CertiK Releases Skynet Report: 'Wrench Attacks' Surge 75% in 2025, Physical Violence Becomes Major Threat in Crypto Space

marsbit发布于2026-03-31更新于2026-03-31

文章摘要

CertiK's Skynet Report reveals a 75% surge in "wrench attacks" in 2025, where physical violence, kidnapping, or intimidation is used to force cryptocurrency holders to surrender private keys or passwords. These attacks, which bypass technical defenses to target individuals directly, resulted in over $40.9 million in confirmed losses—a 44% year-on-year increase. Europe emerged as the highest-risk region, accounting for over 40% of incidents, with France recording the most cases. The report highlights a trend toward increased violence, with physical assaults rising by 250%, and notes that attacks are becoming more organized, often executed by transnational criminal groups using OSINT, signal jammers, and Faraday bags. Targets have broadened from high-value individuals like executives to ordinary holders and their families. CertiK warns that the actual scale of such attacks is likely underestimated due to low reporting rates. Recommendations include using decoy wallets, geographic separation of seed phrases, multisig mechanisms, and comprehensive security training for individuals and organizations. The study underscores that protecting people, not just assets, is critical as wrench attacks become a structured threat in the crypto ecosystem.

On February 2, CertiK, the world's largest Web3 security company, released the "Skynet Wrench Attack Report," pointing out that physical violence against cryptocurrency holders has evolved from extreme isolated cases into a structural risk. As the security protection of crypto assets continues to strengthen, this method of attack, which bypasses technical defenses and directly targets the "person," is spreading rapidly.

The report shows that in 2025, a total of 72 verified wrench attack incidents were recorded globally, an increase of 75% compared to 2024. So-called "wrench attacks" refer to attackers using physical means such as violence, intimidation, or kidnapping to force victims to hand over private keys or passwords. These attacks do not rely on technical vulnerabilities but directly target the individuals behind the crypto assets.

Significant Escalation in Violence, Europe Becomes High-Risk Region

In terms of attack patterns, wrench attacks in 2025 showed a clear trend of escalating violence. The report notes that kidnapping remains the primary attack method, with 25 incidents occurring throughout the year; direct physical assault incidents increased by 250% year-on-year, becoming one of the most noteworthy changes.

Geographically, Europe became the highest-risk region globally for the first time. In 2025, Europe accounted for over 40% of known global incidents, with France recording the highest number of attacks worldwide, surpassing the United States. CertiK noted in the report that this change does not mean that risks in North America have disappeared but reflects that such crimes are spreading to more regions with complex judicial environments and higher cross-border collaboration costs.

Losses Exceed $40 Million, True Scale Likely Severely Underestimated

In terms of financial impact, confirmed losses related to wrench attacks in 2025 exceeded $40.9 million, a 44% increase year-on-year. However, the report warns that this figure is only the "tip of the iceberg" due to factors such as victims' low willingness to report incidents, fear of retaliation, and some assets being involved in tax evasion or gray areas.

By comparing attack patterns, the report found that wrench attacks in 2025 have completely moved away from the early opportunistic and fragmented characteristics and entered a stage of professionalized and industrialized operation. Attackers mostly exist as transnational criminal groups, often preparing for weeks before an attack, using open-source intelligence (OSINT) to analyze the target's digital traces, identify weak defense periods, and even deploy professional equipment such as signal jammers and Faraday bags to cut off the victim's contact with the outside world.

Notably, the targets of attackers are broadening. Although industry executives and project founders remain high-value targets, attackers are now also targeting individuals with smaller holdings. Additionally, attackers are increasingly leveraging "associated targets," applying psychological pressure by threatening the victim's spouse, children, or parents.

How to Respond to Physical Threats? Security Recommendations for Individuals and Institutions

As technical security standards continue to improve, "cracking the system" is becoming increasingly difficult, while "coercing the individual" is cheaper and more efficient. This paradox makes personal safety the weakest and most overlooked link in the current crypto ecosystem.

