The accidental hero

Who Stopped WannaCry?

A researcher analyzing the malware's code, on a hunch, registered a strange unclaimed domain — and it turned out to be the entire kill switch.

Marcus Hutchins, a British security researcher known online as MalwareTech, stopped the global spread of the WannaCry ransomware attack on May 12, 2017. While analyzing the malware's code, he noticed it tried to contact an unregistered, gibberish-looking domain before infecting a system. He registered that domain for about $10.69, which accidentally activated a kill switch built into the malware, halting its spread worldwide.

On May 12, 2017, ransomware began spreading across the world at a pace nobody in cybersecurity had seen in years, crippling hospitals, telecoms, and businesses in over 150 countries within hours.

It was stopped, that same day, not by a government agency or a major security firm's coordinated response, but by one 22-year-old working from his bedroom in England.

A glowing kill switch toggle beside a spreading red infection map, frozen mid-spread
WhoMarcus Hutchins ('MalwareTech')
WhenMay 12, 2017
HowRegistered an unclaimed domain referenced in the malware's code

TL;DR

Quick answer

Marcus Hutchins, a British security researcher known as MalwareTech, stopped the global WannaCry ransomware attack on May 12, 2017, by registering an unclaimed domain referenced in the malware's code, which activated an unintended kill switch. He was arrested by the FBI months later on unrelated charges tied to malware he had authored years earlier.

Last reviewed2026-07-25
Reading time7 min
DifficultyBeginner
EvidenceStrong
Domain cost$10.69
Countries affected before the kill switchOver 150
Major victimUK's National Health Service
Attributed toNorth Korea, according to the U.S. government
Hutchins' fate months laterArrested by the FBI on unrelated malware charges

The setup

A safety mechanism nobody was supposed to be able to trigger accidentally

WannaCry spread using a stolen NSA exploit targeting a Windows vulnerability, encrypting victims' files and demanding a bitcoin ransom to unlock them. Within hours of its release, it had infected computers across dozens of countries, with the UK's National Health Service among the hardest hit — forcing hospitals to turn away patients and cancel procedures.

Buried in the malware's code was a check: before infecting a system, it would first try to contact a specific, oddly named web address. If that address responded, the malware would quietly stop. If it didn't, the infection would proceed. Hutchins, analyzing the code as part of his job at cybersecurity firm Kryptos Logic, noticed the domain was unregistered and bought it — without knowing, at that moment, exactly what would happen next.

The chain of events, simplified

  • WannaCry checked for a specific domain before infecting each system.
  • That domain had never been registered by anyone.
  • Hutchins registered it, which triggered the malware's built-in kill switch worldwide.

Story in brief

  1. May 12, 2017, morning

    WannaCry begins spreading rapidly across networks worldwide, hitting the UK's NHS particularly hard.

    Marked the start of one of the most disruptive ransomware outbreaks to that point.

  2. May 12, 2017, afternoon

    Marcus Hutchins notices an unregistered domain referenced in the malware's code and registers it.

    Accidentally activated the malware's built-in kill switch, halting its spread globally.

  3. Following weeks

    Hutchins and colleagues work to keep the kill switch domain online against attempts to knock it offline.

    Prevented a resurgence of the attack, since disabling the domain would have restarted the spread.

  4. August 2017

    Hutchins is arrested by the FBI in Las Vegas on unrelated charges tied to malware he had written years earlier.

    A dramatic reversal of fortune for someone being publicly celebrated as a global cybersecurity hero months earlier.

The person who saved the internet didn't know he was doing it

The kill switch itself appears to have been built into WannaCry as an anti-analysis measure by its creators, intended to detect whether the malware was running inside a security researcher's simulated environment — not as a deliberate 'off switch' for the public.

Hutchins has said in interviews that he had no idea registering the domain would stop the malware — he was simply following standard malware-analysis practice, which often involves registering suspicious domains to observe what traffic they attract.

It means one of the most consequential cybersecurity interventions in years was, by the researcher's own account, closer to a lucky byproduct of routine analysis than a deliberate rescue mission.

What people get wrong

Myth

Hutchins deliberately engineered a fix for WannaCry.

Reality

He registered a domain as part of routine malware analysis and, by his own account, didn't anticipate it would function as a kill switch.

Myth

Stopping the kill switch domain ended all risk from WannaCry.

Reality

Researchers had to actively defend the domain from being knocked offline, and variants without the same kill switch continued to appear afterward.

Myth

Hutchins' story ended as a straightforward hero narrative.

Reality

He was arrested by the FBI just months later on charges related to malware he had authored years earlier, well before his WannaCry work.

Why would ransomware creators build in something that could stop their own attack?

If the goal was to spread as widely as possible and collect ransom payments, why include a mechanism that could shut the whole operation down?

Most security researchers believe the domain check was intended as a sandbox-evasion technique — malware analysts often run suspicious code inside isolated testing environments that automatically respond to any web request the malware makes, so a piece of malware checking for an always-successful response can use that as a signal it's being watched and studied, and shut down to avoid giving away its full behavior. The attackers likely never expected the domain to go unregistered in the real world.

