A structured analysis of 224 publicly reported cases. This report does not answer “how large is the risk”—public data cannot answer that. It answers a more useful question: When an attack actually occurs, what works—and what only appears to work.
Before looking at any number, one limitation must be accepted: the database includes only cases that werepublicly reported. It describes the distribution of known cases, not the distribution of actual events. The gap may be large.
France leads with 44 cases, followed by the United States with 35.This must not be read as “France is the most dangerous.” France has specialist crypto-crime prosecutors (JIRS/PNACO) that proactively publish cases; police and media disclosure is substantially higher than in most countries.
A more plausible explanation is:France’s number is closer to reality, while other countries are severely undercounted. This report therefore does not publish a “country-risk ranking.”
Cases jumped to 63 in 2025; the first eight months of 2026 already contain 43. The natural question is:Is this related to the crypto price cycle? The answer is: “Yes, but probably not in the way you think.”
Case counts and BTC priceboth have long-term upward trends. Put two rising series together and the correlation is naturally high. That is not the same as “higher prices cause more crime.”
The test usesfirst differences: instead of absolute levels, it asks whether year-to-year changes move together.
During price increases, four things rise together:wealth visibility(media coverage and social display), the fiat revaluation of on-chain balances、expected criminal proceeds, andnews-media attention to crypto。
The last factor is especially important—it can increase both the number of real cases and the proportion that are reported, while this database observes only the latter.Part of the curve’s steepness may therefore reflect greater visibility, not more crime.
If the driver is “old public information suddenly becoming more valuable,” then waiting until wealth is repriced and publicized before upgrading protection means the window has already closed。
The database already contains examples: a Houston victim was targeted after disclosing holdings on social media; perpetrators in Istanbul arrivedtwo monthsbefore the attack to conduct reconnaissance. Attack preparation is measured in months.
The 43 cases recorded through 17 August mechanically extrapolate to about 66 for the year.But that extrapolation is unreliable, for three reasons:
The most defensible reading is to treat the curve as“public risk-signal intensity”, not incidence. It shows the issue becoming more visible, but not precisely how much more severe it has become.
In 94 cases (42.0%), attackersfailed to obtain crypto assets. Calling this a “42% attack-failure rate” misleads twice: once about money and once about people.
In 18 cases, attackers unable to obtain crypto switched to physical valuables. “Crypto assets remained secure” and “the loss was zero” are entirely different outcomes.
Failure to obtain assets does not make attackers stop; it often lengthens control and escalates coercion. In the longest detention in the database—17 days in SoHo—the victimnever surrendered the password—at the cost of 17 days of torture.
Financial outcome and physical safety are independent dimensions. No inference that “strong asset protection equals safety” is supported by these data.
Of 353 victims, only 235 were the attackers’ intended “targets.” The other 118—partners, children, parents and bystanders—were pulled in simply because they were present.
The point estimate is 31.7%, but after sampling variation and coding error, the plausible range is 24%–42%.This report refuses to present “31.7%” as precise—because that would imply more reliability than the data contain.
The vertical line is the point estimate; the band is the 95% confidence interval (Wilson score plus two-way adjustment using the upper coding-error bound). Wider bands mean greater uncertainty.These intervals do not cover unreported cases—see Section Eight.
Four men wearing Canada Post uniforms entered a home and controlled a family of three forthirteen and a half hours. They used waterboarding, beatings and death threats and took more than C$2 million in Bitcoin.
The victims included a minor daughter. The database contains 23 cases involving minors.
Personal asset segregation—cold wallets, multisig and tiered storage— cannot protect people outside your control. When attackers cannot extract assets directly from a holder, pivoting to family members is a recurring pattern.
In an extreme case, the target was evena holder’s friend in another country—the person kidnapped was a 25-year-old woman with no connection to crypto assets.
The discovery channel is “unknown” in 56.2% of cases, and only 31.3% reach C2/C3 evidence quality for this field. The report thereforedoes not rank the “most common leak channels”—the known distribution may simply show which channels are easiest for reporting to reveal.
The clearest chain involves a Houston creator with millions of followers. Prosecutors identified his disclosure of “more than US$20 million in crypto” as a trigger for the targeted robbery.
This risk can be reduced through behavior change.
