Saturday, July 25, 2026

Latest Posts

Violent crypto attacks rise as criminals hunt bigger payouts


Crypto criminals are increasingly targeting people, not just digital wallets, as violent attacks climb globally.

So-called wrench attacks — where criminals use violence to coerce victims to hand over cryptocurrency — have accelerated this year, according to a new report by blockchain security firm CertiK, which tracks cyber threats and security incidents in the digital asset industry. CertiK verified 52 physical attacks against digital asset holders globally in the first half of 2026, up 33% from a year earlier. France, with 33 attacks, accounted for nearly two-thirds of publicly reported cases.

The report is based on verified, publicly reported incidents identified through law enforcement disclosures, court documents, reputable media reports, victim testimony and, where available, on-chain evidence. Because many attacks go unreported, the figures likely understate the true scale of the threat.Criminals are attacking more often, going after bigger targets and reaping larger payouts. The sum of recorded losses and ransom demands rose to about $124 million from just $10.5 million over the same period last year, according to the report.

“The trend suggests that attackers increasingly believe that physical coercion can produce outsized returns,” CertiK researchers wrote, adding that this has changed “criminal economics.”


This is forcing the industry to rethink what security means in crypto. For years, the biggest concern was protecting blockchains and private keys from hackers. Now old-fashioned operational security challenges have become paramount.

Today’s attacks combine online intelligence gathering with real-world violence, according to Ronghui Gu, co-founder of CertiK and a computer science professor at Columbia University.“I wouldn’t describe this as just a physical security attack anymore,” Gu said in an interview. “It’s really a combination of cyberattacks, social engineering and physical attacks.”

The biggest shift has been the rise of home invasions. CertiK verified 20 publicly reported cases in the first six months of the year, compared with just one in the first half of 2025.

One of those attacks in March involved a couple in the Paris suburb of Le Chesnay-Rocquencourt. They were beaten inside their home and forced to transfer roughly $1 million worth of Bitcoin. In another case in the UK, a victim was forced to surrender $24 million worth of crypto that was eventually converted into the privacy-focused token Monero.

Home invasions have replaced kidnappings as the fastest-growing form of crypto-related violence. Kidnappings were up to 16 in the period, compared with 12 last year.

The jump in losses also points to criminals becoming more selective. Attackers are spending more time stitching together blockchain records, leaked customer databases, social media profiles and public records to build detailed profiles of potential victims.

“The important thing is that criminals can now link crypto holders with personal information like home addresses,” Gu said. “Once they can link those datasets together, home invasion becomes possible.”

This increasing sophistication has made crypto crime more distinct from random robberies, with many incidents now involving organized crime.

A single case may involve recruiting a local crew, using data brokers to supply personal information and then transferring stolen funds to money launderers, Gu said. French investigations have also uncovered cases involving minors who were recruited by remote organizers.

These layered operations mean even failed attacks can make economic sense for many involved, as the physical risk is passed to the ground-level crews that are considered disposable.

France appears as the epicenter of this trend for multiple reasons. The country has a sizable crypto ecosystem, while also facing multiple major data breaches, making the location a particularly attractive target.

France also does a better job of recording incidents than other potential hotspots, according to CertiK. French authorities say the true number of attacks is substantially higher — the interior minister said attacks this year numbered 77 through June — but CertiK has limited its numbers to publicly reported and independently verifiable cases.

However, meticulous record-keeping can be a double-edged sword. The report notes that Europe has multiple jurisdictions that keep extensive records. When data breaches occur and are combined with publicly available information, individuals can be easier to identify.

One of the biggest factors skewing the data may be that many attacks still go unreported. “Under-reporting remains severe because victims may fear retaliation, reputational damage, tax exposure, or law-enforcement inaction,” CertiK said in the report.

The country with the second-most verifiable wrench attacks this year is the US, with just four identified cases in the report. Sweden and the UK each had two.

Latest Posts