CertiK reports 52 verified wrench attacks resulted in $124.1 million in losses during the first half of 2026, with incident frequency rising 33.3 percent year-over-year, according to the company's H1 2026 Hack3D Report.

Wrench attacks, also called wrench exploits or wallet draining attacks, involve social engineering or physical coercion to extract private keys or authentication credentials from cryptocurrency holders. CertiK's classification of 52 incidents as verified means each met the firm's confirmation threshold for inclusion in its damage accounting. The 33.3 percent increase from H1 2025 marks the first time CertiK has published damage figures by attack type and geography in a half-year cycle, providing institutional investors and security teams with granular loss attribution data.

Western Europe emerged as the primary geographic hotspot for these attacks during the period, according to the report. CertiK did not disclose the average loss per incident or the identity of targeted entities, though the firm's prior quarterly reports have named specific compromised protocols and exchanges when incident counts crossed their reporting threshold.

The $124.1 million in wrench-attack losses represents a subset of CertiK's broader damage accounting across all cryptocurrency theft vectors. In full-year 2025, the firm documented $14.6 billion in total theft losses across hacking, rug pulls, and social engineering combined, making wrench attacks a material but contained category within the wider loss total.

MSB Intel

CertiK's Hack3D dataset underpins institutional risk models used by custodians, derivative exchanges, and insurance carriers to price counterparty risk and customer protection products. The firm publishes incident data quarterly and in half-year summaries, with each release triggering protocol-level security audits and customer notification cycles among affected networks.

A 33.3 percent increase in incident count does not necessarily imply a proportional rise in total theft volume; losses per wrench attack have compressed as victims hold smaller average balances and as wallets move toward hardware cold storage and multisig custody structures that limit single-key compromise. The report does not break down loss per incident for H1 2026, making year-over-year damage intensity impossible to compute from the figures disclosed.

The document to watch is CertiK's second-half 2026 Hack3D Report, due in late January 2027, which will show whether the Western European attack concentration persists or migrates to other regions.