Crime

Estimated $30 Million Stolen in Violent Crypto Attacks in 2026 as France Records Emerges as Hotspot

Summary

  • Annual value stolen in violent attacks peaked at $58 million in 2025, the highest on record, with 2026 already at $30 million through mid-year.
  • Home invasions now account for 37% of incidents in 2026, up from 26% in 2023. Kidnappings have remained relatively stable year-over-year (YoY) in terms of share of total attacks.
  • On-chain analysis of stolen funds reveals a spectrum of attacker sophistication and implied organized crime links, from criminals who cash out directly to centralized exchanges to highly embedded actors who route funds through laundering services.

 

Most cryptocurrency crime happens entirely online: hacks ($3.4 billion stolen in 2025), scams ($17 billion), ransomware ($820 million), and more that exploit technical vulnerabilities or human psychology. But a different category of crypto crime has been accelerating: one that involves physical violence.

Violent attacks targeting crypto holders, including home invasions, kidnappings, and hostage situations, sometimes called “wrench attacks” in security circles, have surged in recent years. Criminals have recognized that crypto holders are high-value targets because they possess wealth in an instantly and irreversibly transferrable form.

The physical security assumptions that protect traditional wealth, such as bank vaults and armored cars, do not automatically apply in crypto. Often, holders keep their assets in comparatively low security setups, like self-custody wallets, that can be compromised without any institutional gatekeeper standing in the way. And as crypto adoption has grown, so has criminal awareness that a single individual might hold millions of dollars accessible via a smartphone or hardware wallet.

Below, we examine the scale of violent crypto attacks, which countries are hotspots, and what the on-chain patterns reveal about the threat actors involved. We also explore how a single data breach in France may have fueled a dramatic spike in attacks against crypto holders.

More than $30 million stolen in violent attacks so far in 2026

2026 is already proving to be a record year for violent crypto attacks. We estimate that violent criminals have successfully extracted more than $30 million from holders so far this year. If this pattern continues through H2, then 2026 will become the single-worst year for violent crypto attacks on record, surpassing 2025’s total of $58 million.

That figure only represents successful attacks: those where a targeted holder gave up their funds. When we add in attempted extractions, including ransoms demanded, transfers coerced but blocked, and funds later frozen or recovered, the totals are larger: roughly $316 million in 2024, $180 million in 2025, and $107 million so far in 2026. While likely an undercount given that these figures only represent reported attacks, the combined total more fully attests to the scope of the problem.

In the context of a growing year-over-year volume of attacks, attacker success rates tell a different story. Through late June 2026, only 26% of violent theft attempts (12 of 46) have resulted in payment, a drop from 49% (47 of 95) in 2025 and 67% (32 of 48) in 2024.

The declining success rate is being driven by an expanding cluster of attacks in France, where, as we explore later in this report, a compromise of French tax agency records expanded the targetable victim population considerably. These attacks are more numerous, more indiscriminate, and, the public evidence suggests, more often unsuccessful than the targeted, intelligence-driven attacks that characterized prior years.

Shifting attack types

As the number of overall attacks has grown, their nature has also changed. Our data indicate that kidnappings represent a majority of wrench attacks, followed by home invasions, hostage-taking incidents, and other forms of violent crime. Home invasions are up year-over-year, jumping from just 14% in 2025 to 37% through mid-2026. [1]

Home invasions allow criminals to confront victims in a controlled environment where they can compel a transfer of funds. Kidnappings, by contrast, are much more difficult to execute. Attackers must expend considerable time and resources planning logistics; and the extended periods spent with victims leaves the attacker exposed for longer.

The two attack types vary by region. The United States has been an outlier for home invasions  for nearly two years, challenged only recently by France. Meanwhile, France sees kidnapping attempts at a much higher rate than other wrench attack countries in our dataset.

Home invasions surge from 26% to 37% of attacks since 2023

In 2023, home invasions accounted for 26% of documented incidents, with kidnappings representing 39%. By 2026, home invasions have risen to 37% of attacks, while kidnappings have grown to 52%.

France records highest number of attacks

France, the United States, Brazil, and Thailand have recorded the highest cumulative incident counts since 2023, but France now sits in a class of its own. Prior to 2025, France had recorded only a handful of known crypto-related violent incidents. In 2025, that number jumped to 19.

Through mid-2026, France has already logged 30 publicly known incidents. The true scale is almost certainly larger, given that, in late June 2026, Interior Minister Laurent Nuñez said that authorities had documented over 70 crypto-related violent incidents. In response Minister Nuñez announced plans to strengthen protections for people in the crypto sector, including a rapid identification and alert system for at-risk figures.

