A ransomware crypto check screens a wallet for links to addresses used to collect ransom payments; Plastron flags ransomware-related exposure free across seven EVM chains, showing the flagged counterparties involved.
Ransomware Crypto Exposure Check
OFAC has designated multiple ransomware groups and their wallets. Counterparty links to ransomware payment addresses trigger exchange freezes.
Ransomware operations have collected billions of dollars in cryptocurrency from victims around the world, and the payment addresses used in these attacks are tracked exhaustively by law enforcement, blockchain analytics firms, and government agencies. OFAC has designated several ransomware groups on the SDN list — including Evil Corp, REvil, and the operators of Kaseya and Colonial Pipeline ransomware variants — making transactions with their designated addresses a sanctions violation. The FBI, CISA, and Treasury jointly publish ransomware advisory notices that include cryptocurrency wallet addresses used in payment collection, and these addresses are fed into the blockchain analytics databases that exchanges use for screening. For ordinary users, the risk comes from the post-payment fund flows: ransomware operators move payment proceeds through exchanges, DEX protocols, and mixing services in an effort to cash out. Funds moved through these channels reach ordinary wallets through trades, liquidity pools, and protocol interactions. If your wallet has counterparties that were used as ransomware payment collection or laundering addresses, exchange compliance systems will identify that relationship. Additionally, some businesses that were victimized by ransomware paid ransoms and then deposited funds to exchanges — if their paying wallet is in your counterparty history, you carry indirect exposure from their payment.
How Plastron Helps
Ransomware Address Screening
Plastron's known-address database includes ransomware payment collection addresses identified through Forta threat intelligence, CryptoScamDB, and curated threat intelligence from community sources. We flag any counterparties in your wallet history that are directly linked to ransomware payment operations, with severity scores reflecting whether the address is OFAC-designated or non-sanctioned.
OFAC Ransomware Sanctions Coverage
Addresses belonging to OFAC-designated ransomware operators are included in our weekly SDN refresh. These addresses are flagged separately from general ransomware exposure with a sanctions classification and a Critical severity rating. Any direct counterparty relationship with an OFAC-designated ransomware address is the highest-priority compliance risk we surface.
Comprehensive Counterparty Analysis
Ransomware funds move through intermediary wallets before reaching exchanges. Plastron traces your full counterparty graph across 1,000 ETH transactions and 1,000 token transfers to identify whether any addresses in your history are downstream from ransomware payment collection — even if the connection is one or two hops removed from the original payment address.
Risk Categories We Screen
Frequently Asked Questions
Related Screening Tools
Screen Your Wallet Now
Connect your wallet and get a full risk report in under 30 seconds. Free, non-custodial, and completely private.