In the Hauteroche case in France, reporting explicitly states that the victim was identified because “data related to cryptocurrency transactions had been stolen”.
More concerning is the San Francisco Bay Area series: investigators believe offenders obtained home addresses bycompromising victims’ food-delivery accounts. This risk sits beyond an individual’s direct control.
The shortest trust-building period in the database involved a victim and offenders who met at a hotelthe same day, dined the same day and carried out the abduction the same day.。
In another case, the parties hada two-year trading relationship—a long relationship still provided no guarantee of safety.
Sixty-nine attacks occurred at a residence. Among identifiable approach methods, arriving under a false identityappears across the widest range of countries.
Recorded disguises include food-delivery couriers, parcel couriers, Canada Post and USPS workers, painters, construction workers, false police and false military personnel.
In one case, offenders placedsomeone else’s parcel in front of the doorbell camera; the resident saw a parcel on the monitor and opened the door. A security device was turned into bait.
The database contains eight cases involving serving law-enforcement officers, plus ten cases of impersonation. The two forms of genuine officer involvement differ sharply:
Pre-planned group involvement—officers help plan and provide official vehicles or identity cover; Abuse of official access—a victim is lawfully detained for another matter, and officers exploit access to the victim’s phone opportunistically.
The latter means:in some jurisdictions, “cooperating with law enforcement” can itself create exposure.
The database contains eight Hong Kong cases. More important than that count is thatChinese victims appear across eight different countries and regions—from Bangkok, Ho Chi Minh City and Manila to Istanbul and Vancouver. This is a cross-border victim pattern, not a local issue.
In the Hong Kong cases, attacks rarely occurred during negotiation. They occurred atthe moment physical cash changed hands: a vehicle transaction outside a North Point hotel, outside an exchange on Wing Lok Street, and outside a Nathan Road building in Tsim Sha Tsui.
In one case the victim wasthe seller—he had already delivered the crypto and was counting HK$3 million in cash when the vehicle was blocked and the cash taken back. “Transaction complete” does not mean the risk has ended.
Two employees of a Japanese company specializing in crypto and luxury goods carried¥1 billion in cash(about US$6.3 million) to an exchange to convert it into Hong Kong dollars. A group armed with long knives robbed them outside. The event lasted about 30 seconds.
Fifteen people were later arrested. It is the largest single street-robbery cash loss in the database.
A 27-year-old Turkish man carried luggage containing about €5 million in cashto exchange for crypto. Two men armed with long knives attacked him outside the Golden Crown Court building on Nathan Road, cutting his forehead.
But he kept the money.One of the database’s rare “injured but no financial loss” cases.
In a 2021 New Territories kidnapping, police identified offenders as belonging toa Sun Yee On branch. They struck the victim’s legs with a hammer, causing fractures, and demanded bank and crypto-account passwords. Seven were arrested; about eight others, including a group leader, were wanted.
It is the database’sonly crypto robbery in which police formally identified a traditional organized-crime group.
In July 2024, two women abducteda young childfrom a mall and demanded USDT from the family. The child was rescued safely and two suspects were arrested.
The case shows that even if a holder is well protected,family members form an entirely independent attack surface。
| Location | Circumstances | Outcome |
|---|---|---|
| Istanbul, Türkiye 2026-01 |
A 38-year-old Chinese businessman was invited to dinner by a woman who flew from China specifically to meet him, then abducted by four men. Offenders had traveled there in December 2025 to conduct reconnaissance. | Killed About US$2.5 million moved |
| Manila, Philippines 2025-03 |
A Chinese-Filipino entrepreneur and his driver were kidnapped; the family paid about ₱200 million in crypto ransom through multiple transfers. | Killed despite payment |
| Pathum Thani, Thailand 2024-08 |
Four Chinese nationals entered a gated luxury residential compound and threatened a Chinese resident with weapons. | About US$2 million lost |
| Ho Chi Minh City, Vietnam 2025-02 |
A Chinese man was abducted as he left a vehicle, detained in a remote location, and a ransom of more than 600,000 USDT was demanded. | Police solved the case in four hours Rescued |
| Bangkok, Thailand 2025-12 |
Two men posing as police kidnapped a Chinese man and demanded ransom from his brother. | Paid |
| Port Moody, Canada 2024-04 |
One defendantflew from Hong Kong to Vancouverspecifically to participate; the family endured 13.5 hours of waterboarding and coercion. | More than C$2 million That defendant received seven years |
1. Cross-border offending is now a documented pattern.Offenders traveled from China to Türkiye for reconnaissance, from Hong Kong to Vancouver to join an attack, and Chinese groups targeted Chinese residents in Thailand.The assumption that “overseas is safer” does not hold—shared language and social networks may make it easier for same-ethnicity offenders to approach a target.
