RESEARCH REPORT · 2015–2026 · DATA CUT-OFF 2026-08-17

Physical coercion attacks againstcrypto-asset holders

A structured analysis of 224 publicly reported cases. This report does not answer “how large is the risk”—public data cannot answer that. It answers a more useful question: When an attack actually occurs, what works—and what only appears to work.

224
Cases included
195 have sufficient evidence for statistical analysis
33.9%
Attackers obtained nothing
But that does not mean victims were safe
14
Fatal cases
A further 31 cases confirm torture
118
Victims who were not the primary target
Family, partners, children and bystanders: 33% of all victims
8
Countries/regions with identified Chinese victims
From Hong Kong to Istanbul, the cross-border pattern is clear
72%
Kidnapping and home-invasion share
Not random street theft, but prepared control
SECTION ONE

What these data can—and cannot—tell us

Before looking at any number, one limitation must be accepted: the database includes only cases that werepublicly reported. It describes the distribution of known cases, not the distribution of actual events. The gap may be large.

Incidents by year · 2015–2026
The dataset records 63 cases in 2025 and 43 in 2026 through August. The rise is clear, but the database cannot separate true growth from increased media attention and stronger search coverage.
2026 covers January–August only and cannot be compared directly with a full year.
Source-language distribution
There are 193 English-language sources; Chinese and Korean have only one each.
How cases were discovered
87.5% of cases originated from a single English-language list.
A critical qualification on country data

France leads with 44 cases, followed by the United States with 35.This must not be read as “France is the most dangerous.” France has specialist crypto-crime prosecutors (JIRS/PNACO) that proactively publish cases; police and media disclosure is substantially higher than in most countries.

A more plausible explanation is:France’s number is closer to reality, while other countries are severely undercounted. This report therefore does not publish a “country-risk ranking.”

Publicly reported cases · top 14 countries/regions
Bar length represents publicly reported cases, not how dangerous a place is. A high ranking more likely reflects strong police reporting, media coverage and judicial transparency—not greater danger. Low-ranked countries may simply be less visible.
SECTION TWO

Trends, price cycles and reporting intensity

Cases jumped to 63 in 2025; the first eight months of 2026 already contain 43. The natural question is:Is this related to the crypto price cycle? The answer is: “Yes, but probably not in the way you think.”

Publicly reported cases and average BTC price · 2017–2025
Bars show case counts (left axis); the line shows average BTC price (right axis, logarithmic). 2026 is excluded because it contains only eight months of data.
Public case count and BTC price
The two series clearly move together. Spearman ρ = 0.85, apparently a strong relationship.
But most of that 0.85 is misleading

Case counts and BTC priceboth have long-term upward trends. Put two rising series together and the correlation is naturally high. That is not the same as “higher prices cause more crime.”

The test usesfirst differences: instead of absolute levels, it asks whether year-to-year changes move together.

Correlation weakens materially after removing the shared trend
Correlation before and after first differencing
After first differencing, ρ falls from 0.85 to 0.57, below the usual strong-correlation threshold. This means the data cannot support the claim that “rising prices directly cause more violent incidents.”
A more operationally useful interpretation
Bull markets amplify four things at once; violence is one downstream effect

During price increases, four things rise together:wealth visibility(media coverage and social display), the fiat revaluation of on-chain balancesexpected criminal proceeds, andnews-media attention to crypto

The last factor is especially important—it can increase both the number of real cases and the proportion that are reported, while this database observes only the latter.Part of the curve’s steepness may therefore reflect greater visibility, not more crime.

Practical meaning for holders
Security upgrades should lead price peaks, not follow them

If the driver is “old public information suddenly becoming more valuable,” then waiting until wealth is repriced and publicized before upgrading protection means the window has already closed

The database already contains examples: a Houston victim was targeted after disclosing holdings on social media; perpetrators in Istanbul arrivedtwo monthsbefore the attack to conduct reconnaissance. Attack preparation is measured in months.

The 2026 figure cannot be directly annualized

The 43 cases recorded through 17 August mechanically extrapolate to about 66 for the year.But that extrapolation is unreliable, for three reasons:

The most defensible reading is to treat the curve as“public risk-signal intensity”, not incidence. It shows the issue becoming more visible, but not precisely how much more severe it has become.

