2 Oct 2026 · @Paul
Initial, high-level considerations for protecting yourself and your family from physical coercion
Today the BBC reported on a crypto-linked home invasion in Solihull, in the West Midlands. In December 2025, three masked men forced their way into a couple’s home, beat the husband with hammers and threatened his heavily pregnant wife. Only then did they demand that he unlock his phone. A fourth man, watching on a video call, had them go through his apps until he found a crypto wallet. The threats escalated, and the husband transferred his savings, hundreds of thousands of pounds, before the attackers left.
The industry calls this a “wrench attack”. The name comes from a simple idea. You can invest heavily in encryption, hardware wallets and multi-factor authentication, but none of it matters if someone is in your home threatening your family. The attacker doesn’t break the cryptography. They break the person.
I live and work in France, and I’ve spent many years working in converged security, where physical, cyber and human risk meet. Watching this unfold, what strikes me most is not that the threat is new. It is that the answers are not.
What follows are initial, high-level thoughts rather than a security plan. Any effective security strategy has to be tailored to the needs of the individual or organisation it protects. That said, the principles below follow the way a security risk assessment would approach the problem, validated against what official agencies and other sources already say.
This is not an isolated incident
Solihull is one case among many, and the trend is escalating across several countries.
- France has become the global hotspot. The Interior Minister reported 77 crypto-linked kidnapping and extortion cases in the first half of 2026, up from 45 in the whole of 2025. Victims have included senior figures at Ledger, Binance France, The Sandbox and Paymium.
- The UK is now seeing violent robberies linked to digital assets, as Solihull shows.
- The US, Brazil and Thailand are also identified as hotspots, and US prosecutors have brought cases against organised home invasion crews.
- Canada has seen it too. A court in British Columbia heard how masked intruders held a bitcoin investor’s family hostage overnight, an ordeal that ended only when his daughter escaped.
Globally, CertiK verified 52 wrench attacks in the first half of 2026, a third more than a year earlier. Home invasions rose from a single reported case in the first half of 2025 to 20, making the home the most common setting. Chainalysis warns that 2026 is on course to be the worst year on record for violent crypto theft.
The true numbers are likely higher. Many attacks are recorded simply as robberies or home invasions, with no mention of crypto.
1. Understand how targets are chosen
Before anyone reaches for a weapon, an attacker has to answer three questions. Who has the wealth? Who are they? Where can they be found?
Break any link in that chain and you become a much harder target. That means not advertising your holdings online, keeping wallet addresses separate from your identity, and thinking carefully about what family members share, because attackers increasingly go after relatives rather than the holder.
French prosecutors have urged crypto holders to be extremely careful about their exposure on social media. It’s sound advice, but it has a limit. You control your own posts. You don’t control the customer database held by an exchange, a tax service or a hardware wallet supplier, and once that data has leaked it cannot be recalled.
So a sensible approach assumes you can be found, and asks what happens next. This is defence in depth.
2. Accept that duress beats any technical control
Multi-factor authentication assumes the person entering the code is acting freely. When your family is being threatened, you will override every control you have, and you would be right to.
The simplest mitigation is separation. The phone you carry every day should hold no wallets and no crypto apps. When attackers demand your phone and search it, which is often their first move, there should be nothing to find.
Solihull shows exactly why. The attackers knew their victim held crypto, but not how to reach it. His everyday phone gave them the answer.
There’s a refinement worth making. If you were targeted through leaked data, attackers already believe you hold crypto, and a suspiciously clean phone may not convince them. The position you can actually hold under pressure is not “I don’t have any”. It is “I can’t move it”.
Multi-signature arrangements, a trusted co-signer and time-locked withdrawals all support that position. A French prosecutor has suggested measures that slow transfers, ideally by around seven days. Banks have used this principle for decades. Time-lock safes exist so that staff can honestly say they cannot open them.
3. Buy time with physical security
Delay only works if it lasts longer than the response. The question is not whether your front door is strong, but how many minutes it buys you, and how many minutes it will take for help to arrive. In rural areas that response can take a while, so the specification has to reflect reality.
In Solihull, home security cameras recorded the whole 45-minute attack. Recording an attack is not the same as stopping it. Surveillance only helps if it triggers a response.
Layer it:
- A hardened external door, with a firm rule of verifying callers before opening. Attackers frequently pose as delivery drivers, tradespeople or police officers.
