№ xlii The Almanac of GST · EN IT

Enrico·rubbo.li

Tech · Longevity · Markets · Opinions Enrico Rubboli, propr. Dubai, UAE
essay September 11, 2026 8 min

The Threat Model Self-Custody Skips: Someone With a Wrench

Cryptography assumes an adversary who attacks math and machines. Wrench attacks, the ones where somebody brings a tool to your door, assume an adversary who attacks knees. Both show up in the loss tables. Only one of them is flattered by Twitter threads about air gaps.

In January 2025, kidnappers took David Balland and his wife from their home in Vierzon, in central France. They severed one of Balland’s fingers and sent the video to Ledger when the full ransom did not arrive. Investigators wired a single bitcoin, roughly $105,000, to buy time and follow the money; gendarmes freed Balland the next day and found his wife tied up in a van hours later. Balland co-founded Ledger, a company whose entire product line exists to keep private keys away from attackers.[1]

Physical coercion against crypto holders is not a side channel you mention after the real security section. For anyone with a balance large enough to change a life, it is a primary channel. Self-custody arguments that skip it are incomplete in the same way merchant Lightning security was incomplete when it treated a hot node as a vault.[2]

Why wrench attacks belong in the threat model

After high-profile drains and bull-market wealth, attackers need not be nation-states. They need an address that looks rich, a social graph that reveals habits, and a door. Chainalysis counted 46 violent attacks on crypto holders through late June 2026, with more than $30 million successfully extracted, against $58 million across the whole of 2025, itself the worst year on record until then. France alone accounted for 30 publicly known cases by mid-year, up from 19 in all of 2025. Jameson Lopp has kept a public list of these incidents since 2014 and is careful to say it is not comprehensive, because most of them are never reported at all.[3]

One figure in that report cuts against the panic and in favor of the design work. Through late June 2026, 26% of violent theft attempts ended in a payment, down from 49% in 2025 and 67% in 2024. Attacks are getting more common and less productive at the same time. That gap is not luck. It is what happens when the money stops sitting behind one person’s willingness to endure pain.

Digital hygiene does not stop a home invasion. A hardware wallet in a desk drawer is a jewelry box with a seed phrase. Multisig that requires only devices in one apartment is a single scene in a single crime. Publishing your net worth, your stack screenshots, and your travel calendar is marketing for the wrong audience.

This is not an argument that only the paranoid should hold keys. It is an argument that key holders inherit physical security as part of the job, the same way they inherit backup and inheritance.

Architecture beats bravado

What reduces wrench risk is boring and structural:

  1. Do not be an obvious single point of payment. Multisig across devices and locations so that violence in one room does not unlock the treasury.
  2. Duress and decoy paths where your stack and threat model support them, without LARPing past your competence.
  3. Geographic and institutional distribution of cosigners you actually trust, including collaborative custody for the slice of wealth you refuse to lose to either a bug or a crowbar.[4]
  4. Silence. Chainalysis describes victims picked out through exposed information: data breaches, social media activity, or a tip from an insider. Opsec is not a product. It is the absence of a thread.[3]
  5. Right-sizing what lives in hot or semi-hot paths. Tills and treasuries. We keep learning this lesson in software; learn it in furniture too.[2]

Silence has limits worth admitting. Part of the French surge traces to leaks nobody chose: a tax official accused of stealing and selling dossiers on wealthy holders in 2024, and a 2026 breach at the crypto tax-reporting firm Waltio that exposed some 50,000 users. You cannot always control whether you end up on a list. You can control whether you publish one.[3]

None of this requires agreeing that ETFs are the only moral future. It requires admitting that pure single-sig in a nightstand is a lifestyle choice with a body count attached when balances grow.

When not holding keys is rational

A brokerage account can be robbed by lawyers and by account takeovers, but it is harder to extract with a wrench in the kitchen. For people who will not run multisig, will not shut up online, and will not train their family, not holding keys is rational. The ETF narrative after Coldcard is partly opportunistic. It is partly product design for humans as they are.

Outsourcing keys does not remove violence from the world. It changes who gets attacked and which papers get frozen. Choose consciously.

Where the math stops

Math is necessary. It is not sufficient. Self-custody that cannot survive a bad evening at the front door is incomplete self-custody. Design for the adversary who does not care about your air gap.

Cryptography does not care who is holding the wrench. You should.


  1. Ledger co-founder kidnapped and freed in France, DL News, January 24, 2025; French military police rescue co-founder of €1.3bn crypto startup Ledger, Fortune, January 24, 2025.
  2. The Merchant Node Was the Wallet; Safe by default.
  3. Chainalysis, Violent Wrench Attacks Targeting Crypto Holders, August 6, 2026. Incident counts, extraction totals, success rates, and the Waltio and French tax-record leaks are from this report. Jameson Lopp, physical-bitcoin-attacks, a public list of known physical attacks against crypto holders running from 2014 to the present, with the standing caveat that many attacks are never publicly reported.
  4. Coldcard Failed. Self-Custody Didn’t.; The wallet they call unhosted.