2. Familiar channels such as WeChat are documented entry points.The earliest Hong Kong case in the database (2018) began through WeChat contact with a seller. In P2P settings,a referral from an acquaintance provides no additional safety guarantee。
3. Large physical-cash settlement is a distinctive high-risk point in Chinese networks. All five Hong Kong OTC robberies involved physical cash—a materially higher share than in the sample elsewhere.
This is the question holders care about most—and the question on which this reportmost explicitly refuses to advise. The reason is not insufficient data; the data themselves say the outcome cannot be predicted.
| Case | Payment | Outcome |
|---|---|---|
| France · 2023 | €30,000 actually paid (misreported as €1.7 million) | Released |
| Canada · 2023 | Paid | Released |
| Philippines · 2025 | Paid | Still killed |
| Ukraine · 2024 | 3 BTC transferred | Strangled and buried after transfer |
Buenos Aires, Argentina: after receiving US$43,000, offenders recorded the victim under coercion and sent the video to family in Russia,then demanded another US$100,000。
Tallinn, Estonia: the victim escaped by biting off an attacker’s finger, yet weeks later received Telegram photographs of his home and a demand for 30 BTC.
“This event is over” and “I am safe” are not the same thing.
About US$11.8 million of the US$12.5 million in USDT was frozen and widely reported as “94% recovered.” But the database review foundno record that the money was returned to the victims.
A Malaysian case is clearer: a US$2.46 million freezelasted only nine months, and the disposition after expiry remains unknown.
The cases below are ordered bywhat each one demonstrates, not by amount or brutality. Victim identities are tiered and minimized; cases involving minors receive the highest level of protection.
AChinese-Filipino entrepreneurand his driver were kidnapped and held. Offenders demanded US$20 million; the family paid about ₱200 million。
Both victims were still killed. Their bodies were later found. The Philippine National Police Anti-Kidnapping Group arrested three suspects; one surrendered and confessed. All three were charged with two counts of kidnapping resulting in death. About US$205,000 was also frozen by police and the anti-money-laundering authority.
This is a central reason the report refuses to advise whether ransom should be paid.
A Moroccan crypto holder was abducted by four people outside his home and taken to an abandoned building, where he was forced to transfer about 2.55–3 BTC(approximately US$170,000–207,000).
After the transfer, he was strangled and buried. A Ukrainian special police unit, including KORD, solved the case. Four suspects aged 24–29 were charged and prosecutors sought life imprisonment.
The amount was not exceptional, but the outcome was the worst possible.Severity of harm is not correlated with the amount involved—a recurring pattern in the database.
A couple were lured to a meeting by people posing as investors and abducted. The offendersbelievedthe man’s wallet held substantial digital assets and used knives and torture to demand access.
They failed.They then killed and dismembered the couple and buried them in the desert. Accomplices helped plan, rent vehicles and secure a villa. Three suspects were later arrested in Russia.
The attackers’ intelligence was wrong, but the violence did not diminish—it escalated.
A 35-year-old Bitcoin investment-scheme operator was held and tortured for three days byten former members of his investment team, who demanded credentials to ₹450 million (US$62.5 million) that he claimed was inaccessible after an “account hack.”
The offenders never obtained the password.The victim died from his injuries on the third day. Associates took him to two hospitals, where he was declared dead, then left his body in a hospital car park and fled.
More importantly, whether the US$62.5 millionever existed was never established。
A father of two was beaten and shot dead at home. Police saida close friendtold others that his Bitcoin wallet held US$10,000 and connected them to carry out the crime.
A suspect said the wallet containedonly about US$400. While offenders tried to access it through his phone, they shot him twice when he attempted to identify them.
