Don't Blame Bitcoin for Ransomware
Any organization that relies on computers may be vulnerable to digital extortion. But the threat isn’t always clear. Industry expert Marcus Hutchins weighs in.
Amid the growing geopolitical threat of ransomware, crypto has become a stalking horse. Following a slew of high-profile exploits, there have been calls to ban or surveil blockchain networks, with the thinking that bitcoin catalyzes cybercrime.
The risks of ransomware are real: Any organization that relies on computers may be vulnerable to digital extortion. The threat isn’t always clear: Malware can be developed or deployed by individuals, state-backed groups or hacking collectives. And the price is high: Computer hijackings can disrupt critical infrastructure from the electricity grids to watersheds, endangering lives and economies.
This article is excerpted from The Node, CoinDesk's daily roundup of the most pivotal stories in blockchain and crypto news. You can subscribe to get the full newsletter here.
Considering the amorphous threat that ransomware presents, crypto seems like a vector for concrete action. After all, the Colonial Pipeline hackers were paid in BTC. So was REvil, a group that once attacked Apple, and which was paid $70 million in bitcoin for its recent Kaseya exploit. A new crowdfunding site, Ransomwhe.re, looks to track bitcoin payments to wallets associated with ransomware gangs.
But blaming crypto for the rise in ransomware is a mistake, said Marcus Hutchins, a British computer security researcher with a storied career in the malware industry. In a video titled “Why Destroying Bitcoin Wouldn't Stop Ransomware,” Hutchins notes that hackers will find a way, with or without bitcoin.
“Cryptocurrency has certainly made ransomware more accessible and contributed to its proliferation, but without it these kinds of attacks would have persisted,” he told CoinDesk. When the malware industry first emerged in 2012, it was the norm to accept U.S. dollars for exploits.
While the recent trend of corporate hacks has primarily been funded through crypto – Chainalysis found crypto payments to ransomware spiked to $412 million last year – that’s not reason enough to take action against a nascent industry.
“We have absolutely no data on what corporate ransomware attacks might look like without cryptocurrency. We can only theorize based on past techniques, but not future innovations. Therefore, advocating banning cryptocurrency to stop ransomware is naive at best,” he tweeted.
Read more: The Ransom-Ware | Marc Hochstein
Hutchins is renowned in the hacker community for stopping WannaCry in 2017, at the time the largest ransomware attack, which infected hundreds of thousands of computers worldwide and shut down over a dozen U.K. hospitals.
He’s also the architect of darknet sites, botnets and malware scripts. As a teenager, Hutchins began spending time on web forums, where he fell into ghostwriting malicious code. It paid well, in recreational drugs and bitcoin. One script would eventually land him in U.S. custody, in a story told in full by Wired.
Since reformed, Hutchins has worked to reverse engineer malware and provide security advice. He also started a popular blog called Malware Tech. Having watched the ransomware industry evolve over the past decade, Hutchins says emphatically that the recent rise in ransomware cannot be pinned on crypto.
CoinDesk caught up with him to hear more.
Is there a natural rate of ransomware attacks we might expect even if bitcoin/crypto were banned/never existed?
Cryptocurrency has certainly made ransomware more accessible and contributed to its proliferation, but without it these kinds of attacks would have persisted. The sophisticated cyber-crime groups have access to money laundering networks, so are capable of working with USD. It's impossible to estimate how much ransomware there'd be without cryptocurrency, because today's corporate targeted ransomware only came about around 2016, when cryptocurrency was already the norm for payments.
Some have said bitcoin is a horrible currency to use for criminal operations as every transaction is recorded. What happened after the Colonial Pipeline hack is case in point. What do you think?
Typically bitcoin is preferred, as it can facilitate fast, frictionless, automated payment validation infrastructure. But, due to its traceable nature, many gangs opt to cash out the bitcoin and launder in USD instead.
You’ve noted that ransomware uses the banking system, money transmitters like Western Union, alternatives like Liberty Reserve and crypto. Considering the scope and history of cybercrime, is the only potential solution to ransomware more surveillance of all financial systems?
No. This is not a solution at all, only a partial mitigation. While gangs are capable of operating with impunity from non-extradition countries, it doesn't matter how easily they can be tracked down if they cannot be arrested or stopped.
The way hackers are written about sometimes paints ransomware as a professionalizing industry. Does this square with your experience?
Yes, some of these groups have complex organization structures with departments, management and task pipelines.
What would you generally recommend to a company or government that has been infected?
It's important to undergo an external IR to investigate the full scale and scope of the attack.
NTT, a Japanese tech services provider, found that cryptojackers made up 41% of all detected malware in 2020. What do you make of this trend? Is this cause for legitimate concern? Is it just a matter of rising crypto prices?
Cryptojacking is one of the ways to monetize device access with the lowest barrier to entry; as a result, it's accessible to even the lowest skilled hackers, thus very widespread. Due to the non-destructive nature of cryptojacking I believe it's something to be addressed, but not a high priority threat like ransomware.
Note: The views expressed in this column are those of the author and do not necessarily reflect those of CoinDesk, Inc. or its owners and affiliates.
Больше для вас
Pudgy Penguins: A New Blueprint for Tokenized Culture

Pudgy Penguins is building a multi-vertical consumer IP platform — combining phygital products, games, NFTs and PENGU to monetize culture at scale.
Что нужно знать:
Pudgy Penguins is emerging as one of the strongest NFT-native brands of this cycle, shifting from speculative “digital luxury goods” into a multi-vertical consumer IP platform. Its strategy is to acquire users through mainstream channels first; toys, retail partnerships and viral media, then onboard them into Web3 through games, NFTs and the PENGU token.
The ecosystem now spans phygital products (> $13M retail sales and >1M units sold), games and experiences (Pudgy Party surpassed 500k downloads in two weeks), and a widely distributed token (airdropped to 6M+ wallets). While the market is currently pricing Pudgy at a premium relative to traditional IP peers, sustained success depends on execution across retail expansion, gaming adoption and deeper token utility.
More For You
Bitcoin miners surge higher as Anthropic's fundraising efforts boost AI spirits

Anthropic is set to raise $20 billion in its latest funding round, double the amount it initially targeted, according to the FT.
What to know:
- Anthropic, the maker of the Claude chatbot, is set to raise about $20 billion in new funding at a valuation of $350 billion, according to the Financial Times.
- That's double the amount the company initially sought to raise.
- The news is boosting spirits in the AI sector, with bitcoin miners turned AI infrastructure providers like IREN, TeraWulf, Cipher Mining and Hut 8 surging higher.












