What Is the NYC Crypto Kidnapping Case? The Soho Bitcoin Attack Explained — 2026 Case Analysis

By: WEEX|2026-07-21 04:07:00

Summary

  • The NYC crypto kidnapping case centers on John Woeltz and William Duplessie, two cryptocurrency investors who allegedly held a 28-year-old Italian man captive for 17 days inside a Soho townhouse in May 2025 to extract his Bitcoin wallet password.
  • Prosecutors allege the victim was tortured with electric shocks, a chainsaw, cattle prod, and forced drug use, and was dangled from a five-story staircase ledge before escaping barefoot on May 23, 2025.
  • The case is legally significant for the crypto industry because it exposes the structural vulnerability of self-custodied Bitcoin: a private key or seed phrase, once physically extracted under duress, grants irreversible and untraceable access to a wallet's entire balance.
  • A Manhattan judge granted both defendants $1 million bail in July 2025 despite prosecutorial objection, and both men pleaded not guilty to a dozen charges including kidnapping, assault, coercion, and criminal weapon possession.
  • The case has become a reference point in on-chain security discussions around "wrench attacks," physical-coercion threats that no amount of cryptographic security can prevent, prompting renewed industry focus on multi-signature custody and delayed-withdrawal wallet architecture.

Full Market and Narrative Summary

The Soho Bitcoin attack refers to a May 2025 kidnapping and torture case in Manhattan in which two cryptocurrency investors, John Woeltz and William Duplessie, allegedly held an Italian national captive inside an eight-bedroom townhouse to coerce him into surrendering his Bitcoin wallet password. According to New York prosecutors, the victim was lured from Italy under threats against his family, stripped of his passport and devices, and subjected to beatings, electric shocks, and forced narcotics use over 17 days before escaping barefoot to a police officer. The case has become one of the most closely watched examples of a "wrench attack" in crypto security literature: a physical-coercion exploit that bypasses blockchain cryptography entirely by targeting the human holder of a private key. This article explains the case's timeline, the specific on-chain vulnerabilities it exposes, and what self-custody practices the crypto industry has since re-examined in response.

For traders and long-term holders evaluating how custody architecture affects real-world risk exposure, understanding the execution and settlement layer of an asset is a foundational part of risk management. Reviewing available custody, withdrawal, and security configurations on a platform's WEEX Spot Market is one practical way to compare how exchange-based custody differs from self-custody wallet exposure before deciding where and how to hold digital assets.

What Happened in the NYC Crypto Kidnapping Case?

The NYC crypto kidnapping case is a criminal prosecution alleging that John Woeltz, 37, and William Duplessie, 33, kidnapped and tortured a 28-year-old Italian national for 17 days in May 2025 to force him to surrender his Bitcoin wallet credentials. According to the Manhattan District Attorney's office, the victim traveled to New York on May 6, 2025, after Woeltz and Duplessie allegedly threatened to kill his family if he did not comply, and was taken directly to Woeltz's eight-bedroom townhouse in the Soho neighborhood of Lower Manhattan.

Once inside the property, prosecutors say the victim was stripped of his electronics and passport, bound by the wrists, and subjected to a sustained pattern of physical coercion designed specifically to extract his Bitcoin password. The criminal complaint describes beatings, electric shocks delivered via a cattle prod and electrical wires, a leg wound inflicted with a saw, and an incident in which Woeltz allegedly carried the victim to the top of a five-story staircase and dangled him over the ledge while threatening to kill him if he did not provide the password. Prosecutors also allege the defendants poured tequila on the victim and set him on fire, and forced him to smoke crack cocaine throughout the captivity period.

The victim ultimately provided a password after believing he was about to be shot, and escaped down the stairs while Woeltz went to retrieve the laptop needed to access the wallet. He fled the townhouse barefoot and bloodied on May 23, 2025, and located an NYPD traffic enforcement officer, who alerted police. Detectives who searched the property subsequently recovered a firearm, ammunition, a saw, crack cocaine, body armor, night vision goggles, ballistic helmets, and Polaroid photographs depicting the victim with a firearm pointed at his head, along with T-shirts printed with images of the victim holding a crack pipe.

