
Key takeaways
- CertiK verifies 52 wrench attacks in the first half of 2026, with recorded exposure reaching about $124 million.
- Europe accounts for 39 of 52 incidents, while France remains the main hotspot for physical coercion.
- Attackers use sophisticated intelligence to connect real people with Bitcoin holdings before applying force and intimidation.
CertiK recorded 52 verified wrench attacks in the first half of 2026, with recorded financial exposure reaching about $124 million. The exposure, which included ransom demands and stolen funds, rose more than tenfold from the comparable prior period.
Physical attacks carry a larger financial toll
The 52 verified incidents used threats or physical force against people believed to control Bitcoin or crypto assets. Rather than breaking cryptography, a wrench attack targeted a person who could be coerced into handing over access or assets (the person holding the keys, rather than the code protecting them).
CertiK reported about $124 million in recorded financial exposure, including ransom demands and stolen funds, across those 52 verified attacks in the first half of 2026.
Incident count alone does not capture the financial scale of coercion. Exposure is the wider number. It counts value put at risk, not just what was already lost.
Europe accounts for most verified incidents
Europe accounted for 39 of the 52 verified wrench attacks in the first half of 2026. That placed three quarters of CertiK's recorded incidents in one region.
France was the main hotspot, with 33 verified incidents, most of Europe's 39 and nearly two thirds of the 52 attacks recorded worldwide in the first half.
This concentration makes physical location part of the custody risk. Of the 52 attacks CertiK recorded in the first half of 2026, Europe held 39, and France, within Europe, held 33.
Coercion targets the owner, not the code
A wrench attack used threats or physical force against a holder rather than an attempt to defeat the underlying cryptography. The reported incidents therefore belonged to both the custody discussion and the discussion of privacy risk around visible ownership.
This matters because self-custody removes institutional counterparty risk without removing personal security risk. The network can stay secure while an identified person is threatened for access to holdings.
Why It Matters
These verified attacks, and about $124 million in recorded exposure, show why privacy cannot be traded away in the name of security. When Europe accounts for 39 incidents and France alone records 33, the threat is concrete: coercion targets an identified holder when cryptography will not yield. Bitcoin self-custody removes institutional counterparty risk, but CertiK's figures for the first half of the year show why personal privacy and disciplined operational security remain essential parts of custody. Financial mapping that ties an identity to holdings can increase physical exposure, even while the Bitcoin network itself remains secure.




















