Paddle 412
At a Christie's evening sale the lot everyone came for is bought by a specialist standing at a bank of telephones. The room watches the specialist. The buyer is a voice.
Leonardo's Salvator Mundi sold in November 2017 for $450.3 million. Alex Rotter, then co-chairman of post-war and contemporary art, held the handset. The catalogue said nothing. It took a newspaper investigation to establish that the bidder was acting for Saudi Arabia. The most watched art transaction in history, and not one person in that room knew who had bought it.
That is not an exception, it is the default setting. Registration is confidential. The auctioneer says "sold, paddle 412". Catalogues print Property from a Distinguished Private Collection or Property of a Lady. Museum labels print Private collection. Dealers do not publish buyer lists, because the buyer list is the business.
Underneath the discretion there are layers, and each one is load-bearing. An advisor bids in their own name. Title sits in a Delaware or Liechtenstein entity. The object never leaves a bonded warehouse. The collector appears nowhere in the chain except as a beneficiary of a structure.
Four reasons, and only one is about money
Price. A collector known to want Basquiats pays more for Basquiats. Every room they walk into reprices around them. The advisor exists partly so that the market cannot read the appetite.
Safety. High value, portable, and sitting in a house. Dresden's Green Vault lost roughly €113 million of jewels in one night in 2019. Kim Kardashian was tied up in a Paris bathroom in 2016 and robbed of a ring the thieves had watched her post online. Members of that gang said afterwards that social media was how they found her.
Family. Divorce, inheritance, staff, and relatives who now know exactly what is on the wall and roughly what it is worth.
Becoming a mark. The moment you are known to own the thing, every dealer, every charity board, every fundraiser and every thief has your name on a list.
Three of those four are the same reasons a wallet goes pseudonymous. The art market simply solved for them two hundred years earlier, and with different tools.
The inversion
Here is the difference that matters, and it is not a matter of degree.
The traditional collector's name is known to the auction house and their holdings are secret. The crypto anon's holdings are known to everybody and their name is secret.
Same word, opposite structure, and the second one is much weaker. Not because the cryptography is worse. It is far better. Because of what each arrangement asks its secret to do.
A portfolio is a hard secret. It lives in one vault ledger, one insurance schedule, one confidential register that an institution is legally bound to keep and can be sued for losing. It has few copies and each copy has a name attached to its custody.
A legal name is a soft secret. It is in every exchange onboarding packet, every support ticket, every tax filing, every delivery address, every domain registration, every conference lanyard, and every database that any of those parties has ever failed to protect. It has thousands of copies and no custody chain. It only has to leak once, and it does not leak back.
So the anon is defending a public balance sheet with a single soft secret held in copy by dozens of third parties, most of whom they will never meet. That is the whole exposure. In 2026 it was priced.
CertiK Intel3D, H1 2026 Wrench Attacks, July 2026
The year the room came to the collector
A wrench attack is a physical coercion incident: violence, confinement or credible threat used to make somebody hand over keys, unlock a device, or sign. CertiK counted only incidents that were publicly reported and independently verifiable in the first six months of 2026.
Verified incidents
52
Up from 39 in H1 2025. A 33.3% rise.
Recorded exposure
$124.1m
Up from $10.5m. Roughly 11.8 times higher.
Average per incident
$2.39m
Up from about $270,000.
Home invasions
20
Up from a single publicly reported case.
Kidnappings
16
Up from 12. The category that needs planning.
Cases of torture
4
Unchanged year on year.
Murders
1
Unchanged. One confirmed case in each period.
European share
75%
39 of 52 incidents, against 35.9% a year earlier.
The concentration is extreme. France recorded 33 verified incidents, 63.5% of the global total and 84.6% of the European one. The French judicial police counted 41 incidents in the first quarter alone under a broader definition, and the interior minister put the half-year figure at 77. Around two hundred people have been arrested in connection with crypto-related kidnapping and extortion there since the start of the year, several dozen of them minors.
Everything above is the visible portion. Victims do not report, police classify these as ordinary robbery, ransoms go unrecorded, and settlements stay private. The honest reading of $124 million is that it is a floor.
Figures from CertiK's Intel3D H1 2026 Wrench Attacks report. We did not produce this research and have not independently verified the underlying incidents.
The attack is clerical work with a violent last step
The tactical shift in 2026 was not violence. It was that target selection became a desk job.
The old model needed a visible mark: the flex, the conference photo, the car. The new model does not need to watch anybody. A target package is assembled from leaked databases, exchange customer records, tax and compliance files, social profiles, ENS names, property registers, phone intelligence and public chain activity. Full name, home address, family structure, employer, estimated holdings, travel habits. The physical attack is the final stage of a process that is mostly research.
