← Back to Blog

Crypto kidnapping: 2024-2025 cases, attacker playbook, defense model

By Al Jobson · 11 min read · September 2026

Duress PIN and decoy wallet, coercion resistance by design

Jameson Lopp's public index of physical attacks on crypto holders passed 170 documented incidents by mid-2025, with sharp spikes tied to price cycles[1]. The New York Times and Le Monde covered a string of kidnappings in France through 2024 and 2025, including a case where the father of a Ledger co-founder was held for ransom[2][3]. A Manhattan case in May 2025 saw a victim held for 17 days[4]. Every one of these bypassed cryptography by attacking the human. This piece is what the pattern looks like now and what defenses actually help.

The threat, in plain terms

A crypto kidnapping is not a novel category. It is a burglary or an abduction whose objective is a cryptocurrency transfer instead of cash, jewellery, or a business ransom. What is new is the reason it targets crypto: on-chain balances are public, permanent, and (in most cases) impossible to freeze once transferred. From the attacker's perspective, a self-custody wallet is a physical safe whose combination the owner is guaranteed to know and legally able to open under duress.

The three properties that make crypto uniquely attractive to physical extortion:

Documented cases, 2024-2025

Physical crypto attack incidents by year, 2020-2025
Date Location Method Reported outcome
Jan 2024TorontoHome invasion, family heldUndisclosed BTC transferred[5]
May 2024Île-de-FranceKidnap of Ledger co-founder's father€10M ransom demand, victim recovered[2]
Dec 2024Vaucluse, FranceFounder's partner kidnapped and mutilatedMultiple arrests[3]
Feb 2025BangkokTrader lured, tortured for keys~$5M USDT drained[6]
May 2025Manhattan, NYInvestor held 17 days in townhouseTwo indicted, funds unclear[4]
Jun 2025ParisDaytime abduction of exchange executive's daughterRescued same day, four arrests[7]
2024 totalGlobalDocumented incidents~30 in Lopp index[1]
H1 2025GlobalDocumented incidents~35 in Lopp index[1]

Two patterns hold across the data. First, the incident rate correlates with price. Every prior bull run (2017-18, 2021, 2024-25) produced a spike; every bear market brought a decline. Second, the geography clusters where two conditions overlap: significant local crypto wealth and organised-crime infrastructure capable of running a kidnap operation. France, the United States, Thailand, the UAE, Turkey, and Ukraine dominate the 2024-2025 record[1].

How targets get selected

Target selection is the part of the operation that runs on public information. In every documented case the victim was linked to crypto wealth through at least one of the following:

The FBI IC3 explicitly warned in 2024 that on-chain analytics tools designed for compliance are also used by criminals to price potential targets before the physical operation begins[9].

Why traditional defenses fail

The self-custody community's default answer to physical coercion has been the hardware-wallet passphrase, sometimes called the "25th word". A passphrase deterministically derives a different wallet from the same seed. In theory the victim can hand over the "small" wallet and the attacker cannot know the passphrase exists.

In practice this works for maybe 5 percent of the population that would encounter the situation. The reasons it fails for the other 95 percent:

Multisig with an offline co-signer works better because the victim can honestly say "I cannot move funds alone" and demonstrate it. This is the design Casa has offered for years and the reason its multisig product survives in a coercion threat model[10]. The trade is setup complexity most retail users will not accept.

The wallet-level defenses that actually work

Emergency controls, decoy wallet and panic wipe
Defense What it does under coercion Failure mode
Duress PINOpens a plausible small-balance wallet indistinguishable from the real UIFails if the wallet visibly branches on PIN input
Decoy walletSecond full-featured wallet with limited holdings that survives inspectionAttacker who checks on-chain history sees mismatch if decoy is idle
Silent duress alertTriggers a webhook or contact ping when a specific PIN is enteredOnly useful if the alerted party can act in time
Withdrawal limits + delayCaps single-signature transfers, requires wait for larger amountsAttackers may hold victim longer
Threshold multisig with off-site co-signerVictim honestly cannot move funds; attacker cannot force what does not existSetup complexity, co-signer availability
Geographic dispersionBackup shares held out of jurisdiction; wallet on device cannot fully authorizeRequires trusted parties in multiple locations
Panic wipeSpecific input erases wallet state and shows plausible empty installDestroys the victim's access too; only useful with off-device backup

The pattern that survives under stress combines three things: a wallet the attacker sees is real and plausibly holds everything the victim owns (decoy), a mechanism that means the victim cannot move all funds unilaterally (limit, multisig, or geographic dispersion), and a silent signal that competent help is on the way (alert). No single feature solves coercion; the layered stack raises the effort-to-payoff ratio enough to change the target-selection calculus.

