June 25, 2026
Cryptocurrency Did Not Create Ransomware, It Industrialized It
The Floppy Disk in the Mailbox

By David SEHYEON Baek
35 min read
The Floppy Disk in the Mailbox
In December 1989, twenty thousand floppy disks arrived in mailboxes across ninety countries. The package looked official. The disk inside claimed to contain a questionnaire about acquired immune deficiency syndrome, a subject that dominated headlines and frightened the public in equal measure. Researchers, hospitals, and health organizations who had attended a World Health Organization conference earlier that year were among the recipients. They loaded the disk, expecting a survey. What they got instead was the first piece of ransomware in recorded history.
The program, later known as the AIDS Trojan or PC Cyborg, sat quietly on infected machines and counted reboots. After ninety restarts, it sprang. File names scrambled. Directories became unreadable. A message appeared demanding payment to restore access, and the instructions read like something from a spy novel. Victims were told to mail a cashier's check or international money order for one hundred eighty nine dollars, or three hundred seventy eight dollars for a so called lifetime license, to a post office box registered to the PC Cyborg Corporation in Panama City.
The man behind it was Joseph Popp, a Harvard trained biologist. Investigators traced the scheme back to him with relative ease, in part because the entire monetization model depended on a physical address that money had to travel toward. A post office box in Panama is a thread that law enforcement can pull. Popp was arrested at Amsterdam's Schiphol Airport, extradited, and eventually declared unfit to stand trial after his behavior in custody grew erratic, including a period when he reportedly wore a cardboard box on his head to protect himself from radiation.
The technical sophistication of the AIDS Trojan was modest. Its encryption was weak enough that a security researcher named Jim Bates wrote tools to reverse it without paying a cent. But the deeper lesson sat in the economics, not the cryptography. Popp had built a working extortion machine and could not figure out how to get paid without exposing himself. Every dollar he hoped to collect had to flow through a named entity, a checkable address, a banking system that kept records and answered subpoenas. The money was the weakest link in the chain, and it remained the weakest link for the next two decades.
This is the quiet truth that sits beneath the entire modern story of ransomware. For roughly twenty three years, from 1989 through the early 2010s, extortionists who wanted to lock up a victim's files faced a problem that had nothing to do with code. They could break in. They could encrypt. They could threaten. What they could not do, at scale and at a safe distance, was collect. Wire transfers were traceable and reversible. Prepaid cards and money orders were slow, cumbersome, and tied to retail chokepoints where a clerk might remember a face or a camera might catch one. Western Union and its cousins kept ledgers and cooperated with police. The friction of getting paid kept ransomware small, regional, and amateurish, more a nuisance than an industry.
Then a payment rail appeared that erased that friction almost overnight, and the entire criminal calculus changed.
The Payment Rail That Changed Everything
Bitcoin launched in January 2009 as an experiment in money without banks. Its creator, writing under the name Satoshi Nakamoto, wanted a currency that two strangers could exchange directly, anywhere on earth, without asking permission from a financial institution. The system was global from its first day. It settled in minutes rather than business days. And while every transaction was recorded permanently on a public ledger, the identities behind the addresses were not. A wallet was a string of characters, not a name.
For ordinary users, this combination of speed, reach, and pseudonymity was a curiosity. For extortionists, it was the missing piece of a machine they had been trying to build for a generation. Bitcoin gave them a way to demand money from a hospital in Germany, a city government in Florida, or a logistics firm in South Korea, and to receive it without ever touching a bank that knew their name. The post office box in Panama could be retired. In its place sat an address that anyone could pay and no one could easily trace back to a person.
The first criminals to understand this built CryptoLocker, which surfaced in September 2013. CryptoLocker did what the AIDS Trojan had done, but with cryptography strong enough to be genuinely unbreakable and a payment system frictionless enough to be genuinely profitable. Victims found their documents, photos, and spreadsheets encrypted with a key held only by the attackers, and a countdown timer demanding payment in bitcoin or prepaid vouchers. The operation reportedly extorted millions of dollars in a matter of months before an international law enforcement effort disrupted its infrastructure. The proof of concept was complete. Strong encryption plus a borderless payment rail equaled a business that could run at industrial scale.
Four years later, the world saw what that scale looked like. In May 2017, a worm called WannaCry tore across the internet using a stolen exploit that the United States National Security Agency had developed and lost. It infected an estimated two hundred thousand machines across one hundred fifty countries in a matter of days. Britain's National Health Service was hit hard, with hospitals diverting ambulances and canceling operations as their systems froze. The ransom demand appeared in dozens of languages, asking for three hundred dollars in bitcoin, rising to six hundred if victims delayed. WannaCry was technically clumsy in its payment handling, using only a handful of fixed bitcoin addresses that made the proceeds easy to watch, and a researcher named Marcus Hutchins accidentally found a kill switch that halted its spread. But the message landed. A single piece of self propagating code, monetized through a public blockchain, could hold a chunk of the planet's critical infrastructure hostage at once.
What cryptocurrency did, in plain terms, was collapse the cash conversion cycle. In the old model, the time between locking a victim's files and actually holding usable money could stretch for weeks, with each step exposing the criminal to risk. In the new model, the cycle compressed to minutes. A modern ransomware crew generates a unique payment address for each victim, watches the public ledger in real time, and automates the release of a decryption key the moment the funds land. There is no clerk, no wire confirmation, no waiting. The speed itself increases the probability of payment, because a frightened administrator staring at an encrypted hospital network is far more likely to pay when the path to recovery is a single transaction away.