The report is blunt about where the research comes from. In France, a national employment agency was compromised, and the government portal that issues identity documents, passports and driving licences was breached, with up to nineteen million citizens exposed: name, address, date and place of birth, phone number, identity verification data. Authorities alleged that a tax administration employee sold confidential information relating to cryptocurrency holders. Kraken disclosed an extortion attempt after malicious insiders inside its client-support environment recorded systems showing client data. Dark web posts openly recruit staff at exchanges and other data-rich firms for internal access.
The chain tells them how much. The leak tells them who and where. No amount of key discipline touches either half.
The five ways in, in the order the dataset finds them: the doorbell, where an attacker arrives as a delivery driver, utility worker, neighbour or police officer. The fake meeting, where a victim is invited to an over-the-counter trade or an investment pitch in a room the attacker controls. The transit interception between two predictable points. The proxy, where a spouse, parent, child, driver or assistant is taken instead, because they have weaker security and produce more leverage. And the acquaintance, who supplies the routine.
The art market already solved this, and not with secrecy
Every anti-coercion control the security industry now recommends already exists in the art world. Most of it predates photography. It is worth reading the two columns side by side, because the crypto version keeps being presented as novel.
The company with two directors
Multi-signature and MPCTitle sits in an entity, and no single officer can sell. A trust does the same thing with a protector who has to countersign. The structure is four hundred years old and its entire purpose is that one person, alone, in a bad hour, cannot act.
The bonded warehouse
Time locks and withdrawal delaysA Geneva or Singapore freeport opens on business hours, under a two-key protocol, to a named representative. You cannot get your own painting at three in the morning. Neither can the man standing behind you at three in the morning.
One work on the wall, the rest in storage
Staged vaultsSerious collections were never in the house. What hangs at home is what the owner is prepared to lose, and the insurer prices the difference. Nobody calls this a vault architecture. It is one.
The museum loan
Transfer frictionThe picture is on a five-year loan to a public institution in another country under a contract the owner cannot unilaterally break. It is a time lock with a curator attached, and it produces a receipt in the form of a wall label.
Advisor, entity, object, owner
Geographically distributed signersThe advisor is in London, the holding company is in Liechtenstein, the object is in a warehouse near an airport, and the owner is wherever they like. No two of those are in the same jurisdiction, and no one of them can complete a sale.
Read down that list and one property repeats. In none of these arrangements does the owner refuse. In all of them the owner cannot.
That is the only property that survives a room with a wrench in it. A person who will not comply gets hurt. A person who cannot comply, provably and within the first two minutes, is not worth hurting, because hurting them does not produce the money.
A decade of custody advice has optimised for the wrong adversary. Not your keys, not your coins is a defence against a custodian going under. It is not a defence against somebody in your kitchen, and against that person a single-signer hardware wallet in a drawer is close to the worst arrangement available: total, instant, irreversible authority, held by one frightened human who can be made to use it.
What to actually do
Three layers. The first reduces the chance you are selected. The second makes selection unprofitable if it happens anyway, and it is the only layer that works once somebody is already in the room. The third is the household, which is where the report says the year's growth went.
Layer one
Stop being findable
- Never let one address be both your name and your holdings. An ENS on the wallet that holds the collection is a brass nameplate on a vault door. Keep the named address near-empty and public. Keep the holding address unnamed, unposted, and never used to bid, sign a message, or claim anything in public.
- Never ship anything crypto-branded to your home. This is the single most expensive lesson the industry has already paid for and keeps re-learning. A locker, a business address, or a forwarding service.
- Break the join between handle and legal name. One conference badge with both on it, photographed once, ends your pseudonymity permanently and retroactively. Pick which one travels and be rigid about it.
- Strip the location data. Photographs of work on your wall carry GPS coordinates in EXIF, and a window, a skyline or a light switch identifies a building to anyone who cares to look. Post the work, not the room.
- Buy your address back. People-search and data-broker sites sell your home address for the price of lunch. Removal is tedious, it works, and it needs redoing every few months because they repopulate.
- Separate the phone number. A number tied to your legal name links every account you own. Use a distinct number for exchanges and custody, put a port-out lock on the carrier account, and remove SMS as a recovery factor everywhere, not just where it is optional.
- Treat every onboarding packet as a future breach. Identity documents, a selfie, proof of address and proof of holdings, in one file, held by a company whose support staff can read it. Minimise how many of those files exist. Prefer venues that delete rather than retain, and assume the rest will eventually be published.
- Audit your own back catalogue. Old interviews, podcast appearances, property records, company filings and photographs from five years ago are all still there, and they are where a target package starts.
