BTC
ETH
HTX
SOL
BNB
查看行情
简中
繁中
English
日本語
한국어
ภาษาไทย
Tiếng Việt

CertiK報告:扳手攻擊損失暴增近12倍,「運營安全」成防範新核心

CertiK
特邀专栏作者
2026-07-23 10:15
本文約1821字,閱讀全文需要約3分鐘
據彭博社獨家報導,7月22日,全球最大的安全公司CertiK發布《Intel3D:2026上半年扳手攻擊報告》。
AI總結
展開
  • 核心觀點:報告揭示2026年上半年全球針對加密資產持有者的「扳手攻擊」激增,入室搶劫和針對家庭成員的人身脅迫成為主要攻擊形態,現實世界安全風險已成為數位資產生態的核心威脅。
  • 關鍵要素:
    1. 攻擊數量與損失激增:2026年上半年全球發生52起公開核實的扳手攻擊事件,同比增長33.3%;造成的損失約1.24億美元,同比暴增約11.8倍。
    2. 攻擊形態劇變:入室搶劫從2025年上半年的1起增至20起,占總事件數的41%。攻擊者開始通過控制或威脅目標配偶、子女等關聯人員進行心理施壓。
    3. 歐洲成重災區:歐洲共記錄39起事件(占全球75%),其中法國33起(占全球63.5%)。攻擊者利用數據洩露與鏈上活動結合進行精準畫像,降低搜尋成本。
    4. 數據洩露是關鍵入口:攻擊者通過暗網、數據掮客或內部人員非法獲取包含姓名、住址和資產估算的目標畫像,並由底層人員實施線下劫持逼迫轉帳。
    5. 防護模式重構:CertiK推出運營安全(OpSec)服務進行個人信息暴露評估,並與國際刑警組織等合作提供即時威脅情報,推動從技術防護向線下運營安全拓展。

According to an exclusive report by Bloomberg, on July 22, CertiK, the world's largest security company, released the "Intel3D: Wrench Attack Report for the First Half of 2026." The report shows that in the first half of 2026, a total of 52 publicly verified wrench attacks were recorded globally, a 33.3% increase year-over-year. These attacks caused losses of approximately $124 million, an increase of about 11.8 times compared to the same period last year. As the value of digital assets grows and the scale of industry participants expands, attackers are seeking new breakthroughs beyond traditional security protections, making real-world risks an undeniable part of the digital asset ecosystem.

Evolution of Attack Patterns: Targets Expand to Families and Associates

The report highlights that the most significant change in the first half of 2026 is the explosive growth in home invasions, which surged from 1 case in the first half of 2025 to 20 cases, accounting for 41% of the total incidents during the period.

Notably, attackers are increasingly leveraging real-life relationships to apply pressure. By controlling or threatening the spouses, children, parents, or employees of crypto asset holders, they use psychological coercion to force victims to unlock wallets or execute asset transfers. Since these related individuals often lack security awareness and have relatively public daily routines, this places traditional single-person defense mechanisms under severe strain.

Europe Becomes a High-Risk Region for Attacks, With France Accounting for Over 60%

Geographically, Europe emerged as the most concentrated region for wrench attacks in the first half of 2026. During this period, Europe recorded 39 publicly verified incidents, accounting for 75% of the global total. Among them, France reported 33 cases, representing 63.5% of all global incidents, making it the most severely affected country. The United States recorded 4 cases, while the United Kingdom and Sweden each recorded 2 cases, with relatively fewer incidents in other regions.

The report suggests that this phenomenon may be linked to France's active crypto asset ecosystem and several large-scale data breaches in recent years. Attackers can combine leaked data with public information and on-chain activities to identify and profile potential targets, significantly reducing the cost of finding targets for criminals.

Data Breaches Are Becoming a Key Entry Point for Real-World Attacks

The methods attackers use to find targets are also changing. In the past, criminals relied more on public information from social media and in-person events to identify high-value targets. Now, attackers are obtaining precise customer data through the dark web, black markets, data brokers, and public or corporate insiders. Public investigations have revealed that some cases involve the illegal sale of user data by internal personnel.

After obtaining a target profile containing names, addresses, asset estimates, and social relationships, mid-level coordinators recruit low-level executors to carry out physical control measures—such as posing as delivery personnel, intercepting targets en route, or arranging fake business meetings—and then force victims to complete transfers within an extremely short timeframe.

Individuals and Institutions Need to Establish More Comprehensive Security Systems

In response to the evolving attack methods, the report recommends that individuals and institutions reassess their digital asset security strategies.

For individual users, reducing unnecessary public disclosure and avoiding exposing asset scale and identity-related information are crucial measures to lower the risk of becoming a target. Additionally, critical assets should not be concentrated in a single wallet or controlled by a single person; multi-signature schemes and multi-party computation can reduce single points of risk.

For enterprises and high-value asset management institutions, the report advises strengthening permission management to avoid excessive concentration of critical access rights, and isolating the management of wallet permissions, recovery information, and important operational processes. Furthermore, enterprises need to establish emergency response mechanisms for real-world threats to address potential risks of personal coercion or operational disruption.

As attack targets shift from code and systems to the asset controllers themselves, digital asset security is expanding from traditional technical protection to broader operational security domains.

Rebuilding Security Models: Offline Operational Security and Architectural Defense

Facing the threat of transnational criminal networks, security agencies are promoting collaboration with law enforcement.

The report reveals that CertiK has launched Operational Security (OpSec) services covering data exposure assessments for executives, internal system penetration testing, and compliance reviews. These services can assist high-risk individuals and corporate executives in auditing sensitive information exposure risks related to identity, family, residence, and travel itineraries, assess potential risks of exploitation by attackers, and help enterprises meet compliance requirements for operational resilience and business continuity under regulatory frameworks such as VARA, DORA, and MiCA. Moreover, as an important supplement to security management, the CertiK Security Workspace platform performs deep correlation analysis between off-chain intelligence and on-chain transaction flows, as well as Anti-Money Laundering (AML) risk signals, helping institutions track and attribute cybercrime in real-time to quickly lock onto evidentiary leads worth investigating.

The report also mentions that CertiK will continue to establish closer cooperation with international law enforcement agencies, including INTERPOL and Europol. Through CertiK's security tools, it provides real-time threat intelligence and risk monitoring support, and leverages expert resources to offer technical support for major cross-border attack incidents, related investigations, and security policy research.

As attackers continue to break through traditional technical boundaries, protecting the asset controllers themselves will become a crucial component of digital asset security.

Report link: https://indd.adobe.com/view/34999f45-b459-4eec-a889-26e0e0886ba6

安全
歡迎加入Odaily官方社群