The attacks have also spread geographically. The Greater Paris region remains the concentration point, but 2026’s incidents reached across the country, including in Strasbourg, Marseille, Grenoble, Toulouse, Nantes, and numerous smaller communes that had never before recorded incidents.

A data breach is the likeliest culprit of France’s surge. In 2024, a French tax official in the Paris area (Protos) is alleged to have stolen and sold dossiers on high-net-worth crypto holders, which included their names, addresses, holdings, phone numbers, and tax records. Criminal intermediaries are said to have bought the dossiers.

A breakout in wrench attacks followed. Measured against France’s pre-2025 baseline of well under one attack per month, the country has seen roughly 48 attacks in excess of its historical norm by mid-2026.

Attacks occurred roughly 1.9 times per month in 2025, then increased to about 4.6 per month in the first half of 2026. Two factors may be fueling the acceleration. First, in January 2026, French authorities took the tax break case public, creating awareness of the problem, and possibly prompting criminals to expedite their use of the dossier information. Second, also in January 2026, the crypto tax-reporting firm Waltio disclosed a separate breach of some 50,000 users, creating yet more useful data for attackers to distill into target lists.

France’s authorities are treating the epidemic as the work of organized crime, prosecuting the wave with JUNALCO, the country’s specialized organized-crime jurisdiction. By mid-2026 the crackdown had yielded around 200 arrests, 88 indictments, 75 suspects held in pretrial detention, and over a dozen investigations.

Family members are a major target

Attackers are adapting new strategies of exploitation in the current wave. In early years, nearly all attacks targeted the crypto holder directly. More recently, attackers have increasingly used family members and other relations as leverage. By early 2026, incidents targeting family members or acquaintances accounted for approximately 25-30% of cases, up from near zero in 2021. The trend is even more pronounced within France where over 40% of incidents targeted a relation rather than the holder of crypto.

In countries with sufficient incident data, the vast majority of victims are local residents rather than visitors or tourists. In Sweden, 100% of victims with known residency status were locals. In France, 93% were local residents. In Brazil, 82%. In the United States, 77%.

The Netherlands is an exception, where 67% of victims were non-residents. However, with only three documented incidents, this figure should be interpreted cautiously. Violent crypto attacks remain rare events in absolute terms, and small sample sizes can produce unstable proportions that may not reflect broader patterns. In general, the targeting of locals suggests a level of reconnaissance and planning, whether through monitoring social media, analyzing blockchain data, leveraging leaked information, or receiving tips from insiders.

On-chain analysis reveals three tiers of attacker sophistication

When violent attacks succeed, the stolen crypto must be moved and eventually cashed out. On-chain analysis of these fund flows reveals variation in attacker sophistication, which provides clues about who is behind these crimes.

The tradecraft tends to be amateur at the point of violence, but professional at both ends. Most incidents we assessed were premeditated, with victims selected through exposed information, whether from data breaches, social-media activity, or insider knowledge. The physical force itself, by contrast, is increasingly outsourced to disposable, low-skill crews, many of whom are recruited through messaging apps.

We observe three broad categories of threat actors based on their on-chain behavior:

Type 1: Unsophisticated and crypto-unaware

At the lowest end of the sophistication spectrum, some attackers appear to have limited familiarity with cryptocurrency. After obtaining funds, they move them directly to centralized exchanges with no evident obfuscation in between. These actors may be opportunistic criminals who view crypto as simply another form of value to extract, without understanding the traceability of blockchain transactions.

For law enforcement, these cases are often the most tractable. Exchange compliance teams can freeze funds, and subpoenas can quickly identify the account holders who are taking receipt of the stolen funds.

Type 2: Sophisticated and crypto-aware

Mid-tier attackers demonstrate greater familiarity with crypto infrastructure. They may use decentralized exchanges, bridges, MEV bots, and other DeFi tools to swap and move assets across chains. They understand that centralized exchanges represent chokepoints with sophisticated compliance programs and user KYC, and attempt to avoid or delay interaction with them.

In the Chainalysis Reactor graph below, we see that funds reported as stolen (in Bitcoin) moved through a series of intermediary wallets, THORChain Bridge, a decentralized exchange, and more — all in an attempt to obfuscate funds.

Type 3: Sophisticated and criminally embedded

The most concerning category involves attackers who are not merely crypto-aware but appear embedded within broader criminal networks. On-chain analysis of their fund flows reveals connections to numerous illicit actors..

