wrench_toolkit_blog_header

Wrench Attacks: A Basic Personal Security Toolkit for Crypto Investors

2 Oct 2026 · @Paul

Initial, high-level considerations for protecting yourself and your family from physical coercion

Today the BBC reported on a crypto-linked home invasion in Solihull, in the West Midlands. In December 2025, three masked men forced their way into a couple’s home, beat the husband with hammers and threatened his heavily pregnant wife. Only then did they demand that he unlock his phone. A fourth man, watching on a video call, had them go through his apps until he found a crypto wallet. The threats escalated, and the husband transferred his savings, hundreds of thousands of pounds, before the attackers left.

The industry calls this a “wrench attack”. The name comes from a simple idea. You can invest heavily in encryption, hardware wallets and multi-factor authentication, but none of it matters if someone is in your home threatening your family. The attacker doesn’t break the cryptography. They break the person.

I live and work in France, and I’ve spent many years working in converged security, where physical, cyber and human risk meet. Watching this unfold, what strikes me most is not that the threat is new. It is that the answers are not.

What follows are initial, high-level thoughts rather than a security plan. Any effective security strategy has to be tailored to the needs of the individual or organisation it protects. That said, the principles below follow the way a security risk assessment would approach the problem, validated against what official agencies and other sources already say.

This is not an isolated incident

Solihull is one case among many, and the trend is escalating across several countries.

  • France has become the global hotspot. The Interior Minister reported 77 crypto-linked kidnapping and extortion cases in the first half of 2026, up from 45 in the whole of 2025. Victims have included senior figures at Ledger, Binance France, The Sandbox and Paymium.
  • The UK is now seeing violent robberies linked to digital assets, as Solihull shows.
  • The US, Brazil and Thailand are also identified as hotspots, and US prosecutors have brought cases against organised home invasion crews.
  • Canada has seen it too. A court in British Columbia heard how masked intruders held a bitcoin investor’s family hostage overnight, an ordeal that ended only when his daughter escaped.

Globally, CertiK verified 52 wrench attacks in the first half of 2026, a third more than a year earlier. Home invasions rose from a single reported case in the first half of 2025 to 20, making the home the most common setting. Chainalysis warns that 2026 is on course to be the worst year on record for violent crypto theft.

The true numbers are likely higher. Many attacks are recorded simply as robberies or home invasions, with no mention of crypto.

1. Understand how targets are chosen

Before anyone reaches for a weapon, an attacker has to answer three questions. Who has the wealth? Who are they? Where can they be found?

Break any link in that chain and you become a much harder target. That means not advertising your holdings online, keeping wallet addresses separate from your identity, and thinking carefully about what family members share, because attackers increasingly go after relatives rather than the holder.

French prosecutors have urged crypto holders to be extremely careful about their exposure on social media. It’s sound advice, but it has a limit. You control your own posts. You don’t control the customer database held by an exchange, a tax service or a hardware wallet supplier, and once that data has leaked it cannot be recalled.

So a sensible approach assumes you can be found, and asks what happens next. This is defence in depth.

2. Accept that duress beats any technical control

Multi-factor authentication assumes the person entering the code is acting freely. When your family is being threatened, you will override every control you have, and you would be right to.

The simplest mitigation is separation. The phone you carry every day should hold no wallets and no crypto apps. When attackers demand your phone and search it, which is often their first move, there should be nothing to find.

Solihull shows exactly why. The attackers knew their victim held crypto, but not how to reach it. His everyday phone gave them the answer.

There’s a refinement worth making. If you were targeted through leaked data, attackers already believe you hold crypto, and a suspiciously clean phone may not convince them. The position you can actually hold under pressure is not “I don’t have any”. It is “I can’t move it”.

Multi-signature arrangements, a trusted co-signer and time-locked withdrawals all support that position. A French prosecutor has suggested measures that slow transfers, ideally by around seven days. Banks have used this principle for decades. Time-lock safes exist so that staff can honestly say they cannot open them.

