In May 2025, a man was lured to a townhouse in Manhattan’s SoHo neighborhood and held there for seventeen days. According to prosecutors, he was subjected to serious physical abuse in an effort to force him to hand over access to his bitcoin holdings. Two men have since been charged with kidnapping and assault; the case is still working through the courts, and what actually happened inside that townhouse is, legally, still for a jury to decide.

But the pattern around it is no longer in question. Security researchers and reporters have documented dozens of similar cases — so-called “wrench attacks,” named for the idea that a five-dollar tool and a willing attacker can bypass security that would take a nation-state to break digitally. What happened in SoHo was not an isolated horror story. It was one data point in a fast-growing category of crime that most executive security thinking still is not built for.

A threat model built for the wrong century

Executive protection, as a discipline, grew up around a specific kind of target: a person whose wealth and importance are a matter of public record. A CEO has a title, a company, a stock price, sometimes a security line item in a proxy filing. The protective playbook — credentialing, route planning, residential hardening — was built around that visibility.

A crypto holder is a different kind of target entirely. Their wealth exists on a public blockchain but their identity often does not. There is no corporate title, no press profile, no filing that discloses what they are worth. In many cases the only thing that separates them from anyone else on the street is a private key — and the only way to know they have it is for someone to find out.

That inversion is the whole problem. Traditional executive protection assumes the target is known and tries to control access to them. A crypto holder’s real vulnerability is usually the opposite: staying unknown in the first place, because once someone identifies them as holding significant digital assets, the physical threat model changes overnight and no amount of after-the-fact security fixes what was already exposed.

Why the money doesn’t need a password to disappear

Here is the detail that makes wrench attacks specifically brutal, and specifically preventable: unlike a bank, a cryptocurrency wallet has no fraud department, no chargeback, and no one to call. If an attacker gets the private key or seed phrase, the funds move in minutes and are effectively gone. That finality is exactly why coercion works as an attack — there is no institution standing between the threat and the payout.

Which means the entire defense has to happen before the confrontation, not during it. A few principles that hold up across the cases that have been documented:

Custody structure matters more than any bodyguard. A wallet that requires multiple independent approvals to move funds — spread across separate hardware, separate people, or separate locations — cannot be emptied by coercing one person, no matter how effective the coercion is. If a single person under duress can authorize a transfer, that person is the entire security system.

Visibility is the vulnerability. Public wallet addresses, social media posts about gains, conference appearances, and even certain lifestyle signals create a target profile before any physical risk exists. The operational security question isn’t “how do I protect myself once someone knows” — it’s “how do I make sure fewer people ever have reason to guess.”

Residential security has to assume the threat already knows where you live. Wrench attacks are overwhelmingly residential, not street crime. A location that is easy to identify and hard to secure — a known home address with predictable routines and no monitored access — is the setting nearly every documented case shares.

There has to be a plan for coercion itself, not just for prevention. Duress protocols — a decoy wallet, a silent alarm, a code word, a way to comply without actually surrendering the real assets — exist precisely because prevention sometimes fails. An asset structure with no fallback for the moment someone is standing over you with a weapon is not a complete plan.

The lesson isn’t about crypto

It is tempting to read this as a niche problem for a specific asset class. It isn’t. Digital wealth is simply the clearest example of a broader shift: value that used to require an institution to move — a bank, a broker, a corporate structure — increasingly does not. Anything a person can be forced to transfer alone, in the moment, with no third party able to stop it, creates the same exposure. Crypto is just the version of that problem growing the fastest right now.

The people most at risk are rarely the ones who look like traditional protection clients. They don’t have a title, a company car, or a name anyone would recognize. In this threat category, that is exactly the point — and exactly why the protective thinking built for boardrooms hasn’t caught up to it yet.


Nelson Vergara is the founder of a New York-based executive and residential protection practice, focused on physical security for high-net-worth individuals, including holders of digital assets.