OAK — OnChain Attack Knowledge

Worked example · 2025-01

David Balland (Ledger co-founder) kidnapping — crypto ransom, France — 2025-01

Loss
no clean single dollar figure — the value at risk was a multi-million-euro crypto ransom (reported around €10M) demanded after David Balland, a co-founder of hardware-wallet maker Ledger, was kidnapped from his home in central France (Cher) on 2025-01-21 together with his partner. The captors mutilated Balland — severing a finger — and sent it to pressure payment from fellow co-founder Éric Larchevêque. French gendarmerie (GIGN) freed Balland on 2025-01-22 and recovered his partner separately; a portion of a crypto ransom was reportedly paid and then largely traced and frozen, and roughly ten suspects were charged. This entry records the incident as the most-confirmed anchor for the 2024–2026 physical ("wrench") attack wave against identifiable crypto holders — the same class as the TeufeurS ransom (examples/2023-2024-french-streamer-kidnapping-ransom-crypto.md) and the 2026 Kraken/Coinbase coordinated-coercion theft (examples/2026-05-kraken-coinbase-coordinated-physical-wallet-compromise.md).
OAK Techniques observed
OAK-T5.009 (Physical-Coercion Extraction — the wrench-attack class; the coerced-ransom transfer is the extraction primitive, cryptographically authorised by the keyholder's own signature under duress rather than by a contract vulnerability). OAK-T7 (Laundering — the ransom crypto trail; here the trail became the recovery surface, with a reported freeze/seizure of part of the funds). OAK-T8.005 (Operational-Security Procedural Failure — victim-level: the target was a publicly-identifiable, high-net-worth figure whose association with crypto wealth was a matter of record, the predictive targeting field for wrench attacks). (T5.009 was created from this and two sibling cases — the TeufeurS ransom and the 2026 Kraken/Coinbase event — filling the physical-extortion Technique gap the corpus had repeatedly flagged; it is distinct from T5.008 Ransomware, whose leverage is data-encryption/leak rather than physical violence.)
Attribution
confirmed — this is the corpus's most forensically-established physical-coercion case. A French judicial investigation, a GIGN rescue operation, the recovery of the victims, and charges against approximately ten individuals are on the public record and were widely reported by international press (Reuters, BBC, AP, Le Monde). The physical-coercion dimension is confirmed, not merely reported — unlike the Kraken/Coinbase 2026 case, where the physical element is suspected. No claim is made here about the final on-chain disposition beyond the reported partial freeze/seizure.
Key teaching point
A co-founder of the company whose entire business is the secure custody of private keys could not be secured by any of it. This case is the sharpest single demonstration in the corpus that the on-chain security model ends at the person: no hardware wallet, seed-phrase discipline, multisig, or exchange control defends a holder who is physically seized and coerced (or whose associates are coerced on their behalf). The device Ledger sells protects a key from software; it cannot protect a human being from a captor. Prevention, therefore, is not cryptographic — it is physical OPSEC (minimising the public linkage between identity, holdings, and physical location; family security) plus duress-resistant controls that remove the ability to satisfy coercion instantly (time-locked withdrawals, geographically-distributed multisig requiring a remote co-signer, decoy wallets). The crypto layer's one redeeming contribution is the same as in every physical-extortion case: the ransom moved on a public ledger and was therefore traceable and partly freezable, which is why part of it was reportedly recovered.

Summary

On 2025-01-21, David Balland — a co-founder of Ledger, the French manufacturer of the widely-used Ledger Nano hardware wallets — was kidnapped from his home in the Cher department of central France, along with his partner. The kidnappers held them separately and demanded a cryptocurrency ransom, reported at around €10 million, contacting fellow Ledger co-founder Éric Larchevêque for payment. To force compliance, the captors severed one of Balland's fingers and sent it as proof and pressure.

French authorities opened a judicial investigation, and the elite GIGN gendarmerie unit conducted a rescue: Balland was freed on 2025-01-22, and his partner was found, bound, in a separate location. Reporting indicated that a portion of a crypto ransom was paid and subsequently traced and largely frozen or seized by investigators — the on-chain trail serving, as in the TeufeurS case, as the recovery surface. Approximately ten people were subsequently charged in connection with the kidnapping.

The Balland case became the emblematic incident of a broader 2024–2026 wave of physical attacks and attempted kidnappings targeting crypto entrepreneurs, executives, and their families in France and Europe — a wave later quantified by CertiK's wrench-attack tracking (dozens of verified physical attacks in 2026, with a documented shift toward targeting victims' family members). It sits in the corpus alongside the TeufeurS kidnapping (2023, $2M ransom, $800K frozen) and the 2026-05 Kraken/Coinbase coordinated-coercion theft as the confirmed, high-profile anchor for the class.