The numbers tell the rest of the story. According to Chainalysis, the blockchain analytics firm whose annual crime reports have become the closest thing the industry has to a scoreboard, ransomware extortion reached a record of roughly 1.25 billion dollars in 2023. The firm found that ransomware, along with darknet market sales, remained dominated by bitcoin even as other categories of crypto crime shifted toward stablecoins. The overwhelming majority of tracked ransom payments moved through cryptocurrency rails, because no other payment system on earth offered the same blend of global reach, settlement speed, and distance from the victim. Without that rail, the economics simply would not support the scale.
It is worth pausing on a counterfactual. Strip cryptocurrency out of the picture and ransomware does not vanish, but it shrinks back toward the nuisance level of the early 2000s. The affiliate programs that now power the industry, where the people who build the malware split proceeds with the people who deploy it, depend on instant and programmatic payments to keep partners motivated and paid. Remove that, and payment tracking and key release revert to slow, manual, error prone processes that depress payment rates and lengthen every attack cycle. Many of the headline assaults on hospitals, pipelines, and city governments would have been too difficult to monetize to bother with. The billion dollar criminal industry that exists today is, in a real sense, a creature of its payment system.
But that same payment system carries a property its early users underestimated. The ledger is public, and it never forgets.
Colonial Pipeline and the Limits of Anonymity
On the morning of May 7, 2021, employees at Colonial Pipeline discovered a ransom note on their systems. Colonial operated the largest fuel pipeline in the United States, moving roughly half of the gasoline, diesel, and jet fuel consumed on the East Coast. A criminal group called DarkSide, operating a ransomware as a service model out of Eastern Europe, had breached the company's network through a single compromised password on a legacy virtual private network account that lacked multifactor authentication. Within hours, Colonial shut down the entire pipeline as a precaution, and the consequences rolled outward fast. Gas stations across the Southeast ran dry. Drivers panic bought fuel, sometimes filling plastic bags. The price at the pump jumped, and the President of the United States was briefed on a cyberattack that had become a national supply crisis.
Colonial paid. The company transferred roughly seventy five bitcoin, worth about 4.4 million dollars at the time, to DarkSide in exchange for a decryption tool, though the tool worked so slowly that Colonial relied largely on its own backups to restore operations. The payment was a controversial decision, the kind that fuels endless debate about whether paying ransoms simply finances the next attack. But the more instructive part of the Colonial story is what happened next, because it revealed the hidden cost of the very rail that made the attack profitable.
The Federal Bureau of Investigation had been watching. Investigators followed the seventy five bitcoin as it moved across the public ledger, address to address, until a portion of it landed in a wallet whose private key the bureau was able to obtain. In June 2021, roughly a month after the attack, the Department of Justice announced that it had clawed back about sixty three and a half bitcoin, the majority of the ransom. The funds that had flowed out through an allegedly untraceable system had been traced, seized, and returned. According to the deputy attorney general at the time, the message was that the United States would use every tool to make these attacks more costly and less profitable for the people who carried them out.
This is the paradox at the heart of crypto enabled crime. The same transparency that lets a criminal watch a payment arrive in real time also lets an investigator watch it leave. Cash is anonymous in a way bitcoin never was. A briefcase of bills passed in a parking lot leaves no permanent, globally visible record. A bitcoin payment leaves exactly that. The pseudonymity of a blockchain address protects a criminal only until that address is linked to a real identity, and every cash out point, every exchange, every moment where digital value must become spendable money, is a place where that link can be forged.
Criminals understand this, which is why the modern playbook is not simply to receive a ransom and walk away. It is to launder, and laundering on a public ledger is its own arms race. The technique that defines it is called chain hopping. Proceeds that arrive as bitcoin are swapped into stablecoins, pushed through cross chain bridges into entirely different blockchains, run through decentralized exchanges, and funneled toward high liquidity venues or over the counter brokers who can convert the value to cash with minimal questions asked. Each hop is designed to break the analytic heuristics that blockchain investigators rely on, particularly the older tools tuned to follow funds through a single chain or a single mixing service. When the North Korean group Lazarus laundered the proceeds of one of the largest crypto thefts in history, it did exactly this, bridging assets from Ethereum to other chains and swapping them across protocols hundreds of times to muddy the trail.
The extortion itself has grown more vicious in parallel. The original model was simple, encrypt the data and demand payment for the key. Then crews added a second layer, stealing the data before encrypting it and threatening to publish it on leak sites if the victim refused to pay, which defeated the protection that good backups had offered. Then came a third layer, where attackers reach past the victim to pressure the victim's customers, patients, or business partners directly, turning a single breach into a cascade of extortion. This triple extortion approach keeps the operators physically distant from everyone they harm while multiplying the points of leverage. The crypto rail makes the distance possible. The criminal can sit in one jurisdiction, encrypt a network in a second, leak data hosted in a third, and collect payment through a blockchain that respects none of the borders in between.
To understand how a clumsy nuisance from 1989 became this, you have to look at how the business was organized.
The Industrialization of Extortion
The word that best describes modern ransomware is not technical. It is industrial. The crews that dominate the field do not look like lone hackers in basements. They look like companies, with specialized roles, profit sharing arrangements, customer service portals, recruitment drives, and brand reputations they actively manage. The model that made this possible is ransomware as a service, and it functions almost exactly like a legitimate software franchise.
