
{"id":211435,"date":"2026-08-10T14:43:41","date_gmt":"2026-08-10T14:43:41","guid":{"rendered":"https:\/\/mycryptomania.com\/?p=211435"},"modified":"2026-08-10T14:43:41","modified_gmt":"2026-08-10T14:43:41","slug":"30m-stolen-via-wrench-attacks-so-far-in-2026","status":"publish","type":"post","link":"https:\/\/mycryptomania.com\/?p=211435","title":{"rendered":"$30M Stolen Via Wrench Attacks So Far In 2026"},"content":{"rendered":"<p>Image: Grok\u00a0AI<\/p>\n<p><strong>$30M stolen via wrench attacks so far in 2026. The common pattern in every successful one: the victim made their holdings discoverable. Here\u2019s how to reverse\u00a0that.<\/strong><\/p>\n<p>Chainalysis dropped the numbers on August 6. More than $30 million extracted in successful violent attacks on crypto holders through mid-2026. Forty-six documented incidents by late June. Home invasions now make up 37% of them. Kidnappings still dominate the rest. France is the clear hotspot with 30 publicly known cases (authorities there have logged over 70). The year is on track to beat 2025\u2019s $58 million\u00a0record.<\/p>\n<p><a href=\"https:\/\/www.chainalysis.com\/blog\/violent-crypto-wrench-attacks-2026\/\">www.chainalysis.com\/blog\/violent-crypto-wrench-attacks-2026<\/a><\/p>\n<p>The success rate has actually fallen to about 26%. Attackers are getting less selective and more opportunistic. But when they do succeed, the pattern is consistent.<\/p>\n<p><strong><em>The victim\u2019s holdings were discoverable.<\/em><\/strong><\/p>\n<p>Not \u201c<em>rich person vibes<\/em>.\u201d Actual, concrete signals that someone held meaningful crypto and could be forced to move it. Social media posts about gains or portfolios. Conference appearances where people talk about their stack. On-chain activity tied back to a real-world identity. Public tax filings or leaked government databases (the 2024 French tax data breach that sold dossiers with names, addresses, and holdings is the obvious example). Casual comments to construction workers, delivery drivers, or acquaintances. Linked accounts that let an attacker connect a Twitter handle to a known wallet\u00a0cluster.<\/p>\n<p>Jameson Lopp\u2019s long-running list of physical attacks makes the same point over and over. You can read the full archive\u00a0here:<\/p>\n<p><a href=\"https:\/\/github.com\/jlopp\/physical-bitcoin-attacks\">GitHub &#8211; jlopp\/physical-bitcoin-attacks: A list of known attacks against Bitcoin \/ crypto asset owning entities that occurred in meatspace.<\/a><\/p>\n<p>It is not complete\u200a\u2014\u200aplenty of cases never hit the news\u200a\u2014\u200abut it is the best public record we have. Incidents stretch back to 2014 and keep getting added. The ones that work almost always start with some form of targeting data the victim left\u00a0exposed.<\/p>\n<p><strong><em>I wrote about the physical side of this last year, including practical anti-kidnapping measures and duress\u00a0setups:<\/em><\/strong><\/p>\n<p><a href=\"https:\/\/medium.com\/coinmonks\/anti-kidnapping-kit-27d17af2858a\">Anti-Kidnapping Kit<\/a><\/p>\n<p>That piece still holds. The digital discoverability problem has only gotten\u00a0worse.<\/p>\n<h3>How the Exposure Usually\u00a0Happens<\/h3>\n<p>Most people do not sit down and decide to become a target. They leak the information in\u00a0pieces:<\/p>\n<p><em>Posting screenshots, PNL, or \u201cjust bought more\u201d\u00a0updates.<\/em><em>Speaking at events under their real name while also being active on-chain.<\/em><em>Using the same email, phone, or username across exchanges, socials, and on-chain explorers.<\/em><em>Letting KYC data from one service get correlated with public blockchain activity.<\/em><em>Telling the wrong person in real life (\u201cyeah, I hold a bit of Bitcoin\u201d).<\/em><\/p>\n<p>Once that link exists, the rest is logistics. Attackers do not need zero-days. They need an address, a routine, and the knowledge that the money can be moved under pressure.<\/p>\n<h3>How to Reverse the Discoverability<\/h3>\n<p>Start with the assumption that anything public can be used against you. Then shrink the attack\u00a0surface.<\/p>\n<p><strong>Audit what is already out there.<\/strong> Search your real name, old usernames, and known addresses on Google, archive sites, and blockchain explorers. Check data broker sites and old forum posts. If you find clear links between your identity and holdings, treat them as active risk. This is basic <a href=\"https:\/\/github.com\/soxoj\/counter-osint-guide-en\">counter-OSINT<\/a>. I keep a <a href=\"https:\/\/github.com\/OffcierCia\/non-typical-OSINT-guide\">non-typical OSINT guide<\/a> that covers practical techniques for this exact\u00a0purpose.<strong>Stop creating new links<\/strong>. Do not post about your stack. Do not discuss exact amounts or wallet setups in public or semi-public chats. If you speak at events, keep the personal holdings out of it. Use separate identities for public work and private custody. Avoid posting photos that show home exteriors, cars, or locations that can be reverse-searched.<strong>Break the on-chain to real-world chain.