Layer two
Make yourself unable to comply
- Nobody should be able to move everything. Two of three multi-signature, or MPC, with at least one signer in another country and one held by a party who is not at your dinner table. This is the whole ballgame. Every other control on this page is a supporting act.
- Put a clock on the vault. A queued withdrawal with a twenty-four or forty-eight hour cancellation window converts a forty-minute home invasion into a multi-day kidnapping with logistics, guards and exposure. That is a different crime with a different risk profile, and most crews are not equipped for it.
- Be able to prove the limit, fast. Duress ends when the attacker believes you. Know the exact sentence, and be able to demonstrate it on the device in front of them: the co-signer is elsewhere, the timer is on, the transaction is queued and visible and cannot be accelerated. "I will not" invites escalation. "I cannot, look" ends the negotiation.
- Fund a decoy properly. A hot wallet with a real, believable, genuinely painful balance and a real transaction history. An empty decoy is worse than none, because being caught lying is the moment these incidents turn violent. Price it as an insurance premium, not as a trick.
- The recovery material does not live where you live. A seed phrase hidden at home is a liability the moment attackers have an hour and no reason to hurry. Bank deposit box, or split across custodians, and never in the same building as the signing device.
- Spending caps and allowlists on everything that has them. Daily limits, destination allowlists, and a separate small wallet for anything that touches a new contract. Revoke approvals on a schedule, not after an incident.
- Write the freeze procedure down before you need it. The exact phone number and account-freeze process for every venue you hold anything at, on paper, plus a second person authorised to invoke it. In the Malaysian kidnapping in the report, three million USDT was paid and 2.46 million was frozen and recovered. Speed did that.
- Remove your own unilateral authority. If you control a treasury, admin keys, deployment permissions or a multisig share, you are the reason your household is worth visiting. Split it before somebody else works that out.
Layer three
The household
Home invasion went from one publicly reported case to twenty in a year, and proxy targeting is now a standard tactic. A holder who has thought about their own security and not their family's has thought about half of it, and it is the wrong half. Most people will hold a line for their assets. Almost nobody holds one for a child.
- A code word, agreed and practised. One phrase that means: I am under duress, call the police, do not come home. It should be boring, usable in a normal sentence, and known to everyone including whoever collects the children.
- A door protocol that has no exceptions. Nobody opens the door to an unscheduled delivery, a utility worker, a neighbour with a problem, or a uniform. Verify by calling the company on a number you looked up yourself, never the one they offer. The doorbell is the most common entry in the dataset because it is the only one that costs the attacker nothing.
- A camera at the door and a rule attached to it. The rule is that nobody unlocks while the camera shows more than one person, or shows someone standing outside its frame.
- Take the children off the internet. No school name, no uniform, no sports club, no repeating times. The proxy vector runs on routine, and a school run is the most reliable routine most families have.
- Treat meetings as hostile until verified. Confirm the venue, the counterparty and the attendance through a channel you originated. A private over-the-counter trade with someone you met online is the second most common way into these incidents.
- Carry a travel phone. No wallets, no password manager, no exchange apps, no recovery email. What is in your pocket at a conference is what an attacker gets, and biometrics on your own device will be used against your own face.
- Vary the routine. Interception between two predictable points is its own category. Home, office, gym, hotel, airport, school. Change the times before you change the route.
If it happens anyway
Comply. Immediately and completely. Every asset on this page is replaceable and no person is. Do not fight for a wallet, do not stall to protect a balance, and do not gamble that they are bluffing. The entire point of building the architecture above is that full compliance still leaves most of it standing: you hand over everything you are able to hand over, and what you are able to hand over was decided months ago by you, calmly, and not tonight by them.
Afterwards, in this order: police, then every venue on your freeze list, then chain analytics. Hours matter. Frozen funds get recovered and moved funds usually do not.
Where we stand, since we are telling you what to do
We have believed in being our own bank since 2013. We are not, any more, and it would be dishonest to publish the page above without saying so.
Our bitcoin and ether exposure sits in exchange-traded funds at an ordinary bank. There is no hardware wallet in this house.
Neither of those changes happened because self-custody failed. It never failed us, and the cryptography has never once been the weak part. They happened because the threat model moved, we were slow to notice, and then we were not.
Why the hardware wallet went
In July 2020 Ledger's e-commerce and marketing database was breached. Roughly 272,000 customer records with names, physical addresses and phone numbers, plus about a million email addresses. The file was published that December and has circulated ever since.
The devices were fine. No key was exposed, no seed was compromised, and the secure element did exactly what it was sold as doing. That is the entire point. The product worked and the customer list was the vulnerability, and a customer list is a directory of households that had recently spent money on storing cryptocurrency, with the address to deliver it to.
