Wrench Attack Success Rate: How Often Does the Wrench Actually Work?
The short version
We coded every incident on the public physical attacks against Bitcoin holders list maintained by Jameson Lopp, from the first entry in December 2014 through September 29, 2026. That is 363 documented wrench attacks: kidnappings, home invasions, and other physical coercion like muggings, drugged trade partners, and ambushed over-the-counter deals.
- Attackers walked away with funds in 183 of 363 cases (50%). Counting only the 266 cases where the outcome is known, the success rate is 69%.
- Kidnappings succeed 42% of the time overall, 65% when the outcome is known. Of 139 kidnappings, attackers obtained funds in 59. Kidnapping is the hardest attack to pull off and the one most likely to fail.
- Recovery is almost nonexistent. In only 2 of 183 successful thefts were funds verified recovered (1.1%). Once the crypto moves, it is gone.
- 2025 and 2026 match an independent dataset. Chainalysis reports 49% attacker success in 2025 and 26% in the first half of 2026. Our numbers: 49.4% in 2025, 21.9% so far in 2026.
The takeaway is blunt. If someone puts a wrench to you, they win about half the time. Your job is to make sure the wrench gets them nothing.
Where the numbers come from
Lopp’s list is the most complete public record of physical attacks on crypto holders. It is not comprehensive. Many attacks never make the news. But 363 cases over almost 12 years is the best dataset that exists, and it is the one everyone cites.
We read every entry and coded each incident three ways:
- Attack type. K for kidnapping (including being held captive at home). HI for home invasion with no confinement. O for everything else: muggings, trade ambushes, drugging, fake police, stolen ATMs and mining hardware.
- Did the attacker get funds? Yes, no, or unknown. Funds means crypto, cash, or hardware with resale value. Most press coverage stops after the arrest, so 97 cases have no reported outcome.
- Were funds recovered? Counted only when verified in a source. An arrest is not a recovery.
Then we cross-checked against Chainalysis research, which tracks the same phenomenon from on-chain data. Their success rates land within a point of ours for 2025 and within a few points for 2026. Two independent methods, same answer. That is rare in this space.
What the numbers say
Here is the full year-by-year picture. “Paid” means the attacker obtained funds.
| Year | Incidents | Attacker got funds | Kidnappings | Kidnappings that paid |
|---|---|---|---|---|
| 2014-2016 | 10 | 6 (60%) | 2 | 1 |
| 2017 | 12 | 9 (75%) | 3 | 3 |
| 2018 | 26 | 18 (69%) | 1 | 1 |
| 2019 | 10 | 2 (20%) | 3 | 1 |
| 2020 | 15 | 6 (40%) | 5 | 1 |
| 2021 | 36 | 25 (69%) | 6 | 3 |
| 2022 | 36 | 18 (50%) | 11 | 3 |
| 2023 | 25 | 17 (68%) | 11 | 7 |
| 2024 | 42 | 25 (60%) | 20 | 10 |
| 2025 | 87 | 43 (49%) | 46 | 20 |
| 2026* | 64 | 14 (22%) | 31 | 9 |
* 2026 covers January 1 through September 29 only.
Three patterns stand out.
First, kidnappings fail more than any other attack type. Across all 363 incidents, attackers obtained funds in 42% of kidnappings versus 55% of non-kidnappings. Among known outcomes, kidnappings paid 65% of the time versus 71% for everything else. Kidnapping is logistically hard. Victims fight back, bystanders intervene, police respond. 32 of 139 kidnappings ended with the attacker getting nothing.
Second, the 2026 drop in attacker success is real but misleading. Only 22% of 2026 attacks paid out, down from 49% in 2025. That is mostly because France exploded with kidnapping attempts, and most of them failed or are still unresolved. 31 of the 64 2026 incidents are kidnappings, many from the French wave, and 48% of kidnappings have unknown outcomes. The drop says more about reporting lag and failed attempts than about attackers getting worse.
Third, home invasions are the reliable payday. Of 95 home invasions, the attacker obtained funds in most known cases. You are asleep, your hardware wallet is in the drawer, your seed is in the safe. The wrench works because everything is in one place.
The recovery numbers: 2 out of 183
This is the number that should change your planning. Of 183 successful thefts, we found exactly 2 verified cases of funds coming back.
David Balland, January 2025. The Ledger co-founder and his wife were abducted in France. Part of the ransom was paid in crypto, then most of it was frozen and seized with help from Tether before the attackers could cash out. Balland was rescued by French police. Recovery happened because the ransom sat still long enough to be frozen.
Malacca, Malaysia, April 2026. Three South Koreans abducted a man, demanded $10M in USDT, and received $3M. The victim was rescued and most of the ransom was recovered.
Two recoveries in twelve years of data. Both involved ransoms paid in traceable stablecoins, both involved fast police work, both were kidnappings where the victim survived. If a thief drains your wallet at your kitchen table and mixes the coins, there is no recovery story. Plan as if recovery does not exist, because statistically it barely does.
What we cannot know
These numbers describe documented incidents. They do not describe your personal risk. Be honest about the gaps.
- Selection bias. Only publicly reported cases make the list. Many attacks go unreported, especially successful ones where the victim is embarrassed or the amount is small. The true success rate is probably higher, not lower.
- Outcome-reporting bias. Press covers the attack, not the follow-up. 97 of 363 cases have unknown outcomes. Failed attacks are more newsworthy when foiled dramatically, which may inflate the failure count.
- Base rates are unknown. 363 attacks sounds small until you ask: out of how many holders? Nobody knows the denominator. You cannot turn these numbers into “my risk is X percent.”
- 2026 is partial. The list runs through September 29, 2026. Late-year cases and delayed reporting will shift the 2026 numbers.
- One row may be a duplicate. A December 2025 Spain kidnapping case may describe the same incident as an April 2025 case in southern Spain. We kept both and flagged it. Removing one would barely move the totals.
What the data can say: when attackers strike a known holder, they get paid roughly half the time, and the money almost never comes back. That is enough to act on.
What this means for your setup
The data points at one conclusion. Most successful attacks work because the victim can hand over everything on the spot. Single key, single device, seed in the house. The wrench works on that setup every time.
Split your keys. With a multisig setup, no single location holds enough keys to move funds. An attacker who finds your wallet and your seed still cannot spend. That turns a home invasion from a total loss into a failed attack. Our multisig wizard walks you through which configuration fits your situation.
Separate where keys live from where you live. 95 home invasions in the dataset, most of them paid out. If all your keys and backups are in your house, the attacker only needs your house. Geographic separation is the cheapest defense in this dataset.
Your seed phrase alone is not a plan. Read why seed words are not enough. In dozens of these cases the attacker got the seed and that was the whole theft.
Pick a wallet that supports the setup. Not every wallet does multisig well, and some make key separation painful. Check our wallet guide and the hardware wallet compatibility checker before you buy.
For large amounts, go colder. An air-gapped setup means there is nothing to hand over quickly. Our Bitcoin Core cold storage walkthrough shows one way to do it.
Do not advertise. A shocking share of victims were targeted after someone knew they held crypto: the trade partner, the social media post, the conference badge. Opsec is free and it works.
The wrench attack succeeds about half the time. Make your setup the kind where it succeeds zero percent of the time, because there is nothing to take.
