Orca Crypto
Malware

Ransomware

Software that encrypts your files and demands crypto to release them.

Loading live prices
Updated 2026-08-305 min read
The short answer

Software that encrypts your files and demands crypto to release them. Ransomware encrypts everything it can reach and leaves a note demanding payment, almost always in crypto, for a decryption key. Crypto is the payment rail rather than the target, but for anyone holding crypto there is a second problem: the same access that encrypted your files can read your wallet files, your browser extension data and any seed phrase you saved on the machine.

What it is

Ransomware encrypts everything it can reach and leaves a note demanding payment, almost always in crypto, for a decryption key. Crypto is the payment rail rather than the target, but for anyone holding crypto there is a second problem: the same access that encrypted your files can read your wallet files, your browser extension data and any seed phrase you saved on the machine.

How it plays out

  1. It gets in through something ordinary

    A macro in an attached document, a cracked application, a fake software update, a malicious browser extension, or an unpatched remote desktop service.

  2. It waits

    Modern ransomware spends time mapping the network and finding backups before it does anything visible, so the backups go first.

  3. It encrypts and it copies

    Most groups now steal the data as well, so paying for decryption does not stop them publishing it.

  4. The note demands crypto

    With a countdown, a discount for paying quickly, and a support chat. It is run like a business because it is one.

What gives it away

  • Files renamed with an unfamiliar extension, or that will not open.
  • A readme or text file appearing in every folder.
  • A machine that suddenly slows down while disks work hard.
  • Security software disabled without you doing it.

How to not be caught by it

  • Keep offline backups. A backup that is always connected is a backup ransomware encrypts too.
  • Follow the three two one rule: three copies, two kinds of media, one kept offline or offsite.
  • Patch operating systems and browsers promptly, and remove software you do not use.
  • Never run cracked software or "activators". That is one of the most common delivery routes.
  • Never store a seed phrase as a file, a photo, or a note on any computer or phone.
  • Keep meaningful crypto on a hardware wallet, so a compromised computer cannot sign anything.
The hard part is not technical
None of these require technical skill to avoid. They require doing the boring check at the exact moment you feel most rushed, which is the whole difficulty.

If it already happened

  • Disconnect the machine from the network immediately. Do not delete anything yet.
  • Do not pay first. Check whether a free decryptor exists, for example through the No More Ransom project, before considering anything else.
  • Assume every credential and every file on that machine is now in somebody else’s hands.
  • Move crypto from any wallet whose keys touched that machine, using a different clean device.
  • Rebuild the machine from scratch rather than cleaning it, then restore from an offline backup.
  • Report it. In the US that is the FBI IC3, and reporting genuinely feeds the decryptor projects.
Recovery scams
Anybody who contacts you offering to recover lost crypto for a fee is running the second scam on the same victim. There is no recovery service that can reverse a blockchain transaction, because nobody can. Report it through official channels and ignore everyone else.

Common questions

How common is ransomware?

Common enough that it has a name and a playbook. The specific numbers move constantly, so rather than quote a figure that will be wrong next quarter: assume you will meet this one, and set your wallet up so meeting it is survivable.

Can the money be recovered?

Once a blockchain transaction confirms, no. What reporting can occasionally do is get funds frozen at the exchange where a thief tries to cash out, which is why reporting quickly is worth doing even when it feels pointless.

Does a hardware wallet stop this?

It stops anything that needs your keys, because the keys never leave the device. It does not stop you approving a malicious transaction on the device itself, so read what the screen says before you press confirm.

Where to go next

Check your setup before you need to

An hour on a screen share, going through your wallets, your approvals, your backups and your recovery plan. You click everything and we never ask for keys.