At the center sits the operator, the group that writes and maintains the malware, runs the leak site, manages the payment infrastructure, and handles negotiations. Around the operator orbit the affiliates, independent criminals who rent access to the malware and carry out the actual intrusions. When an affiliate breaches a target and collects a ransom, the proceeds are split, often with the affiliate keeping the larger share and the operator taking a percentage off the top. None of this works without instant, programmatic crypto payments. The trust between operator and affiliate, two parties who will never meet and could never sue each other, is enforced by the ledger itself, which makes the split automatic and verifiable. Remove the payment rail and the franchise collapses, because there is no other way to coordinate thousands of dollars in profit sharing between anonymous strangers across hostile borders.
For several years, the dominant franchises were names like LockBit and ALPHV, also known as BlackCat. They ran professional operations. LockBit in particular built a reputation for reliability that attracted affiliates the way a strong brand attracts franchisees, and it pioneered a strategy the industry now calls big game hunting. Rather than spraying ransomware indiscriminately and collecting small payments from many victims, big game hunters carefully select large organizations with deep pockets and low tolerance for downtime, hospitals, manufacturers, critical infrastructure operators, and demand enormous sums from each. According to Chainalysis, the median payment to the most severe ransomware strains climbed from just under two hundred thousand dollars in early 2023 to roughly 1.5 million dollars by the middle of 2024, a shift that reflects exactly this move upmarket. In 2024, a group called Dark Angels reportedly extracted a single payment of around seventy five million dollars, the largest ever recorded at the time.
The years 2023 and 2024 became a turning point, though not in the direction the criminals intended. Law enforcement, having watched the public ledgers for years and built relationships with exchanges willing to freeze funds, began striking at the operators directly. In early 2024, a coordinated effort led by the United Kingdom's National Crime Agency and the United States Federal Bureau of Investigation seized LockBit's infrastructure, took over its leak site, and turned the group's own platform into a stage for announcing the disruption. According to Chainalysis, LockBit's payments fell by roughly seventy nine percent in the second half of that year. Around the same time, ALPHV pulled what observers described as an exit scam, vanishing with funds owed to its own affiliates. The double blow shattered the established order.
The result was visible in the numbers. After the record 1.25 billion dollars extorted in 2023, ransomware payments fell by roughly thirty five percent in 2024 to about 813 million dollars, according to Chainalysis, the first annual decline since 2022. Part of the drop came from the disruptions, part from a growing willingness among victims to refuse payment, and part from a striking change in criminal behavior. The firm observed that ransomware operators, normally a relentlessly financially motivated group, were cashing out less than ever before, apparently spooked by the unpredictability of law enforcement actions and uncertain about where they could safely move their funds. The transparency of the ledger had become a source of paralysis. Money sat in wallets, visible to everyone, that no one dared to spend.
This is the central tension of the whole system. Cryptocurrency industrialized ransomware by solving the payment problem, and in solving it created a permanent, public record that now haunts the people who depend on it. The industry did not retreat in the face of this. It adapted. New franchises rose to fill the vacuum left by LockBit and ALPHV, rebranding leaked or purchased code under fresh names, moving faster, and beginning negotiations within hours of stealing data rather than days. The cat and mouse pattern continued, with criminals innovating around each new pressure point.
And the pressure points the criminals find are rarely the cryptography. They are the gaps in the rules that govern how digital value moves through the world.
The Gaps Criminals Live In
If you want to understand where crypto enabled crime actually thrives, do not look at the code. Look at the seams between legal systems, the places where one jurisdiction's rules end and another's have not yet begun. Criminals are connoisseurs of these seams. The most reliable of them is jurisdictional arbitrage, the practice of routing operations through countries where oversight is thin and cooperation with foreign investigators is thinner.
The Financial Action Task Force, an intergovernmental body that sets global standards against money laundering, has spent years pushing jurisdictions to license and supervise the businesses that handle crypto, known in the regulatory vocabulary as virtual asset service providers. The standards have matured. Yet plenty of light touch jurisdictions still allow exchanges, over the counter desks, and hosting providers to operate with minimal scrutiny, and these become safe harbors for illicit money. The clearest example is Garantex, a Russia based exchange that the United States Treasury's Office of Foreign Assets Control sanctioned for laundering funds on behalf of ransomware operators and other criminals. Garantex kept operating after the sanctions, according to Chainalysis, for the simple reason that Russia does not enforce American sanctions. A line drawn in Washington means nothing in a jurisdiction that refuses to recognize it, and criminals know exactly which jurisdictions those are.
Decentralized finance adds a second seam, this one carved out of legal definitions rather than geography. Many DeFi front ends present themselves as nothing more than non custodial software, mere interfaces to autonomous code, and on that basis argue they bear none of the obligations that bind a brokerage or an exchange. The argument has real legal force, because in a strict sense the protocol never takes custody of anyone's funds. But the practical effect is that something which routes liquidity, matches trades, and offers a polished user experience indistinguishable from a brokerage can sometimes sidestep the screening and reporting duties a brokerage would face. Combine that with privacy coins, which obscure transaction details by design, and with mixing services built into automated market makers, and sanctions screening grows porous in exactly the places where it matters most.
The third seam is the on ramp and off ramp, the moment where crypto becomes cash or cash becomes crypto. This is the chokepoint criminals must eventually pass through, and they look for the weakest gate. Peer to peer markets, smaller exchanges, and over the counter brokers frequently apply minimal know your customer checks and inconsistent compliance with the Travel Rule, the requirement that identifying information accompany transfers. These become pressure valves, the places where illicit funds finally escape into the spendable economy. According to Chainalysis money laundering research, the concentration of cash out activity in a handful of services is high enough that disrupting a few key off ramps can meaningfully damage entire criminal categories, which is why law enforcement has increasingly targeted the no questions asked exchanges that specialize in this work.
