Logic survives the crash; emotion dissolves.
In 2023, Chainalysis reported a 26% ransomware success rate. The industry celebrated. I found a flaw in the denominator.
That number—26%—is not a victory lap. It is a data artifact. A selective sample that excludes privacy coins, off-chain payments, and the silent majority of unreported attacks. The 74% failure rate does not mean victims escaped unscathed. It means the attackers adapted, shifted tactics, and now operate in shadows where Chainalysis’ graph analysis cannot reach.
Context: The Business of Fear
Chainalysis is the dominant player in blockchain forensics. Its clients include the FBI, IRS, and DEA. Its quarterly reports shape regulatory narratives and influence security budgets. When it says ransomware success is down, the market listens. But the report is also a product. A marketing tool for its own services. The data comes from its own surveillance network—on-chain addresses it has tagged, clusters it has identified, and payment flows it can trace. Any attack that uses Monero, a mixer, or a cross-chain bridge is invisible to this lens. The 26% is a measure of detectable attacks, not all attacks.
Precision is the only antidote to chaos.
Let me dissect the methodology. Chainalysis tracks ransomware payments by monitoring known wallet addresses and using clustering algorithms to link new addresses to known threat actors. This works well for lazy attackers who reuse addresses or send funds to centralized exchanges. But the sophisticated ones—the ones who charge $100 million ransoms—have already moved to privacy-preserving layers. The report notes that attackers are becoming “sloppier.” That is a misinterpretation. What is actually happening is that the low-end attackers, the script kiddies and copycats, are flooding the ecosystem. They lack the discipline to use proper opsec. They get caught. Their success rate is low. Meanwhile, the top-tier ransomware groups—those that survived the sanctions against Conti and LockBit—have become more paranoid. They use decentralized exchanges, chain-hopping, and atomic swaps. Their success rate is likely higher than 26%, but they are harder to detect. The reported number is a downward bias driven by composition effects.
Consider the economic incentives. If the average ransom demand is $500,000 and the success rate is 26%, the expected value per attack is $130,000. But the cost of launching an attack—infrastructure, initial access brokers, ransomware-as-a-service fees—is fixed. If the success rate drops, rational attackers will either increase the ransom demand to compensate or target high-value entities that can pay more. The report mentions that financial losses remain high. That is consistent with a shift toward fewer but larger payouts. The 26% figure is a mean, not a median. The distribution is likely bimodal: many small, failed attacks and a few large, successful ones. The average hides the tail risk.
Clarity cuts deeper than noise.
I have seen this pattern before. In 2018, I dissected the Parity Wallet vulnerability. The industry celebrated the “fix” but ignored the systemic flaw in the contract’s access control. The same is happening here. The 26% success rate is a surface-level metric that obscures the real story: ransomware is not declining; it is concentrating. The attackers are professionalizing. The “sloppy” ones are the ones getting caught, and their data is being used to paint a rosy picture of law enforcement effectiveness. But the sophisticated attackers are still out there, and they are learning from the mistakes of the amateurs.
Based on my experience in risk management—auditing DeFi protocols during the 2020 summer and watching Terra/Luna collapse—I have learned that headline numbers are always a trap. The real question is: what is the denominator? Chainalysis measures success rates relative to attacks it can detect. That denominator is shrinking because attackers are moving to undetectable methods. The true success rate, if we could measure it, might be higher. Or it might be lower. The point is we don’t know. The report gives a false sense of precision.
Let me be quantitative. Suppose there are 1,000 attacks per year. Chainalysis detects 500 of them. Of those, 130 succeed (26%). That means 130 successes out of 1,000 total attacks is a 13% success rate. But if the undetected attacks have a higher success rate—say 50%—then the total successes would be 130 + 250 = 380, a 38% success rate. The reported 26% is only valid if the undetected attacks have the same success rate as the detected ones. That assumption is almost certainly false. The detectable attacks are the ones with sloppy attackers. The undetected attacks are the ones with professional attackers. The success rate is likely higher for the latter. Therefore, the true aggregate success rate is probably higher than 26%.
Contrarian: What the Bulls Got Right
To be fair, the bulls have a point. The data does show that law enforcement pressure is working. The number of attacks that are successfully traced and disrupted has increased. The infrastructure for blockchain analytics has improved. The 26% success rate is a real decline from previous years, when success rates were closer to 40-50%. The industry deserves credit for that. The formation of the Ransomware Task Force, the sanctions against cryptocurrency mixers, and the increased cooperation between exchanges and regulators have all contributed to making ransomware less profitable. The bulls are correct that the ecosystem is becoming safer—but only for the part of the ecosystem that is visible. The hidden part is growing.
Takeaway: The Accountability Call
Logic survives the crash; emotion dissolves. The 26% number is not a lie. It is a statistical trap. The industry must stop treating Chainalysis reports as gospel and start demanding full methodology disclosure. Without the raw data—the list of addresses, the clustering parameters, the detection thresholds—the number is a marketing figure. Ransomware is not going away. It is evolving. The next wave will be driven by AI-generated phishing, zero-day exploits, and cross-chain obfuscation. The 26% success rate is a snapshot of the past, not a prediction of the future. The real question is not whether the success rate is falling, but whether the attackers are moving to a plane where our tools cannot see them. The answer is yes. And the industry is not prepared.