CertiK Releases Skynet Report: 'Wrench Attacks' Surge 75% in 2025, Physical Violence Becomes Major Threat in Crypto Space

marsbitPublished on 2026-03-31Last updated on 2026-03-31

Abstract

CertiK's Skynet Report reveals a 75% surge in "wrench attacks" in 2025, where physical violence, kidnapping, or intimidation is used to force cryptocurrency holders to surrender private keys or passwords. These attacks, which bypass technical defenses to target individuals directly, resulted in over $40.9 million in confirmed losses—a 44% year-on-year increase. Europe emerged as the highest-risk region, accounting for over 40% of incidents, with France recording the most cases. The report highlights a trend toward increased violence, with physical assaults rising by 250%, and notes that attacks are becoming more organized, often executed by transnational criminal groups using OSINT, signal jammers, and Faraday bags. Targets have broadened from high-value individuals like executives to ordinary holders and their families. CertiK warns that the actual scale of such attacks is likely underestimated due to low reporting rates. Recommendations include using decoy wallets, geographic separation of seed phrases, multisig mechanisms, and comprehensive security training for individuals and organizations. The study underscores that protecting people, not just assets, is critical as wrench attacks become a structured threat in the crypto ecosystem.

On February 2, CertiK, the world's largest Web3 security company, released the "Skynet Wrench Attack Report," pointing out that physical violence against cryptocurrency holders has evolved from extreme isolated cases into a structural risk. As the security protection of crypto assets continues to strengthen, this method of attack, which bypasses technical defenses and directly targets the "person," is spreading rapidly.

The report shows that in 2025, a total of 72 verified wrench attack incidents were recorded globally, an increase of 75% compared to 2024. So-called "wrench attacks" refer to attackers using physical means such as violence, intimidation, or kidnapping to force victims to hand over private keys or passwords. These attacks do not rely on technical vulnerabilities but directly target the individuals behind the crypto assets.

Significant Escalation in Violence, Europe Becomes High-Risk Region

In terms of attack patterns, wrench attacks in 2025 showed a clear trend of escalating violence. The report notes that kidnapping remains the primary attack method, with 25 incidents occurring throughout the year; direct physical assault incidents increased by 250% year-on-year, becoming one of the most noteworthy changes.

Geographically, Europe became the highest-risk region globally for the first time. In 2025, Europe accounted for over 40% of known global incidents, with France recording the highest number of attacks worldwide, surpassing the United States. CertiK noted in the report that this change does not mean that risks in North America have disappeared but reflects that such crimes are spreading to more regions with complex judicial environments and higher cross-border collaboration costs.

Losses Exceed $40 Million, True Scale Likely Severely Underestimated

In terms of financial impact, confirmed losses related to wrench attacks in 2025 exceeded $40.9 million, a 44% increase year-on-year. However, the report warns that this figure is only the "tip of the iceberg" due to factors such as victims' low willingness to report incidents, fear of retaliation, and some assets being involved in tax evasion or gray areas.

By comparing attack patterns, the report found that wrench attacks in 2025 have completely moved away from the early opportunistic and fragmented characteristics and entered a stage of professionalized and industrialized operation. Attackers mostly exist as transnational criminal groups, often preparing for weeks before an attack, using open-source intelligence (OSINT) to analyze the target's digital traces, identify weak defense periods, and even deploy professional equipment such as signal jammers and Faraday bags to cut off the victim's contact with the outside world.

Notably, the targets of attackers are broadening. Although industry executives and project founders remain high-value targets, attackers are now also targeting individuals with smaller holdings. Additionally, attackers are increasingly leveraging "associated targets," applying psychological pressure by threatening the victim's spouse, children, or parents.

How to Respond to Physical Threats? Security Recommendations for Individuals and Institutions

As technical security standards continue to improve, "cracking the system" is becoming increasingly difficult, while "coercing the individual" is cheaper and more efficient. This paradox makes personal safety the weakest and most overlooked link in the current crypto ecosystem.