3. Buy time with physical security

Delay only works if it lasts longer than the response. The question is not whether your front door is strong, but how many minutes it buys you, and how many minutes it will take for help to arrive. In rural areas that response can take a while, so the specification has to reflect reality.

In Solihull, home security cameras recorded the whole 45-minute attack. Recording an attack is not the same as stopping it. Surveillance only helps if it triggers a response.

Layer it:

  • A hardened external door, with a firm rule of verifying callers before opening. Attackers frequently pose as delivery drivers, tradespeople or police officers.
  • An internal safe room where the family can shelter and where crypto devices are kept.
  • Communications that don’t rely on a single landline that can be cut.
  • Monitored surveillance, with alarm verification through a receiving centre so that police can prioritise the response.

The front door is your first delay. That means a security-rated door and frame, not just a stronger lock, and a way to see and speak to callers without opening it, such as a door viewer or video doorbell. Many of these attacks begin with someone at the door pretending to be a courier or a police officer, so the rule is simple. If in doubt, don’t open it.

My own suggestion goes one step further. Make the safe room the room where the family already spends its evenings, such as the lounge or TV room, ideally without accessible windows, or with lockable security shutters where there are windows.

A dedicated panic room depends on spotting the threat early and getting there in time. If you are already in the protected room when the front door is attacked, the plan is simple. Shut the door, lock it, lower the shutter and call for help.

Making the everyday room work as a safe room

A few basics turn an ordinary lounge into somewhere that buys real time.

  • Choose the right room. An internal room with solid walls is best. Ideally it has no ground-floor windows, or windows that can be covered by lockable security shutters.
  • Upgrade the door. Fit a solid, security-rated door and frame that locks quickly from the inside, with reinforced hinges. It should look like an ordinary door.
  • Keep a way to call for help inside. A charged phone and a panic alarm linked to a monitored alarm centre, neither relying on the house landline.
  • Store your crypto devices there. Hardware wallets and any device that can access your crypto should live in the safe room, not on you or around the house. Combined with multisig or a time lock, no single device in the room can move everything on its own.
  • Watch from inside. A screen showing the entrances and the area just outside the room tells you what is happening and helps you brief the police.
  • Don’t compromise fire safety. You still need a way out if there is a fire, and ventilation if you’re in there for a while. NPSA’s guidance stresses that one security improvement must not undermine another aspect of safety.
  • Rehearse it. Everyone in the household, children included, should know the trigger, what to do and who closes the door. A plan nobody has practised rarely works under stress.

If a professional is helping you, ask them to measure the delay. The time it takes to get through the front door and then the safe room door should exceed the time it realistically takes for help to arrive.

The safe room protects people first. The devices kept in it should never be able to move everything on their own.

4. None of this is new, and that’s the point

The UK’s National Protective Security Authority (NPSA) published guidance in May 2025 on preparing and using safer areas to protect high-risk individuals. It treats a safer area as one layer of home security, measures delay as the total time needed to force entry into the property and then into the safer area, flags accessible windows as a vulnerability to address, and recommends cameras that can be monitored from inside the room.

The French Interior Ministry advises crypto holders to plan in advance how they would handle access to their assets in a situation involving physical risk, and to keep recovery phrases offline.

US court cases show the same attack chain described above. In one, a home invasion crew compromised victims’ email accounts and carried out physical surveillance before attacking.

Banks, cash-in-transit firms and executive protection teams solved most of this problem years ago. The gap isn’t technique. It’s that crypto security has largely been shaped by cyber specialists, while the threat has moved into the physical world. Cyber, physical and human security can’t keep working in separate rooms.

Crypto holders don’t need a new kind of security. They need the old kind, joined up with the new.

Going further

These are high-level thoughts, not a substitute for a proper assessment. The right answer for any household, family office or business depends on its exposure, its property, its routines and how quickly help can reach it.

If you or your organisation would like a tailored security risk assessment and protection strategy, I’m happy to talk it through. You can reach me at paul@hawksightsrm.com.