The report proposes a series of security recommendations for individuals and institutions: At the individual level, it is recommended to reduce coercion losses through "decoy wallets," geographically isolate seed phrase storage, and remove encryption applications from daily devices to minimize risk; at the institutional level, it emphasizes the use of technical measures such as multi-signature mechanisms, time-lock contracts, and transaction friction mechanisms, while extending security training to family members and employees.

CertiK emphasized in the report's conclusion that the situation in 5 indicates that wrench attacks have become an independent type of crime within the crypto ecosystem, and the security model relying solely on seed phrases can no longer cope with the risks. How to upgrade from "protecting assets" to "protecting people" and reduce the feasibility of coercive behavior through institutional design may become a key proposition for the industry's future development.

Report link: https://indd.adobe.com/view/6399f4eb-e37c-485d-a225-a7a1fc68914f

热门币种推荐

相关问答

QWhat is the main finding of CertiK's 'Skynet Wrench Attack Report' regarding physical violence in the crypto space?

AThe report found that physical violence against cryptocurrency holders has evolved from isolated extreme cases into a structural risk, with a 75% increase in verified wrench attacks globally in 2025 compared to 2024.

QWhat is a 'wrench attack' as defined in the CertiK report?

AA 'wrench attack' is an attack where perpetrators use physical means such as violence, intimidation, or kidnapping to force victims to hand over their private keys or passwords, bypassing technical defenses to target the individual directly.

QWhich region became the highest-risk area for wrench attacks in 2025, and what was a key reason for this shift?

AEurope became the highest-risk area, accounting for over 40% of global known incidents, with France recording the highest number of attacks. This shift reflects that such crimes are spreading to regions with more complex judicial environments and higher cross-border collaboration costs.

QWhat was the total confirmed financial loss from wrench attacks in 2025, and why does the report suggest this figure is a significant underestimate?

AThe total confirmed financial loss was over $40.9 million, a 44% year-on-year increase. However, the report warns this is likely a severe underestimate' due to low victim reporting rates, fear of retaliation, and some assets being involved in tax evasion or gray areas.

QWhat are some of the key security recommendations provided in the report for individuals to protect against wrench attacks?

AKey recommendations for individuals include using 'decoy wallets' to minimize losses during coercion, geographically isolating the storage of seed phrases, and removing encryption applications from daily devices to reduce risk.

你可能也喜欢

如何让自己变得让人工智能永远也无法取代

面对人工智能的冲击,许多人担心工作被取代。然而,真正的威胁在于个人对他人和系统的依赖,以及由此产生的“薪资奴役”——即为生存而从事无意义、枯燥的工作。摆脱这种困境的关键,不是抵制技术,而是成为拥有高自主性的“不可受雇”个体。 文章提出了成功抵御AI替代的五个核心要素:自主性(主动行动的能力)、品味(判断事物价值的经验)、说服力(让他人关注你工作的能力)、毅力(坚持并从错误中学习)和迭代(根据反馈持续改进)。这些能力无法仅通过理论学习获得,必须通过实践来培养。 要启动转变,首先要彻底改变环境,重塑身份认同。其次,应选择一个能获得真实、快速反馈的实践领域,例如创业。在众多技能中,内容创作(媒体)比编写代码更具优势,因为其价值是主观的,需要独特的审美和判断力,这正是AI目前难以完全复制的。 具体行动上,可以从三个步骤开始: 1. **挖掘原始素材**:反思自己长期痴迷的知识领域、轻松解决的难题或童年被压抑的兴趣,找到独特的个人经验。 2. **确立反向思考主轴**:找出你坚信但主流观点错误的地方,或行业内普遍忽视的“皇帝新衣”,形成独特的批判性视角。 3. **立即发布**:将前两步的思考融合,撰写并发布第一个核心内容(如帖子、视频),勇敢接受真实世界的反馈,并在此基础上持续学习和迭代。 最终,抵御AI的关键在于构建一份与自身身份深度契合的毕生事业,通过持续的内容创作和真实互动,建立无法被自动化取代的独特价值和影响力。行动,从今天发布第一个想法开始。

