The Impact of Cryptocurrency on Cybersecurity
Terrence August (),
Duy Dao (),
Kihoon Kim () and
Marius Florin Niculescu ()
Additional contact information
Terrence August: Rady School of Management, University of California, San Diego, La Jolla, California 92093
Duy Dao: Haskayne School of Business, University of Calgary, Calgary, Alberta T2N 1N4, Canada
Kihoon Kim: Korea University Business School, Seoul 136-701, Korea
Marius Florin Niculescu: Scheller College of Business, Georgia Institute of Technology, Atlanta, Georgia 30308
Management Science, 2025, vol. 71, issue 11, 9606-9627
Abstract:
Cryptocurrencies have prompted a shift away from classic security attacks toward ransomware-based extortion. To better understand the impact of cryptocurrencies on the cybersecurity landscape, we conduct a comparative analysis of cybersecurity metrics prior to and after the adoption of cryptocurrency using a series of connected software-use models in the presence of security externalities. In this framework, we endogenize the actions of both heterogeneous consumers and attackers, with entry of the latter being driven by both the size of the unpatched consumer population and, as a subset of it, the size of the ransom-paying consumer population. We first examine users’ adoption and patching behavior under both security scenarios. We explore how changes in attacker entry costs impact outcomes under both conventional and post-crypto ransomware threat landscapes. We show that ransomware scenarios may be more desirable than conventional ones when attacker entry costs are low, provided that the gains from entering with standard attacks under the ransomware scenario are not too high. However, under such scenarios, social welfare can increase under the same conditions that lead to larger ransoms being demanded and a higher expected total ransom being paid, which presents a conundrum to policymakers. We also examine the impact of market parameters associated with security losses from conventional attacks and residual losses when victims pay in ransomware attacks.
Keywords: ransomware; cryptocurrency; cybersecurity; open source; interdependent risk (search for similar items in EconPapers)
Date: 2025
References: Add references at CitEc
Citations:
Downloads: (external link)
http://dx.doi.org/10.1287/mnsc.2023.00969 (application/pdf)
Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.
Export reference: BibTeX
RIS (EndNote, ProCite, RefMan)
HTML/Text
Persistent link: https://EconPapers.repec.org/RePEc:inm:ormnsc:v:71:y:2025:i:11:p:9606-9627
Access Statistics for this article
More articles in Management Science from INFORMS Contact information at EDIRC.
Bibliographic data for series maintained by Chris Asher ().