Paul Mercer MPhil CSyP, Founder, HawkSight Security Risk Management

This article was written with AI assistance.

Sources

hybrid-conflict-blog-hero

War, crime or terrorism? Hostile state acts need a name, and a plan

Paul Mercer MPhil CSyP · 28 Sept 2026

In the early hours of Sunday morning, police received a report of three suspicious vehicles heading towards RAF Fairford. One local resident has described finding the road blocked by three vans and a group of hooded, masked men, who ran when they saw her. Five men were arrested, first on suspicion of explosives offences and then on suspicion of preparing a terrorist act. Around 85 households were evacuated while Army bomb disposal teams examined the vehicles.

Fairford isn’t just any airfield. It hosts US heavy bombers and has been used for operations against Iran since February. In July, Iran’s Revolutionary Guard publicly warned Britain that any base used against Iranian territory was a legitimate target. ITV News reports that one line of inquiry is whether representatives of the Iranian regime paid others to carry out the plot on their behalf. At the time of writing, no connection has been confirmed; the five men remain in custody, and it’s right that we let investigators establish the facts.

But whatever they find, the incident exposes a problem I’ve been thinking about for some time, and which clearly resonates with many of you, judging by the discussion on my recent posts.

An academic argument with practical consequences

When I argued that we are, in effect, at war with states using hybrid methods against the UK, I was rightly challenged on the word “war”. War has a legal meaning, and using it loosely carries real risk, not least the risk of escalation with nuclear-armed states.

So let me come at it from a different direction.

What is the difference between a state-sponsored terrorist act and an act of war? The objective is often identical: to coerce another country into changing its behaviour. Clausewitz described war as the continuation of policy by other means, and a proxy with a van full of explosives is simply another means.

The real difference isn’t the implement. It’s the rulebook each one triggers.

An act of war falls under the laws of armed conflict and can justify a state-level response. An act of terrorism is treated as a crime, handled by the police and the courts. The first can reach the state that ordered it. The second, in practice, reaches the people who were caught holding the tools.

That distinction can look academic, but it decides who is allowed to respond, and how.

Choosing the box you land in

Hostile states understand this better than we do. If you want to pressure the UK without paying a state-level price, you don’t send your own forces. You recruit criminals or sympathisers, often online and often for modest sums, and you make sure the act looks like arson, vandalism or terrorism. Once it lands in the criminal box, the proxy is arrested and prosecuted, and the state that directed it pays nothing.

We’ve already seen this pattern. In 2025, men recruited on behalf of Russia’s Wagner Group were convicted over an arson attack on a London warehouse storing equipment bound for Ukraine. The organisers were the first people convicted under the National Security Act 2023. MI5’s Director General has said publicly that Iran, like the Russian services, makes extensive use of criminals as proxies, and in 2025 he reported more than twenty potentially lethal Iran-backed plots in a single year. Different states, same method.

Put simply, we’ve built a system for catching the hand, not the head.

The National Security Act 2023 was a genuine step forward, creating offences for foreign-directed sabotage and interference. But it still works at the level of the individual. It punishes the proxy more effectively without changing the calculation for the state behind them.

A third category

This is where Kenneth Smart’s challenge changed my thinking. Framing these acts as war, within the current framework, does risk rapid escalation, and that’s a serious concern. But the answer can’t be to fall back on treating them as ordinary crime when they are clearly state-directed.

I think we need a third category: hostile state acts below the threshold of armed conflict, with rules of their own.

We already have the tools. Diplomatic expulsions, targeted sanctions, asset freezes, proportionate cyber operations and, under international law, lawful countermeasures against a state that has committed a wrongful act. What we lack is a framework that says when they’ll be used.

We already do this for threats we have defined. When the national terrorism threat level changes, nobody improvises. The level is published, and the protective measures that follow it are planned in advance. Hostile state acts deserve the same treatment. Whatever we choose to call them, they need to become policy, with responses agreed before the next incident rather than after it.

