According to Chainalysis data released in August this year, as of the end of June, 46 violent attacks against cryptocurrency holders have been recorded globally; more than half involved kidnappings, and over one-third involved home invasions. Since the beginning of 2026 alone, over $30 million in cryptocurrency has been stolen through violent coercion.

The crypto community calls this the “$5 wrench attack.”
A name with a touch of dark humor, but a chilling logic: Breaking into a hardware wallet? Too hard. But if I know you own crypto and where you live, all I need is a $5 wrench to pay you a visit and “persuade” you to give up your recovery phrase.
In January 2025, Ledger co-founder David Balland and his partner were kidnapped at their residence in France. The kidnappers demanded a ransom in cryptocurrency and severely disabled Balland’s hand. French police later rescued both individuals and arrested several suspects.

In November 2025, Danylo K., the 21-year-old son of the deputy mayor of Kharkiv, Ukraine, was kidnapped in Vienna, subjected to prolonged torture to obtain his wallet password, and then burned to death with gasoline. The suspects were later arrested in Ukraine, and the associated cryptocurrency accounts have been emptied.
There are also U.S.-based interstate violent robbery gangs, with multiple suspects charged with posing as delivery personnel or pizza couriers in California and other states, breaking into homes, binding and assaulting victims, and forcing them to transfer funds. In one case, approximately $6.5 million in crypto assets were extorted in a single transaction; other gangs have carried out similar attacks across multiple states, resulting in cumulative losses ranging from millions to tens of millions of dollars.
The latest case is even more chilling: A young French couple from the Somme department—a farmer and a bank employee who had never traded crypto—bought a secondhand home, only to discover the previous owner was a retired crypto millionaire. After the former owner’s tax information and old address were leaked onto the dark web, the new owners suffered three break-ins between June 24 and July 17, 2026—less than a month. Although two suspects have been convicted in local court, the victims’ lawyer noted that the dark web leak left the new owners victimized through no fault of their own; the couple now plans to sell the house and move away.
This is what makes the “wrench attack” truly terrifying. You don’t need to own any coins—just having others believe you do is enough to put you at risk.
After "Not your keys, not your coins," there's another challenge ahead.
Actually, just two weeks before the Trezor incident, another wallet provider, Coldcard, experienced a key generation vulnerability, and Galaxy Research later estimated the associated losses at approximately $130 million.
Galaxy thus offered a highly thought-provoking assessment: self-custody does not eliminate custodial risk, but rather shifts it to the hardware, software, and key generation stages.
This time, Trezor has pushed the risk one step further:
The risk will also extend to logistics companies, order databases, your phone number, and your home address.
Hardware wallets enable offline signing, keeping private keys permanently offline, but from the moment the user places an order, they enter another system: e-commerce, payments, warehousing, logistics, and customer service.
A leak at any of these stages could link an anonymous on-chain address to a real-world individual.
Jameson Lopp, co-founder of Casa and a long-time tracker of physical attacks on cryptocurrency, has for years warned holders that the “$5 wrench attack” is no longer a joke. His advice to high-net-worth holders is to avoid publicly flaunting wealth, reduce social media exposure, and store keys in multiple locations using multi-signature setups, so that even if coerced, they cannot immediately complete a transfer.
Anonymous delivery has arrived, but is it "absolutely" secure?
After the Trezor incident, the response was swift: starting in September, "anonymous delivery" was introduced in the EU—separating hardware wallet purchases from home addresses and real identities.
This appears to be merely an adjustment in the logistics process, but it signifies that the hardware wallet industry is redefining "security."
Over the past decade, the most frequently said phrase in the crypto industry has been: Not your keys, not your coins.
As a result, more and more people are transferring their assets from exchanges into cold wallets, thinking the risk ends there.
But now it’s clear that the real trouble begins the moment you transfer your coins into a cold wallet.
Because when your wealth can be transferred to any corner of the world in minutes, when transactions are nearly irreversible, and when control depends solely on a mnemonic phrase—criminals quickly did the math:
Instead of spending months searching for technical vulnerabilities, I just found you.
You can hide your private key in the safest place on Earth, but once the delivery person knocks on your door, it all comes back to square one.
Author: Bear Cookie
Twitter: https://twitter.com/BitpushNewsCN
BitPush Telegram community: https://t.me/BitPushCommunity
BitPush TG subscription: https://t.me/bitpush
Disclaimer: All articles by BiTui represent the authors' opinions only and do not constitute investment advice.