CertiK Report: Wrench Attack Losses Surge Nearly 12 Times, "Operational Security" Becomes New Core for Prevention

CN
5 hours ago

According to exclusive reports from Bloomberg, on July 22, CertiK, the world's largest security company, released the "Intel3D: 2026 First Half Wrench Attack Report". The report shows that there were a total of 52 publicly verified wrench attack incidents recorded worldwide in the first half of 2026, an increase of 33.3% year-on-year; the losses amounted to approximately 124 million USD, a growth of about 11.8 times compared to the same period last year. As the value of digital assets increases and the scale of industry participants expands, attackers are looking for new breakthrough points outside traditional security measures, and real-world risks are becoming an unavoidable part of the digital asset ecosystem.

The evolution of attack forms, with targets extending to families and associated personnel

The report points out that the most significant change in the first half of 2026 is the explosive growth of home invasions, which skyrocketed from 1 in the first half of 2025 to 20, accounting for 41% of the total incidents during the same period.

It is noteworthy that attackers are increasingly leveraging real-life relationships to apply pressure, by controlling or threatening spouses, children, parents, or employees of cryptocurrency asset holders, using psychological pressure to force targets to unlock wallets or execute asset transfers. Since associated personnel often lack awareness of preventive measures and have relatively public daily itineraries, traditional single-person defense mechanisms are facing severe tests.

Europe becomes a high-incidence area for attacks, with France accounting for over sixty percent

From a geographical perspective, Europe has become the region with the highest concentration of wrench attacks in the first half of 2026. In the first half of this year, Europe recorded a total of 39 publicly verified incidents, accounting for 75% of the global total; among them, France recorded 33 incidents, accounting for 63.5% of the total global cases, becoming the most severely affected country. The United States recorded 4 incidents, while the United Kingdom and Sweden recorded 2 incidents each, with other regions having relatively fewer cases.

The report's analysis suggests that this phenomenon may be related to multiple factors, including the active cryptocurrency ecosystem in France and several major data breach incidents in recent years. Attackers are able to combine leaked data with public information, on-chain activities, etc., to identify and profile potential targets, significantly reducing the target search costs for criminals.

Data breaches are becoming an important entry point for real-world attacks

The methods attackers use to find targets are also changing: in the past, criminals relied more on public information from social media, offline activities, and other means to search for high-value targets; now, attackers are starting to obtain precise client information through dark web black markets, data brokers, as well as public or corporate insiders. Public investigations show that some cases have involved internal personnel illegally selling user data.

After acquiring target profiles that include names, addresses, asset estimates, and social relationships, mid-level coordinators recruit lower-level execution personnel to implement offline control through disguising as delivery personnel, intercepting along the way, or holding false business meetings, forcing victims to complete transfers in a very short time.

Individuals and institutions need to establish a more comprehensive security defense system

In response to the continuously changing attack methods, the report advises individuals and institutions to reassess their digital asset security strategies.

For individual users, minimizing unnecessary public information disclosure and avoiding exposing the scale of assets and identity-related information are important measures to reduce the risk of becoming a target for attacks. At the same time, key assets should not be concentrated in a single wallet or controlled by a single individual, and measures such as multi-signature and multi-party computation can be implemented to reduce single point risks.

For businesses and high-value asset management institutions, the report recommends strengthening permission management to avoid excessive concentration of critical access permissions and to implement isolation management for wallet permissions, recovery information, and important operational processes. Furthermore, businesses also need to establish emergency response mechanisms for real-world threats to address potential personal coercion or operational risks.

As attack targets gradually shift from code and systems to the asset controllers themselves, digital asset security is expanding from traditional technical protection to a broader field of operational security.

Reconstructing the protection model: offline operational security and architectural defense

In the face of threats from transnational crime networks, security agencies are promoting collaboration with law enforcement departments.

The report reveals that CertiK has launched operational security (OpSec) services covering executive personal data exposure assessments, internal system penetration testing, and compliance reviews, which can assist high-risk individuals and company executives in identifying potential exposure risks related to sensitive information such as identity, family, residence, and travel trajectories, and assess the potential risks that could be exploited by attackers, while helping companies meet compliance requirements for operational resilience and business continuity under regulatory frameworks like VARA, DORA, and MiCA. On the other hand, as an important supplement to security management, the CertiK Security Workspace platform provides deep relational analysis between off-chain intelligence, on-chain transaction flows, and anti-money laundering (AML) risk signals, helping organizations track and attribute cybercrime in real time to quickly identify evidentiary clues that have investigative value.

The report also mentions that CertiK will continue to establish closer cooperation with international law enforcement agencies, including Interpol and Europol, providing real-time threat intelligence and risk monitoring support through CertiK security tools, and offering technical support for significant cross-border attack incidents, related investigations, and security policy research through expert resources.

As attackers continually break through traditional technical boundaries, protecting the asset controllers themselves will become an important component of digital asset security.

Report link: https://indd.adobe.com/view/34999f45-b459-4eec-a889-26e0e0886ba6

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink