当前位置:首页 > 关于我们 > The WannaCry Bitcoin ransom is on the move

The WannaCry Bitcoin ransom is on the move

2024-09-23 02:22:54 [关于我们] 来源:Anhui News

You've infected hundreds of thousands of computers across the globe with your ransomware, and victims' cryptocurrency payments are flowing into your Bitcoin wallets.

How long should you wait to try and access that cash?

Well, for the perpetrators behind WannaCry, the answer appears to be about two and a half months. We can say this because the three Bitcoin wallets that held the ransomed loot were all suddenly emptied late Wednesday.

SEE ALSO:It won't be easy for WannaCry hackers to get their cash

And while we don't know for sure that the same people who unleashed the attack are still in control of the wallets, the profound absence of a statement from law enforcement suggests, at the very least, the accounts haven't been seized.


You probably remember WannaCry. It hit on May 12, and was soon described by Europol spokesperson Jan Op Gen Oorth in The Washington Postas "the biggest ransomware attack ever."

The malware locked up victims' computers, and instructed them to make Bitcoin payments to the attackers' wallets in exchange for decryption keys. And the money started pouring in.

Sure, the word quickly got out that the attackers weren't decrypting files, so people eventually stopped paying up. Even so, whoever orchestrated the attack found themselves sitting on approximately 52 Bitcoins — worth around $145,000 at the time of writing.

Mashable Light SpeedWant more out-of-this world tech, space and science stories?Sign up for Mashable's weekly Light Speed newsletter.By signing up you agree to our Terms of Use and Privacy Policy.Thanks for signing up!

But that didn't mean the attackers were suddenly rolling around in a bed of USD. No, if they were going to spend the money and not be traced in the process, they had to figure out a way to safely move it.

That process began on August 2.

The thing about Bitcoin, however, is that it's only pseudonymous. That is to say, while you may not know who owns it, anyone can see where it goes. And you better believe interested parties around the globe are watching this specific cryptocurrency closely.

The Bitcoin from one WannaCry wallet was sent to three wallets. The Bitcoin in those wallets was sent to more wallets, and so on, and so on. All three WannaCry wallets were broken down in a similar way, with at least some of the Bitcoin finding its way to ShapeShift — a cryptocurrency exchange — along the way.

As some forms of digital currency (Monero, for example) are more privacy-focused than others, it would make sense that the owners of the tainted Bitcoin would try to swap theirs out. It appears they tried to do just that, although ShapeShift caught on.

SEE ALSO:Ransomware has been around for almost 30 years, so why does it feel like it's getting worse?

"ShapeShift, a digital asset change based in Switzerland, has verified that the WannaCry attacker did breach its terms of service and utilized the services to move a portion of their proceeds of crime," the company said in a statement. "[As] of today, we have taken measures to blacklist all addresses associated with the WannaCry attackers that are known to the ShapeShift team, as is our policy for any transactions we deem breach our terms of service. We are closely watching the situation as it continues to unfold as to block any further addresses associated."

We inquired if the funds had been exchanged for Monero, but a spokesperson declined to "provide more detail due to the ongoing nature of the investigation."

Looking forward

So why does all this matter? The ransomed cryptocurrency got moved from three pseudonymous accounts to a bunch of other pseudonymous accounts — who cares, right?

Well, while WannaCry is one of (if not the) biggest case of ransomware in history, other attackers will surely come for the throne. And when they do, they're going to ask for payments in cryptocurrency. What happens to this WannaCry money, and whether the perps get away with it, will either serve as warning or encouragement to those that follow.

And you can bet your last Bitcoin that others willfollow.

Featured Video For You
Step inside the secretive class that turns people into hackers


  • The Best AMD Ryzen Gaming Laptops (So Far)

    The Best AMD Ryzen Gaming Laptops (So Far) As a culmination to our testing of Ryzen Mobile 4000-H processors and the various laptops they are f ...[详细]
  • [天全]小小明信片情递千万家

    [天全]小小明信片情递千万家 雅安日报讯“希望你们多宣传一下诈骗、拐卖等安全知识,和企业多做交流,加强学校周边的巡逻……”近日,一封封满载着群众心声的明信片寄往天全县公安局政工监督室。在“大走访”开门评警活动中,天全县公安局积极开 ...[详细]
  • 给空气做个“权威体检”

    给空气做个“权威体检” 雅安日报讯经过几个月的紧张筹备,18日,在世界茶文化圣山——蒙顶山上,我市建起第二个空气负氧离子观测点。该观测点的建立将为我市建立空气负氧离子观测网提供更加科学、可信的数据。今年内,我市还将在雨城区上 ...[详细]
  • 雨城地税 三项措施为“桃花节”服好务

    雨城地税 三项措施为“桃花节”服好务 雅安日报讯寒冷退去,桃红柳绿,雨城春意渐浓。一年一度的雨城区第七届龙井山桃花节已于3月20日拉开帷幕。雨城区地方税务局采取多项措施,确保桃花节活动顺利进行。首先,了解去年同期缴纳税款情况,做好纳税服务 ...[详细]
  • Project 2025 Comstock Act: Trump’s new abortion comment exposed.

    Project 2025 Comstock Act: Trump’s new abortion comment exposed. This week, Donald Trump gave his clearest answer to date about whether he would enforce the Comstock ...[详细]
  • 市区猪肉来自本地和邛崃 放心吃

    市区猪肉来自本地和邛崃 放心吃 执法人员对猪肉市场进行检查近日,一则“双汇瘦肉精”猪肉的消息引发市民关注。“如何才能买得放心、吃得放心?”不少市民电话咨询。为此,记者走访了我市部分农贸市场。“知道‘双汇瘦肉精事件’后,我专门留意了电 ...[详细]
  • 石棉县人民法院积极开展保护“三电”设备安全宣传活动

    石棉县人民法院积极开展保护“三电”设备安全宣传活动 5月17日,石棉县人民法院和其他部门开展了保护“三电”设备安全宣传活动。宣传活动上,该院干警以讲解张贴宣传画报、发放传单资料、口头答疑等方式向过往群众进行“三电”安全、保护等宣传。活动当天,共发放宣传 ...[详细]
  • 端午节 吃了粽子还剩下啥?

    端午节  吃了粽子还剩下啥? 从2008年开始,“中国端午节”为国家法定节假日之一,并列入世界非物质文化遗产名录。今年农历五月初五,是端午节作为国家法定假日的第三个年头。传统节日披上假日的外衣后,不少人对传统文化的回归报以期望,三 ...[详细]
  • Our galaxy might crash into Andromeda. What would happen to Earth?

    Our galaxy might crash into Andromeda. What would happen to Earth? Our Milky Way galaxy is a cannibal.It has grown by consuming other galaxies. Yet, it too, may be des ...[详细]
  • 失包者浑然不觉 捡包者完璧归赵

    失包者浑然不觉 捡包者完璧归赵 驾工何昌俊左)将钱包归还失主雅安日报讯从出租车下来,就职于市区某酒业公司的市民侯伟明付钱时不慎将钱包丢失;来自天全县始阳镇切山村的人力客三轮驾工何昌俊拾捡钱包,及时将钱包送到派出所。经民警几经周折找到 ...[详细]