A hardware wallet can keep a private key away from online attackers. It cannot, by itself, stop someone from threatening the person who can unlock it. And if that one person dies without a workable recovery plan, the same arrangement can leave their family unable to access the Bitcoin at all.
That is the central weakness of single-key custody: one signing key or its seed phrase is sufficient to move everything. The issue is not that self-custody is a mistake. It is that a single point of control also becomes a single point of failure.
What is a Bitcoin wrench attack?
A wrench attack is physical violence, kidnapping or intimidation aimed at making a person give up access to cryptocurrency. The name describes a simple threat: a criminal does not need to break the cryptography if they can force the owner to make the transfer. A hardware wallet protects against some remote attacks; it does not make a person immune to coercion. TRM Labs explains the threat.
The most confronting example is the January 2025 kidnapping of David Balland, a Ledger co-founder, and his partner in France. They were taken from their home and held while kidnappers demanded a cryptocurrency ransom. Balland was freed after a police operation and treated for injuries. Reuters reported the kidnapping and rescue. Subsequent reporting said his hand was mutilated; Le Parisien reported that a finger had been cut off. Balland was not Ledger's CEO. The company's chief executive was Pascal Gauthier, and Balland no longer worked there at the time of the attack, according to Reuters' follow-up.
We do not know what wallet arrangement Balland personally used, and this case should not be presented as proof that a particular custody setup failed. It shows something broader: people associated with digital assets, and their families, can become targets regardless of how strong the underlying encryption is.
Are physical attacks on crypto holders increasing?
Security firm CertiK counted 72 verified physical coercion incidents worldwide in 2025, 75% more than in 2024. It reported confirmed losses of more than US$40.9 million, with Europe accounting for over 40% of recorded incidents. These are the firm's documented cases, not a complete count of all attacks or an Australian incidence rate.
That distinction matters. Security researcher Jameson Lopp's public incident tracker explicitly warns that many attacks are never reported. An academic study of wrench attacks likewise found underreporting and observed that technical experience did not make holders immune to physical threats. The trend is serious, but sensational headlines should not replace a realistic assessment of your own exposure.
Three ways a single key can fail
- The key is taken or the holder is coerced. If one seed phrase, passphrase or unlocked device is enough to spend the funds, a thief only needs that one point of access. A second copy of the same seed in another location helps with loss, but does not remove this theft risk.
- The key is lost. A fire, damaged backup or forgotten passphrase can permanently cut off access if there is no valid recovery path. A hardware wallet is replaceable; the only remaining seed may not be.
- The holder dies or loses capacity. A will can express who should receive Bitcoin, but it cannot sign a transaction. If the executor cannot locate the right recovery material or does not know how to use it safely, the estate may be unable to deliver the asset. See our executor's recovery guide.
Single-key custody can still be a reasonable starting point for a small balance when the holder understands its limits. The question is whether it is sufficient for a meaningful long-term holding or an asset your family will need to inherit.
How multisig changes the risk
In a 2-of-3 multisignature wallet, three independent keys exist and any two are needed to move the Bitcoin. If the keys and their backups are genuinely separated, taking one key does not immediately grant control. Losing one key does not immediately make the wallet unrecoverable either: the other two can still sign.
This can also reduce a particular coercion risk. If a holder does not have two signing keys or their backups within reach, that holder cannot move the whole balance alone. But multisig is not a guarantee of personal safety. An attacker may threaten family members, force contact with another signer or not believe that a second signature is needed. In a violent situation, protect people first and contact emergency services. The point of distributed custody is to avoid making any one person the sole technical route to the funds, not to promise that violence will stop.
The design only works if the keys really are independent. Keeping two keys and their backup phrases together defeats the purpose. So does giving one service provider enough material to reconstruct two signing paths. Test recovery, document who can coordinate signatures, and keep the wallet's configuration information available to the people who need it. Bitcoin's PSBT standard describes how partially signed transactions can be passed between signers without bringing their keys together.
What an Australian family's plan needs
A safe custody arrangement should answer two questions at once: Who can authorise a transaction today? And who can lawfully and practically arrange recovery if the holder dies or loses capacity? Those are not the same question.
For an Australian estate, work with your solicitor to record the Bitcoin in your estate plan and identify the people with the authority to act. Keep seed phrases and PINs out of the will, which may be seen by others during estate administration. A separate, securely held instruction letter can identify the wallet arrangement, where to find the non-secret recovery documentation, and whom the executor should contact. The nominated digital agent can support the executor with the technical steps without being given unilateral access. The ATO's deceased-estates guidance is a starting point for estate obligations; legal and tax advice should be tailored to the family's circumstances.
Review the plan after a move, a change in family circumstances, or a change of signer. Periodically confirm that the remaining signers can complete a recovery without asking anyone to disclose a seed phrase. Good custody is not a box you tick once; it is a process that must still work when life does not go to plan.
A practical next step
Write down your current arrangement without writing down the actual keys: how many independent signing keys exist, who can access them, what happens if one is lost, and how an executor would find the right people. If every answer ultimately depends on you and one seed phrase, consider a properly documented multisig design. Our multisig explainer covers the basic structure, and our custody and estate planning service explains how we work with Australian families and their lawyers.
General information only. This is not personal security, legal, tax or financial advice.


