
Crypto Wrench Attacks Just Got Easier: 678,000 French Tax Records Are for Sale
Most data breaches leak credentials. This one leaks something more valuable to a criminal: who is worth robbing, and where they sleep.
A hacker is offering a trove of records allegedly stolen from France's tax authority, the DGFiP, according to French cybersecurity outlet FrenchBreaches. The file covers more than 678,000 people and businesses - 392,867 individuals and 285,570 professionals - and is being offered for a few thousand euros.
France is also, by every available count, the epicentre of physical attacks on crypto owners. Those two facts belong in the same sentence, and that is the problem.
What is actually in the file
A sample reviewed by FrenchBreaches included names, birth details, home and email addresses, phone numbers, income figures, withholding tax rates, family status, dependents and tax-share information.
The income breakdown is what turns a database into a shopping list. According to the report, 26,805 individuals show reference tax income of at least $116,000, 386 are above $1.16 million, and eight are above $11.6 million.
An attacker no longer has to guess who has money. The dataset ranks targets by wealth, attaches a home address to each one, and tells them how many people live there.
How it happened
FrenchBreaches said the DGFiP has officially confirmed an intrusion into its information system. Stolen credentials were used in late June to reach and extract taxpayer data, and the number of people affected remains under investigation.
The report describes an attacker using stolen VPN credentials together with an internal search tool to pull names, contact details, tax identifiers, income figures, withholding rates and family information before officials cut off access.
There is no exotic exploit in that description. Valid credentials and a legitimate internal search function did the work - which is why "our systems were not breached" is a weaker reassurance than it sounds. The tooling that makes a tax authority efficient is the same tooling that makes a credential theft catastrophic.
Why income data is a different class of leak
A password dump is a security problem with a remedy: rotate credentials, enable hardware keys, move on. An income-and-address database has no remedy. You cannot rotate your home.
It also removes the step that has historically protected most crypto holders - obscurity. Criminals rarely know which of their neighbours holds self-custodied assets. A tax file answers the wealth question directly, and the crypto question can then be inferred from the things people publish themselves: wallet addresses tied to real names, portfolio screenshots, conference photos, forum history.
Data sold once gets resold. The correct mental model is not "an incident that has now been contained" but "a standing condition that changes the threat model permanently".
The wrench-attack backdrop
The term "wrench attack" comes from a well-known cartoon: rather than break the encryption, hit the owner with a wrench until they hand over the key. It is no longer a joke about theoretical threat models.
CertiK verified 52 physical attacks on crypto holders worldwide in the first half of 2026, up from 39 in the same period a year earlier, with 33 of them in France. It also found home invasions had overtaken kidnapping as the most common method - a shift that matters, because a home invasion requires exactly one piece of information: the address.
Chainalysis counted 46 attacks through June, 30 in France, with more than $30 million stolen, and said the year was on course to be the worst on record. The two datasets differ in methodology; they agree on direction and on geography.
"Criminals have recognised that crypto holders are high-value targets because they possess wealth in an instantly and irreversibly transferable form," Chainalysis wrote.
That sentence is why a tax leak is a crypto story. Ordinary financial fraud requires laundering through reversible systems and cooperative intermediaries. A coerced on-chain transfer requires neither. Once an attacker knows income bracket and street address, the only remaining unknown is whether that wealth can be extracted under duress - and the attack statistics show a growing number of criminals willing to test it in person.
Jameson Lopp, chief security officer at Bitcoin custody firm Casa, put it bluntly on X: "More bad news for Bitcoiners living in the leading country for wrench attacks. The French tax authority has been hacked, and 678K records leaked."
It is not only tax authorities: the vendor chain leaks too
Governments are not the weakest link. The delivery pipeline for hardware wallets has produced the same class of data, repeatedly.
Trezor disclosed on Thursday that ShipMonk, a shipping provider that stores and ships its products, had told the company on Monday that an unauthorised party reached systems holding customer data. Some 11,742 customers had their full details taken; another 1,947 had names, cities and email addresses exposed - 13,689 people in total. Those affected placed orders between May 10 and August 8, shipped to the United States, United Kingdom, Sweden, Colombia, Brazil, Italy or Portugal.
Trezor said its own systems were not compromised and that no device, private key or wallet backup was touched. It credited a policy requiring partners to delete or anonymise order data 90 days after delivery for limiting the blast radius, and said that in 13 years it had never previously had a breach exposing customer phone numbers and shipping addresses.
The precedent everyone in that customer list is thinking about is Ledger's. After roughly 272,000 Ledger customers had names, addresses and phone numbers published in 2020, some began receiving ransom demands that threatened violence, along with phishing calls from people who spoke as though they knew them. Ledger also disclosed a breach at its e-commerce partner Global-e in January of this year.
To its credit, Trezor's answer addresses the actual failure: it is accelerating an Anonymous Delivery option using locker pickup, neutral packaging, generic sender details and automatic deletion of shipping identifiers, targeting the European Union by September and the United States by year-end. That is the right shape of fix - stop generating the data rather than promising to guard it better.