Underneath all of this runs a fourth seam, the opacity of identity. Criminals forge electronic identity documents to pass automated verification, hijack phone numbers through SIM swap attacks to defeat two factor authentication, recruit money mules to open accounts in their own names, and stack shell companies in layers deep enough that a subpoena issued against the outer shell reveals nothing about the people inside. Each layer buys time, and time is what frustrates asset freezes and lets stolen value slip out the off ramp before anyone can close it.
And then there is the seam of pure speed. A new cross chain bridge, a new layer two network, a new restaking scheme can be designed, built, and deployed in a matter of weeks. The regulatory guidance that should govern it, by contrast, can take months or years to draft, debate, and enact. Criminals move at the speed of software. Regulators move at the speed of law. That mismatch is not a temporary glitch, it is a structural feature of the contest, and it means that by the time a rule arrives to govern a particular innovation, the criminals have often already moved on to the next one. The honest question is not whether regulators can catch up to where the criminals are. It is whether the rule making process can ever accelerate enough to close the gap before attackers reach the next frontier.
The encouraging part of the story is that the machinery of rules, slow as it is, has finally begun to move.
The Slow Machinery of Rules
For most of crypto's history, the regulatory response resembled a patchwork quilt stitched by people who could not see each other's work. Every country improvised. Definitions clashed. A business legal in one place was contraband in another, and a transfer that satisfied one regulator violated the next. Criminals thrived in the seams between these mismatched pieces. Over the past few years, however, a more coordinated picture has begun to take shape, and the direction of travel matters even where the destination is not yet reached.
At the global level, the Financial Stability Board and the Financial Action Task Force have pushed for alignment, and the push has produced movement. Nearly all Financial Stability Board member jurisdictions have adopted new or revised frameworks for crypto assets and stablecoins. The Travel Rule, which requires the businesses handling crypto transfers to collect and share identifying information about senders and receivers, has gained real ground. According to a 2025 update from the Financial Action Task Force, roughly ninety nine jurisdictions have now either passed or are in the process of passing legislation to implement the rule, a sharp increase from prior years. The catch, which the same body acknowledges plainly, is that passing a law and enforcing it are different things. A majority of jurisdictions with Travel Rule legislation on the books had not yet taken meaningful supervisory or enforcement action, and the uneven timing of adoption creates what regulators call the sunrise problem, where a compliant business in one country must transact with a counterpart in a country that has not yet switched its rules on.
The most ambitious regional effort is European. The Markets in Crypto Assets framework, known as MiCA, came fully into force at the end of 2024, replacing a tangle of national regimes with a single set of rules and a passporting system that lets a compliant provider operate across the entire European Union. Enforcement falls to the European Securities and Markets Authority and the European Banking Authority. Alongside it, the European Union's Transfer of Funds Regulation took effect on December 30, 2024, imposing full Travel Rule compliance on every crypto transfer between service providers with no minimum threshold, which is among the strictest requirements anywhere in the world.
Asia's major financial centers have moved in parallel. Singapore and Hong Kong now require crypto exchanges to be licensed under their financial authorities, a step that closes offshore loopholes and forces full anti money laundering and know your customer compliance on businesses that once operated in the shadows. The United Kingdom has advanced its own comprehensive regime for digital assets, and the United Arab Emirates has built out a dedicated Virtual Assets Regulatory Authority, each aiming to position itself as a hub that attracts legitimate innovation while protecting consumers and screening out illicit flows.
Stablecoins, the dollar pegged tokens that have become the preferred vehicle for a growing share of illicit transaction volume, have drawn particular attention. New rules across the European Union, the United Kingdom, the United States, and parts of Asia increasingly mandate that issuers hold genuine reserves backing every token, submit to real time or near real time auditing, and meet transparency requirements designed to prevent the kind of systemic risk that a sudden loss of confidence could trigger. The United States moved on this front with dedicated stablecoin legislation, and the effect across jurisdictions has been to pull stablecoins from a regulatory grey zone toward something closer to the oversight that governs traditional payment instruments.
There is also a quieter, more experimental thread running through all of this, the regulatory sandbox. Across financial hubs in Asia and Europe, regulators have created supervised environments where DeFi projects and other crypto innovators can operate under close watch, demonstrate that their compliance controls work, and refine their practices before facing the full weight of regulation. The sandbox is an attempt to resolve the speed mismatch from the other direction, not by slowing the criminals but by giving honest builders a faster path to legitimacy, so that compliance and innovation can develop together rather than at war.
None of this amounts to a solved problem. Global coordination remains a work in progress, offshore jurisdictions still offer refuge, and cross border enforcement still founders on the rocks of national sovereignty. But the combination of shared standards, licensing regimes, and sandbox programs represents a real step toward closing the gaps that criminals have lived in for years. The question that hangs over it all is one of pace. The machinery of rules is finally moving. Whether it can move fast enough is a different matter, and the cases that test it most severely are the ones where billions of dollars vanish in the time it takes to read this sentence.
To see how that happens, and how it might be prevented, consider the bridge that fell.
The Bridge That Fell
In the spring of 2022, the most popular blockchain game in the world was a thing called Axie Infinity. Players bred, battled, and traded cartoonish creatures called Axies, and at the height of the craze the game generated enormous revenue and supported a play to earn economy that, in some developing countries, people relied on for income. Axie ran on a custom blockchain called Ronin, built by a studio named Sky Mavis. Ronin was a sidechain, a network running alongside Ethereum, and the two were connected by a bridge, a piece of infrastructure that let users move assets back and forth between the chains.
