Skip to main content

CertiK: Crypto “wrench attacks” peak in H1 2026 amid rising home invasions



Crypto “wrench” attacks—incidents where victims are coerced or harmed to obtain access to their digital assets—accelerated sharply in the first half of 2026, according to new analysis from blockchain security firm CertiK.


CertiK verified 52 wrench attacks worldwide in H1 2026, up 33.3% from 39 incidents during the same period in 2025. Home invasions emerged as the most frequent method, climbing to 20 publicly reported cases versus 1 a year earlier. The same report also found that kidnappings increased to 16 from 12, while robberies fell from five incidents to just one.



Key takeaways



  • Wrench attacks rose to 52 verified incidents in H1 2026, up 33.3% year-on-year from 39 in H1 2025, according to CertiK.

  • Home invasions surged to 20 cases, up from 1 a year earlier, becoming the dominant attack pattern.

  • Kidnappings increased to 16 (from 12), while robberies dropped to 1 (from 5).

  • Estimated financial exposure reached about $124.1 million, up from $10.5 million in H1 2025, though the figure includes more than confirmed theft.

  • France accounted for 33 of 52 incidents, with Europe totaling 39, highlighting a major geographic concentration.



A shift toward physical coercion


CertiK’s report attributes part of the trend to a growing willingness by criminals to bypass purely digital defenses through direct physical pressure on victims and their families. The dramatic rise in home invasions is the clearest signal of that change: attacks that once appeared rarely in the dataset became the leading tactic during the first half of 2026.


CertiK also emphasized that its “financial exposure” number is broader than simple theft totals. The company reported that the recorded financial exposure linked to wrench attacks reached approximately $124.1 million, compared with $10.5 million a year earlier. CertiK clarified that the estimate is not restricted to confirmed stolen funds and may include ransom demands, transfers by victims, assets that were frozen or recovered, and even failed ransom attempts.


For investors and users who rely on self-custody, the implication is straightforward: traditional security guidance focused on protecting keys and accounts may not be sufficient when attackers aim to obtain control through coercion.



France dominates the verified caseload


Geographically, the report shows a concentrated pattern. CertiK said Europe accounted for 39 of the 52 verified incidents, with France alone responsible for 33—nearly two-thirds of the global total.


CertiK noted that it used a narrower methodology than French authorities. In particular, CertiK counted only publicly reported incidents that it could independently verify. That distinction matters for interpretation: the French government’s totals could be higher because they may rely on a wider set of cases than CertiK’s verification criteria.


On July 2, French Interior Minister Laurent Nuñez said authorities had recorded 77 crypto-linked kidnappings, extortion cases, or attempted extortion cases during the first half of 2026, up from 45 in the entirety of 2025. CertiK pointed to the possibility that France’s more visible crypto ecosystem contributes to the pattern, citing how data breaches and information flows can connect identities and home addresses with perceived crypto wealth.



Policy and wallet-design countermeasures


French officials have responded to the uptick with targeted enforcement and prevention efforts. In response to the threat, Nuñez said French authorities launched a dedicated prevention platform and a rapid-alert system for crypto holders and professionals. He also said emergency measures have resulted in 200 arrests.


CertiK’s recommendations, meanwhile, focus on making it harder for attackers to quickly convert coercion into irreversible transfers. The firm argued that physical coercion can undermine assumptions behind many “hold your own keys” practices, especially if a victim can be forced to act immediately.


To reduce the speed at which funds can be moved under pressure, CertiK recommended several technical and operational controls, including:



  • Multisignature or multiparty computation arrangements so no single threatened party can unilaterally authorize transfers.

  • Withdrawal delays to slow down transfers after authorizations are initiated.

  • Spending limits to cap the impact of any coerced transaction.

  • Geographically separated signers, so attackers cannot simultaneously pressure all parties needed to move funds.


These measures are designed to change the attacker’s advantage: instead of forcing victims to act immediately, they introduce friction, require multiple approvals, or create time windows that may allow victims to seek help.



Why the jump in home invasions matters


The sharp increase in home invasions suggests attackers are increasingly moving from remote scams or online compromise to scenarios where the victim’s immediate physical compliance becomes the key vulnerability. That trend also helps explain why “wrench” incidents can carry such a wide range of outcomes—ranging from transfers under duress to situations where assets are later recovered or ransom demands fail.


As regulators and law enforcement refine their response, the next test will be whether defensive practices keep pace across borders—particularly in regions where incidents are concentrated. Users should pay close attention to whether both public reporting and independently verified datasets continue to show the same pattern of escalation in the second half of 2026.



https://www.cryptobreaking.com/certik-crypto-wrench-attacks-peak/?utm_source=blogger%20&utm_medium=social_auto&utm_campaign=CertiK:%20Crypto%20“wrench%20attacks”%20peak%20in%20H1%202026%20amid%20rising%20home%20invasions%20

Comments

Popular posts from this blog

Mastercard Launches AI Agent Pay System With Ripple and Solana Help

Mastercard has launched Agent Pay for Machines, a payments system built for autonomous software agents. The service allows AI agents to send and receive payments without direct human action. It brings Ripple, Coinbase, and Solana Foundation into Mastercard’s push for automated digital commerce. Ripple Brings XRPL and RLUSD to Mastercard’s Agent Pay System Mastercard introduced Agent Pay for Machines on June 10 as a tool for machine-led payments. The system targets high-volume and low-value transactions across business and consumer use cases. It also supports automated settlement between software agents and connected machines. Ripple will support the system through the XRP Ledger and its RLUSD stablecoin. The company said that settlement will become more important as automated commerce grows. It also sees blockchain rails as useful for fast and rule-based payments. RippleX senior vice president Markus Infanger said XRPL and RLUSD support enterprise-grade agent payments. He said the tool...

Coinbase's x402 launches AI agents app store for payments

Coinbase-backed x402 has unveiled Agentic.market, a dedicated marketplace aimed at increasing the usefulness of AI agents by aggregating thousands of apps and services that agents can access without any API keys. The rollout positions the platform as a central hub for agents to discover, evaluate, and deploy capabilities across a standardized payments layer. Coinbase product lead Nick Prince described Agentic.market in a video posted on X as a storefront for discovering, comparing, and using x402 services. The marketplace is designed to give both humans and their AI agents access to a wide range of tools—from data feeds to consumer apps—without the friction of managing API credentials. A storefront for discovering, comparing, and using x402 services. Thousands of services. Zero API keys. Powered by x402. Prince added that the market offers a web interface for humans to browse and assess services, alongside a programming layer that lets AI agents autonomously search, filter, and integra...

Solana Policy Institute Calls on SEC to Safeguard DeFi Developers from Overly Strict Regulations

US Crypto Policy Innovation: Advocates Push for Clear Regulations and Developer Protections The Solana Policy Institute has urged the U.S. Securities and Exchange Commission (SEC) to differentiate between centralized crypto exchanges and non-custodial decentralized finance (DeFi) software. The nonprofit emphasizes that developers creating and publishing non-custodial code should not be classified as intermediaries, advocating for balanced regulation that fosters innovation without compromising security or legality. Key Takeaways Advocates call for regulatory clarity distinguishing between non-custodial DeFi protocols and centralized exchanges. The Institute argues that applying traditional securities laws to DeFi code risks stifling innovation and pushing activity offshore. Authorities are encouraged to adopt a custody-and-control-based framework to clarify legal liabilities. Legislation proposals aim to shield developers from legal liabilities associated with blockchain code and activ...