In July 2024, a manufacturing company in Germany was hit by a ransomware attack. The attackers encrypted the company's production systems and demanded 12 Bitcoin (approximately $780,000) for the decryption key. The company's IT team, crisis managers, and legal counsel debated for 48 hours. They paid. The decryption key worked — the systems were restored. But the company's board asked a question that many ransomware victims eventually ask: can we trace where the Bitcoin went, and can we recover any of it?

The short answer is: tracing is possible, recovery is difficult but not impossible. The Department of Justice has recovered ransomware payments in several high-profile cases (Colonial Pipeline, Kaseya, BitPaymer). These recoveries were possible because law enforcement was able to trace the Bitcoin payments through mixers and chainhops and identify the cash-out point before the ransomware group could liquidate the funds. But these recoveries are the exception, not the rule. Most ransomware payments are never recovered.

In this article, I explain how ransomware groups move and launder Bitcoin payments, the forensic methods used to trace ransomware payments, the legal tools available for recovery, and what businesses should do before and after paying a ransom. This article is written for business owners, IT security teams, and legal counsel who are dealing with or preparing for a ransomware incident.

How ransomware groups move payments

Modern ransomware operates on a RaaS (Ransomware-as-a-Service) model. The ransomware code is developed by a core group (the developers), who license it to affiliates (the operators) who carry out the attacks. When a victim pays the ransom, the payment is split between the developers (typically 20-30%) and the affiliate (70-80%). This split happens automatically through the ransomware payment infrastructure.

After receiving the payment, the ransomware group typically follows a multi-stage laundering process:

Stage 1: Initial consolidation

The ransomware group receives the Bitcoin payment into a specific address (the payment address provided to the victim). Once the payment is confirmed, the Bitcoin is immediately moved to a consolidation address — a wallet that collects payments from multiple victims. This consolidation typically happens within minutes of the payment being confirmed.

At this stage, the Bitcoin is still on the Bitcoin blockchain and can be traced. The consolidation address may hold millions of dollars from multiple victims, making it a high-value target for law enforcement.

Stage 2: Mixer or coinjoin

From the consolidation address, the Bitcoin is sent to a mixer or coinjoin service. Mixers (like Blender.io, which was sanctioned by OFAC in 2022, or ChipMixer, which was seized by authorities in 2023) pool Bitcoin from multiple users and redistribute it in smaller amounts, breaking the link between the source and destination addresses. Coinjoin (used by services like Wasabi Wallet and Samourai Wallet) is a similar concept but operates in a more decentralized manner.

After Tornado Cash was sanctioned by OFAC in 2022, many mixers on Ethereum became unusable for ransomware groups — using a sanctioned mixer means the output is tainted and will be flagged by any exchange that receives it. On Bitcoin, however, mixing is still possible through decentralized coinjoin protocols and over-the-counter (OTC) brokers who accept mixed funds.

Stage 3: Chainhopping

After mixing, the Bitcoin may be bridged to another blockchain using cross-chain bridges (see our article on chainhopping for details). Thorchain is the most common bridge for Bitcoin, converting it to Ethereum or other chains. Once on a different blockchain, the funds are harder to trace because the connection between the Bitcoin and the new chain is obscured by the mixing step.

Stage 4: Conversion to stablecoins

The laundered funds are typically converted to a stablecoin (USDT or USDC) to preserve value without the volatility of Bitcoin. The stablecoins are then held in self-custody wallets or moved to exchanges for cash-out.

Stage 5: Cash-out

The final stage is converting the stablecoins to fiat currency. Ransomware groups use several cash-out methods:

The entire laundering process — from initial payment to final cash-out — can take anywhere from a few days to several months. The speed depends on the ransomware group's sophistication and the urgency of their cash needs. Some groups hold Bitcoin for months or years, waiting for favorable market conditions or reduced law enforcement attention.

Tracing ransomware payments: the forensic approach

Tracing a ransomware payment requires following the Bitcoin from the victim's payment to the ransomware group's consolidation address, through the mixer, through any chainhops, and to the final cash-out point. This is a complex forensic process that requires specialized tools and expertise.

The tools

Professional blockchain analytics tools (Chainalysis, TRM Labs, Elliptic) are the primary tools for tracing ransomware payments. These tools have specific features for ransomware investigation:

The process

The tracing process follows these steps:

  1. Document the payment: Record the payment address, the transaction hash, the amount, and the timestamp. This is the starting point for all tracing.
  2. Trace to the consolidation address: Follow the Bitcoin from the payment address to the consolidation address. This is usually straightforward — the ransomware group moves the payment quickly.
  3. Trace through the mixer: If the funds enter a mixer, attempt to trace through it. This is the hardest step. If the mixer has been seized by law enforcement (like ChipMixer), the mixer's internal records can be used to trace through. If the mixer is still active, the tracing may be incomplete.
  4. Trace through chainhops: If the funds cross a bridge, trace through the bridge. See our chainhopping article for the methodology.
  5. Identify the cash-out point: The goal is to identify where the funds will be cashed out — typically a cryptocurrency exchange. If the exchange is in a regulated jurisdiction, a freeze request can be sent.

The time required for tracing depends on the complexity of the laundering. A simple case (payment to consolidation address, then to a single exchange) can be traced in hours. A complex case (mixer, multiple chainhops, multiple exchanges) can take weeks or months.