Bridges are the soft underbelly of the crypto world. To move value from one blockchain to another, a bridge must lock assets on one side and release equivalent assets on the other, which means it has to hold enormous pools of funds and trust some mechanism to authorize their movement. The Ronin bridge used a set of nine validator nodes, and a transaction required the approval of five of them to go through. The design was meant to be decentralized, so that no single point of failure could drain the funds. In practice, the decentralization was an illusion, and that illusion cost more than six hundred million dollars.
The roots of the disaster reached back to November 2021. Overwhelmed by a surge of users, Sky Mavis had asked the Axie decentralized autonomous organization, a community body, for help distributing free transactions. The Axie DAO whitelisted Sky Mavis to sign transactions on its behalf. The arrangement was discontinued the following month, but a fatal detail was overlooked. The access was never revoked. Sky Mavis controlled four of the nine validators directly, and through the lingering whitelist arrangement it retained the technical ability to produce a signature from a fifth validator run by the Axie DAO. Four plus one equals five, and five was the threshold. The security of a six hundred million dollar bridge rested on a permission everyone had forgotten to turn off.
The attackers found it. The group, later identified by United States authorities as Lazarus, the hacking organization tied to North Korea, used social engineering to compromise Sky Mavis systems. According to Sky Mavis, the intrusion traced back to an elaborate effort that included a fake job offer delivered to an employee, a lure designed to plant malware on a machine inside the company. Once inside, the attackers gained control of the four Sky Mavis validators and then exploited the forgotten whitelist to produce the fifth signature from the Axie DAO validator, using a gas free remote procedure call node that Sky Mavis ran. With five of nine validator keys effectively in hand, they had a majority. They authorized two withdrawals, draining roughly 173,600 ether and 25.5 million USD Coin from the bridge, a combined haul worth more than six hundred million dollars at the time.
The most chilling detail is not the theft. It is the silence. The two transactions executed on March 23, 2022, and for nearly six days, nobody at Sky Mavis noticed. The funds were gone, sitting in the attackers' wallets, and the company carried on unaware. The breach came to light only when an ordinary user tried to withdraw five thousand ether through the bridge and found that the money was not there. That single failed withdrawal, almost a week after the fact, was what finally exposed the largest crypto theft in history to that point.
The aftermath was a scramble. Sky Mavis halted the bridge, raised the validator threshold, and brought in Chainalysis and law enforcement to chase the funds. Binance disabled its own bridge to Ronin to add a layer of safety. The company eventually reimbursed users, sourcing liquidity from its own balance sheet, from its founders, and from a 150 million dollar funding round led by Binance. Investigators recovered a fraction of the stolen value over time, and more than a year later law enforcement and the crypto industry managed to seize tens of millions of dollars as Lazarus tried to launder the proceeds through the chain hopping methods described earlier. But the bulk of the money disappeared into the laundering apparatus of a nation state.
The Ronin disaster is a lesson written in three parts. The first is about centralization masquerading as its opposite, a system that called itself decentralized while resting on a handful of keys controlled by one company. The second is about the human layer, since the entire breach began not with broken cryptography but with a fake job offer and a forgotten permission. The third, and perhaps the most damning, is about detection. Six hundred million dollars vanished and the operator did not know for six days. In a world where exploits unfold in seconds, a six day blind spot is not a security failure. It is an absence of any nervous system at all.
Not every story of a stolen fortune ends in the dark, though. Sometimes the money comes back, and the way it comes back is stranger than the theft.
The Hacker Who Gave It Back
On March 13, 2023, a little less than a year after Ronin, a decentralized lending protocol called Euler Finance was attacked. Euler was a respected name in decentralized finance, a permissionless platform on Ethereum that let users lend and borrow crypto assets, and it had been audited by multiple security firms. Its reputation for safety made what happened both shocking and instructive, because the attack exploited not a stolen key or a phishing email but a subtle flaw buried in the protocol's own logic.
The weapon was a flash loan, one of the strangest instruments in all of finance. A flash loan lets a borrower take out an enormous sum with no collateral whatsoever, on the single condition that the loan is borrowed and repaid within the same blockchain transaction. If the borrower cannot pay it back by the end of that atomic sequence of operations, the entire transaction reverses as if it never happened, so the lender faces no risk. Flash loans exist to enable legitimate arbitrage and refinancing, but in the hands of an attacker they become a way to wield millions of dollars of capital for a few seconds, just long enough to manipulate a vulnerable system.
The Euler attacker borrowed thirty million DAI, a dollar pegged stablecoin, through a flash loan from the Aave protocol. The funds were then pushed into Euler and used to exploit a flaw in a function called donateToReserves, which the protocol's developers had failed to protect with a proper check on the health of the resulting financial position. Through a carefully constructed sequence of deposits, borrows, and a self inflicted liquidation, the attacker manufactured a situation in which the protocol treated an artificially distressed position as eligible for liquidation at a steep discount, and walked away with the difference. The maneuver was repeated across several of Euler's pools. By the time the transaction sequence resolved, roughly 197 million dollars in DAI, wrapped bitcoin, staked ether, and USD Coin had been drained from the protocol. It was the largest crypto hack of 2023.
What happened over the following three weeks is what makes the Euler story extraordinary. The Euler team began with the standard moves, contacting law enforcement, engaging auditors, and reaching out to the attacker directly through messages embedded in blockchain transactions. They offered a deal, the attacker could keep ten percent of the stolen funds, worth nearly twenty million dollars, if the rest was returned, with a threat to launch a one million dollar bounty for information leading to an arrest if the offer was refused. At first the signs were grim, as the attacker pushed some of the funds through Tornado Cash, a mixing service, and a small portion of the money even drifted toward wallets associated with Lazarus, the same North Korean group behind Ronin.