SECTION THREE · CORE FINDING

“Attack failure” is a dangerous description

In 94 cases (42.0%), attackersfailed to obtain crypto assets. Calling this a “42% attack-failure rate” misleads twice: once about money and once about people.

Three levels of financial outcome
Among the 94 cases with no crypto extraction, attackers still took cash, watches or jewelry in 18. Only 76 cases left attackers with nothing.
Financial outcome funnel
“Crypto extraction failed: 42.0%” and “attackers obtained nothing: 33.9%” differ by 8.1 percentage points. Reports and media citations must not mix these definitions.
First misconception · money
The cold wallet saved the coins—not the cash and watches at home

In 18 cases, attackers unable to obtain crypto switched to physical valuables. “Crypto assets remained secure” and “the loss was zero” are entirely different outcomes.

Financial outcome × physical-harm severity
If “attack failure” meant safety, harm should be markedly lower in the failure group. The data do not support that assumption.
Financial outcome and physical-harm severity
Second misconception · people
Physical harm still occurred in 76.6% of failed crypto extractions

Failure to obtain assets does not make attackers stop; it often lengthens control and escalates coercion. In the longest detention in the database—17 days in SoHo—the victimnever surrendered the password—at the cost of 17 days of torture.

Financial outcome and physical safety are independent dimensions. No inference that “strong asset protection equals safety” is supported by these data.

SECTION FOUR

The person bearing the harm is often not the holder

Of 353 victims, only 235 were the attackers’ intended “targets.” The other 118—partners, children, parents and bystanders—were pulled in simply because they were present.

Victim roles
Each human icon represents one real victim: 353 in total, grouped by role.
Victim-role composition
Direct targets · 235 Proxy targets · 71 Collateral third parties · 47
Cases involving proxy or collateral victims
By year. Annual samples are small; the trend is indicative only.
Interval estimate · not a point estimate
24%–42% of cases involve proxy or collateral victims

The point estimate is 31.7%, but after sampling variation and coding error, the plausible range is 24%–42%.This report refuses to present “31.7%” as precise—because that would imply more reliability than the data contain.

C01 · Cases involving proxy/collateral victims24% – 42%
0%25%50%75%100%
C10-A · Crypto extraction failure (full-database definition)29% – 58%
0%25%50%75%100%
C10-C · Attackers obtained nothing21% – 50%
0%25%50%75%100%

The vertical line is the point estimate; the band is the 95% confidence interval (Wilson score plus two-way adjustment using the upper coding-error bound). Wider bands mean greater uncertainty.These intervals do not cover unreported cases—see Section Eight.

GWA-000362 · Port Moody, Canada · 2024-04

Four men wearing Canada Post uniforms entered a home and controlled a family of three forthirteen and a half hours. They used waterboarding, beatings and death threats and took more than C$2 million in Bitcoin.

The victims included a minor daughter. The database contains 23 cases involving minors.

Direct implication for high-net-worth holders

Personal asset segregation—cold wallets, multisig and tiered storage— cannot protect people outside your control. When attackers cannot extract assets directly from a holder, pivoting to family members is a recurring pattern.

In an extreme case, the target was evena holder’s friend in another country—the person kidnapped was a 25-year-old woman with no connection to crypto assets.

SECTION FIVE

How attackers find their targets

The conclusions in this section require caution

The discovery channel is “unknown” in 56.2% of cases, and only 31.3% reach C2/C3 evidence quality for this field. The report thereforedoes not rank the “most common leak channels”—the known distribution may simply show which channels are easiest for reporting to reveal.

Discovery channels · full sample including unknowns
“Unknown” must remain visible. Hiding it before calculating shares is the most common misuse of this kind of data.
Evidence grades for discovery channels
C0 = pure inference; C3 = direct evidence. More than half of channel judgments are C0/C1.

Three pathways stand out among evidence-sufficient cases

Path one · active exposure
Self-disclosure on social media · 22 cases

The clearest chain involves a Houston creator with millions of followers. Prosecutors identified his disclosure of “more than US$20 million in crypto” as a trigger for the targeted robbery.

This risk can be reduced through behavior change.

