Home › Intelligence › Brief
BREACH BRIEF🟠 High Breach

Physical ‘Wrench’ Coercion Attacks on Crypto Holders Rise 33% YoY, $124M Losses H1 2026

CertiK reports 52 wrench attacks—face‑to‑face intimidation to force private‑key surrender—through June 2026, a 33 % YoY increase and $124 M in losses. The surge highlights gaps in access‑control policies and training that SOC 2 compliance programs must address.

LiveThreat™ Intelligence · 📅 July 24, 2026· 📰 therecord.media
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
4 recommended
📰
Source
therecord.media

“Wrench” Physical Coercion Attacks on Crypto Holders Surge 33% YoY

What Happened — A new CertiK report documents 52 “wrench” attacks—face‑to‑face coercion to force victims to hand over private keys or transfer crypto—through June 2026, a 33 % increase from the same period in 2025. Reported losses have jumped to $124 million in the first half of 2026, up from $10.5 million a year earlier.

Why It Matters for Compliance & Audit Readiness

  • Physical‑access breaches expose gaps in access‑control policies that SOC 2 expects organizations to define, enforce, and evidence.
  • Demonstrating continuous training and awareness for anyone who may hold or manage private keys satisfies the SOC 2 Common Criteria for personnel security.
  • Collecting incident evidence (e.g., key‑handover logs, physical‑security controls) provides audit‑ready proof that the organization monitors and mitigates credential‑compromise risks.

Who Is Affected – Cryptocurrency investors, custodial‑service firms, and any organization that stores digital assets in self‑custody wallets (financial services, fintech, crypto‑exchanges).

Recommended Actions

  • Map private‑key handling to SOC 2 Access Control criteria (CC6.1, CC6.2) and document physical‑security safeguards.
  • Institute mandatory security‑awareness training covering social‑engineering and physical‑coercion scenarios for all key custodians.
  • Deploy multi‑factor authentication and hardware‑wallet solutions that require a passphrase or biometric factor beyond the private key alone.
  • Capture and retain evidence of key‑transfer requests, approvals, and any physical‑security incidents for audit review.

Source: The Record

Technical Notes – “Wrench” attacks are not a software vulnerability; they exploit physical intimidation to obtain private keys, passwords, or wallet access. Losses are estimated at $124 M in H1 2026. The threat leverages the lack of an intermediary (bank) in self‑custody models, making rapid reversal impossible. Source: The Record

📰 Original Source
https://therecord.media/wrench-attacks-against-cryptocurrency-holders ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your trust posture defensible.

See where you'd stand with Verisq AI Trust Operations →