Then, slowly, the money started coming back. On March 18, the attacker returned a tranche. Over the following days, more followed, including a single return of more than one hundred million dollars worth of ether. The attacker sent a series of on chain messages, at one point apologizing, and by early April had returned essentially all of the recoverable funds. With the price of ether rising during the negotiation period, the value ultimately returned to Euler users came to roughly two hundred forty million dollars, more than the dollar value originally stolen, prompting affected users to joke that the thief had turned out to be a better trader than they were.
The episode is a small miracle that should not be mistaken for a strategy. No protocol can build its security plan on the hope that an attacker will feel remorse. But the Euler case carries two lessons that matter beyond its happy ending. The first is technical, that the most dangerous vulnerabilities in decentralized finance are not always the obvious ones, and that a single unprotected function in audited code can become a doorway to a two hundred million dollar loss in the span of one transaction. The second is about detection again, the same theme that haunts Ronin. The Euler attack generated liquidity movements and price swings far outside any normal statistical range, the kind of anomaly that a system designed to watch for it could have caught in real time. The drain happened in a single day through a sequence of operations that screamed abnormality at every step. The question Euler raises is whether protocols and the exchanges that connect to them can build something that notices the scream while it is happening, rather than reading about it afterward.
That question is no longer hypothetical. The answer is starting to take the shape of an immune system.
Building an Immune System
There is a fact about crypto that should embarrass the entire industry. In far too many cases, a billion dollar breach is discovered on social media before the affected company reacts to it. Someone watching the public ledger spots an enormous, anomalous outflow, posts about it, and the news spreads through the crypto community while the exchange or protocol that lost the money is still figuring out what happened. The Ronin blind spot of six days is the extreme version, but the pattern of external detection beating internal detection is depressingly common. The first principle of a serious defense is that this has to change. Exchanges and protocols must treat blockchain risk as a live operational signal, something monitored continuously and acted on automatically, rather than a quarterly audit item.
The most direct application of this principle is to gate the movement of funds on the real time health of the underlying network. An exchange can monitor confirmation times, the version risk of the node software running across the network, the rate of chain reorganizations, and unusual spikes in the activity of bots that extract value by reordering transactions. When those metrics drift toward instability, or when credible chatter about an active exploit begins to circulate, the system can automatically slow or halt deposits and withdrawals until the integrity of the chain is confirmed. The logic is the same as a circuit breaker on a stock exchange, a mechanism that stops trading when conditions grow violent enough to suggest something has gone wrong. Speed favors the attacker in a crypto exploit, so the defender's best move is often to take speed off the table at the first sign of trouble.
The second layer is a risk engine that behaves like an independent co signer on every transaction. Before any transfer is approved, the engine simulates it and scores it against a set of risk factors, the reputation of the destination address, the traits of any contract code involved, the presence of patterns associated with known drainer attacks, and whether the size of the transfer deviates sharply from the account's normal behavior. If the score crosses a threshold, the engine blocks the transaction, and crucially it does so even if a human operator tries to push it through. This last point matters enormously, because so many catastrophic losses involve a compromised insider or a deceived employee. A risk engine that can be overridden by a single human is a risk engine that a single compromised human can disable. The defense only holds if the machine retains a veto.
The third layer is key management, the discipline of controlling the cryptographic keys that authorize the movement of funds. The Ronin disaster was, at its core, a key management failure, five keys that should have been independent and secure were not. The modern answer is to split signing authority so that no single point of compromise can drain anything. Multi party computation wallets divide a key into shards held by different parties, requiring a quorum to sign, so that stealing one shard accomplishes nothing. Hardware security modules protect the shards in tamper resistant devices. Air gapped signers keep the most sensitive keys on machines that never touch the internet. And any attempt to override these policies should demand out of band human verification through a separate channel, so that a single compromised signer cannot unilaterally authorize a transfer. The goal is to shrink the blast radius of any one compromise to as close to zero as possible.
The fourth layer is bridge hygiene, the specific discipline of managing the cross chain infrastructure that has proven to be the single most exploited category in all of crypto. Bridges are where the money pools, which is why they are where the attacks concentrate. A disciplined exchange maintains a short allowlist of trusted bridges rather than routing funds through whatever connection is convenient. It suspends bridges that show warning signs, validator churn, proof failures, or other indicators of instability. And it subjects any new bridge to rigorous due diligence before sending a single dollar through it. The Ronin bridge would have failed such scrutiny, because a system that calls itself decentralized while resting on five keys controlled by one company is exactly the kind of structure that careful due diligence is designed to catch.
The fifth layer is the one that organizations most often neglect, which is rehearsal. The difference between a company that loses everything in an exploit and one that contains the damage is frequently a matter of minutes, and minutes are won or lost based on whether the team has practiced. Tabletop exercises that simulate a fifty one percent attack on a network, a chain split, or a bridge hack let a team discover its weaknesses in a drill rather than a crisis. Pre drafted communications to users, prepared in advance for various disaster scenarios, let a company speak clearly and quickly when panic would otherwise freeze it. Pre arranged escalation channels with the teams that run the underlying protocols mean that when something breaks at two in the morning, the right people are already reachable. When billions of dollars can vanish in a single exploit, the organizations that survive are the ones that decided, long before the attack, exactly what they would do when it came.