Path two · passive leakage
Data are stolen, independent of your behavior

In the Hauteroche case in France, reporting explicitly states that the victim was identified because “data related to cryptocurrency transactions had been stolen”.

More concerning is the San Francisco Bay Area series: investigators believe offenders obtained home addresses bycompromising victims’ food-delivery accounts. This risk sits beyond an individual’s direct control.

Path three · counterparties
P2P/OTC contact · 24 cases

The shortest trust-building period in the database involved a victim and offenders who met at a hotelthe same day, dined the same day and carried out the abduction the same day.

In another case, the parties hada two-year trading relationship—a long relationship still provided no guarantee of safety.

SECTION SIX

Methods of approach: what happens at the door

Sixty-nine attacks occurred at a residence. Among identifiable approach methods, arriving under a false identityappears across the widest range of countries.

Primary attack types · full sample
Kidnapping accounts for 93 cases and home invasion for 69—a combined 72.3%. The main wrench-attack pattern isnot random street robbery, but prepared control over a person or residence.
Distribution of physical approach channels
The residence is the primary approach point (69 cases). Protection must expand from “where is the wallet?” to “who can predict where I will be?”
Disguised-delivery cluster · 16 cases · 9+ countries
Uniforms, parcels, doorbells

Recorded disguises include food-delivery couriers, parcel couriers, Canada Post and USPS workers, painters, construction workers, false police and false military personnel.

In one case, offenders placedsomeone else’s parcel in front of the doorbell camera; the resident saw a parcel on the monitor and opened the door. A security device was turned into bait.

Offender group size
Human figures show group size; bars show the number of cases. Groups of 3–4 are most common.
Special offender types · case count
Some cases belong to more than one category.
A pattern that should not be ignored

The database contains eight cases involving serving law-enforcement officers, plus ten cases of impersonation. The two forms of genuine officer involvement differ sharply:

Pre-planned group involvement—officers help plan and provide official vehicles or identity cover; Abuse of official access—a victim is lawfully detained for another matter, and officers exploit access to the victim’s phone opportunistically.

The latter means:in some jurisdictions, “cooperating with law enforcement” can itself create exposure.

SECTION SEVEN · SPECIAL FOCUS

Hong Kong and Chinese victims

The database contains eight Hong Kong cases. More important than that count is thatChinese victims appear across eight different countries and regions—from Bangkok, Ho Chi Minh City and Manila to Istanbul and Vancouver. This is a cross-border victim pattern, not a local issue.

Identified cases involving Chinese victims · by location
Only cases explicitly identifying a victim as Chinese, ethnically Chinese or from Hong Kong are counted. The real number is likely higher because most reporting does not state ethnicity.
This is not evidence that “Chinese people are more likely to be attacked.” It reflects the geography of Chinese crypto participants and the reporting practices of Chinese-language media in some places.

Hong Kong’s pattern is distinctive: five of eight cases were offline transaction robberies

Composition of attack types in Hong Kong cases
Hong Kong characteristic one · cash settlement is the primary risk point
Five P2P/OTC robberies, all during the few minutes of settlement

In the Hong Kong cases, attacks rarely occurred during negotiation. They occurred atthe moment physical cash changed hands: a vehicle transaction outside a North Point hotel, outside an exchange on Wing Lok Street, and outside a Nathan Road building in Tsim Sha Tsui.

In one case the victim wasthe seller—he had already delivered the crypto and was counting HK$3 million in cash when the vehicle was blocked and the cash taken back. “Transaction complete” does not mean the risk has ended.

GWA-000295 · Wing Lok Street, Hong Kong · 2025-12

Two employees of a Japanese company specializing in crypto and luxury goods carried¥1 billion in cash(about US$6.3 million) to an exchange to convert it into Hong Kong dollars. A group armed with long knives robbed them outside. The event lasted about 30 seconds.

Fifteen people were later arrested. It is the largest single street-robbery cash loss in the database.

GWA-000234 · Tsim Sha Tsui, Hong Kong · 2025-03

A 27-year-old Turkish man carried luggage containing about €5 million in cashto exchange for crypto. Two men armed with long knives attacked him outside the Golden Crown Court building on Nathan Road, cutting his forehead.

But he kept the money.One of the database’s rare “injured but no financial loss” cases.