<\/strong> Use fresh addresses. Avoid reusing the same ones that have been associated with KYC\u2019d accounts or public activity. For larger amounts, geographic separation of keys in a multisig setup is the single most effective technical control. One key at home is not enough if an attacker can force you to sign. Spread them. Make the process of moving funds slow and multi-party by\u00a0design.<strong>Add friction that survives coercion.<\/strong> Timelocks, velocity limits, and multisig with deliberate delays turn a 20-minute home invasion into something that cannot finish before help arrives or the window closes. Most documented wrench attacks resolve in under 24 hours. Attackers do not want to sit on a victim for days. Anything that forces them to wait raises the cost and the chance of\u00a0failure.<strong>Duress options.<\/strong> Hardware wallets with wipe\/self-destruct PINs (Trezor has this). Secondary passphrases that open a decoy wallet with a small amount while the real funds stay locked behind a different setup. Some people use Tasker + Android + wearables to trigger silent alerts. Others keep a simple \u201canti-kidnapping kit\u201d with GPS trackers, personal alarms, and pre-arranged check-in protocols. Details and examples are in the earlier post linked\u00a0above.<strong>Physical layer still matters.<\/strong> Reinforced entry points, cameras that actually notify someone, and a plan for what happens if people show up at the door. High-net-worth setups sometimes include safe rooms or professional response. Most people do not need that level. They need the basics that raise the difficulty enough that opportunistic crews move\u00a0on.<\/p>\n<p><strong>Interesting edge cases and facts from the\u00a0data:<\/strong><\/p>\n<p><em>Family members are now used as leverage in a growing share of cases (over 40% in France). Protecting only yourself is incomplete.<\/em><em>Many attacks start with insider tips or low-skill crews recruited on messaging apps after the target has already been identified.<\/em><em>Success rates are dropping, which suggests more noise and less careful targeting. That does not help the people who still get\u00a0hit.<\/em><em>Decoy wallets are controversial. Some providers advise against them because a determined attacker may not stop. Use them only as one layer among\u00a0several.<\/em><em>Lopp\u2019s <\/em><a href=\"https:\/\/github.com\/jlopp\/physical-bitcoin-attacks\"><em>repo continues<\/em><\/a><em> to receive new entries almost every week. The trend is not reversing on its\u00a0own.<\/em><\/p>\n<h3>Decoy Wallet Strategies<\/h3>\n<p>A decoy (or duress) wallet is a secondary setup you can open under pressure while the main funds stay out of reach. The idea is simple: give the attacker something real and believable so the immediate threat ends, then deal with the rest\u00a0later.<\/p>\n<p><strong><em>BIP39 passphrase (the \u201c25th word\u201d)<\/em><\/strong><em> Your seed phrase alone opens one wallet. Adding a passphrase creates an entirely different set of addresses. Leave a modest balance on the seed-only wallet. Keep the bulk behind a strong passphrase. When forced to reveal the seed, the attacker sees the small balance and has no technical way to know a passphrase wallet\u00a0exists.<\/em><strong><em>Hardware wallet duress PIN<\/em><\/strong><em> Some devices (Trezor, Blockstream Jade, and others) let you set a second PIN. Correct PIN \u2192 real wallet. Duress PIN \u2192 decoy wallet with a limited amount, or in some cases a full\u00a0wipe.<\/em><strong><em>Separate physical device<\/em><\/strong><em> A cheap hot wallet or second hardware unit that lives in an obvious place and holds a few thousand dollars. You unlock that one\u00a0first.<\/em><\/p>\n<p>The balance has to look plausible. A few hundred dollars on a wallet that an attacker already believes belongs to a large holder will often make things\u00a0worse.<\/p>\n<p>Common advice is $1,000\u2013$10,000 (or local equivalent) with some real transaction history so it does not look freshly created. Occasional small transfers and gas fees help. Keep the decoy \u201calive.\u201d An empty or brand-new looking wallet raises suspicion.<\/p>\n<h4>BIP39 Passphrase Implementation<\/h4>\n<p>The BIP39 passphrase (often called the \u201c25th word\u201d) is an optional string you supply when deriving the master seed from a mnemonic. It is not part of the 12- or 24-word list itself. Changing even one character produces an entirely different wallet with different addresses and keys. There is no \u201cwrong passphrase\u201d error\u200a\u2014\u200aevery string simply opens a valid, independent wallet.<\/p>\n<p>How the derivation actually\u00a0works:<\/p>\n<p><em>Your mnemonic words are converted back to entropy (with checksum validation).<\/em><em>That mnemonic string becomes the password input to PBKDF2-HMAC-SHA512.<\/em><em>The salt is the fixed string \u201cmnemonic\u201d concatenated with your passphrase (empty string if none is\u00a0used).<\/em><em>After 2,048 iterations the function outputs a 512-bit binary\u00a0seed.<\/em><em>That seed feeds BIP32 hierarchical derivation to generate all private keys and addresses.