In one documented case, stolen funds from a violent attack flowed through an instant exchange, then to what appears to be a suspected OTC laundering service, which has previously interacted with cartel-related money laundering services, wallets associated with Olympic snowboarder-turned-alleged-cocaine trafficker Ryan Wedding, terrorist financing clusters and Southeast Asian guarantee services and money laundering networks.

What this means for holders, investigators, and policymakers

For crypto holders, the data underscore the importance of operational security against wrench attacks. Publicly disclosing cryptocurrency holdings, whether through social media, conference appearances, or on-chain activity linked to known identities, can make individuals targets. Privacy practices and secure custody arrangements are increasingly important, and the French tax authority breach illustrates that regulatory frameworks requiring collection of sensitive information must also ensure robust protection of that data.

For law enforcement, the traceability of cryptocurrency provides investigative opportunities even in violent crime cases. Attackers who successfully coerce a transfer leave an on-chain trail. Collaboration between physical crime investigators and blockchain analysts can identify laundering patterns, link cases, and potentially attribute attacks to organized groups. But the rise of violent crypto crime also underscores a broader point: cryptocurrency now intersects with all categories of criminal activity, not just cybercrime. Patrol officers responding to a home invasion, detectives investigating a kidnapping, and task forces tracking organized crime all increasingly encounter crypto. This means blockchain literacy should not be limited to specialized units. Tools like Chainalysis Wallet Scan and Rapid can help frontline officers quickly assess whether cryptocurrency is relevant to a case and take appropriate action.

FAQs

What is a wrench attack?

A wrench attack is a physical attack in which someone uses violence, or the threat of violence, to force a cryptocurrency holder to hand over their assets — for instance, by coercing them to unlock a wallet or transfer funds under duress. The term comes from a well-known security concept: no matter how strong the encryption, an attacker can bypass it by threatening the victim with a “$5 wrench.” In practice, wrench attacks include home invasions, kidnappings, and hostage situations. Chainalysis data shows the value stolen in these attacks reached a record $58 million in 2025, with home invasion robberies accounting for 37% of incidents in 2026.

How many violent crypto attacks have occurred so far in 2026?

Through late June 2026, 46 violent crypto-related incidents have been documented globally for the year, compared to 40 at the same point in 2025. Total documented incidents since 2017 number in the hundreds.

How much has been stolen in violent crypto attacks?

Known stolen value reached $58 million in 2025, the highest annual total on record. Through mid-2026, approximately $30 million has been stolen. These figures likely undercount the true total, as many incidents go unreported.

What types of violent attacks are most common?

These attacks, collectively referred to as wrench attacks, include home invasions, which now account for 37% of attacks in 2026. Kidnappings comprise a relatively stable YoY 52%, with hostage-taking and other violent attacks making up the remainder.

Which countries have the most violent crypto attacks?

France, the US, Brazil, and Thailand have recorded the highest cumulative incident counts since 2023. France has seen a particularly dramatic surge in 2026.

Who is being targeted?

The vast majority of victims are local residents, not tourists, suggesting attackers conduct reconnaissance to identify high-net-worth individuals as targets. Increasingly, attackers also target family members and associates to pressure the crypto holder.

How can crypto holders protect themselves?

Operational security is critical. Avoid publicly disclosing holdings, use secure custody arrangements, be cautious about linking on-chain activity to real-world identity, and consider physical security measures appropriate to your risk profile.

 

[1] Physical crypto attacks frequently blur categories: many begin with forced entry into a residence and then escalate into detention, coercion, or a forced transfer. Where an incident involves both, we classify by the dominant outcome. If the victim was seized, moved, or held, we record a kidnapping; if the coercion happened at the residence without abduction, we record a home invasion. Other trackers classify the same events by the initial access method (forced entry = home invasion), which produces a higher home-invasion share. Under that convention, roughly six of our 2026 kidnappings — most of them in France — would be counted as home invasions, making home invasion the most common category, consistent with other published tallies. The underlying events are the same; only the labeling differs.

 

This website contains links to third-party sites that are not under the control of Chainalysis, Inc. or its affiliates (collectively “Chainalysis”). Access to such information does not imply association with, endorsement of, approval of, or recommendation by Chainalysis of the site or its operators, and Chainalysis is not responsible for the products, services, or other content hosted therein. 

This material is for informational purposes only, and is not intended to provide legal, tax, financial, or investment advice. Recipients should consult their own advisors before making these types of decisions. Chainalysis has no responsibility or liability for any decision made or any other acts or omissions in connection with Recipient’s use of this material.

Chainalysis does not guarantee or warrant the accuracy, completeness, timeliness, suitability or validity of the information in this report and will not be responsible for any claim attributable to errors, omissions, or other inaccuracies of any part of such material.