Who Are the Defendants and What Is Their Background in Crypto?

Both defendants are cryptocurrency investors with documented histories connecting them to prior allegations of coercive behavior tied to digital asset extraction. John Woeltz, described in court by his own defense attorney as the "crypto king of Kentucky," was previously accused in a separate, unrelated matter of holding another individual for ransom over cryptocurrency in Kentucky, a detail prosecutors introduced during bail arguments to establish an alleged pattern of behavior. William Duplessie had also previously been investigated in Switzerland for a domestic violence matter.

The involvement of two individuals identified specifically as crypto investors rather than professional criminals is a detail that has drawn significant attention from blockchain security researchers, because it illustrates that wrench attacks are not exclusively an external threat from organized criminal groups; they can also originate from within the investor's own social or professional network. Prosecutors noted that Woeltz and Duplessie knew the victim personally before the alleged abduction, which meant the victim had no reason to suspect the danger until he had already traveled internationally and entered the townhouse voluntarily.

Why Does This Case Matter for Crypto Security? The Wrench Attack Problem

A wrench attack, named after a well-known webcomic illustrating how a five-dollar wrench can defeat any amount of cryptographic security, refers to physical coercion used to extract a private key, seed phrase, or wallet password from a person rather than attempting to break the underlying blockchain cryptography. The Soho case is one of the most extensively documented wrench attacks in US legal history because it produced a detailed criminal complaint, physical evidence, and courtroom testimony describing exactly how the coercion was applied and what specific credential the attackers were attempting to extract.

The core structural issue this case exposes is that Bitcoin's security model assumes the private key holder is a rational, unthreatened actor capable of protecting their own key material. Self-custody, often summarized by the phrase "not your keys, not your coins," transfers full custodial responsibility to the individual holder, eliminating counterparty risk from exchanges or custodians but simultaneously creating a single point of physical failure: the holder's own body and immediate environment. Unlike a bank vault, which requires defeating institutional-grade physical security, a self-custodied hardware wallet, seed phrase, or exchange password can, in principle, be extracted from any individual holder given sufficient time, isolation, and coercive pressure.

This is structurally different from smart contract exploits, private key brute-forcing, or exchange hacks, all of which require some form of technical circumvention that leaves detectable on-chain or system-log evidence. A wrench attack produces a technically valid, cryptographically correct transaction, since the attacker is using the legitimate credentials under duress, meaning the resulting transfer is indistinguishable on-chain from a voluntary transaction. Once funds move to an attacker-controlled address, the transaction is final and irreversible under Bitcoin's consensus rules, and standard blockchain forensics tools cannot differentiate a coerced transfer from a legitimate one without external evidence, such as the criminal complaint itself.

How Do High-Net-Worth Crypto Holders Reduce Wrench Attack Exposure?

The most direct mitigation against a wrench attack is architectural: distributing signing authority across multiple keys and multiple physical locations so that no single point of coercion, including the holder's own body, can unilaterally authorize a transfer. Multi-signature wallet configurations, which require a threshold of signatures (for example, two of three, or three of five) from geographically or custodially separated keys before a transaction executes, directly address this vulnerability because an attacker holding one victim under duress cannot produce the additional required signatures without also physically compromising the other key holders.

A second widely discussed mitigation is time-delayed withdrawal architecture, sometimes implemented through smart contract-based vaults or custodial policy settings, which impose a mandatory waiting period between a withdrawal request and fund release. This does not prevent a coerced authorization request from being submitted, but it creates a window during which the legitimate holder, once released or once law enforcement is alerted, can cancel the pending withdrawal before funds actually move. Some institutional custody providers and even certain centralized exchange account tiers offer withdrawal delay settings specifically marketed around this exact threat model.