<\/em><\/p>\n<p>Because the passphrase is part of the salt, two passphrases that differ by a single space, capital letter, or character produce completely unrelated wallets. The hardware or software never stores the passphrase; you must re-enter it every time you want the protected wallet.<\/p>\n<p>Under coercion you can reveal the seed words. The attacker recovers the default wallet, sees the decoy amount, and has no cryptographic evidence that another wallet exists. This only works if the decoy balance looks realistic relative to what the attacker already believes about your holdings.<\/p>\n<h4>Choosing and Handling the Passphrase<\/h4>\n<p><em>Aim for real entropy. Four to six random BIP39 words (Diceware-style) give roughly 44\u201366 bits. Six or more is preferred against offline brute-force once an attacker already has the\u00a0seed.<\/em><em>Avoid single dictionary words, birthdays, pet names, or short strings. Capitalization, spaces, and punctuation all matter and must be reproduced exactly.<\/em><em>Back it up separately from the seed\u200a\u2014\u200adifferent physical location, different medium. Memory alone is not a\u00a0backup.<\/em><em>Test restore with a small amount first. A single typo silently opens an empty\u00a0wallet.<\/em><\/p>\n<h4>The Hard\u00a0Limits<\/h4>\n<p>Jameson Lopp and Casa have been clear on this for years: duress wallets are unreliable under real violence.<\/p>\n<p><em>Attackers who did any reconnaissance may already know the approximate size of the\u00a0stack.<\/em><em>Once they suspect you are lying, the situation can escalate.<\/em><em>There is almost no public data showing these strategies consistently end attacks cleanly. One documented case involved the victim handing over a large amount and still being beaten for\u00a0hours.<\/em><\/p>\n<p>A decoy is not a substitute for making the main funds impossible to move quickly. It is at best a temporary de-escalation tool.<\/p>\n<h4>Better When Combined With Other\u00a0Layers<\/h4>\n<p>Most experienced operators treat the decoy as one small piece of a larger\u00a0setup:<\/p>\n<p><em>Multisig with keys in different physical locations so no single person under duress can authorize a large transfer.<\/em><em>Time-locks or velocity limits that force any movement to wait hours or\u00a0days.<\/em><em>Strong privacy so the attacker never knows how much is actually there in the first\u00a0place.<\/em><em>A practiced script (\u201cthe rest is in a 2-of-3 with a key at the lawyer\u2019s office and a 48-hour\u00a0delay\u201d).<\/em><\/p>\n<p>If you use a decoy, test the entire flow yourself under calm conditions. Know exactly what you will say and show. Assume the attacker may keep pushing after the first wallet. Decoy wallets buy time and options. They do not make you safe by themselves.<\/p>\n<h3>Conclusion<\/h3>\n<p>None of this is theoretical. The $30 million figure is only the successful transfers that got reported. Attempted extractions run higher. The common factor remains the same: the victim\u2019s holdings were visible enough to select\u00a0them.<\/p>\n<p>Make the selection step fail. That is the highest-leverage move available right\u00a0now!<\/p>\n<p><a href=\"https:\/\/medium.com\/coinmonks\/30m-stolen-via-wrench-attacks-so-far-in-2026-3054111cf06f\">$30M Stolen Via Wrench Attacks So Far In 2026<\/a> was originally published in <a href=\"https:\/\/medium.com\/coinmonks\">Coinmonks<\/a> on Medium, where people are continuing the conversation by highlighting and responding to this story.<\/p>","protected":false},"excerpt":{"rendered":"<p>Image: Grok\u00a0AI $30M stolen via wrench attacks so far in 2026. The common pattern in every successful one: the victim made their holdings discoverable. Here\u2019s how to reverse\u00a0that. Chainalysis dropped the numbers on August 6. More than $30 million extracted in successful violent attacks on crypto holders through mid-2026. Forty-six documented incidents by late June. [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":211436,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[],"class_list":["post-211435","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-interesting"],"_links":{"self":[{"href":"https:\/\/mycryptomania.com\/index.php?rest_route=\/wp\/v2\/posts\/211435"}],"collection":[{"href":"https:\/\/mycryptomania.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mycryptomania.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/mycryptomania.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=211435"}],"version-history":[{"count":0,"href":"https:\/\/mycryptomania.com\/index.php?rest_route=\/wp\/v2\/posts\/211435\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mycryptomania.com\/index.php?rest_route=\/wp\/v2\/media\/211436"}],"wp:attachment":[{"href":"https:\/\/mycryptomania.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=211435"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mycryptomania.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=211435"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mycryptomania.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=211435"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}