TL;DR
- Because crypto compresses enormous, quickly transferable value into something one person can surrender under pressure, and because organised groups can now identify and locate holders from leaked data, physical coercion has grown into a serious threat. 2025 made it measurable: incidents up 75 percent year on year, with violence escalating faster than frequency; that stronger cryptography also nudges attackers toward people is a plausible inference rather than a measured cause.
- Targets are mostly self-identified: public boasting, visible on-chain wealth, media appearances and leaked customer databases do the attacker's research for them. Awareness of these channels is defensive knowledge; every item on the list is something you can stop feeding.
- Treat information about your holdings like the asset itself: never displayed, never casually shared, never linkable from your public identity. The goal is a boring profile, because target selection is a comparison and the comparison is won by whoever looks least worth the risk.
- Yes, in one precise sense: architecture decides what coercion can extract, and a design where no single person can move the funds converts "force the victim" from a plan into a dead end. A single seed phrase is the opposite design, and attackers know it.
In one block
A wrench attack is a physical attack on a crypto holder that replaces hacking with force: robbery, home invasion, kidnapping or extortion aimed at making the victim hand over keys or authorise transfers. The name comes from a security comic's observation that a five-dollar wrench beats expensive cryptography by hitting the person instead of the maths.
Why are crypto holders targeted physically?
Quick answer
Because crypto compresses enormous, quickly transferable value into something one person can surrender under pressure, and because organised groups can now identify and locate holders from leaked data, physical coercion has grown into a serious threat. 2025 made it measurable: incidents up 75 percent year on year, with violence escalating faster than frequency; that stronger cryptography also nudges attackers toward people is a plausible inference rather than a measured cause.
Three properties make a crypto holder a different robbery target from a bank customer. The value is bearer-like: whoever controls the key controls the funds, with no institution standing in between to freeze a coerced transfer in real time. The transfer is final: minutes after a forced signature, the assets can be scattered across chains. And the ceiling is high: a single seed phrase can guard a life's savings, so one successful coercion can yield what dozens of conventional robberies would.
The 2025 numbers put shape on it. CertiK's review counted 72 verified physical incidents worldwide, a 75 percent increase over 2024, with confirmed losses of 40.9 million dollars and physical assaults up 250 percent. Europe's share of incidents roughly doubled to about 40 percent, and France became the epicentre with 19 recorded attacks, including the January 2025 kidnapping of Ledger co-founder David Balland, in which the attackers severed a finger while demanding a ten-million-euro ransom. Jameson Lopp's long-running public register of physical bitcoin attacks, the fullest open dataset, shows the same curve and also its floor: these are only the cases that reached the press or the courts. Victims who quietly pay do not appear in anyone's statistics.
The security industry frames this as a paradox, offered as interpretation rather than measured fact: every improvement in digital custody may raise the relative appeal of attacking the human. What CertiK does document is the mechanism of targeting, organised groups mining leaked data and open sources, so the practical lesson holds regardless: the better your cryptography, the more your physical footprint becomes the surface that matters.
How do attackers find their targets?
Quick answer
Targets are mostly self-identified: public boasting, visible on-chain wealth, media appearances and leaked customer databases do the attacker's research for them. Awareness of these channels is defensive knowledge; every item on the list is something you can stop feeding.
Reconstructions of 2025 cases, particularly the French cluster, point again and again to the same discovery channels.
Public association is the widest one. Social media posts about gains, screenshots of portfolios, a username that appears both on a crypto forum and on an account with your real name, podcast and conference appearances introduced with "early investor": each is a durable, searchable link between an identity and an assumption of wealth. Several 2025 victims were content creators whose income was the content.
On-chain visibility is subtler. Blockchains are public, so a single known address unravels into a full financial history; a human-readable name on an address, or a donation link on a public profile, publishes your balance to anyone curious. The privacy article in this cluster covers the mechanics; the physical-security consequence is simple: a visible balance plus a findable identity equals a target profile.
Leaked data does the locating. Breaches of crypto businesses have spilled names, home addresses and purchase histories; the 2020 leak of a hardware wallet vendor's customer database was followed by years of threatening emails and, investigators believe, contributed targeting data for later physical incidents. A database of people who bought a device for storing crypto, with delivery addresses, is a burglary shopping list.
Proximity finishes the job. High-profile cases have involved acquaintances, business contacts, staged romantic relationships and, in several French incidents, attackers who researched family members as softer routes to the holder. The target is a household, never just an individual, which is why the defensive habits below extend to family.

Which habits actually shrink your exposure?
Quick answer
Treat information about your holdings like the asset itself: never displayed, never casually shared, never linkable from your public identity. The goal is a boring profile, because target selection is a comparison and the comparison is won by whoever looks least worth the risk.