Taken together, these layers form something like an immune system, a defense that watches continuously, recognizes threats by their patterns, and responds automatically before a human could even be roused from sleep. But an immune system raises a hard question of its own. How much watching is too much. A blockchain that monitors everything, freezes anything suspicious, and demands identity at every turn begins to look like the very surveillance apparatus that crypto was invented to escape. The challenge is to build the immune system without building a panopticon, and that is where the deepest debate in the field lives.
Decentralization Without Surrender
There is a tempting story that says decentralization and regulation are natural enemies, that any movement toward compliance is a retreat from the founding promise of crypto, and that the only honest positions are total freedom or total control. The story is wrong, and the future of the field probably belongs to the people who refuse to believe it. The more interesting path runs between the two poles, toward systems that can satisfy a regulator without dismantling the properties that make a blockchain worth using in the first place. The name for this path is privacy preserving compliance, and the technologies that enable it are no longer theoretical.
Consider first the role that artificial intelligence can play in monitoring. Traditional compliance tools are reactive, built to catch problems after the damage is done, generating reports that get reviewed days or weeks later. An AI driven risk engine can watch a blockchain continuously and flag suspicious patterns as they form, validator behavior that suggests collusion, clusters of approvals that deviate from any normal distribution, the specific signature of a flash loan manipulation in progress. Apply that lens to the cases already described and the value becomes obvious. A model trained on the normal behavior of Ronin's validators might have noticed the unusual pattern of approvals that drained the bridge and paused it before the second withdrawal cleared, rather than waiting six days for a confused user to raise the alarm. A model watching Euler might have caught the wild, statistically impossible swings the flash loan attack produced and triggered a freeze before the final drain. Paired with automated circuit breakers, this kind of monitoring gives a protocol the reflexes it needs, letting legitimate transactions flow while slamming on the brakes the instant activity crosses a genuine risk threshold.
Then comes the cryptography that resolves the apparent conflict between compliance and privacy. The breakthrough is the zero knowledge proof, a mathematical technique that lets one party prove a statement is true without revealing the information behind it. Applied to compliance, a zero knowledge proof lets a user demonstrate that they have passed anti money laundering and know your customer checks without exposing any of their personal data to the protocol or the counterparty. The regulator gets the assurance it needs, that this user has been vetted, while the user keeps their identity private. This single tool dissolves the false choice between a surveillance network and a lawless one. It becomes possible to prove compliance and preserve privacy at the same time, which is something the traditional financial system, built on the wholesale collection of personal data, has never managed to do.
Account abstraction extends the idea further. It allows the rules a regulator might care about, spending limits, geographic restrictions, risk thresholds, to be enforced at the level of an individual wallet rather than hardcoded permanently into the protocol itself. This keeps the base layer of the blockchain neutral and flexible while letting compliance requirements live where they belong, close to the user, configurable, and upgradeable. A protocol does not have to become a compliance machine for everyone in order to let those who need compliance achieve it.
From these pieces a hybrid structure emerges, often described as tiered compliance. The permissionless rails stay open for ordinary users who want to transact directly, preserving the openness that defines the technology. Meanwhile, institutions that face strict reporting obligations can route their transactions through whitelisted, policy aware pools that satisfy every requirement their regulators impose. Two worlds coexist on the same underlying infrastructure, one optimized for openness and one for oversight, and a user or institution chooses the lane that fits their needs. Regulators get verifiable assurance that controls are in place where they are required, and the blockchain as a whole avoids becoming a single surveilled network where every transaction is logged against a real name.
The encouraging reality is that this is not a distant vision. Many DeFi projects are already building in this direction, developing on chain monitoring tools, experimenting with privacy preserving compliance mechanisms, and engaging with regulators proactively rather than treating every rule as an existential threat. The destination they are working toward is a system where trust is established through cryptographic proof rather than through the mass collection of personal data, a world in which innovation and systemic safety reinforce each other instead of pulling in opposite directions. It is an optimistic vision, and there is real work behind it.
But there is a threat on the horizon that could, in a single technological leap, render much of this moot. It does not come from criminals exploiting a forgotten permission or a flawed function. It comes from physics.
The Asteroid on the Horizon
Every blockchain in existence rests on a foundation of cryptography that, for now, no computer on earth can break. The digital signatures that prove you own your coins, the algorithms with names like ECDSA, BLS, and RSA, are secure because reversing them would require an amount of computation so vast that the fastest classical supercomputers would need longer than the age of the universe to do it. This is not a comforting margin of safety so much as an assumption, and the assumption has an expiration date. Its name is quantum computing.
A sufficiently powerful quantum computer, running an algorithm devised by the mathematician Peter Shor in 1994, could break these signatures not through brute force but through a fundamentally different way of computing that collapses the hard problem into a tractable one. The machines capable of this do not yet exist at the necessary scale. The threat is not present tense. But it is approaching, and the approach has already begun to cause damage in a way that catches many people off guard, through a strategy known as harvest now, decrypt later.
The logic is patient and unsettling. An adversary does not need a quantum computer today to begin attacking the cryptography of tomorrow. It only needs storage. By collecting encrypted blockchain traffic and sensitive communications now, an attacker can simply wait, holding the data until a quantum breakthrough arrives that lets them decrypt it retroactively. Anything that needs to stay secret for years, and the contents of a blockchain are meant to stay verifiable forever, is already exposed to an adversary who is willing to wait. The harvest is happening in the present. The decryption is scheduled for a future that grows closer each year.