marsbit37分钟前

如何让自己变得让人工智能永远也无法取代

marsbit37分钟前

通过掷骰子离线保管比特币密钥:并非人人愿意为之

文章探讨了通过投掷骰子生成比特币钱包种子短语的安全方法及其现实挑战。核心观点如下: **1. 骰子提供物理熵源** 骰子结果由众多微小变量决定,理论上虽可预测,但实践中无法被攻击者复制或计算,从而提供高质量的随机性。每个六面骰子投掷约产生2.585比特熵,50次投掷即可满足典型12词助记词(128比特熵)的安全需求。 **2. Coldcard漏洞事件凸显手工熵源的价值** 近期Coldcard硬件钱包因固件漏洞导致其内部随机数生成器存在缺陷,致使约1128枚比特币被盗。但那些**完全**通过足量骰子投掷生成种子短语的用户未受此漏洞影响,因为他们的主密钥未使用有缺陷的生成器。 **3. 重要警示:手工种子并非万能保护** 安全研究员指出,即使用户使用骰子生成了安全的种子,若他们使用了Coldcard的其他功能(如生成纸钱包、克隆密钥、共享签名密钥、密码等),这些**衍生密钥**仍可能调用有漏洞的随机数生成器,从而存在风险。安全种子不保证设备生成的所有秘密都安全。 **4. 手工生成熵源的现实局限性** 尽管数学上可靠,但该方法对大多数用户并不友好: * **过程繁琐易错**:需投掷50-99次,精确记录,任何输入错误都会导致钱包完全不同。 * **引入新风险**:用户可能在记录、转换过程中泄露信息,或使用有偏的骰子/投掷方式。 * **用户体验差**:难以想象大规模推广需要用户手动投掷近百次骰子。安全措施需适应现实生活场景和普通用户的知识水平。 **5. 给用户的建议** 受影响的Coldcard用户应: * 更新固件至最新版。 * 检查是否使用过有漏洞的功能生成了次级密钥或密码,如有则需立即更换。 * 考虑采用多签方案,使用不同厂商的设备分散风险。 **结论**:手工投掷骰子生成熵源是技术娴熟用户的一个有效安全选项,但其过程复杂、容易出错,不适合作为主流用户的默认方法。长远目标是依赖安全、透明且无需专业知识的硬件/软件随机数生成方案。

cryptonews.ru3小时前

通过掷骰子离线保管比特币密钥:并非人人愿意为之

cryptonews.ru3小时前

交易

现货

热门文章

如何购买S

欢迎来到HTX.com!我们已经让购买Sonic(S)变得简单而便捷。跟随我们的逐步指南,放心开始您的加密货币之旅。第一步:创建您的HTX账户使用您的电子邮件、手机号码注册一个免费账户在HTX上。体验无忧的注册过程并解锁所有平台功能。立即注册第二步:前往买币页面,选择您的支付方式信用卡/借记卡购买:使用您的Visa或Mastercard即时购买Sonic(S)。余额购买:使用您HTX账户余额中的资金进行无缝交易。第三方购买:探索诸如Google Pay或Apple Pay等流行支付方法以增加便利性。C2C购买:在HTX平台上直接与其他用户交易。HTX场外交易台(OTC)购买:为大量交易者提供个性化服务和竞争性汇率。第三步:存储您的Sonic(S)购买完您的Sonic(S)后,将其存储在您的HTX账户钱包中。您也可以通过区块链转账将其发送到其他地方或者用于交易其他加密货币。第四步:交易Sonic(S)在HTX的现货市场轻松交易Sonic(S)。访问您的账户,选择您的交易对,执行您的交易,并实时监控。HTX为初学者和经验丰富的交易者提供了友好的用户体验。

3.3k人学过发布于 2025.01.15更新于 2026.06.02

如何购买S

相关讨论

欢迎来到HTX社区。在这里,您可以了解最新的平台发展动态并获得专业的市场意见。以下是用户对S(S)币价的意见。

活动图片