Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
  • Reviews
    • Best antivirus software for 2026: independent picks from Ransomnews
    • Best ransomware-resistant backup for 2026: cloud, hybrid, and immutable picks reviewed
    • Best ransomware protection for business 2026: ESET PROTECT and 5 alternatives reviewed
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
  • Reviews
    • Best antivirus software for 2026: independent picks from Ransomnews
    • Best ransomware-resistant backup for 2026: cloud, hybrid, and immutable picks reviewed
    • Best ransomware protection for business 2026: ESET PROTECT and 5 alternatives reviewed
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews
OSINT

How to verify a ransom payment on-chain: tutorial with Mempool, OXT, and Ransomwhe.re

Ransomnews Research TeamBy Ransomnews Research TeamMay 7, 2026Updated:May 7, 2026No Comments4 Mins Read51 Views
Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
A Bitcoin transaction passing through verification checkpoints to a green checkmark
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Ransomware operators sometimes claim a victim has paid when they haven’t, and victims occasionally claim non-payment when they have. The blockchain is the ground truth. This tutorial walks through verifying a claimed payment from start to finish using free tools.

Step 1: Get the alleged transaction details

You need either the transaction hash, the receiving wallet address, or the date/amount window claimed. With one of these you can find the others.

If the operator’s leak site lists a wallet (common for the negotiation contact form), grab that. If the victim’s negotiator has the receipt-style transaction confirmation, that’s better. Most ransom payments are in BTC; some operators take USDT or Monero (Monero can’t be verified on-chain, that’s the whole point of Monero).

Step 2: Look up the wallet

Drop the receiving address into Mempool.space. The page shows every transaction sent to or from that address, confirmation count, value, timestamp. Visually inspect the recent transactions for one that matches the claimed amount and date.

Cross-reference with Blockchain.com Explorer or OXT.me to confirm. The same transaction should show up identically in all three.

Step 3: Confirm the amount in fiat

Ransom demands are usually quoted in fiat. Convert the claimed BTC amount to fiat using the BTC/USD rate at the transaction’s timestamp, CoinGecko’s historical chart works for this. If the dollar value matches the claimed demand within a few percent, it’s almost certainly the payment. Off by 50%? That’s a different transaction.

Step 4: Confirm sender authenticity

The trickier question: did the victim actually send this payment, or did the operator self-fund the wallet to fake a paid-victim list?

Click into the transaction on Mempool. The “Inputs” panel shows the sending addresses. Run those through WalletExplorer, if WalletExplorer labels the cluster as a known exchange (Coinbase, Kraken, etc.), that’s consistent with a real victim payment from a fiat-funded exchange account. If the input cluster is itself unlabelled and small, it might be the operator self-staging.

Step 5: Check Ransomwhe.re for known operator wallets

Ransomwhe.re is a public, crowdsourced database of wallets attributed to ransomware operations. Drop the receiving address, if it’s already there with attribution, you have a strong starting point. If it’s not, consider submitting it (after you’ve finished your own verification).

Step 6: For ETH/USDT instead

Same workflow but on Etherscan for ETH and ERC-20 USDT, or Tronscan for TRC-20 USDT. The “Token Transfers” tab shows all stablecoin movements. Same logic on confirming amount, sender cluster, exchange labels.

Step 7: Document the verification

Save: the transaction hash, the receiving address, the timestamp in UTC, screenshots of the explorer pages, the BTC/USD rate at timestamp, the WalletExplorer labels for input cluster. The transaction hash is the immutable evidence, anyone can independently verify everything else from that one string.

Step 8: Common scenarios and what they mean

Operator claims victim paid; victim denies. If you can find a transaction matching amount + date going to the operator’s wallet from an exchange-cluster sender, the victim is likely lying. Some companies pay quietly to avoid disclosure obligations. Public-record transparency benefits when these are documented.

Victim claims paid; operator continues to publish data. Blockchain confirms payment happened. Operator violated the agreement. Goes into the operator’s reputation track record, research firms factor this when advising future victims.

No transaction found. Either the payment was on a non-public chain (Monero), the addresses you have are wrong, or the payment never happened. All three are worth distinguishing.

The blockchain doesn’t lie, and these tools are free. Anyone willing to spend an hour can verify or refute most ransom-payment claims with public-record evidence. That capability changes the dynamics of how victims, operators, and journalists negotiate the truth.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Previous ArticleHow to build a threat actor profile from public sources: MITRE ATT&CK + Mandiant + Malpedia tutorial
Next Article How to set up a malware analysis sandbox at home: FlareVM, REMnux, and Cuckoo tutorial
Ransomnews Research Team

The Ransomnews Research Team is the collective byline used for collaborative pieces, editorial briefings, and articles drawing on contributions from multiple researchers. Coverage spans ransomware operations, breach economics, threat actor profiling, OSINT methodology, and emerging risks across security, privacy, and AI.

Related Posts

Ransomware leak-site OSINT: 2026 investigation walkthrough

May 16, 2026

MSPs: ransomware’s #1 target of 2026 [Field Report]

May 11, 2026

LockBit, 2 years after Operation Cronos: where are they now?

May 11, 2026

Comments are closed.

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links — when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

// Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Reviews
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck

// Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

// Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Affiliate Disclosure
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.