Silence is the foundation. No portfolio talk with strangers, no gains posts, no photographs of hardware wallets or safes, no "crypto investor" in a dating or social profile. This costs nothing and removes the single most common discovery channel in the incident record.
Separate your identities. If you participate publicly in crypto, as a builder, writer or creator, keep that persona's wallets, usernames and payment links unlinked to your legal name and home region, and assume the persona is the one that gets targeted. Public addresses tied to your name should hold working balances only, the way a shop till holds a float rather than the takings.
Manage the data trail you cannot see. Have devices and correspondence delivered to a pickup point or box address rather than your home. Minimise real personal data given to crypto services where the service does not legally require it, and assume every database you appear in will eventually leak. In France, investigators traced parts of the 2025 wave to exactly such leaked customer data.
Extend the perimeter to your household. Partners, children and parents should know never to confirm holdings, never to share travel plans publicly in real time, and to treat unexpected callers claiming crypto business with the same suspicion you would. Several recorded attacks began with a family member because the family member was easier.
Add friction where it is cheap: vary routines if your profile is public, be unremarkable in person at conferences, and keep home security conventional and visible. None of this is paranoia priced against what it defends; it is the same discretion any visibly wealthy person has always needed, applied to an asset class that is easier to hand over than a house.
Can custody design protect you when prevention fails?
Quick answer
Yes, in one precise sense: architecture decides what coercion can extract, and a design where no single person can move the funds converts "force the victim" from a plan into a dead end. A single seed phrase is the opposite design, and attackers know it.
Under coercion, a victim will comply. Planning that assumes otherwise is fantasy, so the honest question is what compliance can surrender. With a single-key wallet the answer is everything: one recited seed phrase, extractable in one conversation, transfers the entire balance with no delay and no second opinion. The prevalence of exactly this setup is what makes wrench attacks pay.
Distributed designs change the answer. In a multisignature arrangement, moving funds needs signatures from a quorum of keys, say two of three or three of five, held on different devices, in different places, sometimes by different people. Threshold cryptography and MPC reach a similar property with mathematics rather than multiple on-chain signatures: signing splits authority into shares and produces a signature without reconstructing a whole key, and where setup uses distributed key generation there is no complete key anywhere to steal or recite. The coercion-relevant point holds under either setup. This academy's article on threshold cryptography covers the mechanics; the physical consequence is what matters here. A coerced victim in one location, controlling one share, cannot comply their way to the balance, and an attack that needs coordinated pressure on several people in several places is a different, far rarer crime.
Time and limits are force multipliers. Spending policies with daily caps, delays on large transfers, and allowlisted destinations mean even a partly successful coercion yields little before someone, or something, can react. Guardian-based recovery schemes replace the recitable master secret entirely, removing the single sentence a victim could be forced to speak.
Two caveats keep this honest. First, deterrence needs belief: controls reduce risk best when an attacker can be convinced, quickly and credibly, that the victim genuinely cannot move the money, so a setup whose limits you can calmly explain is worth more than a clever one you would have to prove under duress. Second, never build a fortress you would die defending. The correct design goal is a small, surrenderable working balance and a cold majority that nobody present can unlock, so that full compliance is possible, fast, and cheap.

What should high-value holders do beyond habits?
Quick answer
Above a certain size, physical security becomes an engineering and planning problem: written threat model, distributed custody, briefed family, professional advice, and possibly insurance. The threshold is lower than most people assume, because targeting is about perceived wealth.
Start with a threat model on paper: who could learn what you hold, from which data, and what they would have to do to extract it. This exercise, standard in institutional custody, usually surfaces one or two embarrassingly cheap fixes, a public link that can be broken or a concentration that can be split.
Restructure custody deliberately. The institutional playbook translates surprisingly well: quorum signing across geographies, role separation so no individual is singly capable, spending policies with delays and limits, and rehearsed recovery that does not depend on one memory or one location. For families, inheritance planning belongs in the same design, since an arrangement that dies with your memory is its own failure mode, and guardian-based recovery addresses both risks at once.
Prepare responses as a household. Agree what happens if someone claims to have a family member, who calls whom, and the principle that no balance is worth a life. Rehearsing an unpleasant scenario once, calmly, is what makes the real version survivable and is standard practice for families with visible wealth of any kind.
Consider transferring risk. Specialist insurers, including Lloyd's of London syndicates, now write cover that extends to ransom and coercion incidents involving digital assets. For holders above the size where self-insurance is rational, this converts a catastrophic tail risk into a premium.
