In July 2024, a manufacturing company in Germany was hit by a ransomware attack. The attackers encrypted the company's production systems and demanded 12 Bitcoin (approximately $780,000) for the decryption key. The company's IT team, crisis managers, and legal counsel debated for 48 hours. They paid. The decryption key worked — the systems were restored. But the company's board asked a question that many ransomware victims eventually ask: can we trace where the Bitcoin went, and can we recover any of it?
The short answer is: tracing is possible, recovery is difficult but not impossible. The Department of Justice has recovered ransomware payments in several high-profile cases (Colonial Pipeline, Kaseya, BitPaymer). These recoveries were possible because law enforcement was able to trace the Bitcoin payments through mixers and chainhops and identify the cash-out point before the ransomware group could liquidate the funds. But these recoveries are the exception, not the rule. Most ransomware payments are never recovered.
In this article, I explain how ransomware groups move and launder Bitcoin payments, the forensic methods used to trace ransomware payments, the legal tools available for recovery, and what businesses should do before and after paying a ransom. This article is written for business owners, IT security teams, and legal counsel who are dealing with or preparing for a ransomware incident.
How ransomware groups move payments
Modern ransomware operates on a RaaS (Ransomware-as-a-Service) model. The ransomware code is developed by a core group (the developers), who license it to affiliates (the operators) who carry out the attacks. When a victim pays the ransom, the payment is split between the developers (typically 20-30%) and the affiliate (70-80%). This split happens automatically through the ransomware payment infrastructure.
After receiving the payment, the ransomware group typically follows a multi-stage laundering process:
Stage 1: Initial consolidation
The ransomware group receives the Bitcoin payment into a specific address (the payment address provided to the victim). Once the payment is confirmed, the Bitcoin is immediately moved to a consolidation address — a wallet that collects payments from multiple victims. This consolidation typically happens within minutes of the payment being confirmed.
At this stage, the Bitcoin is still on the Bitcoin blockchain and can be traced. The consolidation address may hold millions of dollars from multiple victims, making it a high-value target for law enforcement.
Stage 2: Mixer or coinjoin
From the consolidation address, the Bitcoin is sent to a mixer or coinjoin service. Mixers (like Blender.io, which was sanctioned by OFAC in 2022, or ChipMixer, which was seized by authorities in 2023) pool Bitcoin from multiple users and redistribute it in smaller amounts, breaking the link between the source and destination addresses. Coinjoin (used by services like Wasabi Wallet and Samourai Wallet) is a similar concept but operates in a more decentralized manner.
After Tornado Cash was sanctioned by OFAC in 2022, many mixers on Ethereum became unusable for ransomware groups — using a sanctioned mixer means the output is tainted and will be flagged by any exchange that receives it. On Bitcoin, however, mixing is still possible through decentralized coinjoin protocols and over-the-counter (OTC) brokers who accept mixed funds.
Stage 3: Chainhopping
After mixing, the Bitcoin may be bridged to another blockchain using cross-chain bridges (see our article on chainhopping for details). Thorchain is the most common bridge for Bitcoin, converting it to Ethereum or other chains. Once on a different blockchain, the funds are harder to trace because the connection between the Bitcoin and the new chain is obscured by the mixing step.
Stage 4: Conversion to stablecoins
The laundered funds are typically converted to a stablecoin (USDT or USDC) to preserve value without the volatility of Bitcoin. The stablecoins are then held in self-custody wallets or moved to exchanges for cash-out.
Stage 5: Cash-out
The final stage is converting the stablecoins to fiat currency. Ransomware groups use several cash-out methods:
- OTC brokers: Over-the-counter brokers who accept large amounts of crypto and pay fiat currency, often without strict KYC. Many OTC brokers operate in jurisdictions with weak AML enforcement (Russia, UAE, Southeast Asia).
- Cryptocurrency exchanges: The funds are deposited on a cryptocurrency exchange and sold for fiat. Exchanges in regulated jurisdictions (US, EU) will flag the deposit if it matches known ransomware addresses. Exchanges in less regulated jurisdictions may not.