The report proposes a series of security recommendations for individuals and institutions: At the individual level, it is recommended to reduce coercion losses through "decoy wallets," geographically isolate seed phrase storage, and remove encryption applications from daily devices to minimize risk; at the institutional level, it emphasizes the use of technical measures such as multi-signature mechanisms, time-lock contracts, and transaction friction mechanisms, while extending security training to family members and employees.

CertiK emphasized in the report's conclusion that the situation in 5 indicates that wrench attacks have become an independent type of crime within the crypto ecosystem, and the security model relying solely on seed phrases can no longer cope with the risks. How to upgrade from "protecting assets" to "protecting people" and reduce the feasibility of coercive behavior through institutional design may become a key proposition for the industry's future development.

Report link: https://indd.adobe.com/view/6399f4eb-e37c-485d-a225-a7a1fc68914f

Related Questions

QWhat is the main finding of CertiK's 'Skynet Wrench Attack Report' regarding physical violence in the crypto space?

AThe report found that physical violence against cryptocurrency holders has evolved from isolated extreme cases into a structural risk, with a 75% increase in verified wrench attacks globally in 2025 compared to 2024.

QWhat is a 'wrench attack' as defined in the CertiK report?

AA 'wrench attack' is an attack where perpetrators use physical means such as violence, intimidation, or kidnapping to force victims to hand over their private keys or passwords, bypassing technical defenses to target the individual directly.

QWhich region became the highest-risk area for wrench attacks in 2025, and what was a key reason for this shift?

AEurope became the highest-risk area, accounting for over 40% of global known incidents, with France recording the highest number of attacks. This shift reflects that such crimes are spreading to regions with more complex judicial environments and higher cross-border collaboration costs.

QWhat was the total confirmed financial loss from wrench attacks in 2025, and why does the report suggest this figure is a significant underestimate?

AThe total confirmed financial loss was over $40.9 million, a 44% year-on-year increase. However, the report warns this is likely a severe underestimate' due to low victim reporting rates, fear of retaliation, and some assets being involved in tax evasion or gray areas.

QWhat are some of the key security recommendations provided in the report for individuals to protect against wrench attacks?

AKey recommendations for individuals include using 'decoy wallets' to minimize losses during coercion, geographically isolating the storage of seed phrases, and removing encryption applications from daily devices to reduce risk.

Related Reads

Warsh Hearing Concludes: What Are the Notable Signals for the Crypto Industry?

The Senate Banking Committee held a confirmation hearing for Judy Shelton, a Federal Reserve nominee, who faced intense questioning regarding her ability to maintain the central bank's independence amid pressure from President Trump to lower interest rates. Shelton denied any pre-arranged commitments on rate cuts and emphasized her independence, though Democrats remained skeptical, citing contradictions with Trump's public statements. Shelton characterized post-pandemic inflation as a major policy failure and called for a "regime change" in the Fed’s approach, including reforms to inflation measurement and communication strategies. She criticized the current practice of Fed officials frequently signaling future rate moves and did not commit to maintaining post-meeting press conferences, suggesting potential reductions in transparency. Regarding crypto markets, Shelton’s extensive investments in digital asset companies—including Solana, DeFi, and blockchain infrastructure—were noted, though she has pledged to divest these holdings due to ethics rules. Her familiarity with the crypto industry and deregulatory leanings may signal a more open, though cautious, stance toward digital assets. However, concerns were raised about potential conflicts of interest, especially given Trump family involvement in crypto-financial ventures. The timing of her confirmation remains uncertain, pending a Justice Department investigation into current Chair Powell. Shelton’s potential leadership could lead to a more hawkish, productivity-focused Fed with tighter policy communication—factors that may significantly influence liquidity conditions and macro narratives for crypto markets.

marsbit4h ago

Warsh Hearing Concludes: What Are the Notable Signals for the Crypto Industry?

marsbit4h ago

Trading

Spot
Futures

Hot Articles

Discussions

Welcome to the HTX Community. Here, you can stay informed about the latest platform developments and gain access to professional market insights. Users' opinions on the price of S (S) are presented below.

活动图片