A third mitigation, particularly relevant to the Soho case's specific mechanics, is decoy wallet architecture: maintaining a wallet with a modest, plausible balance that can be surrendered under duress while the substantial majority of holdings remain secured behind a separate, non-disclosed credential structure. Security researchers who study wrench attacks generally advise against publicly disclosing wallet balances, holdings, or crypto wealth on social media or in professional contexts precisely because visible wealth signals create the initial target selection that begins the wrench attack chain, as appears to have occurred in this case given that the defendants reportedly knew the victim personally and were aware of his holdings.

Custody ModelCoercion ResistanceKey MechanismTypical Use Case
Single-key self-custodyLowOne private key, one point of failureSmall individual holdings
Multi-signature (2-of-3, 3-of-5)HighRequires multiple geographically separate signersHigh-net-worth individual or fund holdings
Time-delayed withdrawal vaultModerate-HighMandatory delay window allows cancellationInstitutional treasury, cautious individuals
Centralized exchange custodyModerateCustodian holds keys, subject to account recovery/freezeActive traders, smaller balances
Cold storage with decoy walletModerateVisible smaller balance, hidden primary balanceIndividuals with known or suspected crypto wealth

What Are the Current Legal Proceedings in the Case?

Both defendants were arraigned separately, with Woeltz taken into custody on May 23, 2025, the day of the victim's escape, and Duplessie surrendering to authorities several days later after learning of Woeltz's arrest. A Manhattan grand jury indicted both men on charges including kidnapping, assault, unlawful imprisonment, coercion, and criminal possession of a weapon, with Duplessie facing a potential sentence range described by prosecutors as 15 years to life on the assault-related charges and 25 years to life on the kidnapping charge if convicted.

At their arraignment, both men pleaded not guilty, and their defense attorneys presented an alternative narrative supported by photographic and video evidence allegedly showing the victim moving freely around Manhattan during the period he claims to have been held captive, including footage the defense says shows him visiting an eyeglass store, smoking a cigarette alone on a public street, and participating in other activity inconsistent with confinement under duress. Prosecutors countered that the victim's escape, described as barefoot and bloodied, combined with internal messages allegedly exchanged between Woeltz and an assistant instructing continued surveillance of the victim, corroborated the coercion narrative regardless of any intervals of apparent freedom captured on camera.

In July 2025, a Manhattan judge set bail at $1 million for each defendant over the explicit objection of the district attorney's office, citing what the court described as material discrepancies between the prosecution and defense accounts that warranted further evidentiary review before trial. Both defendants were required to surrender their passports, submit to electronic monitoring, and remain under home confinement pending trial. As of the most recent public court filings, both men remain under indictment and the case continues through pretrial proceedings.

How Does This Case Compare to Other Crypto-Related Physical Security Incidents?

The Soho case is part of a broader and increasingly documented pattern of physical-coercion crimes targeting cryptocurrency holders, distinct from the far more common categories of phishing, exchange hacks, or smart contract exploits that dominate crypto security headlines. Unlike a rug pull or an exchange insolvency event, which are financial or code-level failures, wrench attacks are violent crimes that specifically exploit the irreversibility and bearer-asset nature of self-custodied cryptocurrency: once a credential is extracted, the resulting transaction has the same legal and technical finality as any voluntary transfer, with no chargeback mechanism analogous to traditional banking fraud protections.

Security researchers tracking this category of incident have noted an increase in publicly reported cases globally in recent years, correlating loosely with periods of elevated Bitcoin and altcoin prices, since higher nominal wallet values increase the potential payoff for an attacker willing to accept the legal risk of a violent crime. The specific pattern in the Soho case, in which the alleged perpetrators were personally acquainted with the victim and were themselves established figures in the crypto investment space rather than anonymous criminals, is a variation that security analysts flag as particularly difficult to prevent through purely technical means, since the victim's initial vulnerability stemmed from a trust relationship rather than a targeted external attack on a wallet address visible on a public blockchain explorer.

What Should Crypto Holders Take Away From This Case?

