Violent cryptocurrency theft crossed $30 million in the first half of 2026 and is tracking to surpass 2025's full-year total, according to Chainalysis data shared by CoinMarketCap on August 7. France recorded 30 publicly known attacks, the most of any country over the period.
These are not exchange hacks or smart contract exploits. They are in-person robberies, kidnappings, and coercion aimed at forcing holders to hand over their crypto directly. The industry calls them "wrench attacks," a reference to the idea that an attacker with a physical weapon can bypass any amount of cryptographic security by threatening the person who holds the keys.
The offline threat is outgrowing the online one
For most of crypto's history, the dangerous attack surface was digital: phishing links, drained hot wallets, exchange breaches. Chainalysis figures point to a different picture for 2026. The $30 million counted here comes only from publicly reported violent incidents, which means the real total is almost certainly higher. Many victims never report attacks, either out of fear of retaliation or because they do not want to reveal how much crypto they hold.
France leading the count at 30 attacks stands out. Several high-profile cases in the country over the past two years, including the kidnapping of relatives of crypto executives, have drawn attention from French law enforcement and made the risk concrete rather than theoretical. The pattern shows attackers targeting people they can identify as holders, often through social media posts, public wallet activity, or leaks that tie a name to a balance.
The through-line is that self-custody removes counterparty risk but shifts responsibility onto the individual. If you hold your own keys, there is no support desk to freeze a transfer and no insurance backstop once funds leave your wallet under duress. That trade-off is worth understanding before deciding how, and where, to hold significant balances. For readers weighing that decision, our overview of spending from your own wallet covers how non-custodial setups actually work in practice.
Attackers follow visible wealth
The people most exposed are those whose holdings are easy to connect to a real identity and physical location. Public figures, founders, and anyone who posts about large gains fit that profile. On-chain transparency compounds the problem: a wallet that receives a large transfer is visible to anyone watching, and clustering tools can sometimes link that wallet back to an owner.
A few habits reduce exposure without requiring a security detail:
- Keep holdings and identity separated. Avoid publicly linking your name or face to specific wallets or balance figures.
- Use a decoy setup. A hardware wallet with a small balance, plus a hidden passphrase-protected wallet holding the bulk, gives you something to hand over under coercion without losing everything.
- Limit what you carry and reveal in person. Do not discuss holdings with strangers, and treat any unsolicited in-person meeting about crypto as a risk.
- Split storage geographically so no single location holds everything.
None of this is a guarantee. The point of a wrench attack is that it defeats technical defenses by targeting the human. Reducing how identifiable you are as a target is the more durable defense.
Everyday spending changes the calculation
For most users, the practical takeaway is not to abandon self-custody but to match custody choices to how much is at stake. Keeping a large treasury in cold storage and a smaller, refillable balance for daily use lowers the amount an attacker could extract on the spot. Cards that spend from a dedicated hot wallet or a stablecoin balance fit that model, since the exposed balance stays small and the vault stays offline and unlinked.
This is also where the difference between custodial and non-custodial products matters in a specific way. A custodial provider can, in theory, flag or freeze suspicious transfers, though it introduces the insolvency risk that self-custody avoids. Non-custodial spending keeps you in control but means a coerced transfer is final. Neither is strictly safer; they fail in different ways. The right choice depends on your balance size and threat model.
The rise in physical attacks does not change the math on any single card or wallet. It changes the math on visibility. The less an attacker can learn about who holds what, the smaller the target.
Overview
Chainalysis data reported on August 7, 2026 puts violent crypto theft above $30 million for the first half of the year, on pace to break 2025's record, with France leading at 30 publicly known attacks. The figures reflect physical coercion rather than online exploits, and the true total is likely higher given underreporting. The clearest defense is reducing how identifiable you are as a holder: separate identity from wallets, use decoy balances, and keep only small amounts in easily accessible spending wallets while the bulk stays offline and unlinked.



