Physical threats: when the attack isn't digital

·5 min read·By SSP Editorial Team
SSP Academy cover: physical threats and wrench attacks against crypto holders

Physical threats: when the attack isn't digital

Most crypto security advice assumes the attacker is somewhere else — a phishing site, a malicious contract, a compromised laptop. There's a category of threat that ignores all of that. Someone who knows you hold crypto, and who is willing to threaten you in person, doesn't need to break any cryptography. They need you to unlock your phone.

The industry calls it the "wrench attack", after the old joke that no encryption survives someone with a wrench. It's uncomfortable to think about, which is exactly why it's worth ten minutes of calm thought before it's ever relevant.

Why this threat is growing

Physical attacks on crypto holders are no longer rare curiosities. Kidnappings, home invasions and violent robberies targeting people believed to hold crypto have been reported in many countries, and they tend to cluster where holders are publicly identifiable.

The reason is simple economics. As digital security improves, the cheapest path to someone's coins moves from their devices to their person. Crypto is bearer value: whoever controls the keys controls the money, and a transfer can't be reversed once it confirms. For a criminal, that's the attraction.

Privacy is the first and best defence

Almost every physical attack starts with the attacker knowing you hold crypto — and ideally how much.

Don't advertise holdings. Posting balances, wins, or screenshots of portfolios makes you a target. So does talking about it at events, in bars, or with people you've just met.

Separate identity from wealth. Social media accounts linked to your real name, your city and your crypto activity form a map. Consider what a stranger could piece together.

Watch data trails. Exchange data leaks, delivery addresses for hardware devices, and doxxing from on-chain analysis have all been used to find holders. Your addresses reveal more than you'd think, and linking a publicly known address to your identity links your whole history to you.

The most effective defence against a wrench attack is never being selected. That's mostly about what you don't say.

What multisig does — and doesn't — do here

SSP puts your funds in a 2-of-2 multisig: one key in your browser extension, one on your phone. That protects you well against a single compromised device, a stolen phone, or a phished laptop. What it's designed to prevent is one point of failure giving someone everything.

Be clear-eyed about coercion, though. If both devices are with you — your phone in your pocket and your laptop at home — an attacker who has you can compel you to approve on both. Two keys held by one person in one place is not a defence against someone threatening that person.

Multisig starts to help against physical threats only when the keys are genuinely separated in a way an attacker can't overcome on the spot: in different locations, or held by different people. That's one reason businesses use multi-person vaults — organisations that split signing across people make a single coerced individual insufficient by design. For an individual, keeping the second key somewhere you can't reach immediately does the same thing at the cost of convenience.

And there's a harder truth. Making yourself unable to comply can escalate a violent situation rather than end it. Separating keys is a deterrent that works best when it's known in advance, not a trick to spring during an attack.

Structuring holdings to reduce exposure

Don't keep everything instantly spendable. Everyday amounts can live on the devices you carry. Larger holdings are better kept where moving them requires time, travel, or other people.

Consider a spending wallet. A separate wallet with a modest balance is something you can hand over under duress. It's not a guarantee — a determined attacker may not believe it's everything — but it changes the calculation.

Don't carry your recovery material. Seed phrases belong somewhere secure and separate from your devices, never in a wallet, bag or phone note.

Plan for your household. If others live with you, they're part of your threat model. They should know enough to stay safe, not enough to be targeted.

If it happens

Nobody can offer a script for a violent situation, and nothing here outweighs your safety or anyone else's. The general guidance from security professionals is consistent: your life is worth more than your coins. Comply, stay calm, and focus on getting through it.

Afterwards, report it to the police immediately and treat every key you had with you as compromised. Move what remains to fresh keys. Tell exchanges where funds may arrive — occasionally stolen funds can be frozen if they reach a regulated platform quickly.

The honest summary

Cryptography can't protect you from someone who can threaten you in person. What can protect you is not being identified as a target, not having everything instantly accessible, and — for larger holdings — making sure no single person in a single place can move all of it.

Two-of-two multisig is excellent protection against the attacks that happen through screens. Against the attacks that happen in the real world, privacy is the first line, separation is the second, and your personal safety always comes before either.

Share this article

Related articles