Why this is structurally significant

  1. It is the corpus's cleanest confirmation that the security perimeter is the body, not the device. Every other custody Technique — hardware isolation, seed hygiene, multisig, exchange 2FA — defends the key. This case defeats all of them at once by attacking the keyholder (and, decisively, an associate of the keyholder). The irony that the victim helped build the industry's flagship security device is not incidental: it is the proof that no device solves this.

  2. The confidence level is unusually high. Most physical-crypto events reach OAK with a suspected or reported physical dimension. Here the coercion is confirmed by a rescue operation, physical injury, and criminal charges — making it the reference case when the corpus needs a confirmed wrench-attack anchor rather than a reported one.

  3. The recovery pattern repeats and is teachable. As in TeufeurS, the ransom's on-chain nature is what allowed part of it to be traced and frozen. The consistent lesson across the class: at the moment of attack there is no defence, but afterward the public ledger is the only recovery surface a cash ransom would never provide.

What defenders observed

  • Targeting / exposure (pre-event): the victim was a publicly known figure whose association with crypto wealth was a matter of record. Wrench attacks begin with identifying and locating a high-value holder; a public identity↔wealth linkage is the enabling condition. The defensible edge is minimising that linkage — for ordinary holders, not self-disclosing balances and segregating a doxxable identity from large wallets; for public figures, executive-protection and family-security measures.
  • At-event (no cryptographic defence): coercion against the holder — or against an associate able to pay, as here — produces an authentic transfer that the cryptographic perimeter cannot distinguish from a free one. Multisig and hardware wallets do not help. Duress-resistant controls (time-locked withdrawals, remote co-signers, decoy/duress wallets, exchange withdrawal delays) are the relevant mitigation class because they remove the ability to satisfy the coercion instantly.
  • Post-event (recovery): the ransom moved on-chain and part of it was reportedly traced and frozen — the standard interception lever, on a clock of hours, before mixing or off-ramping. This is the crypto layer's only favourable property in the whole event.
  • Trend (macro): the case is one node in an organised, Europe-concentrated wave that CertiK and others documented growing sharply into 2026, including the escalation to targeting family members.

What this example tells contributors writing future Technique pages

  • Physical coercion maps to T5 (extraction) + T7 (laundering/recovery) + T8.005 (targeting exposure), as the corpus already does — the coercion itself is not an on-chain technique, but the compelled transfer, the ransom trail, and the identity↔holdings↔location targeting surface are all in scope.
  • This is the confirmed anchor for the proposed wrench-attack Technique. The corpus has now flagged the covering-Technique gap in three physical-extortion cases (TeufeurS, Kraken/Coinbase, and here). If a coercion-based-extraction Technique is added under T5, these three examples are its first citations, with this case as the highest-confidence one.
  • Duress-resistant controls are the mitigation class to record for the whole physical-coercion family — decoy wallets, withdrawal time-locks, remote co-signers, exchange delays — because they, uniquely, defend where the cryptographic perimeter cannot.

Public references

Reference URLs are representative of the widely-syndicated reporting on this case and are provided for verification; pin the specific outlet URLs on the next citation sweep.

Discussion

The Balland kidnapping is the incident that made the "wrench attack" concept concrete for the crypto industry: the co-founder of the sector's most recognisable self-custody company, taken from his home and mutilated for a crypto ransom, rescued only by a national counter-terrorism unit. For an on-chain-attack taxonomy the case matters for three reasons — it is confirmed where most physical-crypto events are merely reported; it demonstrates with unusual clarity that the custody security model terminates at the human being and that an associate able to pay is part of the attack surface; and it repeats the class's one recoverable property, the on-chain traceability of the ransom.

OAK records the incident under its standard treatment for physical-extortion-to-crypto events (extraction T5, laundering/recovery T7, targeting exposure T8.005) and re-flags the standing Technique gap: physical-extortion / coercion-based extraction — the wrench-attack class — has no covering Technique, and this case, with TeufeurS and the 2026 Kraken/Coinbase event, is the evidentiary basis for adding one. The prevention lesson is deliberately non-cryptographic: break the identity↔holdings↔location linkage, and build duress-resistant controls that make instant, total surrender impossible before it is ever demanded.

Techniques demonstrated (3)