- Peer-to-peer platforms: Platforms like Paxful, Bisq, or Huobi P2P allow users to sell crypto directly to other users for fiat currency, bank transfer, or gift cards. These platforms are harder to trace because the transactions are bilateral.
- Prepaid cards: Crypto-backed prepaid cards (like the now-defunct BitPay card) allow users to spend crypto as fiat. Some ransomware groups use these cards for personal expenses.
The entire laundering process — from initial payment to final cash-out — can take anywhere from a few days to several months. The speed depends on the ransomware group's sophistication and the urgency of their cash needs. Some groups hold Bitcoin for months or years, waiting for favorable market conditions or reduced law enforcement attention.
Tracing ransomware payments: the forensic approach
Tracing a ransomware payment requires following the Bitcoin from the victim's payment to the ransomware group's consolidation address, through the mixer, through any chainhops, and to the final cash-out point. This is a complex forensic process that requires specialized tools and expertise.
The tools
Professional blockchain analytics tools (Chainalysis, TRM Labs, Elliptic) are the primary tools for tracing ransomware payments. These tools have specific features for ransomware investigation:
- Address clustering: The tools identify addresses controlled by the same entity by analyzing transaction patterns. If two addresses always send funds together or to the same destination, they are likely controlled by the same entity.
- Ransomware address databases: The tools maintain databases of known ransomware payment addresses, identified from previous cases and from law enforcement collaboration. If a payment goes to one of these addresses, the tool automatically identifies it as a ransomware payment.
- Mixer tracing: While mixers break the direct link between source and destination, analytics tools can sometimes reconstruct the link by analyzing the timing and amounts of mixer transactions. This is not always possible, but when the mixer's logs are available (e.g., after a law enforcement seizure), full tracing is possible.
- Cross-chain tracing: The tools can trace through some cross-chain bridges, particularly the larger ones (Thorchain, Stargate). The tracing is not always complete — some bridges have better coverage than others.
The process
The tracing process follows these steps:
- Document the payment: Record the payment address, the transaction hash, the amount, and the timestamp. This is the starting point for all tracing.
- Trace to the consolidation address: Follow the Bitcoin from the payment address to the consolidation address. This is usually straightforward — the ransomware group moves the payment quickly.
- Trace through the mixer: If the funds enter a mixer, attempt to trace through it. This is the hardest step. If the mixer has been seized by law enforcement (like ChipMixer), the mixer's internal records can be used to trace through. If the mixer is still active, the tracing may be incomplete.
- Trace through chainhops: If the funds cross a bridge, trace through the bridge. See our chainhopping article for the methodology.
- Identify the cash-out point: The goal is to identify where the funds will be cashed out — typically a cryptocurrency exchange. If the exchange is in a regulated jurisdiction, a freeze request can be sent.
The time required for tracing depends on the complexity of the laundering. A simple case (payment to consolidation address, then to a single exchange) can be traced in hours. A complex case (mixer, multiple chainhops, multiple exchanges) can take weeks or months.
Legal tools for ransomware recovery
Tracing the payment is only the first step. To actually recover the funds, legal authority is needed to freeze and seize the Bitcoin at the cash-out point. The available legal tools depend on the jurisdiction and whether the recovery is pursued through civil or criminal channels:
Criminal channel: law enforcement
The most effective recovery path is through law enforcement. If you report the ransomware attack to the relevant law enforcement agency (FBI IC3 in the US, BKA in Germany, NCA in the UK, FedPol in Switzerland), they can:
- Trace the payment using their own forensic tools (FBI's cryptocurrency analysis unit, Europol's EC3)
- Coordinate with exchanges in multiple jurisdictions to freeze the funds
- Obtain seizure warrants for the Bitcoin at the cash-out exchange
- Coordinate with international law enforcement through MLAT (Mutual Legal Assistance Treaty) requests
The advantage of the criminal channel is that law enforcement has powers that private parties do not — they can seize funds, arrest suspects, and prosecute. The disadvantage is that law enforcement is slow (investigations can take months or years) and prioritizes cases based on the amount involved and the public interest. A $100,000 ransomware payment may not get the same attention as a $10 million payment.
