Skip to main content
← Back to home

Blog

Wrench Attack: When Physical Risk Outweighs Digital Threats

Published on 2026-10-02

You've secured your keys. Have you secured your environment?

Self-custody rests on a solid premise: your private keys never leave an offline device. Ledger, Trezor, Coldcard — these devices do their job. The encryption is robust. For a knowledgeable user, the digital attack surface is difficult to exploit.

But there is a category of attacks that no hardware wallet in the world can counter. It's called the wrench attack. And it doesn't target your keys — it targets you.

Wrench attack: a plain definition

The term comes from a blunt formulation, sometimes summarized in security circles as "$5 wrench encryption" — the wrench used to physically coerce someone into revealing their information.

In the context of self-custody, the scenario unfolds as follows:

  • someone knows — or suspects — that you hold significant digital assets;
  • they approach you in a context where you are vulnerable;
  • they apply physical or psychological pressure to obtain your seed phrase, your PIN codes, or access to your hardware wallet.

No phishing. No malware. No cryptographic vulnerability. The coercion is direct and human.

Why this risk grows with visibility

The wrench attack is not new. It existed long before Bitcoin, in other forms. What changes with self-custody is the combination of three factors:

1. The immediate liquidity of assets. A crypto transaction is irreversible and near-instant. Coercing someone into sending funds to a third-party address takes under two minutes. There is no reaction window.

2. The absence of an intermediary. With a bank account, a third party can block the transaction, trigger an alert, freeze the funds. In self-custody, no institutional safety net exists.

3. Public or semi-public visibility. Attending crypto conferences, mentioning amounts on social media, displaying visible signals (Ledger stickers, branded merchandise, public conversations): each signal increases your exposure surface.

The attacker doesn't need to know exactly what you hold. A sufficiently motivated suspicion is enough.

What this threat changes in your thinking

Against a digital risk, the response is technical: stronger passphrase, hardware wallet, air gap, multisig. These solutions are relevant and necessary.

Against a physical risk, the response is different. It rests on two pillars:

Discretion as the first line of defense

Not disclosing what you hold — neither the amount, nor the devices you use, nor their location — remains the most effective protection against a wrench attack. An attacker who doesn't know your situation cannot target it.

This doesn't mean paranoia. It means distinguishing contexts: what you share with trusted peers, what you publish, what you leave visible in your home environment.

Physical storage as the second line

If discretion is compromised — through an overheard conversation, a deteriorated relationship, an unforeseen situation — the question becomes: where is your hardware wallet? Where is your seed phrase?

A Ledger sitting on a visible desk, or stored in a standard drawer, is accessible within seconds to anyone in your home. A seed phrase stored in a text file or an undisguised notebook presents the same problem.

This is where secure physical storage changes the equation — not because it makes coercion impossible, but because it removes immediate access. If your sensitive assets cannot be located or retrieved within thirty seconds, the wrench attack scenario loses much of its practicality.

Where to store your Ledger: wrong answers and better ones

What doesn't work

  • An ordinary locked drawer. Standard drawers yield easily. The key is often nearby.
  • A freestanding safe placed on the floor or unfixed. A portable safe offers no more protection than a bag.
  • An "obvious" hiding spot. Under the mattress, the back of a wardrobe, a cereal box: these locations are known to anyone who has ever conducted a quick search.
  • A location memorized by people around you. If several people know where your hardware wallet is, your exposure surface scales with that number.

What works better

The goal is not absolute impermeability — no device can guarantee that. The goal is to remove immediate access and to make the location non-obvious.

Several complementary approaches:

  • Separate the hardware wallet from the seed phrase. The two should never be in the same place. An attacker who finds one without the other cannot access the funds.
  • Use an additional BIP39 passphrase. Even if your hardware wallet is seized, a memorized passphrase — one that is never written down — protects the associated funds. This is one of the few technical measures that remains partially effective against physical coercion.
  • Store in a concealed, fixed space. A wall-mounted safe sealed into the building's structure, discreet by design, answers this logic: it cannot be seen, it cannot be moved, it cannot be carried away.

A wrench attack is not inevitable

This risk deserves to be understood, not simply endured. The most exposed holders are often those who have thoroughly secured the digital perimeter — and left the physical perimeter without an answer.

The response is not technical in the cryptographic sense. It is organizational: discretion about exposure, separation of sensitive elements, deliberate physical storage.

Knowing where to store your Ledger also means understanding why location matters — and recognizing that physical security is not a logistical afterthought. It is the last line of defense when every other layer has been bypassed.


NEXOVAULT designs wall-mounted safes for the discreet storage of sensitive assets — hardware wallets, seed phrases, documents, valuables. Conceived in France, crafted in our Poitiers workshop.

← Back to blog