June 29th, 2026. This supports CertiK’s observation that physical attacks were becoming more common during that time.
These numbers shouldn’t be added together or compared as if they measure the same thing. Lopp’s data includes unsuccessful attacks, errors in identifying targets, and situations that CertiK’s standard method doesn’t fully cover. For instance, one case involved attackers who tried to steal cryptocurrency from someone who didn’t actually have any.
Both sets of data acknowledge they don’t offer a complete picture. They largely agree on the broad trend: physical attacks were happening frequently in multiple countries, particularly in France.
The $124.1 Million Total Was Driven by Outliers
The number of confirmed incidents went up by about a third compared to last year. However, the potential financial losses from these incidents skyrocketed – increasing over ten times! Looking at those two separate changes tells us more than just calculating an overall average.
In my analysis, it appears the recent financial gains were heavily influenced by just a few exceptionally large deals or instances. A relatively small number of significant cases seem to account for most of the overall financial improvement.
In March, a game developer known as Sillytuna lost around $23.6 million worth of digital currency from their account on Aave. This money was held in the form of a token representing US Dollars deposited within Aave’s lending system.
That one incident accounted for approximately 19% of CertiK’s entire H1 exposure figure.
CertiK’s report doesn’t include average or detailed figures for each attack. Because of this, while the report suggests the biggest hacks caused the most financial damage, it can’t tell us how much money was typically lost in a single incident.
The $124.1 million figure doesn’t solely represent money gained through criminal activity. CertiK’s total includes reported losses, ransom requests, funds that were frozen or recovered, and incomplete data. It *doesn’t* cover less quantifiable costs like medical bills, moving expenses, increased security measures, lost income, and the lasting impact on victims and their families.
The Cases Show Why Cryptography Is Not the Only Target
In a separate incident in March, near Paris, three people pretending to be police officers allegedly broke into a home and forced a couple to transfer around €900,000 worth of bitcoin, according to reports in Le Parisien.
The hackers didn’t break into any devices or hack any programs. Instead, they simply gained control over the individuals authorized to confirm the transfer.
As an analyst, I’ve found that focusing on hardware wallets shifts the core security concern. While they’re great at shielding keys from things like viruses or hackers accessing them remotely, they don’t address the risk of a single person being able to instantly approve all transactions – that remains a significant vulnerability.
France May Be the Largest Hotspot, or the Most Visible One
Europe accounted for 39 of CertiK’s 52 verified cases, with France alone representing 33.
France seems to have a higher number of violent crimes linked to cryptocurrency than other countries. They also appear particularly good at finding these connections, monitoring them, and making that information public.
By July 7, 2026, France’s national police force (the Gendarmerie nationale) had recorded 77 instances of kidnapping and illegal imprisonment linked to cryptocurrency. However, CertiK’s count is lower because they only included cases they were able to confirm themselves, making a direct comparison with the police data difficult.
Having an official count of crypto-related crimes helps researchers find and confirm more incidents. Countries that don’t specifically track these crimes might seem safer in global data, even if they’re actually recording the same crimes as general offenses.
I’ve been looking at why certain areas seem to attract more crypto activity, and simply being ‘visible’ doesn’t fully explain it. Take France, for example – they have a really active and open crypto scene with lots of events, founders, investors, and companies working in the space. It seems like readily available personal data, whether from official records, hacks, or just what’s online, might make people there easier to target, potentially explaining some of the concentration we’re seeing.
France’s data protection authority, the CNIL, issued a fine to France Travail following a security breach where personal information – such as home addresses, emails, phone numbers, and social security details – was accessed by attackers.
We haven’t found any proof linking that security breach to a specific ‘wrench attack’. However, it does show how stolen personal details can be combined with publicly available information – like blockchain records, company details, social media, and property records – to create a much more complete picture of a potential target.
Criminals Can Build the Target Before Reaching the Door
An attack could happen at a place like someone’s home, a hotel, or where people are meeting, but the planning often starts online.
A personal profile could contain information like where someone lives, their family connections, job details, events they’ve attended, assets they own, cryptocurrency wallets, contact numbers, cars they drive, and typical travel patterns.
Sharing a screenshot of your investment portfolio carries a unique risk compared to simply stating your market views. It can link your real name to how much money you appear to have. When combined with posts revealing your current location or travel plans, this information can expose you or your family to potential accessibility issues.
Just because home robberies involving cryptocurrency holders are happening doesn’t mean everyone who owns crypto is at risk. These incidents highlight a flaw in security practices – relying only on protecting against online hacking isn’t enough when someone has a large amount of easily accessible crypto and their identity is publicly known.
We have a dedicated guide that explores how cryptocurrency owners can lower the risk of being physically forced to give up their assets. It looks at the real-world effectiveness of things like multi-signature wallets, delayed withdrawals, using a custodian service, and storing key parts of your access in different locations.
We verified the data in this report by comparing it to CertiK’s H1 2026 findings and an independent log of crypto attacks maintained by Jameson Lopp. For France, we confirmed our numbers with official reports from the Gendarmerie and CNIL. We also checked individual incidents against news coverage from the time they occurred. All sources were last reviewed on July 25, 2026.
As a researcher, I want to clarify that this information is purely for educational purposes – to raise awareness about security issues. It’s not intended to be a substitute for professional advice on things like legal matters, physical security, or custody arrangements. If you are in immediate danger, your safety is the most important thing; please reach out to emergency services right away.
2026-07-25 01:10