Wrench Attacks: Physical Coercion Bypasses Cryptocurrency Wallet Encryption Amid 33% YoY Surge in H1 2026 — Threadlinqs Intelligence
As of 2026-07-28, Wrench Attacks: Physical Coercion Bypasses Cryptocurrency Wallet Encryption Amid 33% YoY Surge in H1 2026 is a high-severity threat intel threat attributed to Multiple Independent Criminal Groups, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 21 indicators of compromise.
Threat ID: TL-2026-1737 · Severity: HIGH · Status: ACTIVE · Category: THREAT_INTEL
Attribution: Multiple Independent Criminal Groups · FINANCIAL
Blockchain-security firms TRM Labs and CertiK document a sharply escalating global pattern of 'wrench attacks' — kidnapping, home invasion, torture, and extortion used to physically coerce
"Wrench attacks" — named for the xkcd "$5 wrench" rubber-hose-cryptanalysis joke — describe a non-technical attack vector in which adversaries bypass wallet encryption entirely by targeting the human holding the key rather than the cryptography itself. Victims are coerced through home invasion, kidnapping-for-ransom, armed/knifepoint robbery, torture, or credible threats of violence against themselves or family members until they unlock a wallet, disclose a seed phrase, or approve an on-chain transfer under duress.
The pattern has escalated sharply through 2025-2026. TRM Labs recorded roughly 55 wrench attacks globally in 2025 (the worst year on record at the time), while independent tracker Jameson Lopp's 'physical-bitcoin-attacks' GitHub list logged over 70 incidents in the same period and now exceeds 200 entries since 2014, with a 169% increase in reported attacks in the first six months of 2025 alone. CertiK's Intel3D H1 2026 Wrench Attacks Report — the most current authoritative dataset — verified 52 distinct global incidents in H1 2026, a 33% year-over-year increase from 39 in H1 2025, with total recorded financial exposure jumping to $124.1 million (versus $10.5M in H1 2025), an almost 12-fold increase. Average exposure per incident rose from roughly $270,000 to $2.39 million. Home invasion overtook kidnapping as the most common method (20 vs. 1 incident YoY), kidnappings rose from 12 to 16, and the report recorded 4 torture incidents and 1 murder. Europe accounted for 79.6% of verified H1 2026 incidents, with France alone responsible for 33 incidents (63.5% of the global total).
Named incidents anchor the pattern: Ledger co-founder David Balland and his partner were kidnapped from their central-France home in January 2025 (€10M ransom demand, finger severed, rescued after ~24 hours); in May 2025 the daughter and grandson of a Paris crypto executive narrowly escaped an abduction attempt, and separately the father of a crypto entrepreneur was kidnapped and held 58 hours under a €5-7M ransom demand (finger severed, five suspects arrested); in a Vancouver, Canada home invasion (court records unsealed November 2025) victims were waterboarded and a family member sexually assaulted while $1.5M in Bitcoin was stolen; in March 2026 a UK-based crypto figure ('Sillytuna') was held down by four assailants under threats of weapons and rape and forced to transfer roughly $24M in stablecoin; and in April 2026 a mother and child were kidnapped in France. In the US, DOJ prosecutors used RICO organized-crime statutes against a 13-defendant conspiracy (fronted by Malone Lam) that stole over $230-263M in cryptocurrency via SIM-swapping and home invasions, in one case remotely tracking a Washington DC victim's real-time physical location through a compromised iCloud account to coordinate an armed robbery on August 18, 2024. A related, earlier home-invasion crew led by Remy Ra St Felix combined SIM-swapping with gunpoint robbery to steal $3.5M+; St Felix was sentenced to 47 years, later extended by 6 years 10 months for assaulting a trial witness. UK cases date back to 2018 (Danny Aston, Oxfordshire, gunpoint Bitcoin transfer) and include a 2021 knifepoint robbery of a university student and a 2021-2022 London teen-gang spree that stole £115,000 via crypto-app muggings.
TRM Labs researchers (Ari Redbord, Phil Ariss) attribute the rise to three converging factors: cryptocurrency's mainstream adoption expanding the pool of visible, reachable targets; the perceived irreversibility/pseudonymity of on-chain transfers making crypto holders attractive relative to traditional banking targets; and criminals' increasing use of social media (Instagram, TikTok, podcast appearances) for OSINT-driven wealth-signal profiling and victim identification. Attackers increasingly target proxy victims — a holder's spouse, parent, child, employee, driver, or assistant — who often have weaker personal security and more predictable routines than the primary targ
Target sectors: finance, cryptocurrency, technology
Target regions: Europe, North America, france, united kingdom, united states of america, canada
Detections & IOCs
As of 2026-08-25, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 21 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
THREAT_INTEL, HIGH, threat intelligence, cybersecurity, T1593, T1591, T1589, T1596, T1586, T1078, T1199, T1078, T1078, T1078