Hong Kong characteristic two · organized-crime involvement
A triad branch participated; hammer blows caused fractures

In a 2021 New Territories kidnapping, police identified offenders as belonging toa Sun Yee On branch. They struck the victim’s legs with a hammer, causing fractures, and demanded bank and crypto-account passwords. Seven were arrested; about eight others, including a group leader, were wanted.

It is the database’sonly crypto robbery in which police formally identified a traditional organized-crime group.

Hong Kong characteristic three · targeting family
A child taken from a shopping mall; US$660,000 in USDT demanded

In July 2024, two women abducteda young childfrom a mall and demanded USDT from the family. The child was rescued safely and two suspects were arrested.

The case shows that even if a holder is well protected,family members form an entirely independent attack surface

Cross-border patterns among Chinese victims

LocationCircumstancesOutcome
Istanbul, Türkiye
2026-01
A 38-year-old Chinese businessman was invited to dinner by a woman who flew from China specifically to meet him, then abducted by four men. Offenders had traveled there in December 2025 to conduct reconnaissance. Killed
About US$2.5 million moved
Manila, Philippines
2025-03
A Chinese-Filipino entrepreneur and his driver were kidnapped; the family paid about ₱200 million in crypto ransom through multiple transfers. Killed despite payment
Pathum Thani, Thailand
2024-08
Four Chinese nationals entered a gated luxury residential compound and threatened a Chinese resident with weapons. About US$2 million lost
Ho Chi Minh City, Vietnam
2025-02
A Chinese man was abducted as he left a vehicle, detained in a remote location, and a ransom of more than 600,000 USDT was demanded. Police solved the case in four hours
Rescued
Bangkok, Thailand
2025-12
Two men posing as police kidnapped a Chinese man and demanded ransom from his brother. Paid
Port Moody, Canada
2024-04
One defendantflew from Hong Kong to Vancouverspecifically to participate; the family endured 13.5 hours of waterboarding and coercion. More than C$2 million
That defendant received seven years
Three direct implications for Chinese holders

1. Cross-border offending is now a documented pattern.Offenders traveled from China to Türkiye for reconnaissance, from Hong Kong to Vancouver to join an attack, and Chinese groups targeted Chinese residents in Thailand.The assumption that “overseas is safer” does not hold—shared language and social networks may make it easier for same-ethnicity offenders to approach a target.

2. Familiar channels such as WeChat are documented entry points.The earliest Hong Kong case in the database (2018) began through WeChat contact with a seller. In P2P settings,a referral from an acquaintance provides no additional safety guarantee

3. Large physical-cash settlement is a distinctive high-risk point in Chinese networks. All five Hong Kong OTC robberies involved physical cash—a materially higher share than in the sample elsewhere.

SECTION EIGHT

What happens after payment

This is the question holders care about most—and the question on which this reportmost explicitly refuses to advise. The reason is not insufficient data; the data themselves say the outcome cannot be predicted.

Four outcomes after ransom payment
Four CONFIRMED cases; four entirely different outcomes.
CasePaymentOutcome
France · 2023€30,000 actually paid
(misreported as €1.7 million)
Released
Canada · 2023PaidReleased
Philippines · 2025PaidStill killed
Ukraine · 20243 BTC transferredStrangled and buried after transfer
The four cases sit at opposite extremes, yielding no reliable behavioral rule. The inability to give advice is itself one of this report’s findings.
Payment is not the end
Two cases show extortion continuing after payment

Buenos Aires, Argentina: after receiving US$43,000, offenders recorded the victim under coercion and sent the video to family in Russia,then demanded another US$100,000

Tallinn, Estonia: the victim escaped by biting off an attacker’s finger, yet weeks later received Telegram photographs of his home and a demand for 30 BTC.

“This event is over” and “I am safe” are not the same thing.

Distribution of obtained-asset value bands
Caution: about 70% of US-dollar values are estimates converted at monthly average prices and cannot support precise amount-trend analysis.
Only one case falls in the highest band (US$20m–100m). Large cases are too sparse to support a claim that amounts are rising year by year.
Latest judicial status of cases
Grouped by the latest known status per case. Green denotes convictions.
Only 21 cases reached conviction (9.4%); 92 remain under investigation.But a low conviction share does not equal law-enforcement failure—some cases remain in court. Public sources readily report arrests but rarely follow final judgments. This project has repeatedly found rulings years after an incident.
Recovery: frozen does not mean returned
What Montenegro’s “94% recovery rate” actually means

About US$11.8 million of the US$12.5 million in USDT was frozen and widely reported as “94% recovered.” But the database review foundno record that the money was returned to the victims.