- An internal safe room where the family can shelter and where crypto devices are kept.
- Communications that don’t rely on a single landline that can be cut.
- Monitored surveillance, with alarm verification through a receiving centre so that police can prioritise the response.
The front door is your first delay. That means a security-rated door and frame, not just a stronger lock, and a way to see and speak to callers without opening it, such as a door viewer or video doorbell. Many of these attacks begin with someone at the door pretending to be a courier or a police officer, so the rule is simple. If in doubt, don’t open it.
My own suggestion goes one step further. Make the safe room the room where the family already spends its evenings, such as the lounge or TV room, ideally without accessible windows, or with lockable security shutters where there are windows.
A dedicated panic room depends on spotting the threat early and getting there in time. If you are already in the protected room when the front door is attacked, the plan is simple. Shut the door, lock it, lower the shutter and call for help.
Making the everyday room work as a safe room
A few basics turn an ordinary lounge into somewhere that buys real time.
- Choose the right room. An internal room with solid walls is best. Ideally it has no ground-floor windows, or windows that can be covered by lockable security shutters.
- Upgrade the door. Fit a solid, security-rated door and frame that locks quickly from the inside, with reinforced hinges. It should look like an ordinary door.
- Keep a way to call for help inside. A charged phone and a panic alarm linked to a monitored alarm centre, neither relying on the house landline.
- Store your crypto devices there. Hardware wallets and any device that can access your crypto should live in the safe room, not on you or around the house. Combined with multisig or a time lock, no single device in the room can move everything on its own.
- Watch from inside. A screen showing the entrances and the area just outside the room tells you what is happening and helps you brief the police.
- Don’t compromise fire safety. You still need a way out if there is a fire, and ventilation if you’re in there for a while. NPSA’s guidance stresses that one security improvement must not undermine another aspect of safety.
- Rehearse it. Everyone in the household, children included, should know the trigger, what to do and who closes the door. A plan nobody has practised rarely works under stress.
If a professional is helping you, ask them to measure the delay. The time it takes to get through the front door and then the safe room door should exceed the time it realistically takes for help to arrive.
The safe room protects people first. The devices kept in it should never be able to move everything on their own.
4. None of this is new, and that’s the point
The UK’s National Protective Security Authority (NPSA) published guidance in May 2025 on preparing and using safer areas to protect high-risk individuals. It treats a safer area as one layer of home security, measures delay as the total time needed to force entry into the property and then into the safer area, flags accessible windows as a vulnerability to address, and recommends cameras that can be monitored from inside the room.
The French Interior Ministry advises crypto holders to plan in advance how they would handle access to their assets in a situation involving physical risk, and to keep recovery phrases offline.
US court cases show the same attack chain described above. In one, a home invasion crew compromised victims’ email accounts and carried out physical surveillance before attacking.
Banks, cash-in-transit firms and executive protection teams solved most of this problem years ago. The gap isn’t technique. It’s that crypto security has largely been shaped by cyber specialists, while the threat has moved into the physical world. Cyber, physical and human security can’t keep working in separate rooms.
Crypto holders don’t need a new kind of security. They need the old kind, joined up with the new.
Going further
These are high-level thoughts, not a substitute for a proper assessment. The right answer for any household, family office or business depends on its exposure, its property, its routines and how quickly help can reach it.
If you or your organisation would like a tailored security risk assessment and protection strategy, I’m happy to talk it through. You can reach me at paul@hawksightsrm.com.
Paul Mercer MPhil CSyP, Founder, HawkSight Security Risk Management
This article was written with AI assistance.
Sources
- BBC report on the Solihull attack (syndicated)
- NPSA: The Preparation and Use of Safer Areas to Protect High-Risk Individuals
- Ministère de l’Intérieur, Ma Sécurité: renforcer la sécurité de ses cryptoactifs
- Slate.fr: PNACO prosecutor on crypto-linked kidnappings
- Cointelegraph: France reports 77 crypto wrench attacks in 2026
- Parameter: high-profile French victims
- Decrypt: CertiK H1 2026 wrench attacks report
- crypto.news: Chainalysis H1 2026 findings
- CBC: British Columbia bitcoin hostage case
- US Department of Justice: St Felix home invasion conviction
- Coin Alert News: 2026 US home invasion indictment

