Skip to main content

Chainalysis has counted 46 documented physical coercion attempts against crypto holders so far in 2026. Twelve of them ended with the victim paying. The running total is north of $30 million. The headline writes itself, and it is the wrong headline. The detail that actually matters sits one line down in the report: the attacks are increasingly seeded by data leaks, and increasingly aimed at relatives rather than holders.

That is a sentence about databases, not about blockchains. And it lands on crypto gaming harder than the industry has noticed, because we argue endlessly about whether outcomes are verifiable and almost never about what gets published about the person who won.

TL;DR

  • Chainalysis logged 46 physical coercion attempts on crypto holders in 2026, 12 successful, over $30 million taken, with data leaks and attacks on relatives widening the risk surface.
  • A wrench attack needs two things: knowledge that a balance exists, and a link from that balance to a human being. The chain supplies the first. It almost never supplies the second.
  • The identity link overwhelmingly comes from off-chain sources, and the richest of those is a KYC customer database, which is exactly the layer centralised gaming adds and on-chain gaming does not have.
  • A centralised casino holds your legal name, address, ID scan, payment details and the exact size of your win in one table, and still cannot show you that the game was fair. It is the worst of both trades.
  • On-chain gaming does not make you anonymous. Pseudonymity is fragile, clustering is real, and a payout lands on the address that placed the bet. The honest claim is narrower: there is no customer table to breach because none is collected.

The number is a floor, not a total

Start with the arithmetic, because it is doing quiet work. Forty-six attempts is a count of incidents somebody documented, and wrench attacks are among the most under-reported crimes in the sector for obvious reasons: reporting means telling a police force that you hold a large, portable, irreversible asset, while the people who came to your door are still at large. Twelve payments out of 46 is not a 26% success rate for attackers. It is a 26% success rate among the subset visible enough to be counted, and $30 million is a floor with an unknown ceiling.

Verifiability and exposure are one property

We have spent months on this blog arguing that on-chain settlement is what makes a game checkable. Every one of those arguments has a bill attached, and this is it. A public ledger that lets you verify a stranger’s payout also lets a stranger verify yours. You cannot keep the half you like. Anybody claiming provable fairness with no privacy cost is either not thinking about it or hoping you are not.

So the honest question is not whether on-chain gaming has an exposure problem. It is which exposure, and whether it is the one that gets people hurt.

The chain publishes an amount, not a name

Two things get bundled together as “exposure” and they behave completely differently.

The first is balance visibility. A raffle payout on Base is a public transfer of a known size to a known address, timestamped, permanent, queryable by anyone with an RPC endpoint. That is unavoidable and it is the point.

The second is identity linkage: knowing that the address belongs to a specific person at a specific address with a specific family. This is the part that turns a database row into a knock at the door, and the chain does not provide it. It has to come from somewhere else: a breached exchange, a leaked hardware wallet customer list, a KYC file at a broker, an ENS name, a doxxed social account, or a winner who could not resist posting the screenshot.

Almost every case in the public record follows that shape. The balance was on the chain. The name and the postcode came from a company that collected them.

Centralised gaming assembles the targeting package as a feature

Now look at what a licensed crypto casino requires before it lets you play. Legal name. Residential address. A photograph of your passport. Sometimes a selfie holding it. A payment method that resolves to a bank account. Then it records every deposit, every wager and every payout against that identity, in a table you cannot read, retained for years because a compliance regime says it must be.

That single table is a wrench attacker’s entire shopping list, pre-assembled, sorted by balance, held by an operator whose security you have no way to inspect. The 2020 Ledger breach put roughly 270,000 names and home addresses into public circulation off the back of a marketing database, and people were still receiving threats years later. Ledger’s actual product was never compromised. The customer list was, and the customer list was enough.

And here is the part that should end the argument. That same platform, holding that same table, still cannot show you that its coinflip was fair. You hand over the data that makes you targetable in exchange for a promise you cannot check. It is the worst available trade, and it is the default across the industry.

What on-chain gaming does not fix

Being straight about this matters more than the pitch.

Pseudonymity is not anonymity. Chain analysis clustering is genuinely good, and if the address that received your payout has ever touched a KYC’d exchange, or paid gas from an address that has, the link is available to anyone with a commercial subscription and a reason to look. Fiat has to enter somewhere, and that somewhere knows who you are.

Nor does the architecture help here. The atomicity we praise, where stake, resolution and payout happen in one transaction, means the winnings land on the address that played. That is a real constraint, not a feature, and pretending otherwise would be the same overreach we criticised when the industry stretched “trustless” to cover things it does not cover.

The player-side mitigations are ordinary and they are not ours to grant: use a fresh address, keep it away from your salary address, do not name it, do not post it. All of that works without asking any platform for permission, which is rather the point.

What Satoshie holds about you

Nothing, and that is the whole claim. There is no account, so there is no account table. No email, no name, no document scan, no payment method, no support agent who can be socially engineered into confirming that a particular person had a particularly good week. A raffle entry is a ticket held by an address; a coinflip is a stake resolved in a Chainlink VRF callback and paid in the same transaction.

A platform cannot leak what it never collected. That is not a security posture we maintain, it is a consequence of not having built the layer where the leak happens. Verify the outcome yourself from the chain; there is nothing else to ask us for.

Three questions

  1. If the platform you play on were breached tonight, what could an attacker learn about you personally, and does it include a home address?
  2. Is the identity you handed over doing any work you benefit from, or does it exist purely because the operator needs a customer record?
  3. Which is actually visible about your last win: the amount, or the amount and you?

The wrench-attack data is not an argument against on-chain settlement. It is an argument against collecting the other half of the pair. Crypto gaming has been asked for years to prove its games are fair and has mostly answered with licences and badges. It has never really been asked why it needs your passport to run a coin toss.

📷 Photo by Scott Webb on Unsplash

Valentina Ní Críonna

Author Valentina Ní Críonna

More posts by Valentina Ní Críonna