Civil channel: private recovery
Private recovery through civil courts is also possible but more limited. The main tools are:
- Freeze injunctions: In some jurisdictions (UK, Singapore, Hong Kong), you can obtain a freezing order (Mareva injunction) against the traced Bitcoin, preventing the holder from moving it. This requires identifying the holder, which is often the hardest part.
- Norwich Pharmacal orders: You can compel exchanges to disclose information about the account holder who received the traced funds. This is useful for identifying the ransomware group member who holds the exchange account.
- Conversion claims: You can file a civil claim for conversion (the common law equivalent of theft) against the holder of the traced Bitcoin. If the court finds in your favor, it can order the Bitcoin to be returned.
The civil channel is faster than the criminal channel in some cases — a freezing order can be obtained within 24-48 hours if the evidence is strong. But the civil channel requires identifying the defendant, which is often impossible in ransomware cases where the perpetrators are anonymous.
Case studies: successful ransomware recoveries
Several high-profile ransomware payments have been recovered by law enforcement:
- Colonial Pipeline (2021): The FBI recovered 63.7 of the 75 Bitcoin paid to the DarkSide ransomware group. The recovery was possible because the FBI had identified the wallet and obtained a seizure warrant. The funds were still in the wallet because the ransomware group had not yet moved them to a mixer.
- Kaseya (2021): The FBI obtained the decryption key for the REvil ransomware attack without paying the ransom. The key was obtained through intelligence operations, not payment tracing. No ransom was paid, so no recovery was needed.
- BitPaymer (2021): The DOJ seized $6 million in ransomware payments from a Russian national who was extradited to the US. The funds were traced through multiple wallets and exchanges, and the seizure was made at a US-based exchange where the funds were cashed out.
These cases share a common pattern: law enforcement was able to identify the cash-out point before the funds were fully liquidated. In each case, the ransomware group made the mistake of holding funds on a US-based or regulated exchange, where the FBI could obtain a seizure warrant. If the funds had been cashed out through an unregulated OTC broker, recovery would have been much harder.
Should you pay the ransom?
The decision to pay a ransom is one of the most difficult choices a business can face. Law enforcement agencies (including the FBI, Europol, and the UK's NCSC) advise against paying ransoms, because paying encourages further attacks and funds criminal organizations. However, when a business is facing operational shutdown, data destruction, or reputational damage, the practical pressure to pay is enormous.
From a legal perspective, the situation is complex:
- OFAC sanctions: Paying a ransom to a sanctioned entity (many ransomware groups are sanctioned by OFAC) is illegal under US law. US persons and businesses operating in or through the US must screen the ransomware group against the OFAC SDN list before paying.
- EU guidance: The EU has not banned ransomware payments outright, but several member states (including France, Germany, and Ireland) discourage payments and require reporting to the national CERT.
- UK guidance: The UK's NCSC advises against paying but does not make it illegal. However, paying a sanctioned entity is illegal under UK sanctions law.
- Insurance: Many cyber insurance policies cover ransomware payments. However, insurers increasingly require the insured to engage law enforcement and attempt recovery before paying the ransom.
If you decide to pay, the practical advice is:
- Screen the ransomware group against OFAC and EU sanctions lists before paying. Your legal counsel should handle this.
- Report to law enforcement before paying (FBI IC3, BKA, NCA, or your national CERT). Law enforcement may have the decryption key or may be able to trace the payment.
- Record the payment address and transaction hash for future tracing.
- Engage a blockchain forensics firm to trace the payment in real time. If the funds reach an exchange, a freeze request can be sent.
- Do not attempt to negotiate directly with the ransomware group. Use a professional negotiator (typically provided by your cyber insurance or crisis management firm).
What to do before a ransomware incident
The best recovery is prevention. Before a ransomware incident occurs, businesses should:
- Back up critical data offline: If you have offline backups, you can restore without paying the ransom. Test the backups regularly — many businesses discover their backups are corrupted only after a ransomware attack.
- Implement multi-factor authentication: MFA prevents most ransomware attacks, which typically begin with compromised credentials.
- Segment networks: If your production network is segmented, a ransomware attack on one segment does not encrypt the entire system.