A Malaysian case is clearer: a US$2.46 million freezelasted only nine months, and the disposition after expiry remains unknown.

SECTION NINE

Fourteen representative cases

The cases below are ordered bywhat each one demonstrates, not by amount or brutality. Victim identities are tiered and minimized; cases involving minors receive the highest level of protection.

I · Ransom was paid; victims were still killed

Greater Manila, Philippines · 2025-03 · GWA-000235

AChinese-Filipino entrepreneurand his driver were kidnapped and held. Offenders demanded US$20 million; the family paid about ₱200 million

Both victims were still killed. Their bodies were later found. The Philippine National Police Anti-Kidnapping Group arrested three suspects; one surrendered and confessed. All three were charged with two counts of kidnapping resulting in death. About US$205,000 was also frozen by police and the anti-money-laundering authority.

This is a central reason the report refuses to advise whether ransom should be paid.

Kyiv, Ukraine · 2024-07 · GWA-000364

A Moroccan crypto holder was abducted by four people outside his home and taken to an abandoned building, where he was forced to transfer about 2.55–3 BTC(approximately US$170,000–207,000).

After the transfer, he was strangled and buried. A Ukrainian special police unit, including KORD, solved the case. Four suspects aged 24–29 were charged and prosecutors sought life imprisonment.

The amount was not exceptional, but the outcome was the worst possible.Severity of harm is not correlated with the amount involved—a recurring pattern in the database.

II · Attackers could not obtain the money, so they killed

United Arab Emirates · 2025-10 · GWA-000274

A couple were lured to a meeting by people posing as investors and abducted. The offendersbelievedthe man’s wallet held substantial digital assets and used knives and torture to demand access.

They failed.They then killed and dismembered the couple and buried them in the desert. Accomplices helped plan, rent vehicles and secure a villa. Three suspects were later arrested in Russia.

The attackers’ intelligence was wrong, but the violence did not diminish—it escalated.

Dehradun, India · 2019-08 · GWA-000056

A 35-year-old Bitcoin investment-scheme operator was held and tortured for three days byten former members of his investment team, who demanded credentials to ₹450 million (US$62.5 million) that he claimed was inaccessible after an “account hack.”

The offenders never obtained the password.The victim died from his injuries on the third day. Associates took him to two hospitals, where he was declared dead, then left his body in a hospital car park and fled.

More importantly, whether the US$62.5 millionever existed was never established

Delta State, Nigeria · 2020-01 · GWA-000059

A father of two was beaten and shot dead at home. Police saida close friendtold others that his Bitcoin wallet held US$10,000 and connected them to carry out the crime.

A suspect said the wallet containedonly about US$400. While offenders tried to access it through his phone, they shot him twice when he attempted to identify them.

One leaked fact, one stale balance, one life.

III · The largest amounts

Hong Kong · 2026-03 · GWA-000318 · about US$24 million

A game developer and crypto collector publicly stated that under weapon threats, abduction and threats of sexual violence, he was forced to surrender about US$24 million in stablecoins. He said offenders placed an axe against his hands and feet.

The victim offered a public 10% recovery reward. An on-chain security firm initially misclassified the transfer as address poisoning; the victim clarified that it was unrelated.

The largest confirmed Hong Kong loss in the database and the largest verified loss in Asia.

Chicago, United States · 2024-10 · GWA-000197 · US$15 million

Three family members anda household employeewere abducted. Afterfive daysof detention, offenders forced a transfer of about US$15 million in crypto and released all four near a dry cleaner.

The facts appear in a 44-page FBI affidavit. Investigators recovered receipts, unused zip ties and surveillance footage from rental vehicles, a suburban short-term rental and several shops. Six men were charged with kidnapping.

The household employee had no connection to crypto—he was simply present

San Francisco, United States · 2025-11 · GWA-000366 · US$13 million

Offenders posing as UPS couriers entered a home, used firearms and tape, beat residents andthreatened to sever fingers, whilereceiving instructions remotely by phoneto force transfers of about US$13 million in BTC and ETH.