We used those devices from early on and we are not making a claim about the engineering. We are saying that owning one required handing a name and a home address to a company whose competence is building secure elements and not warehousing addresses, that the file leaked, that it cannot be unleaked, and that the report above counts twenty home invasions in six months.
A hardware wallet defends a key. Nothing about it defends the person holding the key, and by 2026 the person is the attack surface.
The part you cannot opt out of
Both of those were choices. This next one is not, and it is why the two above were worth making.
DAC8 became applicable on 1 January 2026. Crypto-asset service providers operating in the European Union now collect reportable transaction data on every EU-resident user and pass it to tax authorities, which exchange it automatically between member states. Whatever you make of the policy, the mechanical output is a set of registries joining a legal name to a home address to a reasonably precise estimate of what somebody holds.
Now set that beside the record on holding the data that already existed, catalogued further up this page: employment agencies and national identity systems breached at the scale of tens of millions of people, tax staff alleged to have sold holder information, and criminal forums recruiting inside exchanges. Then put the outcome next to it. Three quarters of the world's verified wrench attacks in the first half of 2026 took place in Europe, and the report's own explanation for the concentration is the density of administrative records and the frequency with which they escape.
We do not think those two things are unrelated. Building the registry and failing to hold it are two halves of one exposure, and the second half is the half no amount of personal discipline touches. There is no operational security practice that protects you from a database you are legally obliged to appear in.
None of this is a tax position. We file, we comply, and the policy case for transparency is a serious one that we are not arguing with. The security case is a different case, it points the other way, and it has not been made anywhere near as carefully.
Which is the uncomfortable part of this page. Every other control on it is something you can go and do this afternoon. This one is not a control at all. It is a standing condition of holding these assets, and the only decision left inside it is how much of your physical safety should rest on being a row in a table that keeps getting published.
What the bank buys, and what it costs
The trade, stated plainly, because anybody who recommends this arrangement without stating it is selling something.
Holding an ETF at a bank gives up censorship resistance, self-sovereignty, weekend settlement, and the ability to transact without asking. It accepts counterparty risk and seizure risk. Both are real, both have precedent, and neither is hypothetical: a bank can freeze you, a regulator can reach you, and a fund can be wound up on terms you did not pick. We know exactly what we handed over, and we gave up the part of this technology we spent a decade arguing for.
What we got back is narrow, and it is the whole subject of this page. There is nothing in the house to take. There is no key a threat can convert into a settled transfer. An institution cannot be coerced by frightening one family. Its transfers are traceable, its systems keep business hours, its staff answer to procedure rather than to whoever is standing in the room, and no quantity of pain applied to one person at three in the morning produces a wire.
It is the freeport, wearing a suit. Somebody else holds the object, they hold it somewhere nobody can reach in a hurry, and the delay is the product.
This is a disclosure, not a recommendation, and it is not investment advice. Most people reading it should not copy it. It is here because we are about to have opinions about your custody, and you are entitled to know where ours sits and what it cost to put it there.
The art is a different problem
You cannot put a Fidenza in an ETF. A collection is self-custodied, unavoidably, which means the argument above stops at the gallery door. Two things follow, and the first of them is good news.
Named work makes poor loot. Every headline case in the report was fungible: about €900,000 in bitcoin taken during a home invasion, a ten million USDT ransom demand in a kidnapping, roughly $24 million in a stablecoin in an assault. Crews want assets that launder, and they route them through chains and into Monero. A work with a public provenance record is the opposite of that. Every transfer is visible, marketplaces flag and delist it, and the buyer pool for a stolen grail is close to nobody. The same ledger that makes you findable makes your collection nearly unsellable by anyone else, and that asymmetry is on the collector's side.
The bad news is that the wallet is not the art. If the address holding the collection also holds liquid assets, or has live approvals, or is the one attached to your ENS and your profile, then the art is not the target. It is the advertisement. It is the thing that tells a stranger this address is worth a visit.
So separate them, and treat the named wallet as a shop window with nothing behind the glass.
One address carries the name, holds close to nothing, and does all the public work: bidding, signing, minting, claiming. A second address has never been named and never posted, receives from the first and never sends back to it, and holds the collection behind whatever multi-signature and delay you can live with. Nothing signs on a phone. Approvals get revoked on a calendar. It is not elegant, and neither is a freeport.
What the room knew
The auction room worked this out across three centuries and never needed cryptography for any of it. It needed intermediaries who could be sued, objects that could not move quickly, and owners who genuinely could not deliver on demand.
We rebuilt the first part out of mathematics, which was the hard one, and skipped the second and third entirely because they looked like friction. Fifty-two households found out last half-year why they were there.
Anonymity was never the defence. It was the thing that bought time while the real defence, which is being structurally incapable of handing everything over, did the work.