Within the first six months of 2026, France recorded more crypto-related kidnappings than it did in all of 2025. No longer sticking to online hacks, attackers are now physically targeting people with large cryptoasset holdings. One victim was the cofounder of Ledger, a hardware wallet company, who had a finger cut off during a ransom demand. In another incident, a viral video showed the family of a crypto exchange CEO being attacked on a Paris street in broad daylight. Attackers find and target people whose identities are already linked to crypto wealth, often using the same KYC databases that custodial platforms are supposed to protect.
If you ask a trading platform why they want your ID, address, or phone number before you can open an account, they’ll probably say it’s to prevent money laundering, stop fraud, and comply with regulations. While that’s true, it also means all your details (your name, home address, and contact info) are stored centrally with the platform and linked to your crypto holdings. If that information ever gets out, criminals would have no trouble quickly compiling a list of targets.
RELATED: Crypto Firms Boost Security Amid Rising Physical Attacks — Certik
What Are Crypto Wrench Attacks, and Why Are They On the Increase?
A wrench attack in crypto simply refers to a situation where an individual is physically threatened, kidnapped, or assaulted and forced to hand over access to their crypto assets. Instead of hacking systems, attackers bypass technology entirely by targeting the person who controls the funds.
These attacks work well because of how crypto works. If someone steals from a bank account, they have to deal with things like fraud alerts, reversal periods, or the bank taking the money back before they get it. But if someone steals crypto, once the transaction is signed, the money is gone for good. There’s no way to undo it or call a bank for help. For criminals, that makes it much less risky.
One big reason wrench attacks are happening more often is that people sometimes put themselves at risk without realizing it. Many share screenshots of their portfolios on social media, brag about good trades in group chats, or add their wallet address to their Twitter bio to look credible. It doesn’t feel risky at the time; ideally, it feels like just excited people sharing wins. But to someone on the hunt for targets, these posts show who has money, money that can be forcefully extorted under physical duress instead of through online hacks.
How Are KYC and Centralized Data Collection Creating Exposure Risks?
KYC exists for a reasonable purpose: to reduce fraud and money laundering while giving platforms a way to verify who they’re actually dealing with. But it’s worth asking whether the system built to protect crypto users ends up putting them at risk instead. The personal information KYC collects doesn’t disappear once verification is done. It sits somewhere, and anything that sits somewhere can eventually be leaked, stolen, or misused.
Centralized databases create concentrated targets
Signing up for a custodial crypto platform usually requires providing a full name, a government ID, a phone number, an email, and sometimes a home address. All of that ends up stored in one place. For the platform, it’s convenient, but it also means a single breach can hand an attacker everything they need at once, not just account access, but the real-world details tied to a person’s finances.
The 2020 Ledger data leak is a well-documented case of this playing out. Attackers exposed more than 1 million email addresses and roughly 272,000 full customer records: names, phone numbers, home addresses. No crypto was actually stolen in the breach itself. But affected users paid for it in a different way. Their inbox became a target the moment the leak went public, with phishing emails dressed up as Ledger support and, in some cases, direct threats from people who now knew exactly who owned a hardware wallet and where to find it.
Identity data gets riskier once it’s tied to real money
A KYC record differs from a typical consumer database in what it implies. It doesn’t just say who someone is; it says they own or interact with digital assets, and that single fact changes how valuable the record becomes to a criminal. Nobody needs to know exactly how much a person holds; believing someone has meaningful crypto exposure is enough to put them on a list, whether that leads to a scam attempt, an extortion threat, or something far worse.
Data exposure does not always come from direct hacks
Some risks may come from internal sources, including improper data handling, service providers, and phishing campaigns that use information leaked elsewhere. Information that finds its way to the internet cannot just be deleted after the incident is resolved; it may very well be copied and used at a later date. This isn’t unique to crypto. The 2019 Capital One breach exposed the information of more than 100 million customers and applicants, showing that centralized data collection carries the same risk everywhere it’s practiced. What makes crypto different is what happens after the data gets out.
A January 2026 breach at Waltio, a French crypto tax reporting platform, exposed data belonging to roughly 50,000 users. The breach included email addresses, crypto gains and losses, and year-end balances. The stolen database appeared on a dark web marketplace on December 24, 2025, according to the dark web intelligence firm Brinztech. This was nearly a month before Waltio was even aware of the breach. As reported by Forbes, hackers have since claimed through BreachForums that the stolen data was directly linked to at least three kidnappings that netted criminals a combined $17.1 million, although French investigators haven’t confirmed that link.
Ce vendredi matin, nous avons déposé plainte pour tentative d’extorsion et atteinte à un système de traitement automatisé de données.