Three Tennessee men were indicted by a federal grand jury. Investigators said the group obtained addresses bycompromising victims’ food-delivery accounts and carried out a series of attacks in San Francisco, San Jose, Sunnyvale and Los Angeles.

Remote direction by phone means:subduing the people on scene may not stop an asset transfer.

Montenegro · 2023-11 · GWA-000168 · US$12.5 million

Several executives linked to a major exchange’s VIP client were lured there on abusiness trip, abducted and forced to transfer approximately US$12.5 million in USDT from their wallets.

The exchange’s head later said on-chain tracing and the stablecoin issuer helped freeze about US$11.8 million and move it to a secure wallet, producing a “94% recovery rate.”

But the database review found no record that the funds werereturned to the victims. Frozen is not the same as recovered.

IV · Cases with wider implications

Port Moody, Canada · 2024-04 · GWA-000362

Four men—two wearingCanada Post uniforms—entered a residence under the pretext of delivery and controlled a husband, wife andminor daughterfor approximately 13.5 hours. They used waterboarding, beatings, threats of sexual violence and death, and took more than C$2 million in Bitcoin.

The daughter escaped and called police. One defendant whoflew from Hong Kong to Vancouverspecifically to participate received seven years; other accomplices remain at large.

This is the first case in the database in whichwaterboarding was recorded as actually carried outrather than merely threatened.

SoHo, New York · 2025-05 · GWA-000363

A 28-year-old Italian man was held bytwo business partnersfor 17 days. He was bound, whipped with electrical cable, electrocuted after his feet were immersed in water, forced to take drugs, cut on the leg with a chainsaw and at one point suspended outside a fifth-floor window.

He never surrendered the password.On 23 May he escaped and sought help from a traffic officer, who called police.

Reporting explicitly states that his refusal “only brought more extreme violence.” It must never be converted into advice to refuse credentials.

Chalon-sur-Saône, France · 2025-11 · GWA-000283

Six men, including two minors, followed a holder and tried to drag him into a vehicle. The victim alerted someone close to him; the offenders fled and policearrested all six at the scene

Dijon judicial-police investigators confirmed:this was the same group’s fourth kidnapping attempt against the same victim. Details of the first three were never reported. The victim is now under permanent police protection.

Only the fourth attempt, ending in on-scene arrests, revealed the full history. This suggests attempted cases may be far more underreported than completed ones.

Tallinn, Estonia · 2023-07 · GWA-000189

The founder of a crypto-gambling group, worth more than A$2.2 billion, was ambushed in his apartment stairwell by two men posing aspainters. They tried to force him into a rental van. One, a former Greco-Roman wrestler, covered his mouth; the victim bit off the attacker’s index fingerand escaped. The severed fingertip was later found about 100 meters away.

Weeks later, however, offenders sent himphotographs of his homevia Telegram and demanded 30 BTC.

A successful escape does not mean the threat is over.

Bondy, France · 2026-05 · GWA-000360

Three armed men entered a home at dawn, beat and tied up a couple, and searched for crypto assets.

Neither victim held any cryptocurrency.The offenders acted on false intelligence and obtained nothing. Three suspects were briefly located north of Paris but escaped; no arrest was found by the review cut-off.

The database now contains ten cases of incorrect attacker intelligence, six in 2025–2026. “I do not own that much crypto” is not protection.

SECTION TEN · THE MOST IMPORTANT SECTION FOR HOLDERS

Testing popular advice against the evidence

This section does not provide a checklist. It does something else: it examines widely repeated advice item by item and askswhether the data actually support it

A fundamental methodological limit

The database includes only cases in which peoplewere attacked. There is no control group of high-net-worth holders who were not attacked.

The database thereforecan never calculate the “effectiveness rate” of any protective measure. It can say only that a measure prevented or reduced loss in N cases—not that it lowers risk by X%. Any analysis claiming the latter is wrong.

