“Wrench” Physical Coercion Attacks on Crypto Holders Surge 33% YoY
What Happened — A new CertiK report documents 52 “wrench” attacks—face‑to‑face coercion to force victims to hand over private keys or transfer crypto—through June 2026, a 33 % increase from the same period in 2025. Reported losses have jumped to $124 million in the first half of 2026, up from $10.5 million a year earlier.
Why It Matters for Compliance & Audit Readiness
- Physical‑access breaches expose gaps in access‑control policies that SOC 2 expects organizations to define, enforce, and evidence.
- Demonstrating continuous training and awareness for anyone who may hold or manage private keys satisfies the SOC 2 Common Criteria for personnel security.
- Collecting incident evidence (e.g., key‑handover logs, physical‑security controls) provides audit‑ready proof that the organization monitors and mitigates credential‑compromise risks.
Who Is Affected – Cryptocurrency investors, custodial‑service firms, and any organization that stores digital assets in self‑custody wallets (financial services, fintech, crypto‑exchanges).
Recommended Actions
- Map private‑key handling to SOC 2 Access Control criteria (CC6.1, CC6.2) and document physical‑security safeguards.
- Institute mandatory security‑awareness training covering social‑engineering and physical‑coercion scenarios for all key custodians.
- Deploy multi‑factor authentication and hardware‑wallet solutions that require a passphrase or biometric factor beyond the private key alone.
- Capture and retain evidence of key‑transfer requests, approvals, and any physical‑security incidents for audit review.
Source: The Record
Technical Notes – “Wrench” attacks are not a software vulnerability; they exploit physical intimidation to obtain private keys, passwords, or wallet access. Losses are estimated at $124 M in H1 2026. The threat leverages the lack of an intermediary (bank) in self‑custody models, making rapid reversal impossible. Source: The Record