Le 21 janvier 2026, nous avons été destinataire d’une tentative d’extorsion. Celle-ci semble faire suite à une attaque particulièrement…
— Waltio (@Get_Waltio) January 23, 2026
Even without that connection being verified, the breach is still one of the clearest illustrations of how identity data collected for compliance purposes can end up circulating through the same channels used to physically target crypto holders. This makes data exposure more pressing in crypto, since money can be moved quickly once someone gains access to or control over a user’s account.
Geographic Hotspots for Physical Crypto Attacks
Physical crypto attacks are not spread evenly around the world. Some countries show up in the data far more than others, for reasons that go beyond how much crime is actually happening there, a point covered in more detail further down.
France
France looks like the hottest spot on record right now. According to Bitcoin journalist Joe Nakamoto, about 70% of all reported wrench attacks on crypto holders and their families are believed to occur there, and recorded incidents continue to climb.

- In January 2025, David Balland, cofounder of the hardware wallet firm Ledger, and his wife were abducted from their home. Reports say the attackers severed a finger from Balland and demanded a €10 million ransom before police intervened and carried out a rescue operation.

- In a separate case, the father of an unnamed French crypto entrepreneur was abducted from a Paris street in May 2025 and held for two days at a rental home outside the city. His kidnappers severed one of his fingers and sent his son a video of the injury while demanding a ransom of several million euros. He was freed after a French police tactical unit stormed the house where he was being held.
- In yet another incident that occurred in May 2025, armed men tried to kidnap Paymium CEO Pierre Noizat’s pregnant daughter and his two-year-old grandson. The perpetrators’ attempt was foiled when the daughter fought back, supported by a shop owner who used a fire extinguisher to help chase them away.
Jameson Lopp, CEO of crypto wallet and key management company Casa, calls the situation in France a critical risk created by financial regulation. In his words, “France is the canary in the coal mine, demonstrating how financial regulations create a surveillance apparatus that causes direct harm to bitcoin holders”.
France is the canary in the coal mine, demonstrating how financial regulations create a surveillance apparatus that causes direct harm to bitcoin holders.https://t.co/FxxXcM3Dw6
— Jameson Lopp (@lopp) May 23, 2026
A higher concentration of attacks doesn’t automatically mean a country is less safe overall; the next section explains why France’s numbers look the way they do. Still, France leads by volume, and it isn’t the only country dealing with this. Blockchain security firm CertiK recorded 34 verified physical crypto attacks worldwide between January and April 2026, a 41% increase over the same period in 2025. That figure measures something narrower than the kidnapping counts cited above; it covers verified physical attacks of any kind, not just abductions.

Europe accounted for about 82% of those cases, with France logging 24 of them, more than France’s entire 2025 total on its own. The remaining incidents were spread across the UK, the US, Belgium, Hong Kong, the Philippines, Spain, and Turkey.
United States
In May 2025, 37-year-old John Woeltz (dubbed the “Crypto King of Kentucky”) and his business partner William Duplessie kidnapped an Italian tourist in New York. The victim was tracked using an Apple AirTag and held captive for more than two weeks inside a luxury townhouse in Manhattan’s Nolita neighbourhood. The attackers subjected the victim to severe physical abuse to force him to reveal his Bitcoin credentials. When police later raided the townhouse, they uncovered a horrific crime scene filled with blood, a saw, chicken wire, body armor, night-vision goggles, and Polaroid photos of the victim with a gun pointed to his head.
The attackers also used a Taser, pistol whipped the victim, forced him to consume crack cocaine, and threatened dismemberment with a chainsaw. The victim eventually managed to escape the home and flag down a traffic enforcement agent who looked like a police officer. Both suspects were subsequently arrested and charged with kidnapping and extortion.
United Kingdom
In March 2026, British game developer and crypto investor Alex Amsel, better known online as “Sillytuna”, became the target of one of the year’s most alarming crypto-related robberies.
Amsel was ambushed by a group of armed attackers in the UK, who assaulted him and threatened to kidnap him unless he gave them access to his digital assets. Fearing for his safety, he unlocked his cryptocurrency wallet and authorized a transfer of funds. The attackers walked away with about $23.6 million worth of Aave-USDC (aUSDC) from his Ethereum wallet.
Blockchain investigators later traced the stolen assets as they were quickly moved through Layer-2 networks before being converted into stablecoins such as DAI and privacy-focused cryptocurrencies like Monero, making the money far more difficult to track.
TRACKING TODAY’S $24 MILLION CRYPTO THEFT
Sillytuna was targeted in a real-world attack by thieves who stole $23.6M of AAVE USDC from him.