Finally, involve professionals at the right threshold. Executive protection consultants, the same industry that serves conventionally wealthy families, increasingly understand crypto-specific exposure. If your holdings would justify a burglar alarm in house form, they justify a consultation in key form. And if you are ever the subject of a credible, specific threat, that is a police matter first and a custody matter second.
Frequently asked questions
Am I really a potential target if I am not rich by crypto standards?
Target selection runs on perceived extractable value against risk, and perception is set by what you display. Mid-size holders who post gains publicly appear in the incident record; large holders nobody can identify do not. Your visibility, more than your balance, is the variable you control.
Should I keep a decoy wallet to hand over?
A modest working balance you can surrender quickly is sensible and defuses many situations; the incident record includes cases ended by exactly that. Elaborate deception under coercion is dangerous, because being caught lying escalates violence. The safer version of the same idea is structural: a small hot balance plus a distributed cold majority you demonstrably cannot unlock alone.
Does a hardware wallet protect me in a home invasion?
The device is a strongbox; a coerced owner will open it. A PIN, and even a hidden-wallet passphrase, buys negotiating time rather than safety, and its seed phrase backup is one recitable sentence. Physical protection comes from architecture, distribution, quorums and delays, rather than from any single object in your house.
Is talking about crypto at work or conferences dangerous?
Professional participation is a manageable risk; broadcasting holdings is the unmanageable one. Speak as someone who works in the industry, never as someone who owns a specific amount, keep public wallets thin, and keep home details, travel plans and family off the public record. Several documented targets were selected at industry events.
What should I do first if my details were in a crypto company's data breach?
Assume the data is permanently in criminal hands and reduce what it can unlock: change delivery arrangements, review what a stranger holding your name, address and purchase history could infer, harden home security, and brief your household on unexpected visitors and callers referencing crypto. Then reduce on-chain linkability going forward, as covered in the privacy article in this cluster.
Sources and further reading
Key references for this article, current as of July 2026. Volatile figures are re-checked at each quarterly review.
- CertiK, Skynet Wrench Attacks Report: incident counts, loss figures and regional distribution. https://www.certik.com/ko/skynet-report/skynet-wrench-attacks-report
- Jameson Lopp, Known Physical Bitcoin Attacks: the open register of documented incidents since 2014. https://github.com/jlopp/physical-bitcoin-attacks
- Chainalysis, 2026 Crypto Crime Report: violence and extortion trends in crypto crime. https://www.chainalysis.com/blog/2026-crypto-crime-report-introduction/
- CoinDesk reporting on the rise of wrench attacks and the concentration of cases in France. https://www.coindesk.com/business/2026/04/19/inside-the-rise-of-wrench-attacks-against-crypto-holders-and-how-france-has-become-the-focus
- Decrypt, record 2025 wrench attack figures and case timeline. https://decrypt.co/356604/41m-in-losses-as-crypto-wrench-attacks-hit-record-high-in-2025
- The Block, physical security practices for crypto holders amid rising risks. https://www.theblock.co/post/384018/record-year-wrench-attacks-how-crypto-holders-maintain-physical-security-rising-risks
- CoinDesk, Ledger co-founder's kidnapping sheds light on soaring crypto robberies (24 January 2025): the Balland case and its context. https://www.coindesk.com/policy/2025/01/24/ledger-co-founder-s-kidnapping-sheds-light-on-soaring-crypto-robberies
- xkcd 538, Security: origin of the "five-dollar wrench" framing. https://xkcd.com/538/
- NIST, guidance on multi-party and threshold cryptography (background for distributed custody). https://csrc.nist.gov/projects/threshold-cryptography
- RFC 9591 (FROST threshold signatures): threshold signing need not reconstruct the key, and setup may use a trusted dealer or distributed key generation. https://www.rfc-editor.org/rfc/rfc9591.html
- AnchorWatch, kidnap and ransom coverage for bitcoin holders backed by Lloyd's of London (product announcement). https://www.anchorwatch.com/blog/anchorwatch-announces-kidnap-ransom-coverage-backed-by-lloyds-of-london
- FBI Internet Crime Complaint Center, extortion and kidnapping reporting channels. https://www.ic3.gov
- Reporting: in England, Wales and Northern Ireland, Report Fraud (which replaced Action Fraud in December 2025) at https://www.reportfraud.police.uk; in Scotland, Police Scotland on 101; in an emergency anywhere, the local emergency number.
Quick quiz: did it stick?
A few questions to check the fundamentals landed. Answers with explanations follow, and nobody is grading you except your future portfolio.
You have completed a quiz on “Physical Security and Coercion: Staying Off the Radar”! Share your achievement on social media.




