In the first six months of 2025, reported physical attacks targeting cryptocurrency holders increased by 169%. The incidents include armed home invasions, kidnappings, torture, and at least one case in which a victim was held for weeks before the funds could be recovered. The perpetrators are not opportunistic criminals. They are organised, patient, well-resourced, and specifically targeting people known — or believed — to hold significant digital assets. If you are reading this, you may be one of those people.
The Changing Threat Landscape
For the first decade of Bitcoin’s existence, the primary threat to digital asset holders was technical: phishing attacks, exchange hacks, malware-infected wallets. The technical defences against these threats have matured considerably, and attackers have responded rationally by shifting to the cheapest attack vector: the human holding the keys.
Physical coercion attacks on cryptocurrency holders — colloquially known as “$5 wrench attacks” for the minimal equipment required — have evolved from unsophisticated muggings to sophisticated, research-intensive operations run by transnational criminal networks. The typical pattern now involves months of target identification and reconnaissance, coordinated multi-person operations, and willingness to deploy serious violence.
Documented incidents from 2025 illustrate the operational sophistication:
- In Minnesota, two brothers were charged with an armed kidnapping targeting a cryptocurrency holder, forcing him to transfer approximately $8 million at gunpoint over a prolonged period of captivity.
- In San Francisco, a homeowner lost $11 million after a criminal posing as a delivery driver gained entry to his property and produced a firearm. The attack was one of over 60 similar operations recorded that year in the United States.
- In France, a 23-year-old was attacked with his partner, with attackers forcing disclosure of hardware wallet credentials under threat of violence.
The perpetrators of these attacks are not guessing. They identify targets through public blockchain analytics tools that link wallet addresses to identities, social media disclosures, public company records, professional conference attendance lists, and domestic staff. The targeting is specific, deliberate, and increasingly accurate.
How Targets Are Identified
Understanding how attackers identify targets is the first step in reducing your exposure. The primary identification vectors include:
Blockchain analytics. On-chain data is public and permanently preserved. Wallet addresses associated with large holdings can often be linked to real-world identities through exchange KYC data leaks, transaction patterns, and on-chain metadata. Tools available to motivated criminals include the same analytical platforms used by regulatory agencies.
Public disclosures. Conference speaking slots, industry publication interviews, social media posts referencing digital asset holdings, and public company filings that reference cryptocurrency treasury positions all create targeting intelligence. Even indirect disclosures — a post about a hardware wallet purchase, a public celebration of a profitable trade — contribute to an attacker’s confidence in their target selection.
Professional networks. Membership in digital asset industry organisations, participation in exclusive investment communities, and professional relationships within the sector all provide targeting information to sophisticated actors. The digital asset industry’s culture of openness about holdings and strategies — useful in networking contexts — creates significant operational security risk.
Domestic and professional staff. Cleaners, nannies, drivers, personal assistants, and other domestic staff represent the single highest-risk information leak vector for high-net-worth individuals. They have regular access, observe daily routines, and may have relationships with individuals who monetise the information they inadvertently provide.
Operational Security Principles for UHNW Digital Asset Holders
Effective operational security for individuals with significant digital asset holdings requires a systematic approach across three domains: information, access, and resilience.
Information discipline. The foundational principle of operational security is that information not shared cannot be exploited. This means: no public disclosure of holdings, investment activity, or custody arrangements; careful management of social media presence to avoid signals that attract attention; and deliberate limitation of how many people in your professional and personal network know the scale of your digital asset holdings.
Geographic and structural key distribution. The most effective mitigation against physical coercion is architectural: constructing a custody arrangement in which no single person — including you — can authorise a transfer unilaterally or under duress. Multi-signature arrangements with keys held by independent parties in different jurisdictions, with time-lock mechanisms that prevent immediate transfer even with full cooperation, are the gold standard for serious holdings.
A well-constructed multi-signature arrangement means that an attacker compelling you at gunpoint cannot immediately transfer your assets. They would need to simultaneously compel multiple other parties, in multiple locations, with appropriate time delays between signing steps. This architecture converts a manageable physical security risk into an impractical operational one from the attacker’s perspective.
The stress wallet strategy. Sophisticated operators maintain a secondary, smaller wallet with a visible, plausible balance — sufficient to satisfy a coercive actor who demands access to a hardware wallet, without exposing the primary holdings. This is not deception in any meaningful legal sense; it is a security architecture decision. The stress wallet should be hardware-based, access-realistic, and contain enough value to be credible without being catastrophic if surrendered.
Travel and routine discipline. Predictable routines create predictable targeting opportunities. Varying travel routes, limiting advance disclosure of travel schedules, and avoiding public association between travel patterns and digital asset activity are all relevant precautions for individuals holding material positions.
Due diligence on domestic staff. Background verification, reference checking, and appropriate information compartmentalisation for domestic and professional staff are not optional for individuals whose household staff could inadvertently or deliberately expose their financial position to criminal actors.
Why Institutional Custody Is the Most Effective Physical Security Measure
The architecture that best protects against physical coercion attacks is, counterintuitively, the same architecture that provides the best protection against technical attacks: truly distributed, multi-institutional custody where no single individual holds sufficient key material to authorise a transfer.
When your assets are held under a 3-of-5 multi-signature arrangement with signatories in different jurisdictions, with time-lock requirements and mandatory notification periods, physical coercion of any single party — including you — cannot result in immediate asset transfer. The attacker’s risk-reward calculation changes fundamentally: the effort and legal exposure required to compel five parties across multiple jurisdictions makes the target disproportionately difficult relative to alternatives.
This is not theoretical. The incidents that make headlines almost universally involve targets who maintained unilateral access to their assets. The assets held under genuinely distributed institutional custody arrangements do not make news, because successful physical attacks against them are vanishingly rare.
The 169% increase in physical attacks in 2025 is a direct consequence of the industry’s growth in visible wealth and its continued reliance on custody architectures that concentrate access. The solution is not better locks on the door. It is ensuring that no amount of coercion at your door can transfer your assets.
CryptoVault provides comprehensive OPSEC assessments and distributes custody architecture that eliminates single-point coercion risk for UHNW digital asset holders.
Explore OPSEC Services