The attackers moved funds to layer 2 networks, Bitcoin, and even Monero. Here’s a breakdown of the current fund locations: https://t.co/PDPqmrvmnm pic.twitter.com/cBB3Ho55jY
— Arkham (@arkham) March 5, 2026
The ordeal left Amsel deeply shaken, and shortly afterwards, he announced that he was stepping away from the cryptocurrency industry altogether.
Canada
In April 2024, four men disguised as postal workers walked up to a home in Port Moody, British Columbia. Once inside, they held a couple and their 18-year-old daughter hostage for 13 hours, working to drain the family’s crypto savings.
What followed was brutal. The father was beaten and waterboarded repeatedly. The mother was bound, blindfolded, and gagged. The attackers assaulted the daughter and filmed it, using the footage as leverage to force her parents to keep transferring funds. By the end of it, the family had handed over roughly $1.6 million in bitcoin.
One of the four men, Tsz Wing Boaz Chan, flew in from Hong Kong for the job and was paid a flat CAD 50,000 fee. He was sentenced to seven years in late 2025 after admitting his role. As of the time of writing, his three accomplices haven’t been caught and remain free.
These examples show the extent to which criminal elements can go to cause harm to holders of crypto assets, not just through hacks but in the physical world as well.
More Reporting Doesn’t Always Mean More Crime
From gathered research, France’s numbers dwarf every other country’s, but that gap may say much about reporting as it does about where these crimes actually happen. Where incidents are well recorded, media attention is high, and law enforcement is actively investigating, case counts tend to be higher simply because more incidents get reported and confirmed in the first place.
France’s national anti-organized crime prosecutor, Vanessa Perrée, announced in April 2026 that 88 people (including more than 10 minors) had been formally charged across 12 separate crypto kidnapping investigations. By the end of June 2026, French Interior Minister Laurent Nuñez reported the country had logged 77 crypto-related kidnapping cases in just the first half of the year, already surpassing all of 2025’s total of 45, with roughly 200 arrests made in connection with these crimes.
Ce soir, je me suis rendu auprès des représentants et acteurs de la filière crypto pour leur redire que les services du ministère de l’Interieur sont à leurs côtés pour garantir leur sécurité.
J’ai pu leur présenter notre nouveau plan d’actions en la matière, qui vient… pic.twitter.com/7BtMGbVQ2g
— Laurent Nuñez (@NunezLaurent) June 30, 2026
That level of tracking and disclosure is unusual. The US, UK, and Canadian cases outlined above suggest the same underlying threat exists well beyond France, it’s just not being counted, prosecuted, or publicized with the same consistency. As crypto adoption grows globally, the gap between France’s numbers and everyone else’s is likely to say more about which countries are paying attention than about where the actual risk is concentrated.
It would therefore not be right to believe that the problem of theft is restricted to one country only. As cryptocurrency adoption increases around the world, physical security becomes an important aspect of the discussion on digital assets.
What Users and Platforms Can Do to Reduce Risk
As physical and digital risks associated with cryptocurrency become more common, it is essential to implement practical measures to mitigate them and protect privacy.

Limit public disclosure of crypto holdings
Oversharing (screenshots of profits, a wallet address in a bio, bragging about trades) is the obvious risk, but smaller details add up too. Tagging a workplace, posting recognizable landmarks, or linking a real name to a crypto-focused account can all be pieced together by someone building a target list. Keeping financial activity and personally identifiable details on separate, unlinked accounts makes that job harder.
Set up duress protocols with custody providers
Security researcher Jameson Lopp, who tracks physical attacks on crypto holders, recommends countermeasures that go beyond discretion. One is agreeing on a duress phrase with a custody provider in advance, a prearranged word or signal that tells the company a holder is being coerced, so it can freeze funds and alert authorities. Another is keeping a small “decoy” wallet on hand to surrender under threat, rather than revealing the location or size of larger holdings.
Use separate wallets for different purposes
By having multiple addresses for various purposes, you can limit possible losses. For instance, an individual may have a hot wallet on their phone and another for long-term cryptocurrency investments. Hence, the majority of assets will be safe in the event of theft of a private key for a particular wallet.
Avoid reusing phone numbers and emails across services
Reusing your contacts for different services increases the chances of identity tracking. For example, if one email address is exposed in a leak, attackers may try that same email across other platforms to find additional accounts, building a clearer picture of a user’s financial activity.
Minimize stored sensitive data
Exchanges and fintech platforms can reduce long term risk by limiting what they store. For example, instead of keeping full document copies indefinitely, some systems can use encrypted verification or third-party identity providers that confirm compliance without retaining unnecessary personal data. This reduces the impact if a breach occurs.
