BTC
ETH
HTX
SOL
BNB
View Market
简中
繁中
English
日本語
한국어
ภาษาไทย
Tiếng Việt

CertiK Report: Wrench Attack Losses Surge Nearly 12x, "Operational Security" Becomes New Core of Defense

CertiK
特邀专栏作者
2026-07-23 10:15
This article is about 1821 words, reading the full article takes about 3 minutes
According to an exclusive report by Bloomberg, on July 22nd, CertiK, the world's largest security company, released the "Intel3D: Wrench Attack Report for the First Half of 2026."
AI Summary
Expand
  • Core Insight: The report reveals a surge in "wrench attacks" targeting crypto asset holders globally in the first half of 2026, with home invasions and coercion against family members becoming the primary attack vectors. Real-world security risks have become a core threat to the digital asset ecosystem.
  • Key Findings:
    1. Surge in Attack Count and Losses: 52 publicly verified wrench attacks occurred globally in H1 2026, a 33.3% increase year-over-year; resulting losses amounted to approximately $124 million, a staggering roughly 11.8x increase year-over-year.
    2. Drastic Change in Attack Patterns: Home invasion incidents rose from 1 case in H1 2025 to 20 cases, accounting for 41% of total events. Attackers are now exerting psychological pressure by controlling or threatening targets' spouses, children, and other related individuals.
    3. Europe Becomes a Hotspot: 39 incidents were recorded in Europe (75% of the global total), with 33 occurring in France (63.5% of the global total). Attackers combine data breaches with on-chain activity to create precise profiles, reducing their search costs.
    4. Data Breach is the Key Entry Point: Attackers illegally obtain target profiles containing names, addresses, and asset estimates via the dark web, data brokers, or insiders, and then deploy lower-level personnel to carry out physical hijackings and coerce transfers.
    5. Restructuring the Defense Model: CertiK has launched Operational Security (OpSec) services for personal information exposure assessments and collaborates with organizations like Interpol to provide real-time threat intelligence, driving the expansion from technical protection to real-world operational security.

According to an exclusive report by Bloomberg, on July 22, CertiK, the world's largest security company, released the "Intel3D: Wrench Attack Report for H1 2026." The report shows that 52 publicly verified wrench attacks were recorded globally in the first half of 2026, a year-over-year increase of 33.3%, resulting in losses of approximately $124 million, up about 11.8 times compared to the same period last year. As the value of digital assets grows and the scale of industry participants expands, attackers are seeking new breakthroughs beyond traditional security measures, making real-world risks an increasingly critical part of the digital asset ecosystem.

Evolution of Attack Patterns: Targets Extending to Homes and Associates

The report indicates that the most significant change in H1 2026 was the explosive growth of home invasion robberies, surging from 1 case in H1 2025 to 20 cases, accounting for 41% of the total incidents during the period.

Notably, attackers are increasingly leveraging real-world relationships to apply pressure. By controlling or threatening the spouses, children, parents, or employees of crypto asset holders, they use psychological coercion to force targets to unlock wallets or execute asset transfers. As associates often lack security awareness and have relatively predictable daily routines, this poses a serious challenge to traditional individual protection mechanisms.

Europe Becomes a High-Risk Zone for Attacks, France Accounts for Over 60%

Geographically, Europe became the most concentrated region for wrench attacks in H1 2026. During this period, 39 publicly verified incidents were recorded in Europe, representing 75% of the global total. Among them, France recorded 33 cases, accounting for 63.5% of the global total, making it the most severely affected country. The United States recorded 4 cases, the UK and Sweden each recorded 2, with relatively fewer cases in other regions.

The report analyzes that this phenomenon may be linked to several factors, including France's active crypto asset ecosystem and multiple large-scale data breaches in recent years. Attackers can combine leaked data with public information and on-chain activities to identify and profile potential targets, significantly reducing the cost of finding victims.

Data Leaks Becoming a Major Entry Point for Real-World Attacks

The methods attackers use to find targets are also changing. In the past, criminals relied more on publicly available social media information and offline events to identify high-value targets. Now, attackers are obtaining precise client data through dark web black markets, data brokers, and public or corporate insiders. Public investigations show that some cases have involved insiders illegally selling user data.

After obtaining a target profile containing names, addresses, asset estimates, and social relationships, middle-level coordinators recruit low-level operatives to carry out physical control through methods such as disguised deliveries, road interception, or fake business meetings, forcing victims to complete transfers within a very short time frame.

Individuals and Institutions Need to Establish More Comprehensive Security Systems

In response to the evolving attack methods, the report advises individuals and institutions to re-evaluate their digital asset security strategies.

For individual users, reducing unnecessary information disclosure and avoiding exposure of asset size and identity-related information are important measures to lower the risk of becoming a target. At the same time, critical assets should not be concentrated in a single wallet or under a single controller. Multi-signature and multi-party computation (MPC) methods can be used to mitigate single points of failure.

For enterprises and institutions managing high-value assets, the report recommends strengthening access control to prevent excessive concentration of critical access permissions, and implementing segregated management for wallet permissions, recovery information, and critical operational processes. Additionally, companies should establish emergency response mechanisms for real-world threats to address potential personal coercion or operational risks.

As attack targets shift from code and systems to the asset controllers themselves, digital asset security is expanding from traditional technical protection to a broader spectrum of operational security.

Security Model Restructuring: Offline OpSec and Architectural Defense

Facing the threat of transnational crime networks, security agencies are promoting collaboration with law enforcement.

The report reveals that CertiK has launched an Operational Security (OpSec) service covering executive personal data exposure assessment, internal system penetration testing, and compliance review. This service can help high-risk individuals and corporate executives identify exposure risks in sensitive information such as identity, family, residence, and travel itineraries, evaluate the potential for such information to be exploited by attackers, and assist companies in meeting compliance requirements for operational resilience and business continuity under regulatory frameworks like VARA, DORA, and MiCA. As a crucial supplement to security management, the CertiK Security Workspace platform conducts deep correlation analysis between off-chain intelligence, on-chain transaction flows, and anti-money laundering (AML) risk signals, helping institutions track and attribute cybercrime in real-time to quickly identify evidence chains with investigative value.

The report also mentions that CertiK will continue to build closer cooperation with international law enforcement agencies, including INTERPOL and Europol, providing real-time threat intelligence and risk monitoring support through CertiK security tools, and offering technical support for major cross-border attack incidents, related investigations, and security policy research through expert resources.

As attackers continuously push beyond traditional technical boundaries, protecting the asset controllers themselves will become a vital component of digital asset security.

Report link: https://indd.adobe.com/view/34999f45-b459-4eec-a889-26e0e0886ba6

Safety
Welcome to Join Odaily Official Community