Cybercrime Bitcoin Revenue Estimations: Quantifying the Impact of Methodology and Coverage
Gibran Gómez, Kevin van Liebergen, Juan Caballero
Abstract
Multiple works have leveraged the public Bitcoin ledger to estimate the revenue cybercriminals obtain from their victims. Estimations focusing on the same target often do not agree, due to the use of different methodologies, seed addresses, and time periods. These factors make it challenging to understand the impact of their methodological differences. Furthermore, they underestimate the revenue due to the (lack of) coverage on the target's payment addresses, but how large this impact remains unknown. In this work, we perform the first systematic analysis on the estimation of cybercrime bitcoin revenue. We implement a tool that can replicate the different estimation methodologies. Using our tool we can quantify, in a controlled setting, the impact of the different methodology steps. In contrast to what is widely believed, we show that the revenue is not always underestimated. There exist methodologies that can introduce huge overestimation. We collect 30,424 payment addresses and use them to compare the financial impact of 6 cybercrimes (ransomware, clippers, sextortion, Ponzi schemes, giveaway scams, exchange scams) and of 141 cybercriminal groups. We observe that the popular multi-input clustering fails to discover addresses for 40% of groups. We quantify, for the first time, the impact of the (lack of) coverage on the estimation. For this, we propose two techniques to achieve high coverage, possibly nearly complete, on the DeadBolt server ransomware. Our expanded coverage enables estimating DeadBolt's revenue at $2.47M, 39 times higher than the estimation using two popular Internet scan engines.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext cb7a6010-1cd2-4e95-a60b-28f7d6afc09eCited by top-tier papers5
- The Poorest Man in Babylon: A Longitudinal Study of Cryptocurrency Investment ScamsMuhammad Muzammil, Abisheka Pitumpe, Xigao Li, Amir Rahmati et al.WWW 2025 · 13 citations
- Like, Comment, Get Scammed: Characterizing Comment Scams on Media PlatformsXigao Li, Amir Rahmati, Nick NikiforakisNDSS 2024
- Ctrl+Alt+Deceive: Quantifying User Exposure to Online ScamsPlaton Kotzias, Michalis Pachilakis, Javier Aldana-Iuit, Juan Caballero et al.NDSS 2025
- All your (data)base are belong to us: Characterizing Database Ransom(ware) AttacksKevin van Liebergen, Gibran Gómez, Srdjan Matic, Juan CaballeroNDSS 2025
- Beyond the Stars: Multimodal Detection of Scams on GitHubTillson Galloway, Kevin Valakuzhy, Manos Antonakakis, Fabian MonroseUSENIX Security 2026
Builds on10
- Tracking Ransomware End-to-endDanny Yuxing Huang, Maxwell Matthaios Aliapoulios, Vector Guo Li, Luca Invernizzi et al.S&P 2018 · 208 citations
- How You Get Shot in the Back: A Systematical Study about Cryptojacking in the Real WorldGeng Hong, Zhemin Yang, Sen Yang, Lei Zhang et al.CCS 2018 · 120 citations
- Cybercriminal Minds: An investigative study of cryptocurrency abuses in the Dark WebSeunghyeon Lee, Changhoon Yoon, Heedo Kang, Yeonkeun Kim et al.NDSS 2019 · 100 citations
- Towards Understanding and Demystifying Bitcoin Mixing ServicesLei Wu, Yufeng Hu, Yajin Zhou, Haoyu Wang et al.WWW 2021 · 81 citations
- Just the Tip of the Iceberg: Internet-Scale Exploitation of Routers for CryptojackingHugo L. J. Bijmans, Tim M. Booij, Christian DoerrCCS 2019 · 32 citations
Related papers
- Watch Your Back: Identifying Cybercrime Financial Relationships in Bitcoin through Back-and-Forth ExplorationGibran Gómez, Pedro Moreno-Sanchez, Juan CaballeroCCS 2022 · 19 citations
- Double and Nothing: Understanding and Detecting Cryptocurrency Giveaway ScamsXigao Li, Anurag Yepuri, Nick NikiforakisNDSS 2023
- Demystifying Bitcoin Address Behavior via Graph Neural NetworksZhengjie Huang, Yunyang Huang, Peng Qian, Jianhai Chen et al.ICDE 2023 · 16 citations
- Ghost Clusters: Evaluating Attribution of Illicit Services through Cryptocurrency TracingKelvin Lubbertsen, Michel van Eeten, Rolf van WegbergUSENIX Security 2025
- Blockchain Address PoisoningTaro Tsuchiya, Jin-Dong Dong, Kyle Soska, Nicolas ChristinUSENIX Security 2025