Salisbury in 2018 shows it can be done. The government attributed the attack to Russia on a “highly likely” intelligence assessment, rather than waiting for a conviction, and responded at state level alongside its allies. The problem is that the response was built after the fact, and ad hoc responses deter very little.

A proper framework would do three things.

First, define what a hostile state act is, so that incidents are assessed as part of a campaign rather than one at a time.

Second, set a published standard for attribution, a high-confidence assessment rather than proof beyond reasonable doubt, which runs alongside any criminal investigation instead of waiting for it.

Third, declare the kinds of proportionate, graduated response a state can expect when that threshold is met.

The honest counterargument is that publishing a threshold tells an adversary exactly where to stop. That’s a real risk. But I’d argue the current position is worse, because right now there is no threshold at all, and the fog of uncertainty is doing our adversaries’ work for them.

Why this matters beyond defence

Businesses are already on this battlefield. Critical infrastructure, defence supply chains and the companies around them are obvious targets, but anyone whose disruption creates pressure is in scope. Organisations can’t plan properly against a threat their own government hasn’t defined, and a clear national framework would give security leaders something concrete to assess risk against and to explain to their boards.

I don’t claim to have all the answers, and I’d genuinely welcome challenge. Is a third category the right approach? And if it is, where would you set the threshold?


A note of thanks

I’d like to thank everyone who took the time to respond to my recent posts on this subject. The volume and quality of the discussion made it clear this is something that matters to many of us working in security, defence and resilience.

In particular, I’d like to thank Kenneth Smart, whose thoughtful academic input on the challenges of framing these acts as war made me think harder about the problem. His challenge is a large part of why this piece explores a third category of conflict, rather than simply arguing that we are at war.

A note on how this was written

These are my own views, shaped by that discussion. I used AI to help research and draft this piece, mainly so that I could get it out while the conversation is still live and people are still engaged with it. It has also helped me organise my thinking and put it across more clearly. The arguments, and any errors, are mine.

truro_martyns_law_featured_1200x628

Martyn’s Law and Truro’s cancelled Bonfire Night: what it really tells us

Truro City Council has cancelled its Bonfire Night and fireworks display for the second year in a row.

With up to 5,000 people expected, the council treated the event as Enhanced Tier under Martyn’s Law. After a summer of planning around venue, road closures, ticketed entry and crowd management, it concluded the event couldn’t be staged safely within budget while keeping tickets affordable.

It’s a disappointing outcome for the community. I suspect it won’t be the last decision of its kind as councils and community groups plan their winter events.

So it’s worth slowing down and looking at what the law actually asks for, where the uncertainty sits, and how organisers can reach proportionate decisions rather than default ones.

Where Martyn’s Law stands today

The Terrorism (Protection of Premises) Act 2025 received Royal Assent in April 2025. It’s expected to come into force in spring 2027, with the Security Industry Authority (SIA) as regulator.

The Home Office published its statutory guidance in April 2026. The SIA has consulted on its own guidance covering how it will inspect and enforce, and the final version is still to come but rumoured to be this autumn.

Nobody is legally required to comply yet. Organisers are, however, being encouraged to prepare as if the law were already in force. That’s sensible advice, and it’s exactly what Truro tried to do.

Not every large event is in scope

This is the point I think gets lost most often. A crowd of 5,000 doesn’t automatically make an event a “qualifying event”.

For events not held at premises already in scope, two conditions matter. There must be a reasonable expectation of 800 or more people present at the same time. There must also be measures in place to check a condition of entry, such as a ticket, pass or payment. A suggested donation doesn’t count.

That creates a real tension. Ticketed or controlled entry is often introduced for good crowd safety reasons, to manage numbers and flow, and it’s also what can bring an event within the Act.

Organisers should understand that trade-off early and make the decision with their eyes open, rather than discover it halfway through planning.

What the enhanced tier actually asks for

Every in-scope premises and event needs public protection procedures: evacuation, invacuation, lockdown and communication. These cover what staff and volunteers do if an attack is happening or about to happen.

