Chainalysis initially estimated that ransomware victims paid about $813.55 million in cryptocurrency during 2024, 35% less than its then-estimated $1.25 billion in 2023. A February 2026 Chainalysis update revised the 2024 total upward to $892 million, so 35% is the original 2025 headline—not the latest unqualified comparison. These figures estimate identified on-chain ransom payments, not every attack, payment method, or category of damage.
What the 35% figure actually measured
Chainalysis published the 35% decline in its February 2025 ransomware analysis. Its figures were approximately $813.55 million in 2024 versus $1.25 billion in 2023, based on cryptocurrency flows that the company attributed to ransomware addresses.
Chainalysis later refined its attribution and reported $892 million for 2024 in February 2026. Attribution can improve as investigators identify more addresses and transactions, which means historical totals are revisable. The later figure supersedes the original $813.55 million estimate for current reporting, while the 35% statistic remains accurate as a description of the earlier estimate.
How the year changed from a possible record to a decline
First-half payment growth
Through June 2024, Chainalysis counted about $459.8 million in ransomware inflows, approximately 2% above the comparable 2023 period. On that trajectory, the firm said 2024 could become a record year.
#1 Best Overall
Second-half slowdown
Chainalysis subsequently measured a roughly 34.9% slowdown in payment activity after July 2024. That second-half change reversed the mid-year outlook and produced a lower full-year total in the initial estimate.
Did ransomware attacks also fall?
Not necessarily. A decline in money received is not a count of attacks. Chainalysis reported that leak-site victim claims increased during the second half of 2024 even as on-chain payments fell. Leak sites are an imperfect indicator: claims can be false, duplicated, delayed, or otherwise misleading.
Rank #2
- Ideal for Gifting
- Ideal for a bookworm
- Compact for travelling
The payment data therefore supports a narrower conclusion: less cryptocurrency reached identified ransomware wallets than the prior estimate suggested. It does not establish that fewer organizations were attacked, that fewer files were encrypted, or that overall disruption decreased.
Why might payments have fallen?
The available analyses identify several plausible contributors but do not isolate a single cause or quantify how much each factor contributed.
Rank #3
Disruption of major groups
Law-enforcement actions, infrastructure seizures, and the collapse or disruption of prominent operations changed the criminal market. Lizzie Cookson, senior director of incident response at Coveware, told Chainalysis that the market did not return to its previous status quo after the collapse of LockBit and BlackCat/ALPHV. She described more lone actors and newcomers serving small and midsize targets rather than one replacement group rapidly absorbing the lost market share.
Victims may have been less willing or able to pay
Organizations may refuse demands more often, obtain workable recovery from backups, involve law enforcement, or face legal and compliance constraints. The cited Chainalysis reports discuss changing victim willingness to pay as a possible contributor, but they do not provide a quantified share for any one practice or policy.
Rank #4
Harder laundering and cash-out
Ransomware operators need to move and convert cryptocurrency. Chainalysis points to constraints on laundering and off-ramps as another possible reason for lower observed inflows. This is a market-friction explanation, not proof that a particular exchange, sanction, or enforcement action caused the annual decline.
A shift toward smaller demands
Cookson’s description of newcomers concentrating on small and midsize organizations is consistent with more modest ransom demands. A larger number of incidents can therefore coexist with lower aggregate payments if the typical demand or payment falls.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Best Value
- It can be a gift option
- Comes with secure packaging
- Helpful in various ways
How FinCEN’s 2024 number differs
In a December 2025 analysis of U.S. Bank Secrecy Act filings, the Financial Crimes Enforcement Network (FinCEN) reported 1,476 ransomware incidents and $734 million in aggregate reported payments during 2024. Its analysis uses incident dates and information reported by U.S. financial institutions. That is a separate administrative dataset, not a replacement for or addition to Chainalysis’ global on-chain estimate.
| Measure | 2024 figure | What it covers |
|---|---|---|
| Chainalysis, February 2025 estimate | About $813.55 million | Estimated cryptocurrency payments attributed on-chain; original estimate behind the 35% headline |
| Chainalysis, February 2026 revision | $892 million | Updated historical on-chain estimate after additional attribution |
| FinCEN, December 2025 | $734 million | Payments reported in U.S. Bank Secrecy Act filings, organized by incident date |
| FinCEN median transaction | $155,257 | Median reported single ransomware transaction in 2024 filings |
FinCEN also found that the most common payment band in its review of 2022–2024 reports was below $250,000. Because the two organizations use different sources, geography, collection methods, and definitions, their totals cannot be reconciled by simply adding them or calculating a conversion rate.
What the totals leave out
- Unidentified or unreported cryptocurrency addresses: Chainalysis’ estimate can rise when additional wallets and transactions are attributed.
- Non-cryptocurrency payments: The Chainalysis series is an on-chain estimate and is not a census of cash, wire, or other arrangements.
- Unpaid incidents: An attack that was contained, restored from backups, or refused does not appear as a ransom payment.
- Operational and societal damage: Downtime, recovery costs, legal expenses, lost revenue, safety effects, and data exposure are not represented by ransom inflows alone.
Chainalysis’ 2026 discussion specifically cautions that revenue figures do not describe the full harm caused by ransomware. The reviewed sources do not provide a comprehensive, directly comparable global damage total for 2024.
How to quote the statistic accurately
- Identify the publisher: say that Chainalysis’ February 2025 estimate put 2024 payments at about $813.55 million.
- State the comparison: that estimate was 35% below the then-estimated $1.25 billion for 2023.
- Add the revision: Chainalysis’ February 2026 update revised 2024 to $892 million.
- Define the metric: these are estimated on-chain ransom payments, not attack counts or total economic losses.
- Keep datasets separate: label FinCEN’s $734 million as U.S. BSA-reported payments rather than a directly comparable global total.
What businesses should infer—and what they should not
The most defensible inference is that ransomware monetization weakened in the second half of 2024 according to Chainalysis’ payment tracking, even while reported victim claims remained high. That may reflect disruption, lower willingness to pay, smaller demands, or payment-rail constraints acting together.
It would be a mistake to treat the headline as evidence that ransomware is solved, that attacks decreased by 35%, or that one enforcement operation or security product caused the change. The revised estimate and the limitations of leak-site and payment data require a more cautious reading.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




