A crypto whale has been robbed remotely. This time the victim lost more than $25 million after having a mixture of cryptocurrencies (including wrapped Bitcoin) stolen and swapped for DAI and ETH. I don’t doubt that this sort of thing happens all the time. After all, uncensorable electronic cash is a very attractive for criminals of all kinds.
Having your digital dosh hacked and spirited away is very disturbing. That’s why the hard core of cryptousers hold to the mantra “not your keys, not your coins”. They don’t want to store their cryptocurrency in the bank or in a wallet that could be hacked: they want to hold the keys to their cryptocurrency themselves. They want to be their own banks and beliece that rather than hold Bitcoin in Binance or Circle in Coinbase, you should manage the key to your cryptocurrency yourself and, what’s more, you should hold those keys in “cold wallets”,
Cold wallets operate on the principle of “offline signing”. This process ensures that private keys are never exposed to an internet-connected environment, effectively eliminating remote exploit paths and malware vectors. By using a cold wallet that is not connected the Internet, cryptocurrency holders can keep the their money safe. Well, sort of. Just a couple of weeks ago, more than $100 million was stolen from more than 5,000 cold wallets. It turned out there was a firmware bug in these wallets that silently routed seed generation through a weak software pseudo-random number generator instead of the hardware entropy source.
While cryptocurrency crime happens entirely online. Last year crime such as hacks ($3.4 billion stolen in 2025), scams ($17 billion) and ransomware ($820 million) brought in big bucks for criminals for sure, but so-called “wrench attacks” involving physical violence are on the way up. Violent attacks targeting crypto holders, including home invasions (now more than a third of cases), kidnappings and other “wrench attacks” are surging. Criminals are not idiots and they recognise the benefits of uncensorable electronic cash just as much as the rest of us do. Wealth in an instantly and irreversibly transferrable form is a dream come true.
Even if the hackers cannot get hold of the private keys, then, they can still get hold of the private key owners. Trezor, which sells hardware wallets, had a data breach at one of its shipping providers which resulted in the names, addresses, phone numbers and email addresses of 11,742 buyers of the secure devices from the US, UK, Sweden, Colombia, Brazil, Italy and Portugal being exposed. Once the bad guys have hold of information like this, they will use it. Just recently, masked criminals attacked the daughter, partner and gtandchild of a French cryptocurrency boss. The woman and her partner fought off the attackers, with one witness reporting that the assailants tried to ‘pull a young woman by force‘ into a waiting van.
This is far from unusual in France, where recent figures show a sharp uptick in violent crypto-targeted crimes. CertiK reported 52 confirmed cases of “crypto wrench attacks” during the first half of 2026 and more than half of them occurred in France. In that same period, home invasions tied to crypto demands increased from one in the first half of 2025 to 20 this year. In one recent case, three different criminal groups targeted the same couple in France’s Somme department within one month, trying to get €1 million in cryptocurrency that the residents never owned. The attackers were using leaked records relating to the a property’s former owners. The former owner’s tax details had been for sale on the dark web after a data breach.
(I expect to see a lot more of this sort of thing in the coming months following the news that a hacker got into the French tax authority’s databases and made off with the records of around 700,000 people.)
Of course these sort of breaches will not be restricted to the French border. For one thing, France is about to start exporting sensitive personal data associated with cryptocurrency transactions to 48 other countries. In July, the French Minister for Europe and Foreign Affairs, introduced text 921 in the Senate to enable the automatic exchange of information as part of the Crypto-Asset Reporting Framework (CARF) developed by the Organization for Economic Co-operation and Development (OECD). This would transmit data including specific transactions, user names, addresses, tax identification numbers and the aggregate value transacted during the reporting period to foreign tax authorities where presumably it will be stolen by foreign hackers rather than French ones, but the outcome will be the same.
I’m not suggesting that France has particularly poor information security habits. Everyone does. Just last week Israel’s largest crypto broker Bits of Gold suffered a breach such that the names, bank account details and national ID numbers of some 200,000 customers were snaffled and are presumably allready up for sale on the dark web.
What all of this says to me is that under no circumstances do I want to be my own bank. Apart from anything else, being your own bank means being your own bank IT security department. Chainalysis suggest that cryptocurrency holds avoid publicly disclosing holdings, use caution when linking on-chain activity to real-world identity and taking physical security measures (Coinbase spent more than $7 million on their CEOs security last year). These are all sensible measures but the fact is that I don’t want the keys to be my problem, I want them to be the problem of a regulated entity that has experience in the management and secure distribution of cryptographic keys, partiocularly when it comes to the secure transport of keys into tamper-resistant hardware like, oh I don’t know, maybe… my bank?