One leaked fact, one stale balance, one life.
A game developer and crypto collector publicly stated that under weapon threats, abduction and threats of sexual violence, he was forced to surrender about US$24 million in stablecoins. He said offenders placed an axe against his hands and feet.
The victim offered a public 10% recovery reward. An on-chain security firm initially misclassified the transfer as address poisoning; the victim clarified that it was unrelated.
The largest confirmed Hong Kong loss in the database and the largest verified loss in Asia.
Three family members anda household employeewere abducted. Afterfive daysof detention, offenders forced a transfer of about US$15 million in crypto and released all four near a dry cleaner.
The facts appear in a 44-page FBI affidavit. Investigators recovered receipts, unused zip ties and surveillance footage from rental vehicles, a suburban short-term rental and several shops. Six men were charged with kidnapping.
The household employee had no connection to crypto—he was simply present。
Offenders posing as UPS couriers entered a home, used firearms and tape, beat residents andthreatened to sever fingers, whilereceiving instructions remotely by phoneto force transfers of about US$13 million in BTC and ETH.
Three Tennessee men were indicted by a federal grand jury. Investigators said the group obtained addresses bycompromising victims’ food-delivery accounts and carried out a series of attacks in San Francisco, San Jose, Sunnyvale and Los Angeles.
Remote direction by phone means:subduing the people on scene may not stop an asset transfer.
Several executives linked to a major exchange’s VIP client were lured there on abusiness trip, abducted and forced to transfer approximately US$12.5 million in USDT from their wallets.
The exchange’s head later said on-chain tracing and the stablecoin issuer helped freeze about US$11.8 million and move it to a secure wallet, producing a “94% recovery rate.”
But the database review found no record that the funds werereturned to the victims. Frozen is not the same as recovered.
Four men—two wearingCanada Post uniforms—entered a residence under the pretext of delivery and controlled a husband, wife andminor daughterfor approximately 13.5 hours. They used waterboarding, beatings, threats of sexual violence and death, and took more than C$2 million in Bitcoin.
The daughter escaped and called police. One defendant whoflew from Hong Kong to Vancouverspecifically to participate received seven years; other accomplices remain at large.
This is the first case in the database in whichwaterboarding was recorded as actually carried outrather than merely threatened.
A 28-year-old Italian man was held bytwo business partnersfor 17 days. He was bound, whipped with electrical cable, electrocuted after his feet were immersed in water, forced to take drugs, cut on the leg with a chainsaw and at one point suspended outside a fifth-floor window.
He never surrendered the password.On 23 May he escaped and sought help from a traffic officer, who called police.
Reporting explicitly states that his refusal “only brought more extreme violence.” It must never be converted into advice to refuse credentials.
Six men, including two minors, followed a holder and tried to drag him into a vehicle. The victim alerted someone close to him; the offenders fled and policearrested all six at the scene。
Dijon judicial-police investigators confirmed:this was the same group’s fourth kidnapping attempt against the same victim. Details of the first three were never reported. The victim is now under permanent police protection.
Only the fourth attempt, ending in on-scene arrests, revealed the full history. This suggests attempted cases may be far more underreported than completed ones.
The founder of a crypto-gambling group, worth more than A$2.2 billion, was ambushed in his apartment stairwell by two men posing aspainters. They tried to force him into a rental van. One, a former Greco-Roman wrestler, covered his mouth; the victim bit off the attacker’s index fingerand escaped. The severed fingertip was later found about 100 meters away.
Weeks later, however, offenders sent himphotographs of his homevia Telegram and demanded 30 BTC.
A successful escape does not mean the threat is over.
Three armed men entered a home at dawn, beat and tied up a couple, and searched for crypto assets.
Neither victim held any cryptocurrency.The offenders acted on false intelligence and obtained nothing. Three suspects were briefly located north of Paris but escaped; no arrest was found by the review cut-off.
The database now contains ten cases of incorrect attacker intelligence, six in 2025–2026. “I do not own that much crypto” is not protection.
This section does not provide a checklist. It does something else: it examines widely repeated advice item by item and askswhether the data actually support it。
The database includes only cases in which peoplewere attacked. There is no control group of high-net-worth holders who were not attacked.