Reviewing the claims one by one

Popular adviceEvidence statusWhat the data actually show
Fight back against attackers Evidence unreliable The observed “success rate” for resistance is 8/8.That figure cannot represent reality—failed resistance resulting in severe injury or death is unlikely to be reported as a “resistance case.” This is classic survivor bias.
Tiered storage / decoy wallet Sample insufficient Only two relevant cases exist; inone, attackers recognized the decoyand kept asking about a second wallet. n=2 cannot support a general conclusion.
Do not display wealth on social media Partly supported Social self-disclosure was the discovery channel in 22 cases, several with clear evidence chains.But that covers only a small part of known channels—56% of discovery channels are unknown.
Meet in public for greater safety Evidence against Cases occurred in shopping-center and pharmacy car parks, cafés and hotel lobbies.The key question is not “is this public?” but “can I be moved into a controlled space?”
Install cameras and alarms Limited effect In the database,a doorbell camera was used in reverse as baitwhen a parcel was placed in view. In another case, an alarm stopped a third intrusion—but the same home had already been attacked twice.
Refuse to surrender the password Extremely high cost The SoHo victim withheld his password through 17 days of continuous torture. Reporting says refusal “only brought more extreme violence.”This cannot be offered as advice.

A more useful framework: coercible value

The data repeatedly point to one conclusion:attackers care not about total net worth, but what they believe can be coerced out within 24–72 hours. Those figures can differ by orders of magnitude.

Critical self-test
If my phone and I were controlled for 12 hours, how much could the other side transfer?

If the answer is “a lot,” more cold wallets have not changed the exposure—attackers do not need to break cryptography; they breakyou

Then ask a second question:Could they bypass me through support desks, email, a SIM, family or employees? In at least one case, offenders completed operations throughremote instructions by phone.

Asset layerIndicative sizeControl objective
Carry / travel layer≤30 days’ expenses
or 0.1%–0.5% of net worth
The portion you cansurrender on scene. Contains no core recovery material.
Operating-liquidity layerAbout 0.5%–3% Allowlisting, tiered approval, velocity limits and review of unusual destinations.
Core-wealth layerUsually ≥90% Even with full cooperation, the holder cannot transfer it alone or immediately. Geographically separate multi-party control and non-bypassable 24–72-hour delay.
Recovery and succession layerNot routinely online Independent legal and control paths; the holder cannot unilaterally reset every control.
Why “credible inability to transfer” is stronger than a decoy wallet

Decoy wallets, coercion PINs and disguised balances depend ondeceiving attackers. The database already contains a decoy that failed: in Los Angeles, offenders kept asking about a second wallet.

When deception fails, violence commonly escalates. A more robust objective is not convincing attackers that no money exists, but making “I genuinely cannot transfer it now” an objectively verifiable fact—through delays, multi-party approval and controllers in other locations. These controls can be shown honestly to attackers.

The few conclusions the data do support

SECTION ELEVEN

What we do not know

This may be the report’s most important section. Any crime statistic claiming precision should first state what it cannot see.

The dark figure: three hard pieces of evidence

Evidence one · never reported to police

A victim in one US casenever made a police report. The case entered the public record only after the victim disappeared a year later and police reconstructed the earlier event during the missing-person investigation.

Evidence two · a public figure attacked, with zero reporting

A Swedish gaming creator with millions of followers was tortured at home. Repeated searches in Swedish and Englishfound no local-media report. The case became known only because the victim described it publicly.

Evidence three · disclosed only on the fourth attempt

In Chalon, France, officials confirmed this was the same group’sfourthkidnapping attempt against the same victim. The first three never appeared in reporting; only arrests during the fourth attempt revealed the full history.

What these three facts mean together

Attempted attacks are probably underreported at a much higher rate than completed attacks. Attempts may create no case, no judgment and often no news.

If that inference is correct, the report’s“attackers obtained nothing: 33.9%” figure is systematically understated—the true failure share should be higher. This is the clearest directional bias known to the report.

What this report explicitly refuses to provide

Data-quality disclosure
Known error rates and correction record

Four internal error-rate rounds produced 26%–40% under progressively stricter definitions. All 84 load-bearing cases received manual review, identifying six problem classes including motive miscoding, suspect-identification errors and currency-unit errors.

An external audit found five additional errors, including a contradiction in which a judicial date preceded the incident dateand the financial-definition issue discussed in Section Three. All were corrected and automated validation rules were added.