- Have an incident response plan: Know who to call (legal counsel, cyber insurance, law enforcement, forensic firm) before an incident occurs. Time is critical in ransomware cases.
- Understand your cyber insurance coverage: Know what your policy covers (ransom payment, forensic costs, legal costs, business interruption) and what it excludes (acts of war, sanctioned entities).
The OFAC sanctions effect on ransomware tracing
OFAC sanctions have changed the ransomware landscape significantly. In September 2021, OFAC designated Suex, a Russian cryptocurrency exchange, as the first sanctioned crypto exchange — effectively cutting it off from the global financial system. In 2022, OFAC designated Garantex, another Russian exchange, and Blender.io, a Bitcoin mixer. In 2023, ChipMixer was seized by US and German authorities.
These actions have had two effects on ransomware tracing. First, sanctioned mixers and exchanges are no longer safe for ransomware groups to use. If the funds pass through a sanctioned entity, they become tainted and cannot be easily cashed out at any compliant exchange. This has forced ransomware groups to use alternative laundering methods, which are sometimes easier to trace. Second, the sanctions have created a legal basis for seizing funds at sanctioned entities — if ransomware Bitcoin is identified at a sanctioned exchange, law enforcement can seize it without needing cooperation from the exchange.
However, ransomware groups have adapted. Many now use Russian OTC brokers who operate outside the sanctioned system and accept mixed funds without question. These brokers convert Bitcoin to rubles through underground channels that are invisible to Western law enforcement. When funds enter this underground Russian financial system, tracing becomes extremely difficult. The funds may eventually emerge through legitimate-looking accounts (businesses, real estate purchases, luxury goods), but the connection to the original ransomware payment is all but impossible to prove.
The double extortion problem
Modern ransomware has evolved beyond simple encryption. Most groups now practice "double extortion" — they encrypt the victim's data AND exfiltrate a copy before encrypting. The ransom demand includes both the decryption key and a promise not to publish the stolen data. Some groups practice "triple extortion" — adding DDoS attacks to pressure the victim, or contacting the victim's customers directly to apply additional pressure.
This evolution complicates recovery. Even if you trace and recover the ransom payment, the ransomware group still has your data. They may publish it anyway, sell it to competitors, or use it for future extortion. The recovery of the payment does not solve the data breach problem. This is why ransomware response should always include a parallel data breach response: legal notification to affected parties, regulatory reporting, and cybersecurity remediation.
Insurance and recovery: the coordination problem
Many ransomware payments are made through cyber insurance. The insurer pays the ransom, and the insurer becomes the subrogated claimant — meaning the insurer has the right to recover the funds. This creates an interesting dynamic: the insurer wants to recover the payment, but the insured (the business) just wants their systems back and may not care about recovery.
The coordination between the insurer, the insured, law enforcement, and forensic firms can be complex. The insurer typically has its own panel of forensic firms and legal counsel. The insured may want to use their own. Law enforcement may impose restrictions on what can be shared publicly. The result is that recovery efforts are sometimes delayed by coordination issues — which benefits the ransomware group, who has more time to cash out.
If you have cyber insurance, the practical advice is to follow the insurer's panel requirements for forensic firms and legal counsel, but insist on parallel law enforcement reporting. The insurer's goal is to minimize the payout (recovering the ransom reduces their loss), and your goal is to recover your systems and protect your data. These goals are aligned in the recovery phase but may diverge in the remediation phase.
The bottom line
Ransomware payment tracing is possible but challenging. The funds move through mixers, bridges, and multiple exchanges, making the trail difficult to follow. Recovery is possible when the funds can be traced to a regulated exchange before they are cashed out. Law enforcement has been successful in several high-profile cases, but most payments are never recovered. The best strategy is prevention: backups, network security, and incident response planning. If you do pay, trace the payment immediately and report to law enforcement — the faster you act, the better your chances of recovery.
If your business has been hit by ransomware and you need assistance tracing the payment or coordinating with law enforcement, contact us. We work with blockchain forensics firms and law enforcement agencies across jurisdictions to trace and recover ransomware payments.