Watch for account activity tied to known breaches
A fraud detection system built to catch stolen card numbers can do the same job for stolen KYC data. If a platform knows its user data surfaced in a leak, flagging logins, password resets, or large withdrawal attempts from unfamiliar devices in the weeks after gives it a chance to catch an attacker trying to capitalize on that data before funds move.
Treat leaked KYC data as a social engineering tool, not just a targeting list
Attackers who obtain KYC records often use the details inside them (a real name, a verified account, a past transaction) to sound credible when posing as platform support. Anyone who knows their information was part of a breach should be especially wary of contact that references the same details and asks for a seed phrase or a “verification” step.
Strengthen withdrawal and transfer delays for high-risk actions
Platforms add cooling-off periods for risky operations, such as changing passwords and moving large sums of money. For example, for 24 to 48 hours after making significant changes or attempting a large withdrawal, users will not be able to continue their transactions or access their funds.
KYC Doesn’t Cause Wrench Attacks, But It Raises the Risk
No investigator has traced a specific wrench attack back to a specific KYC record. That link hasn’t been proven, and this piece isn’t claiming otherwise. What’s provable is narrower and still troubling. The data these attacks run on (names, home addresses, phone numbers), tied to confirmed crypto activity, keeps ending up in criminal hands anyway. Ledger’s 2020 breach and Waltio’s breach this January put the same kind of list into circulation: records tying real names to real crypto exposure. Neither company lost customer funds directly. Both handed attackers something more useful: a list of who to go after.
The turn of events in France is what that list looks like in action. 88 people charged, 77 kidnapping cases in six months, a cofounder missing a finger, a CEO’s daughter and grandson ambushed on a residential street in broad daylight. None of that required breaking into a wallet. It required knowing whose door to knock on.
That’s the real issue worth sitting with. Crypto was designed such that owning an asset meant holding a key, full stop. But once identity checks, tax reporting, and centralized platforms sit between a person and their holdings, the key stops being the whole story. What increasingly determines whether someone keeps their crypto, or gets hurt trying to, is how much identity data is attached to it, who’s holding that data, and how carelessly it gets handled.
FAQs
What is a crypto “wrench attack”?
A wrench attack is a physical crime where someone is threatened, kidnapped, or assaulted and forced to hand over access to their crypto, rather than having it stolen through hacking. The term comes from a well-known webcomic joke: no amount of encryption stops someone holding a wrench to your head. It’s now used as shorthand across the crypto industry for this entire category of coercion-based theft.
Why has France become a global hotspot for crypto-related kidnappings?
France logged 77 crypto-linked kidnapping cases in the first half of 2026, already more than its full 2025 total of 45, and now accounts for roughly 70% of such attacks reported worldwide. Researchers point to a mix of factors: rising crypto adoption, organized networks recruiting young locals to carry out attacks, and a string of data breaches, including the 2020 Ledger leak and the January 2026 breach at French tax platform Waltio, that put identity and financial data into circulation.
Does using KYC platforms make crypto holders easier to target?
Not automatically, but it increases exposure risk because identity details are stored in centralized systems. If that data is leaked or combined with other publicly available information, attackers have an easier time identifying whom to target and where to find them.
Can crypto held in self-custody still be traced back to a real identity?
Yes, in some cases. Even a wallet held entirely outside an exchange can become linked to a real identity if it has ever interacted with a regulated service that required KYC. This creates a traceable connection between on-chain activity and a real name.
What is a duress phrase, and how can it protect crypto holders during an attack?
A duress phrase is a prearranged word or signal a crypto holder sets up in advance with a custody provider. If someone uses it during a coerced transaction, the provider can freeze funds and alert authorities rather than processing the transfer normally. Some researchers have recommended this alongside keeping a small “decoy” wallet to hand over under threat instead of revealing larger holdings.
Are data leaks the only way criminals identify crypto holders?
No. Criminals also rely on social media activity, public interviews, and blockchain transaction tracing to identify people who may hold significant digital assets, even without access to a leaked database.
Disclaimer: This article is intended solely for informational purposes and should not be considered trading or investment advice. Nothing herein should be construed as financial, legal, or tax advice. Trading or investing in cryptocurrencies carries a considerable risk of financial loss. Always conduct due diligence.
Enjoyed this? Bookmark DeFi Planet, explore related topics, and follow us on Twitter, LinkedIn, Facebook, Instagram, Threads, and CoinMarketCap Community for seamless access to high-quality industry insights.
Take control of your crypto portfolio with DEFI PLANET PRO, DeFi Planet’s suite of analytics tools.






















































































