Cybercriminals are increasingly targeting people, not just digital wallets, as violent attacks increase globally.
According to a new report from blockchain security CertiK, which tracks cyber threats and security incidents in the digital assets industry. CertiK verified 52 physical attacks against digital asset holders globally in the first half of 2026, up 33% from the previous year. France, with 33 attacks, accounts for nearly two-thirds of publicly reported cases.
The report is based on verified and publicly reported incidents identified through law enforcement disclosures, court documents, reputable media reports, victim testimonies and, where available, on-chain evidence. Since many attacks go unreported, the numbers likely underestimate the true scale of the threat.
Criminals attack more often, going after bigger targets and reaping bigger gains. The sum of recorded losses and ransom demands amounted to approximately $124 million, compared to just $10.5 million for the same period last year, according to the report.
“The trend suggests that attackers increasingly believe that physical coercion can produce outsized profits,” the CertiK researchers wrote, adding that this has changed the “criminal economy.”
This is forcing the industry to rethink what security means in crypto. For years, the biggest concern has been protecting blockchains and private keys from hackers. Today, old operational security challenges have become paramount.
Today’s attacks combine online intelligence gathering with real-world violence, according to Ronghui Gu, co-founder of CertiK and professor of computer science at Columbia University.
“I would no longer describe this as just an attack on physical security,” Gu said in an interview. “It’s actually a combination of cyberattacks, social engineering and physical attacks.”
The most important change was the rise in power home invasions. CertiK verified 20 publicly reported cases in the first six months of the year, compared to just one in the first half of 2025.
One of these attacks in March involved a couple in Chesnay-Rocquencourt, a Paris suburb. They were beaten inside their home and forced to transfer around $1 million worth of Bitcoin. In another case in the UK, a victim was forced to return $24 million worth of crypto that was eventually converted to the privacy-focused Monero token.
Home invasions have replaced kidnappings as the fastest-growing form of crypto-related violence. Kidnappings reached 16 during this period, compared to 12 last year.
The increase in losses also indicates that criminals are becoming more selective. Attackers are spending more time gathering blockchain records, leaked customer databases, social media profiles, and public records to create detailed profiles of potential victims.
“The important thing is that criminals can now associate crypto holders with personal information such as home addresses,” Gu said. “Once they can connect these data sets, home invasion becomes possible.”
This growing sophistication has made it possible to further distinguish crypto crime from random thefts, with many incidents now involving organized crime.
A single case may involve recruiting a local team, using data brokers to provide personal information, and then transferring stolen funds to money launderers, Gu said. French investigations have also revealed cases involving minors recruited by remote organizers.
These multi-layered operations mean that even failed attacks can make economic sense for many of those involved, as physical risk is transferred to ground crews who are considered disposable.
France appears to be the epicenter of this trend for multiple reasons. The country has a significant crypto ecosystem, while also facing several major data breaches, making the location a particularly attractive target.
France also does a better job of recording incidents than other potential hotspots, according to CertiK. French authorities say the true number of attacks is significantly higher – the interior minister said attacks numbered 77 this year through June – but CertiK has limited its figures to publicly reported and independently verifiable cases.
However, meticulous record keeping can be a double-edged sword. The report notes that Europe has several jurisdictions that maintain extensive records. When data breaches occur and are combined with publicly available information, individuals can be more easily identified.
One of the biggest factors skewing the data could be that many attacks still go unreported. “Underreporting remains significant because victims may fear retaliation, reputational damage, tax exposure, or inaction by law enforcement,” CertiK said in the report.
The country with the second most verifiable number of keystroke attacks this year is the United States, with only four cases identified in the report. Sweden and the United Kingdom each had two.



