Enhanced Tier premises and qualifying events go further. They need public protection measures, so far as reasonably practicable, to reduce both the vulnerability of the event and the risk of harm.

Where the responsible person is an organisation, it must appoint a designated senior individual. It must also prepare a document setting out its procedures and measures, including an assessment of how those are expected to reduce the risk.

One detail matters here. The statutory guidance is explicit that the Act assumes an attack could happen anywhere, so the requirements aren’t tied to how likely an attack is at a particular site.

That’s a different starting point from a traditional threat-led security risk assessment. The question is closer to this: if something happened here, how vulnerable would we be, and what reasonable steps would reduce the harm?

The threats the law is designed around

Martyn’s Law is specifically about terrorism, and it helps to be precise about the attack methods it’s intended to address. Recent history gives clear examples.

Vehicle as a weapon. In Nice in July 2016, a lorry was driven through crowds on the Promenade des Anglais on Bastille Day. The Berlin Christmas market was attacked the same way that December. For outdoor events with road access, this is often the first vulnerability to consider.

Person-borne improvised explosive device. At Manchester Arena in May 2017, the attacker detonated his device in the foyer outside the ticketed area as the audience was leaving. Twenty-two people were killed, including Martyn Hett.

Marauding attacks with firearms or bladed weapons. Examples include the Bataclan in Paris in 2015, and London Bridge and Borough Market in 2017, where a vehicle attack was followed by a knife attack.

Hostile reconnaissance sits underneath all of these. Attackers plan, and visible, well-run security is a deterrent in its own right.

It does show how exposed a dense, celebrating crowd is to a vehicle, whatever the motive. Good event planning will address that regardless of what the law requires.

NPSA and ProtectUK already publish a great deal of free guidance on these threats, including hostile vehicle mitigation. I’d expect that material to sit closely alongside the SIA’s regulatory guidance.

The cost question

This is where Truro’s story will generate the most debate. The Home Office’s position is that compliance should be proportionate. Its impact assessment put average annual costs for the enhanced tier at around £5,200, mostly staff time rather than physical upgrades.

Many security professionals, me included, will find that difficult to square with an open-air event for thousands of people. That’s particularly true if the chosen answer involves vehicle mitigation, search regimes, extra stewarding and road closures.

But the Act doesn’t require every possible measure. It requires what is reasonably practicable, which the guidance equates with proportionate.

The risk is that, without clear examples of what proportionate looks like for a community event, organisers price in the maximum and conclude the event can’t happen.

The answer to that is evidence. You can’t protect what you don’t understand, and you can’t defend a decision you haven’t recorded.

An organiser who can show how they assessed their vulnerabilities, which measures they chose, which they considered and set aside, and why, is in a far stronger position than one who either gold-plates everything or does nothing.

Where support can help

Until the SIA publishes its final guidance, we’re all in something of a holding pattern on the detail. Anyone responsible for an event should watch for it and engage with it.

In the meantime, the people carrying this responsibility are often council officers and volunteers rather than security professionals. What they need is a simple, structured way to work through their vulnerabilities, set them against the current threat level and their local context, and record the reasoning behind the measures they choose.

That’s an area we’ve been exploring at HawkSight. It includes how templated procedures for evacuation, invacuation, lockdown, communication and crowd management could be tailored to an event rather than written from scratch.

It won’t replace the SIA’s guidance, or professional judgement where an event is genuinely complex. It could take a lot of the blank-page anxiety out of the process.

Keeping sight of why this matters

Figen Murray has spent years campaigning so that other families don’t go through what hers did. The law named after her son deserves to be taken seriously, and it deserves to work.

A community losing its Bonfire Night isn’t the outcome anyone wants.

If you’re with the SIA, NPSA, a local authority or an events team and I’ve got any of this wrong, or you can see how the final guidance will address it, I’d welcome the correction.

And if you’re planning an event now, what would help you most in reaching a proportionate answer?

Sources