The greater danger lies in what becomes possible once the machines mature. An attacker who can break the digital signatures underlying a blockchain could forge transactions, draining funds from any wallet whose public key is visible on the chain. They could potentially rewrite parts of blockchain history. They could, in the worst scenarios, dissolve the entire trust model that makes a cryptocurrency function, because a signature that anyone can forge is no signature at all. The whole edifice of ownership and verification depends on the assumption that only the holder of a private key can produce a valid signature, and a quantum computer running Shor's algorithm would shatter that assumption.
Preparing for this is harder than it sounds, because there will be no single moment when the world flips to quantum safe cryptography. There is no flag day, no coordinated switch that every blockchain, wallet, node, and custodian throws at once. The transition has to be gradual and carefully sequenced, and it demands a property that most crypto systems were not designed with, cryptographic agility, the ability to upgrade the underlying algorithms without breaking interoperability or splitting the network into incompatible halves. Hybrid signing periods, during which a system accepts both the old classical signatures and the new quantum safe ones, will be necessary to give users time and confidence to move their funds into quantum secure accounts before the old signatures become dangerous.
The work of defining the replacements is already underway, led by the United States National Institute of Standards and Technology, which in 2024 finalized its first set of post quantum cryptography standards, algorithms designed to resist attack by both classical and quantum computers. The institute's guidance points toward deprecating the weaker classical algorithms around 2030 and moving toward quantum safe adoption in the years that follow. The most forward looking organizations are not waiting for that deadline. They are already inventorying their cryptographic dependencies, cataloging exactly where and how they rely on the vulnerable algorithms, testing migration tooling, and running simulated upgrade scenarios so that when the transition becomes urgent they are not improvising under pressure.
The teams that act early will gain more than technical safety. They will earn a trust premium from users and regulators who can see that they took the threat seriously while there was still time to act with care. The organizations that delay risk the opposite, a chaotic scramble when the first credible quantum attack reaches the headlines, or worse, the irreversible loss of assets secured by cryptography that suddenly no longer works. The advantage belongs to the prepared, and preparation is something that can only be done in advance, never in the moment of crisis.
Quantum computing is best understood as an asteroid that astronomers have already spotted on the horizon. The arrival date is uncertain, the precise size is unknown, but the trajectory is real and the impact, if nothing is done, would be catastrophic. The difference between an asteroid and most security threats is that this one announces itself years ahead, which means there is time to build a deflection plan. The only way to waste that time is to assume the asteroid is someone else's problem. The blockchains that treat quantum security as a strategic priority today are the ones that will still be trustworthy a decade from now, and the projects that dismiss it as science fiction are the ones whose history may, in the worst case, be rewritten by a machine they refused to take seriously.
What the Ledger Remembers
Trace the whole arc and a strange symmetry appears. Joseph Popp's failure in 1989 and the crypto criminal's predicament in 2024 are mirror images of the same problem. Popp could not get paid because the money he wanted left an unavoidable trail back to a post office box in Panama. The modern ransomware operator can get paid instantly from anywhere on earth, and yet sits on wallets full of money he is increasingly afraid to spend, because the ledger that delivered his ransom also recorded it forever and showed it to everyone, including the investigators who froze the off ramps and the analysts who watched the funds hop from chain to chain. Cryptocurrency solved the criminal's collection problem and handed him a surveillance problem in exchange. The trail never went away. It only changed shape.
That is the deepest truth running through every case in this story. The Ronin bridge fell because of a permission no one revoked and a network that pretended to be decentralized while resting on five keys, and yet the public nature of the chain is precisely what let investigators chase Lazarus and seize a portion of the funds. Euler lost two hundred million dollars to a flaw in a single function, and the transparency of the ledger is what made the negotiation, and the eventual return, possible. The same property that exposes a blockchain to certain attacks is the property that makes those attacks traceable, which is why the contest between criminals and defenders is not a simple story of vulnerability but a constant tension between visibility and obscurity, speed and caution, openness and control.
The regulatory machinery grinds slowly toward closing the gaps that criminals live in, and it will never grind fast enough to satisfy anyone, because law moves at the speed of consensus while software moves at the speed of a single developer with an idea. The defensive technologies, the immune systems built from real time monitoring and risk engines that cannot be overridden, grow more capable each year, and so do the laundering techniques designed to defeat them. The cryptographers building zero knowledge proofs and quantum safe algorithms are, in a sense, racing two different clocks at once, one set by regulators and one set by physics. None of these races has a finish line. They are conditions to be managed rather than problems to be solved.
If there is a single lesson worth carrying out of all of it, it is that the systems people build reflect the assumptions they make, and the assumptions that fail are usually the ones nobody thought to question. Sky Mavis assumed a discontinued permission had been turned off. Euler assumed an audited function was safe. An entire generation of early ransomware victims assumed their money could not be taken back, and a generation of criminals assumed their payments could not be traced. Each assumption was reasonable until the moment it was catastrophic. The quantum threat is the largest unquestioned assumption of all, the belief that the cryptography holding up the entire edifice will keep holding, and the organizations preparing for its failure now are the ones treating an assumption as what it has always been, a thing that can break.
The ledger remembers everything. It remembers the ransom paid by a pipeline company and the path that money took before the FBI pulled most of it back. It remembers the six hundred million dollars that left a game's bridge in two silent transactions, and the hundreds of hops Lazarus used to launder it. It remembers the two hundred million dollars a hacker drained from a lending protocol and then, inexplicably, gave back. In a world of forgetting, the blockchain is the rare thing that does not forget, and that permanence is both the criminal's enabling tool and the criminal's lasting threat. Whoever understands that paradox most deeply, and builds for it most honestly, will define which systems still deserve trust when the next assumption fails.