The central lesson for any cryptocurrency holder, whether managing a modest retail position or a substantial institutional treasury, is that on-chain security architecture and physical personal security operate as two separate risk domains that require independent mitigation strategies. A wallet secured with a 24-word seed phrase, hardware signing device, and strong operational security against remote hacking attempts remains fully vulnerable to a coercion scenario in which the holder is physically present and under duress, because the cryptographic system has no mechanism to distinguish a voluntary signature from a coerced one.

Practical steps that reduce this specific risk category include structuring meaningful holdings behind multi-signature arrangements that require signers who are not physically co-located with the primary holder, avoiding public disclosure of wallet balances or crypto wealth in any context, whether professional networking, social media, or in-person conversation, and considering custodial or semi-custodial arrangements with built-in withdrawal delays for balances that exceed what an individual is prepared to lose entirely under a worst-case physical threat scenario. For active traders who prioritize speed of execution and liquidity over the specific coercion-resistance properties of multi-signature cold storage, understanding the custodial protections, account recovery procedures, and withdrawal security settings available on a regulated trading venue is a reasonable complementary layer, and reviewing the account security and custody configuration options on the WEEX Spot Market is one way to evaluate how exchange-based safeguards differ from the exposure created by pure self-custody. No single custody model eliminates all risk categories, and a risk-managed framework that separates day-to-day trading balances from long-term, coercion-resistant cold storage remains the most defensible approach for any serious market participant continuing their on-chain education in this environment.

Frequently Asked Questions About the NYC Crypto Kidnapping Case

1. What is the NYC crypto kidnapping case about

The NYC crypto kidnapping case involves John Woeltz and William Duplessie, two cryptocurrency investors charged with kidnapping and torturing a 28-year-old Italian national for 17 days inside a Soho townhouse in May 2025 to force him to reveal his Bitcoin wallet password. The victim was allegedly lured to New York under threats against his family, then subjected to beatings, electric shocks, and forced drug use before escaping barefoot on May 23, 2025.

2. Who are John Woeltz and William Duplessie

John Woeltz, 37, and William Duplessie, 33, are both cryptocurrency investors who prosecutors say personally knew the victim before the alleged abduction. Woeltz has been previously linked to a separate crypto-related coercion allegation in Kentucky, and Duplessie had previously been investigated in Switzerland for an unrelated domestic violence matter, details prosecutors introduced during bail hearings to argue against pretrial release.

3. What is a wrench attack in cryptocurrency and how does it relate to this case

A wrench attack refers to using physical coercion to extract a private key, seed phrase, or wallet password from a cryptocurrency holder rather than attempting to defeat the underlying blockchain cryptography. The Soho case is a documented real-world example of this attack pattern, illustrating how self-custodied Bitcoin's security model assumes an unthreatened holder and offers no cryptographic defense against direct physical coercion of the key holder.

4. How can Bitcoin holders protect themselves from wrench attacks

Effective mitigations include multi-signature wallet structures that require signatures from multiple, physically separated key holders so no single coerced individual can authorize a transfer, time-delayed withdrawal architecture that creates a cancellation window after a withdrawal request, and avoiding public disclosure of wallet balances or crypto wealth to reduce the likelihood of being targeted in the first place.

5. What is the current legal status of the Soho Bitcoin kidnapping case

Both Woeltz and Duplessie were indicted by a Manhattan grand jury on charges including kidnapping, assault, unlawful imprisonment, and criminal possession of a weapon, and both have pleaded not guilty. A Manhattan judge granted each defendant $1 million bail in July 2025 over the prosecution's objection, requiring passport surrender, electronic monitoring, and home confinement, and the case remains in pretrial proceedings as of the most recent public court filings.

-- Price

--

Disclaimer: This content is provided for general branding and informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online events, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets or to use any services. Crypto assets are highly volatile and may result in loss. WEEX services and online events may not be available in all regions and are subject to applicable laws, regulations, and eligibility requirements. You are responsible for ensuring that your use of WEEX services complies with local laws and for carefully assessing the risks before participating in any crypto-related activities.

You may also like

iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:bd@weex.com
VIP Program:support@weex.com