The phishing wave arrives first
Physical risk is the tail event. The immediate, near-certain consequence of a leak like the DGFiP's is fraud that no longer looks fraudulent.
As FrenchBreaches noted, a scammer holding genuine tax information and aware of a taxpayer's prior dealings with the authority can construct a message far more credible than a generic fake. Expect contact that quotes a real withholding rate, names an actual dependent or cites a correct income figure, and then routes the target toward a verification page, a wallet-draining signature or a call from a convincing fake fraud desk.
Advice to "check for spelling mistakes" is obsolete against an attacker holding the same records your government holds. The only durable rule is procedural: never act on inbound contact, only on channels you initiate yourself.
Why holders are already moving custody
The custody conversation shifted this summer for an unrelated reason, and the two trends are now compounding.
Galaxy Research, tracking the Coldcard seed-recreation exploit since it opened on July 30, said the attack has drained more than 1,778 BTC - roughly $112 million - and that the final figure will likely be higher. The root cause was not phishing or malware: a 2021 firmware update rerouted seed generation off the hardware random-number chip onto a software stand-in, collapsing key strength from 128 bits to as low as 40, which let attackers rebuild seeds from a device's serial number and clock state without ever touching the hardware. Galaxy's largest confirmed wave took 1,082.65 BTC from 1,195 addresses in the opening minutes, and across three proven waves and 41 smaller footprints it charts more than 5,200 drained addresses.
The aftermath is visible on-chain in a second way. Casa attributed part of the roughly 233,000 BTC that left long-term holder wallets around the breach - worth around $15 billion - to Ledger and Trezor owners rather than Coldcard customers, moving into multi-signature setups after watching the exploit unfold.
In other words: a large cohort of holders is restructuring custody right now, at the same moment their names, addresses and income brackets are circulating in criminal markets. Restructuring under time pressure is exactly when mistakes happen, and phishing operators know it.
A defensive baseline
For anyone in an exposed population - and realistically for anyone whose holdings are guessable from public activity - the priorities shift from account security to personal security.
- Treat the exposure as permanent. Assume the file is in circulation indefinitely and plan for a threat that does not expire.
- Break the link between identity and holdings. Reused addresses tied to a real name, portfolio screenshots and public event photos are the enrichment layer that turns a tax record into a target profile.
- Split custody so no single location can complete a transfer. A multisig arrangement distributed across locations, and ideally across people, removes the point of coercion: what cannot be moved from one place under duress is worth less to an attacker. For a company the same scheme cuts the other way: a 3-of-3 arrangement can stall a sale exactly when cash is needed.
- Keep a plausible duress balance. A modest, visible hot wallet is a realistic answer to a demand made in person. A single vault holding everything is not.
- Harden the physical layer. Deliveries to lockers or alternative names, neutral packaging, no visible hardware wallet boxes in the household rubbish, and deliberate caution about who knows your address.
- Rehearse the response. Everyone in the household should know what to do if someone appears at the door claiming an emergency involving your accounts.
- Verify all tax and exchange contact out-of-band for the foreseeable future, using numbers and addresses you already had.
One structural point deserves stating plainly, because it cuts against the usual self-custody maxim: withdrawal controls, time delays and human review are a genuine security property when the threat is a person in your home rather than a hacker on the network. Coercion does not produce an instant irreversible transfer where those controls exist. That trade-off is worth weighing honestly rather than dismissing.
Bottom line
The DGFiP breach did not move a single satoshi. It did something more durable: it published, to anyone willing to pay a few thousand euros, an income-ranked list of French households with addresses attached - in the country already leading the world in physical attacks on crypto owners, during a year that Chainalysis says is on course to be the worst on record. The next twelve months of attack statistics will measure how much that matters.
FAQ
What is a wrench attack?
A physical attack in which criminals use violence or the threat of violence to force a crypto holder to transfer funds, rather than attempting to break cryptography or compromise a device.
How common are wrench attacks in 2026?
CertiK verified 52 worldwide in the first half of the year, up from 39 a year earlier, with 33 in France. Chainalysis counted 46 through June with more than $30 million stolen and described the year as on course to be the worst on record.
Was any crypto stolen in the France tax breach?
No. The breach exposed taxpayer records - names, addresses, income figures and family details. The risk it creates is targeted fraud and physical targeting, not direct theft of funds.
Does a hardware wallet protect me from this?
Not from this threat class. A hardware wallet protects keys from remote compromise. It does not help when an attacker knows your address and can compel you to unlock it, and - as the Trezor and Ledger shipping breaches show - buying one can itself generate a record of your name and address.
What actually reduces physical risk?
Reducing the information available about you, and distributing custody so that no single person in a single location can complete a transfer. Geographic multisig, a plausible small hot wallet, anonymous delivery and disciplined social-media hygiene do more than any additional device.
Crypto markets expert and head of content and marketing at EIDEX. Covers market structure, exchange infrastructure and cross-chain trading — turning on-chain data and market shifts into clear, actionable research for traders.


