Chainalysis reports that the ransomware success rate has dropped to 26%. Attackers are getting 'sloppier.' The numbers are neat, clean, and perfectly aligned with the narrative that blockchain forensics works. But neat numbers in cybersecurity often hide messy realities—data blind spots, selection biases, and the uncomfortable truth that the math only holds if you verify the assumptions.
Let me start with a cold fact: The 26% figure is not a measure of total ransomware incidents. It is a measure of payments traced to known on-chain addresses that Chainalysis monitors. Every ransomware payment made via Monero, a privacy coin, or through an off-chain settlement (e.g., fiat via intermediaries) lives outside this dataset. The report’s authors admit this implicitly by calling attackers 'sloppier.' Sloppier is a relative term. It means the ones that get caught are the ones that reuse addresses or fail to tumble coins. The sophisticated ones? They are not counted. Assumptions are just risks wearing disguises, and the assumption that on-chain data captures the full picture is a risk the industry is comfortable taking.
From my own experience auditing DeFi protocols in 2020, I learned that market efficiency is an illusion during rapid capital influx. The Compound protocol’s interest rate models appeared stable until a flash loan attack exploited a latency edge case. The same principle applies here: The 26% success rate may be a lagging indicator of a changing attacker population, not a reflection of improved defenses. In 2022, after the Terra Luna collapse, I modeled the death spiral dynamics and concluded that algorithmic stability requires infinite confidence. Ransomware deterrence similarly requires infinite confidence from victims that paying is futile. But victims still pay. The 74% of ransom attempts that 'failed' still caused financial losses—recovery costs, downtime, and reputational damage. The report states that financial losses persist, but it does not quantify the magnitude of those losses. A 26% success rate on a larger number of attacks could still yield higher total revenue for attackers.
The core of the Chainalysis narrative is that attackers are becoming less professional, hence more detectable. This is a comforting story for law enforcement and compliance vendors. But the data can also be interpreted as a sign of market fragmentation: The professional ransomware groups (like those behind Conti or LockBit) have been disrupted by sanctions and arrests, leaving a swarm of low-skill copycats who use off-the-shelf malware and lazy payment addresses. These amateurs drive down the average success rate because they lack the infrastructure to negotiate effectively or to launder proceeds. The math holds, but the humans did not verify it. The humans are the attackers, and the ones who do verify their opsec are not in the dataset.
Let me pivot to the contrarian angle: The bulls (those who see this as a win for crypto security) are not entirely wrong. The decline in success rate does correlate with increased chain analysis adoption by exchanges and law enforcement. I have seen this in my own work with risk management for institutional clients: The cost of moving illicit funds has risen, and the probability of seizure has increased. Correlation is the comfort of the unprepared, but in this case, the correlation is real. The timing aligns with the deployment of KYT (Know Your Transaction) tools by major exchanges. However, the bulls ignore a critical blind spot: the substitution effect. When one channel is blocked, attackers shift to another. The 26% figure may be a temporary equilibrium before attackers fully embrace privacy coins or decentralized mixers. The Terra Luna collapse taught me that non-consensus monetary policy is mathematically impossible. Similarly, non-consensus forensics—where the defender must track all transactions while the attacker only needs to hide one—is a losing game in the long run.
The takeaway is not a victory lap. It is an accountability call. The 26% success rate is a data point that requires verification from multiple independent sources. TRM Labs and Elliptic should release their own numbers. If they converge, the industry can claim progress. If they diverge, the debate moves to methodology. Until then, the 26% is a story we agree to believe in. The real test will come when attackers fully adopt privacy coins. Then the math will change, and the humans will have to verify it again.
Based on my audit experience, I have seen too many projects claim security improvements based on selective metrics. The 26% ransomware success rate is no different. It is a useful headline, but it is not a proof of systemic safety. The only way to verify is to demand the raw data: the number of addresses monitored, the total ransom demand volume, and the breakdown by payment method. Without that, the 26% remains a statistical mirage—a mirage that may comfort the unprepared but will not stop the next wave of attacks.


