What happened
CertiK counted roughly $124. 1 million in ransom demands and outright losses from physical attacks on crypto holders during the first half of 2026, per its H1 2026 security tally. Incident volume jumped about 20 times year-over-year.
CryptoSlate first surfaced the numbers on Friday. The firm was explicit that the headline figure measures exposure, meaning the sum criminals demanded plus what victims reported losing, rather than net criminal profit. Actual take is smaller and harder to pin down: some victims refused to pay, some assets transferred under duress were later frozen, and several cases remain open.
That distinction matters. It's the difference between a threat surface and a P&L.
Why it matters
The 20x jump validates a threat model self-custody advocates have flagged for years. On-chain wealth is searchable. That searchability creates a targeting funnel.
The industry uses the term wrench attack, a nod to the xkcd comic where a $5 wrench defeats any cryptographic scheme, and CertiK's methodology suggests the joke is now a category. If the H1 rate holds through H2, wrench attacks graduate from a niche horror story into a persistent risk line alongside exchange hacks and smart contract exploits. Custody providers, hardware wallet vendors, and personal security firms with a crypto specialty all get a fresh data point to sell against.
Insurance underwriters will be reading the same report.
Market impact
There's no ticker that trades on wrench statistics, and none of the majors flinched on the CertiK release. The read-through is structural, not tape-driven. Institutional custodians pitching cold storage get an easier sales conversation.
