- How Digital Extortion Works
- The State as a Source of Threat: DGFiP Leak
- From Keyboard to Wrench: The “Wrench Attacks” Phenomenon
- Why Did France Become a Target?
- How to Protect Yourself: Instructions from Hasheur and Experts
The French cryptocurrency industry is experiencing an unprecedented security crisis. What began as classic phishing emails has evolved into sophisticated psychological attacks backed by theft of state databases.
Owen Simonin, one of the most recognizable faces in the French crypto community (known under the pseudonym Hasheur) and founder and CEO of the Meria platform, has sounded the alarm. According to him, the country is facing massive leaks of personal information and a sharp increase in physical attacks on digital asset holders.
How Digital Extortion Works
The new wave of crimes is based on social engineering brought to automation. Scammers no longer send spam blindly — thanks to the black market for personal data, they know everything about their victims.
The Mechanics of Deception
The scheme looks frighteningly plausible:
• Identification: A scammer calls a client of a legitimate exchange (Binance, Coinbase, or French Meria).
• Data Collection: Posing as a support service employee, the scammer mentions the user’s name, partial phone number, or last digits of a card purchased on the dark web following another data breach.
• Creating panic: The victim is told that their account has been hacked, the company’s servers are under attack, or a suspicious transaction requires immediate cancellation.
• “Safe” transfer: The user is convinced to transfer funds to a “backup wallet” that actually belongs to criminals.
“We are experiencing a period when data breaches are accumulating in both private companies and the public sector: all these breaches intersect. This is how we identify cryptocurrency owners and the platforms they use,” Owen Simonin said.
Simonin emphasizes the main vulnerability of a person — the fear of losing savings. A sense of urgency disables critical thinking.
“If you panic and fall for their trick, that’s exactly where your money will go — to their address,” warns the entrepreneur.
He reminds of the golden rule of digital hygiene: no legal financial platform will ever initiate a call demanding a transfer of funds to “save” them. Any request to provide a seed phrase or press the “send” button is a one hundred percent sign of fraud.
The State as a Source of Threat: DGFiP Leak
The scale of the problem became evident in August 2026, when France’s General Directorate of Public Finances (DGFiP) confirmed a major breach. Hackers gained access to the data of 678 thousand taxpayers.
For criminals, this became a jackpot. Unlike random leaks of logins and passwords, the tax database contains verified information:
• Full name and residential address.
• Financial identifier number.
• Information about income and assets.
With a list of high-income individuals in hand, criminals can easily cross-reference it with lists of cryptocurrency buyers that leak online after breaches of small exchanges or marketplaces. This turns the hunt for digital gold into precise work for criminal profilers.
From Keyboard to Wrench: The “Wrench Attacks” Phenomenon
Digital fraud is just the tip of the iceberg. France is recording an alarming increase in so-called “wrench attacks” (wrench attacks, a term from the famous xkcd comic).
The essence is simple: if it’s too difficult for a hacker to remotely compromise a victim’s hardware wallet, they simply find their physical address (thanks to those very data breaches) and come to their home. Under the threat of violence — using hammers, knives, or firearms — the victim is forced to unlock their phone and transfer assets to the robbers’ wallets.
Why Did France Become a Target?
France has historically held one of the leading positions in Europe in terms of the number of active cryptocurrency users. This was facilitated by favorable laws in previous years and a developed startup infrastructure. However, this same popularity has made cryptocurrency holders from France easy targets.
Criminal groups realized that cryptocurrency has a unique property: it is instantly liquid and practically irreversible. If stolen euros get stuck in the banking system when attempting to withdraw them, USDT or ETH can be converted to cash within an hour.
Artificial Intelligence: A New Level of Threat
Owen Simonin points to a factor that could render current protection methods useless — the implementation of neural networks.
In conclusion, he clarified that “this trend will intensify with the implementation of artificial intelligence, since malicious actors will gain more computing resources and will be able to automate such fraud attempts.”
AI is changing the threat landscape in the following ways:
• Voice Cloning (Vishing): Just a three-second audio clip from social media is enough for AI to recreate the voice of your relative or boss asking you to “send some crypto as a loan.”
• Deepfake videos: Scammers can generate video calls allegedly from the exchange CEO announcing an emergency.
• Call Automation: Robots call thousands of numbers using data from the DGFiP database and conduct meaningful dialogue, recognizing victims’ responses.
• Historical Reference: Evolution of Crypto-Crime
The problem of robberies for cryptocurrency is not new, but it has undergone significant evolution:
• Stage 1 (2017–2019): Keyboard crime. Mass mailing of letters: “Your Binance account is blocked”. Success depended on computer illiteracy.
• Stage 2 (2020–2023): SIM swapping. Hacking mobile numbers of high-ranking officials and investors to intercept SMS codes for two-factor authentication.
• Stage 3 (2024–2026): Physical terror. Transition to direct violence against the backdrop of rising Bitcoin and Ethereum prices, which made many ordinary citizens dollar millionaires “on paper.”
A striking example from the past is the case of Ilya Lichtenstein and Heather Morgan (the Bitfinex hack for $4.5 billion). Their downfall was caused by digital negligence. Modern criminals are learning from these mistakes: they prefer not to hack the blockchain, but to hack people.
How to Protect Yourself: Instructions from Hasheur and Experts
Against the backdrop of the state’s inability to fully protect its databases, responsibility falls on the users. Experts recommend reviewing basic security protocols:
Hardware isolation: Never store large amounts on exchanges (“not your keys — not your coins”). Use cold wallets (Ledger, Trezor) hidden in a secure location.
Profile Separation: Do not use your primary phone number and primary email for registering on cryptocurrency exchanges. Create a separate “digital footprint.”
Pause Rule: When you receive any incoming call from “customer support,” hang up. Call back yourself using the official number listed on the exchange’s official website.
Social silence: Avoid displaying your wealth. Public boasting about the amount of BTC on Twitter or Instagram makes you a priority target for those very “wrench attacks”.
