While most crypto crime unfolds online, physical violence against holders is accelerating rapidly. So-called "wrench attacks," including home invasions and kidnappings, have surged as criminals recognize that crypto holders possess wealth in an instantly and irreversibly transferrable form. With more than $30 million already stolen through mid-2026, this year is on pace to surpass 2025's record $58 million total. Key insights include:
- Home invasions have climbed from 26% of documented incidents in 2023 to 37% in 2026, allowing criminals to compel immediate transfers in controlled environments. Attacks targeting family members have grown from near zero in 2021 to 25-30% of cases.
- France has emerged as the global hotspot, logging 30 publicly known incidents through mid-2026 (with authorities citing over 70), likely fueled by a 2024 breach in which a French tax official allegedly sold dossiers on high-net-worth crypto holders to criminal intermediaries.
- Attacker success rates have dropped from 67% in 2024 to 26% in 2026, driven largely by more indiscriminate French attacks.
- On-chain analysis reveals three tiers of attacker sophistication: unsophisticated actors who cash out directly to exchanges, mid-tier attackers who route funds through DEXs and bridges, and criminally embedded actors whose flows connect to cartel laundering services and terrorist financing clusters.
Read our full analysis here.
Anatomy of the Coldcard Exploit: $38M+ Swept in 25 Minutes
A firmware vulnerability in Coldcard hardware wallets has enabled one of the largest self-custody exploits on record. Confirmed losses are currently more than $38 million, though estimates from Galaxy Research suggest that the total impact could reach $110 million as attacks continue. Key insights include:
- The attacker systematically swept 500 distinct victim wallets over the course of 25 minutes, prioritizing the largest holdings first. Cumulative value stolen skyrocketed to roughly $30 million within the first 10 minutes, and three of the 10 largest victim wallets each held over $636K (10 BTC).
- The early targeting of high-value wallets, including a single $1.8 million victim, suggests that the attacker studied the victim wallet population in advance, rather than sweeping indiscriminately.
- Wallet redundancy offered no protection in this exploit: the two biggest victims lost a combined $4 million, despite splitting their holdings across multiple independent wallets, all of which were generated using the same flawed firmware.
- Canadian bitcoiners are bearing the heaviest impact, accounting for 25% of attributable losses, while Australia, the United States, and Thailand are also seeing major losses.
- Applying the latest Coldcard hotfix is not enough to protect a seed that was generated on vulnerable firmware; users must generate an entirely new seed on patched hardware, and a strong BIP-39 passphrase provides critical additional protection.