Keeping the internet safe meant keeping a random website online, indefinitely

Once researchers realized the domain functioned as a kill switch, they had to actively maintain and defend it against attacks trying to take it offline — because if the domain ever went down, every infected but not-yet-triggered machine could resume encrypting files.

It turned an accidental fix into an ongoing responsibility, with real consequences riding on a single domain registration staying active.

The hero's past caught up with him almost immediately

Hutchins spent his teenage years writing malware himself, including a banking trojan called Kronos, before turning toward legitimate security research. Just months after being celebrated worldwide for stopping WannaCry, U.S. authorities arrested him for exactly that earlier chapter of his life.

The NHS disruption

WannaCry's impact on the UK's National Health Service was severe enough that hospitals canceled appointments and diverted emergency patients, later estimated to have cost the NHS more than £92 million in disruption and recovery.

It's a stark illustration of how quickly a piece of malware exploiting an already-patched vulnerability can still cause enormous real-world harm when organizations haven't kept their systems updated.

confirmed

So, who stopped it?

Marcus Hutchins, a British security researcher, stopped WannaCry's global spread by registering a domain referenced in the malware's code, activating an unintended kill switch.

A well-documented, widely confirmed account — corroborated by researchers, court records, and Hutchins' own public statements.

Major cybersecurity crises are often resolved by individuals, not institutions

WannaCry is a striking reminder that some of the most consequential moments in cybersecurity history have come down to a single researcher's attentiveness rather than a coordinated institutional response — a pattern that's shaped how the security community thinks about the value of independent research ever since.

The short version

  • Marcus Hutchins, known online as MalwareTech, stopped WannaCry's global spread on May 12, 2017.
  • He registered an unregistered domain referenced in the malware's code, activating an unintended kill switch.
  • The kill switch was likely designed as a sandbox-evasion technique, not a deliberate public off switch.
  • Hutchins was arrested by the FBI months later on charges related to malware he had authored years earlier.

Questions people ask

Where to go next

Can the dark web be hacked?

A related look at how security incidents and dark web infrastructure sometimes intersect.

Why do hackers use Tor?

How the anonymity tools connected to this world actually get used.

Is Bitcoin actually anonymous?

Relevant to how ransomware payments like WannaCry's are tracked.

Has the FBI ever run a dark web marketplace undercover?

Another case of law enforcement and security research colliding in unexpected ways.

What happens to seized dark web cryptocurrency?

What typically happens to ransom payments and other cryptocurrency once authorities get involved.

Ten dollars and a hunch

The single most consequential fix to a global cyberattack in recent memory cost less than a large pizza, and nobody involved knew that's what it was doing until it already had.

You now know

  • Marcus Hutchins stopped WannaCry's global spread on May 12, 2017, by registering a domain referenced in the malware's code.
  • The kill switch was likely a sandbox-evasion technique that backfired once discovered, not a deliberate off switch.
  • Hutchins was arrested by the FBI months later on unrelated charges tied to earlier malware he had authored.

Safety note

Educational, not operational

This guide is educational. It does not provide instructions for illegal activity, evading law enforcement, buying prohibited goods, or attacking systems. Laws and risks vary by country, so stay within your local rules and avoid interacting with unknown services.

Common myth

Myth vs reality

Myth

Hutchins deliberately engineered a fix for WannaCry.

Reality

He registered a domain as part of routine malware analysis and, by his own account, didn't anticipate it would function as a kill switch.

FAQs

Questions people ask

Sources

Further reading

  • The sinkhole that saved the internetTechCrunch
  • Marcus Hutchins, who stopped WannaCry's spread, avoids prison timeCyberScoop

Continue learning

Next useful step

Keep going

The next door is usually the interesting one

The answer you came for touches a few neighboring questions. These are the ones most likely to make the picture click.

What you should remember

Ten dollars and a hunch

  • The single most consequential fix to a global cyberattack in recent memory cost less than a large pizza, and nobody involved knew that's what it was doing until it already had.
  • Marcus Hutchins stopped WannaCry's global spread on May 12, 2017, by registering a domain referenced in the malware's code.
  • The kill switch was likely a sandbox-evasion technique that backfired once discovered, not a deliberate off switch.
  • Hutchins was arrested by the FBI months later on unrelated charges tied to earlier malware he had authored.

A few useful next steps

Where this question wanders next

The dark web is less a single tunnel than a set of side passages. These are the useful ones from here.

If this made you wonder

wannacry collection

Place it in context

1

What Is a Ransomware Leak Site?

When encrypting a victim's files stopped being enough leverage on its own, ransomware groups built something new: public, dark-web-hosted pages threatening to publish stolen data on a countdown clock.

2

What Was Silk Road?

One 26-year-old, one laptop in a public library, and a marketplace that processed over a billion dollars before it fell apart.

3

What Is Cicada 3301?

An anonymous puzzle appeared online in 2012 with no explanation and no prize. It's still one of the internet's strangest unsolved stories.

4

What Was Dream Market?

For six years it was the corner shop of the dark web underworld. Then, one day, it politely told its customers to leave — and pointed them somewhere worse.

5

What Was Empire Market, And Why Did It Disappear?

It filled the gap left by AlphaBay and Hansa, became the dark web's biggest English-language marketplace, and then simply stopped answering.

Questions people ask first

Choose by the time in your pocket