The database thereforecan never calculate the “effectiveness rate” of any protective measure. It can say only that a measure prevented or reduced loss in N cases—not that it lowers risk by X%. Any analysis claiming the latter is wrong.
| Popular advice | Evidence status | What the data actually show |
|---|---|---|
| Fight back against attackers | Evidence unreliable | The observed “success rate” for resistance is 8/8.That figure cannot represent reality—failed resistance resulting in severe injury or death is unlikely to be reported as a “resistance case.” This is classic survivor bias. |
| Tiered storage / decoy wallet | Sample insufficient | Only two relevant cases exist; inone, attackers recognized the decoyand kept asking about a second wallet. n=2 cannot support a general conclusion. |
| Do not display wealth on social media | Partly supported | Social self-disclosure was the discovery channel in 22 cases, several with clear evidence chains.But that covers only a small part of known channels—56% of discovery channels are unknown. |
| Meet in public for greater safety | Evidence against | Cases occurred in shopping-center and pharmacy car parks, cafés and hotel lobbies.The key question is not “is this public?” but “can I be moved into a controlled space?” |
| Install cameras and alarms | Limited effect | In the database,a doorbell camera was used in reverse as baitwhen a parcel was placed in view. In another case, an alarm stopped a third intrusion—but the same home had already been attacked twice. |
| Refuse to surrender the password | Extremely high cost | The SoHo victim withheld his password through 17 days of continuous torture. Reporting says refusal “only brought more extreme violence.”This cannot be offered as advice. |
The data repeatedly point to one conclusion:attackers care not about total net worth, but what they believe can be coerced out within 24–72 hours. Those figures can differ by orders of magnitude.
If the answer is “a lot,” more cold wallets have not changed the exposure—attackers do not need to break cryptography; they breakyou。
Then ask a second question:Could they bypass me through support desks, email, a SIM, family or employees? In at least one case, offenders completed operations throughremote instructions by phone.
| Asset layer | Indicative size | Control objective |
|---|---|---|
| Carry / travel layer | ≤30 days’ expenses or 0.1%–0.5% of net worth |
The portion you cansurrender on scene. Contains no core recovery material. |
| Operating-liquidity layer | About 0.5%–3% | Allowlisting, tiered approval, velocity limits and review of unusual destinations. |
| Core-wealth layer | Usually ≥90% | Even with full cooperation, the holder cannot transfer it alone or immediately. Geographically separate multi-party control and non-bypassable 24–72-hour delay. |
| Recovery and succession layer | Not routinely online | Independent legal and control paths; the holder cannot unilaterally reset every control. |
Decoy wallets, coercion PINs and disguised balances depend ondeceiving attackers. The database already contains a decoy that failed: in Los Angeles, offenders kept asking about a second wallet.
When deception fails, violence commonly escalates. A more robust objective is not convincing attackers that no money exists, but making “I genuinely cannot transfer it now” an objectively verifiable fact—through delays, multi-party approval and controllers in other locations. These controls can be shown honestly to attackers.
This may be the report’s most important section. Any crime statistic claiming precision should first state what it cannot see.
A victim in one US casenever made a police report. The case entered the public record only after the victim disappeared a year later and police reconstructed the earlier event during the missing-person investigation.
A Swedish gaming creator with millions of followers was tortured at home. Repeated searches in Swedish and Englishfound no local-media report. The case became known only because the victim described it publicly.
In Chalon, France, officials confirmed this was the same group’sfourthkidnapping attempt against the same victim. The first three never appeared in reporting; only arrests during the fourth attempt revealed the full history.
Attempted attacks are probably underreported at a much higher rate than completed attacks. Attempts may create no case, no judgment and often no news.
If that inference is correct, the report’s“attackers obtained nothing: 33.9%” figure is systematically understated—the true failure share should be higher. This is the clearest directional bias known to the report.
Four internal error-rate rounds produced 26%–40% under progressively stricter definitions. All 84 load-bearing cases received manual review, identifying six problem classes including motive miscoding, suspect-identification errors and currency-unit errors.
An external audit found five additional errors, including a contradiction in which a judicial date preceded the incident dateand the financial-definition issue discussed in Section Three. All were corrected and automated validation rules were added.