Legal tools for ransomware recovery

Tracing the payment is only the first step. To actually recover the funds, legal authority is needed to freeze and seize the Bitcoin at the cash-out point. The available legal tools depend on the jurisdiction and whether the recovery is pursued through civil or criminal channels:

Criminal channel: law enforcement

The most effective recovery path is through law enforcement. If you report the ransomware attack to the relevant law enforcement agency (FBI IC3 in the US, BKA in Germany, NCA in the UK, FedPol in Switzerland), they can:

The advantage of the criminal channel is that law enforcement has powers that private parties do not — they can seize funds, arrest suspects, and prosecute. The disadvantage is that law enforcement is slow (investigations can take months or years) and prioritizes cases based on the amount involved and the public interest. A $100,000 ransomware payment may not get the same attention as a $10 million payment.

Civil channel: private recovery

Private recovery through civil courts is also possible but more limited. The main tools are:

The civil channel is faster than the criminal channel in some cases — a freezing order can be obtained within 24-48 hours if the evidence is strong. But the civil channel requires identifying the defendant, which is often impossible in ransomware cases where the perpetrators are anonymous.

Case studies: successful ransomware recoveries

Several high-profile ransomware payments have been recovered by law enforcement:

These cases share a common pattern: law enforcement was able to identify the cash-out point before the funds were fully liquidated. In each case, the ransomware group made the mistake of holding funds on a US-based or regulated exchange, where the FBI could obtain a seizure warrant. If the funds had been cashed out through an unregulated OTC broker, recovery would have been much harder.

Should you pay the ransom?

The decision to pay a ransom is one of the most difficult choices a business can face. Law enforcement agencies (including the FBI, Europol, and the UK's NCSC) advise against paying ransoms, because paying encourages further attacks and funds criminal organizations. However, when a business is facing operational shutdown, data destruction, or reputational damage, the practical pressure to pay is enormous.

From a legal perspective, the situation is complex:

If you decide to pay, the practical advice is:

What to do before a ransomware incident

The best recovery is prevention. Before a ransomware incident occurs, businesses should:

The OFAC sanctions effect on ransomware tracing

OFAC sanctions have changed the ransomware landscape significantly. In September 2021, OFAC designated Suex, a Russian cryptocurrency exchange, as the first sanctioned crypto exchange — effectively cutting it off from the global financial system. In 2022, OFAC designated Garantex, another Russian exchange, and Blender.io, a Bitcoin mixer. In 2023, ChipMixer was seized by US and German authorities.

These actions have had two effects on ransomware tracing. First, sanctioned mixers and exchanges are no longer safe for ransomware groups to use. If the funds pass through a sanctioned entity, they become tainted and cannot be easily cashed out at any compliant exchange. This has forced ransomware groups to use alternative laundering methods, which are sometimes easier to trace. Second, the sanctions have created a legal basis for seizing funds at sanctioned entities — if ransomware Bitcoin is identified at a sanctioned exchange, law enforcement can seize it without needing cooperation from the exchange.

However, ransomware groups have adapted. Many now use Russian OTC brokers who operate outside the sanctioned system and accept mixed funds without question. These brokers convert Bitcoin to rubles through underground channels that are invisible to Western law enforcement. When funds enter this underground Russian financial system, tracing becomes extremely difficult. The funds may eventually emerge through legitimate-looking accounts (businesses, real estate purchases, luxury goods), but the connection to the original ransomware payment is all but impossible to prove.

The double extortion problem

Modern ransomware has evolved beyond simple encryption. Most groups now practice "double extortion" — they encrypt the victim's data AND exfiltrate a copy before encrypting. The ransom demand includes both the decryption key and a promise not to publish the stolen data. Some groups practice "triple extortion" — adding DDoS attacks to pressure the victim, or contacting the victim's customers directly to apply additional pressure.

This evolution complicates recovery. Even if you trace and recover the ransom payment, the ransomware group still has your data. They may publish it anyway, sell it to competitors, or use it for future extortion. The recovery of the payment does not solve the data breach problem. This is why ransomware response should always include a parallel data breach response: legal notification to affected parties, regulatory reporting, and cybersecurity remediation.

Insurance and recovery: the coordination problem

Many ransomware payments are made through cyber insurance. The insurer pays the ransom, and the insurer becomes the subrogated claimant — meaning the insurer has the right to recover the funds. This creates an interesting dynamic: the insurer wants to recover the payment, but the insured (the business) just wants their systems back and may not care about recovery.

The coordination between the insurer, the insured, law enforcement, and forensic firms can be complex. The insurer typically has its own panel of forensic firms and legal counsel. The insured may want to use their own. Law enforcement may impose restrictions on what can be shared publicly. The result is that recovery efforts are sometimes delayed by coordination issues — which benefits the ransomware group, who has more time to cash out.

If you have cyber insurance, the practical advice is to follow the insurer's panel requirements for forensic firms and legal counsel, but insist on parallel law enforcement reporting. The insurer's goal is to minimize the payout (recovering the ransom reduces their loss), and your goal is to recover your systems and protect your data. These goals are aligned in the recovery phase but may diverge in the remediation phase.

The bottom line

Ransomware payment tracing is possible but challenging. The funds move through mixers, bridges, and multiple exchanges, making the trail difficult to follow. Recovery is possible when the funds can be traced to a regulated exchange before they are cashed out. Law enforcement has been successful in several high-profile cases, but most payments are never recovered. The best strategy is prevention: backups, network security, and incident response planning. If you do pay, trace the payment immediately and report to law enforcement — the faster you act, the better your chances of recovery.

If your business has been hit by ransomware and you need assistance tracing the payment or coordinating with law enforcement, contact us. We work with blockchain forensics firms and law enforcement agencies across jurisdictions to trace and recover ransomware payments.

N. Silinevics
Nils Silinevics Crypto Compliance Counsel · Former FIU Investigator · Valken Legal AG