Ransomware Payments Are Getting Bigger as Hackers Shift Focus to Larger Targets: Chainalysis
New research from blockchain surveillance firm Chainalysis shows that ransomware gangs are getting more sophisticated.

The average size of ransomware payments hit an all-time high in 2021, according to a new report by blockchain research firm Chainalysis.
Chainalysis’ data shows the average ransomware payment size last year reached $118,000 in cryptocurrency, up from $88,000 in 2020, according to a report published Thursday. In 2019, the average ransomware payment was only $25,000. Kim Grauer, Chainalysis’ head of research, attributes this jump to the growing sophistication of ransomware groups.
Over the last two years, ransomware attacks have skyrocketed. Chainalysis has identified $692 million worth of payments to wallet addresses affiliated with ransomware groups in 2020 and, at the time of publication, $602 million in 2021. However, Grauer stressed that the real number is likely to be much higher – setting a new record for ransomware payments in 2021 – as Chainalysis continues to identify ransomware-associated wallets.
As ransomware gangs continue to profit and gain experience, they are learning how to adapt to avoid detection and go after bigger targets. Grauer told CoinDesk that data shows many ransomware gangs are reinvesting a larger percentage of stolen funds back into their operations. In 2021,16% of all funds sent from wallets associated with ransomware operators were spent on tools and services, like penetration testing or more secure web hosting, to make their attacks more effective.
“They're investing in their business,” Grauer said. “You know, you have to spend money to make money.”
The jump, up from 4% in 2020, is largely driven by the rise of ransomware as a service (RaaS), which enables ransomware gangs to purchase already-developed strains of ransomware, like Conti or DarkSide, from ransomware creators, usually in exchange for a portion of the proceeds.
However, Grauer also pointed out that, while RaaS might be growing, blockchain data shows that at least 140 ransomware developers received payments from victims last year – a new all-time high. The growth signals that ransomware strains are becoming dormant faster, which Grauer said is a tactic used to avoid law enforcement detection, but is also a sign of the rise of home-brewed ransomware tools.
“We’re actually starting to see some places where there’s a move away from RaaS and back to self-produced ransomware,” Grauer said. “We’re seeing that in Iran, where Iranian bad actors are just building their own ransomware from scratch.”
Grauer told CoinDesk that, by creating their own ransomware, ransomware gangs can create a more tailored attack for specific or high-security targets.
“One thing we did see in Iran was some geopolitical attacks against targets in Israel,” Grauer said.
The geopolitical implications of ransomware are growing. After a Russia-based ransomware group carried out the Colonial Pipeline attack last summer, the Biden administration has made cracking down on ransomware a priority.
President Biden has called out Chinese state actors for ransomware and cryptojacking attacks, and pushed Russia to arrest known members of ransomware gangs. The administration also began adding crypto exchanges to its sanctions blacklist last year.
More For You
Protocol Research: GoPlus Security

What to know:
- As of October 2025, GoPlus has generated $4.7M in total revenue across its product lines. The GoPlus App is the primary revenue driver, contributing $2.5M (approx. 53%), followed by the SafeToken Protocol at $1.7M.
- GoPlus Intelligence's Token Security API averaged 717 million monthly calls year-to-date in 2025 , with a peak of nearly 1 billion calls in February 2025. Total blockchain-level requests, including transaction simulations, averaged an additional 350 million per month.
- Since its January 2025 launch , the $GPS token has registered over $5B in total spot volume and $10B in derivatives volume in 2025. Monthly spot volume peaked in March 2025 at over $1.1B , while derivatives volume peaked the same month at over $4B.
More For You
Cascade Unveils 24/7 Neo-Brokerage Offering Perpetuals on Cryptos, U.S. Stocks

The platform will let retail traders use one margin account to trade round-the-clock perpetual markets.
What to know:
- Cascade has introduced a 24/7 brokerage-style app for perpetual markets spanning crypto, U.S. equities and private-asset exposure.
- The firm is pitching a single, unified margin account with direct-to-bank U.S. dollar capability for deposits and withdrawals.
- The company has raised $15 million from investors including Polychain Capital, Variant and Coinbase Ventures.