Wallet-by-wallet, what ships

Wallet Duress PIN Decoy wallet Withdrawal limits Notes
LedgerNo, passphrase onlyVia passphraseNoDocumentation of passphrase is public
Trezor Model TNo, passphrase onlyVia passphraseNoSame as Ledger
ColdcardYes, "duress PIN" featureYes, "trick PIN" opens alternate walletNoBest-documented hardware duress feature[11]
Samourai (Bitcoin)Yes, "stealth mode" until 2024 shutdownYesNoDiscontinued after founders' arrest[12]
Casa (multisig)N/AN/AYes, co-signer required for large withdrawalsHonest "cannot move alone" answer[10]
MetaMask, Trust, PhantomNoMultiple wallets manuallyNoNo design-level duress protection
VEYRNOXYes, Safety Plus tierYes, full-featured decoy with independent historyYes, per-tier caps + optional delayPanic wipe available; alert webhook optional

OpSec that reduces target selection risk

The wallet layer matters. The layer above it matters more. Every documented crypto kidnapping traces back to an OpSec failure that told the attackers there was something to take. The list is boring, and every item has been ignored by a victim in a documented case:

If the worst happens: what wallet design changes

Under coercion the victim's goal is not to win; it is to reduce loss and end the incident alive. Wallet design that supports both is design that:

Every one of those is a design choice, not a cryptographic one. The reason so few wallets ship them is that they are UX-invasive at setup and require the vendor to think about a threat model most wallet teams avoid discussing publicly.

Bottom line

Crypto kidnapping is not a niche 2024 phenomenon. The physical-attack index is now growing at the same rate as retail on-ramp adoption, and the pattern is stable enough to plan for. The defenses that actually reduce loss under coercion are not the passphrase, not "keep quiet online" alone, and not "buy a bigger hardware wallet". They are (1) an OpSec discipline that makes target selection expensive, and (2) a wallet with design-level duress features that let the victim comply without revealing the real balance.

Every wallet vendor should be shipping duress PIN, decoy wallet, and withdrawal limits as defaults on any tier above the smallest hot wallet. Users who hold meaningful balances should be running one. The alternative is what the Lopp index already documents.

Coercion resistance in VEYRNOX

VEYRNOX Safety Plus ships a duress PIN that opens a full-featured decoy wallet with independent history, plus configurable withdrawal caps and an optional silent alert. The decoy wallet is not visibly branched from the main UI; the attacker sees a plausible small balance and no seam. Download or read the duress-wallet page.

Sources

  1. Jameson Lopp, "Known Physical Bitcoin Attacks." github.com/jlopp
  2. Le Monde, coverage of Ledger co-founder's father kidnapping. lemonde.fr
  3. The Guardian, Vaucluse crypto kidnapping report. theguardian.com
  4. The New York Times, "Crypto Kidnapping in Manhattan." nytimes.com
  5. Toronto Star, home-invasion crypto extortion coverage. thestar.com
  6. Reuters, Thailand crypto trader torture case. reuters.com
  7. Le Figaro, Paris crypto executive daughter abduction. lefigaro.fr
  8. Ledger, "July 2020 data breach post-mortem." ledger.com
  9. FBI IC3, "Cryptocurrency Fraud Report 2023." ic3.gov
  10. Casa, multisig product docs. keys.casa
  11. Coldcard, "Duress PIN documentation." coldcard.com
  12. DOJ press release, Samourai Wallet founders' 2024 arrest. justice.gov
  13. Chainalysis, "2025 Crypto Crime Report." chainalysis.com
  14. TRM Labs, "Physical crypto attack timeline." trmlabs.com
  15. Elliptic, "Ransom laundering analysis." elliptic.co
  16. Cointelegraph, aggregated crypto-kidnapping timeline 2024. cointelegraph.com
  17. The Block, "France's crypto kidnapping wave." theblock.co
  18. CoinDesk, coverage of on-chain ransom flows. coindesk.com
  19. Bitcoin Magazine, wrench-attack analysis. bitcoinmagazine.com
  20. Trezor, "Passphrase feature documentation." trezor.io
  21. Ledger, "Passphrase documentation." support.ledger.com
  22. Interpol, "Notes on organised crime and crypto." interpol.int
  23. Europol, "IOCTA report crypto-crime chapter." europol.europa.eu
  24. Chainalysis, "Crypto Crime H1 2025 update." chainalysis.com
  25. Verichains, industry threat notes. verichains.io
  26. Wired, feature on high-net-worth crypto security practice. wired.com

Al Socrates Jobson, Co-Founder and CTO, Veyrnox LTD · ← Back to Blog