Crypto’s New Security Threat: Wrench Attacks

Crypto security used to sound like a software problem: seed phrases, phishing kits, smart-contract bugs, exchange hacks, SIM swaps. But the latest warning sign is much more primitive. According to a CoinDesk report drawing on CertiK data, crypto holders have lost roughly $124 million to so-called wrench attacks — robberies, kidnappings, extortion and assaults designed to force a victim to hand over digital assets.
That number is alarming not because it rivals the largest protocol exploits. It is alarming because it shows attackers adapting. If a hardware wallet, multisig setup or cold-storage routine makes a remote hack too hard, criminals can target the person who controls the keys. In crypto, the weakest link is no longer always the password. Increasingly, it is the human being behind it.
What a Wrench Attack Is — and Why It Works
A wrench attack is the physical version of a crypto hack. Instead of tricking a victim into signing a malicious transaction, the attacker threatens them until they do. The term comes from the famous XKCD comic about bypassing encryption with a wrench: why crack cryptography when you can coerce the person who knows the secret?
In practice, the category is broad. It can mean a home invasion where thieves force someone to unlock a phone, Ledger or Trezor. It can mean kidnapping a trader and demanding a ransom in stablecoins. It can mean extortion after doxxing a founder, an OTC broker or an influencer who has spent years publicly signaling wealth. The common feature is simple: the blockchain transaction may be digital, but the pressure point is physical.
That makes these attacks brutally effective. Crypto transactions settle quickly, can cross borders in minutes and are often irreversible. A victim under threat has little time to call an exchange, notify law enforcement or freeze assets. Even when investigators later trace funds on-chain, recovery is uncertain. The attacker’s bet is that fear will beat security hygiene.
Why the Threat Is Surging Now
The rise in wrench attacks is not random. It is the result of several crypto trends colliding.
First, self-custody has gone mainstream among sophisticated users. After exchange failures and custody scandals, more investors moved assets into wallets they control. That is good for sovereignty, but it also changes the threat model. A bank can place friction between a robber and a wire transfer. A self-custody user may be the only checkpoint.
Second, crypto wealth is easier to identify than many people think. Public blockchains do not reveal names by default, but they do create permanent transaction trails. Combine those trails with ENS names, NFT purchases, exchange leaks, social media boasting, conference photos, Telegram handles and corporate filings, and a motivated criminal can build a target list.
Third, prices matter. When bitcoin, ether and major tokens rally, old wallets become newly tempting. A hardware wallet in a drawer may represent life-changing money. Criminals know this. The same bull-market visibility that attracts investors also attracts predators.
Finally, the culture of crypto often rewards public proof of success. Screenshots of PnL, luxury watches, high-end conference travel and influencer-style transparency can become operational-security liabilities. In traditional finance, rich people often hide behind institutions, lawyers and private banking layers. In crypto, many holders have spent years being proudly, visibly self-sovereign.
The Examples Are No Longer Edge Cases
For years, physical crypto crime sounded like a dark corner of the industry: a handful of home invasions, scattered robberies, a few infamous kidnappings. That is no longer a comfortable assumption. Security researcher Jameson Lopp’s public archive of physical bitcoin and crypto attacks runs for years and includes incidents across multiple countries, from forced wallet transfers to abductions and violent robberies.
Recent cases have made the threat harder to dismiss. In France, the kidnapping of a Ledger co-founder and his wife shocked the industry because it targeted someone associated with one of crypto’s best-known hardware wallet companies. Other reported incidents have involved crypto entrepreneurs, traders and family members of people believed to hold large balances. The pattern is clear: attackers are not always going after anonymous whales. They are going after anyone who appears to be a viable route to funds.
This is the uncomfortable shift. A person’s partner, child, assistant or driver may know enough to be used as leverage. A public address may not expose a legal identity, but a leaked database, an old conference badge photo or a careless tweet might. The attack surface now includes daily routines, home addresses, travel plans and social circles.
Better Security Means Designing for Duress
The old advice — use a hardware wallet, never share your seed phrase, beware phishing links — is still necessary. It is no longer sufficient. Serious crypto security now has to include physical safety and duress planning.
Start with visibility. Do not advertise balances, wallet addresses, trades or lifestyle markers that imply liquid crypto wealth. Separate public identity from financial infrastructure. Avoid reusing handles across exchanges, wallets, Discord, X, GitHub and Telegram. Treat doxxing as a security event, not an inconvenience.
Next, reduce single-person control. Multisig wallets can require multiple keys held in different locations or by different people. Properly designed, this means one coerced victim cannot instantly move everything. Institutional custody, collaborative custody and vault products with withdrawal delays can add friction. That friction is exactly what you want when the threat is a gun, not malware.
Duress wallets are also useful, but they must be realistic. A small decoy balance may satisfy opportunistic thieves, but it will not fool attackers who know, or believe they know, the victim’s net worth. The better model is layered: a hot wallet for spending, a modest decoy, and long-term holdings behind multisig, time locks or geographically distributed keys.
Personal routines matter too. High-value holders should consider basic executive-security practices: private home addresses where possible, cautious ride-share and delivery habits, secure travel planning, alarm systems and clear family protocols. If relatives know you are in crypto, they should also know what to do if someone calls with threats, impersonates police or demands wallet access.
Crypto’s Human Layer Is Now the Front Line
The industry has spent a decade hardening code. Wallet interfaces are better, audits are standard, exchanges monitor suspicious flows and hardware devices are far more usable than they once were. Attackers noticed. When the digital perimeter improves, they look for a softer perimeter.
That does not mean self-custody is broken. It means self-custody has matured into a real-world responsibility. The private key is not just a cryptographic object; it is a power to move wealth. Anyone who controls that power needs a plan for what happens when persuasion becomes coercion.
The lesson from the surge in wrench attacks is blunt: in crypto, security is no longer only about keeping hackers out. It is about making sure no one person, under pressure, can be turned into the master key.