Skip to main content
Kent Academic Repository

Cashing out crypto: state of practice in ransom payments

Patsakis, Constantinos, Politou, Eugenia, Alepis, Efthimios, Hernandez-Castro, Julio C. (2023) Cashing out crypto: state of practice in ransom payments. International Journal of Information Security, 23 (2). pp. 699-712. ISSN 1615-5270. (doi:10.1007/s10207-023-00766-z) (KAR id:105461)

Abstract

The fast pace of blockchain technology and cryptocurrencies’ evolution makes people vulnerable to financial fraud and provides a relatively straightforward monetisation mechanism for cybercriminals, in particular ransomware groups which exploit crypto’s pseudo-anonymity properties. At the same time, regulatory efforts for addressing crimes related to crypto assets are emerging worldwide. In this work, we shed light on the current state of practice of ransomware monetisation to provide evidence of their payment traceability, explore future trends, and—above all—showcase that over-regulating cryptocurrencies is not the best way to mitigate their risks. For that purpose, first, we provide an overview of the legislative initiatives currently taken by the USA, the EU, and the OECD to regulate cryptocurrencies, showing that strict laws and the divergences between the regulatory regimes can hardly efficiently regulate the global phenomenon of cryptocurrency, which transcends borders and states. Next, we focus on illicit payments in bitcoin to ransomware groups, illustrating how these payments are siphoned off and how criminals cash out the ransom, often leaving traceable evidence behind. To this end, we leverage a publicly available dataset and a set of state-of-the-art blockchain analysis tools to identify payment patterns, trends, and transaction trails, which are provided in an anonymised form. Our work reveals that a significant amount of illicit bitcoin transactions can be easily traced, and consequently, many cyber crimes like ransomware can actually be tracked down and investigated with existing tools and laws, thus providing fertile ground for better and fairer legislation on crypto.

Item Type: Article
DOI/Identification number: 10.1007/s10207-023-00766-z
Uncontrolled keywords: Regulation, Taint analysis, Ransomware, Blockchain forensics, Cryptocurrencies, Bitcoin
Subjects: Q Science > QA Mathematics (inc Computing science)
Divisions: Divisions > Division of Computing, Engineering and Mathematical Sciences > School of Computing
SWORD Depositor: JISC Publications Router
Depositing User: JISC Publications Router
Date Deposited: 10 Apr 2024 14:45 UTC
Last Modified: 05 Nov 2024 13:11 UTC
Resource URI: https://kar.kent.ac.uk/id/eprint/105461 (The current URI for this page, for reference purposes)

University of Kent Author Information

Hernandez-Castro, Julio C..

Creator's ORCID: https://orcid.org/0000-0002-6432-5328
CReDIT Contributor Roles:
  • Depositors only (login required):

Total unique views for this document in KAR since July 2020. For more details click on the image.