Who Stopped WannaCry?
A researcher analyzing the malware's code, on a hunch, registered a strange unclaimed domain — and it turned out to be the entire kill switch.
Marcus Hutchins, a British security researcher known online as MalwareTech, stopped the global spread of the WannaCry ransomware attack on May 12, 2017. While analyzing the malware's code, he noticed it tried to contact an unregistered, gibberish-looking domain before infecting a system. He registered that domain for about $10.69, which accidentally activated a kill switch built into the malware, halting its spread worldwide.
On May 12, 2017, ransomware began spreading across the world at a pace nobody in cybersecurity had seen in years, crippling hospitals, telecoms, and businesses in over 150 countries within hours.
It was stopped, that same day, not by a government agency or a major security firm's coordinated response, but by one 22-year-old working from his bedroom in England.

TL;DR
Quick answer
Marcus Hutchins, a British security researcher known as MalwareTech, stopped the global WannaCry ransomware attack on May 12, 2017, by registering an unclaimed domain referenced in the malware's code, which activated an unintended kill switch. He was arrested by the FBI months later on unrelated charges tied to malware he had authored years earlier.
The setup
A safety mechanism nobody was supposed to be able to trigger accidentally
WannaCry spread using a stolen NSA exploit targeting a Windows vulnerability, encrypting victims' files and demanding a bitcoin ransom to unlock them. Within hours of its release, it had infected computers across dozens of countries, with the UK's National Health Service among the hardest hit — forcing hospitals to turn away patients and cancel procedures.
Buried in the malware's code was a check: before infecting a system, it would first try to contact a specific, oddly named web address. If that address responded, the malware would quietly stop. If it didn't, the infection would proceed. Hutchins, analyzing the code as part of his job at cybersecurity firm Kryptos Logic, noticed the domain was unregistered and bought it — without knowing, at that moment, exactly what would happen next.
The chain of events, simplified
- WannaCry checked for a specific domain before infecting each system.
- That domain had never been registered by anyone.
- Hutchins registered it, which triggered the malware's built-in kill switch worldwide.
Story in brief
- May 12, 2017, morning
WannaCry begins spreading rapidly across networks worldwide, hitting the UK's NHS particularly hard.
Marked the start of one of the most disruptive ransomware outbreaks to that point.
- May 12, 2017, afternoon
Marcus Hutchins notices an unregistered domain referenced in the malware's code and registers it.
Accidentally activated the malware's built-in kill switch, halting its spread globally.
- Following weeks
Hutchins and colleagues work to keep the kill switch domain online against attempts to knock it offline.
Prevented a resurgence of the attack, since disabling the domain would have restarted the spread.
- August 2017
Hutchins is arrested by the FBI in Las Vegas on unrelated charges tied to malware he had written years earlier.
A dramatic reversal of fortune for someone being publicly celebrated as a global cybersecurity hero months earlier.
The person who saved the internet didn't know he was doing it
The kill switch itself appears to have been built into WannaCry as an anti-analysis measure by its creators, intended to detect whether the malware was running inside a security researcher's simulated environment — not as a deliberate 'off switch' for the public.
Hutchins has said in interviews that he had no idea registering the domain would stop the malware — he was simply following standard malware-analysis practice, which often involves registering suspicious domains to observe what traffic they attract.
It means one of the most consequential cybersecurity interventions in years was, by the researcher's own account, closer to a lucky byproduct of routine analysis than a deliberate rescue mission.
What people get wrong
Myth
Hutchins deliberately engineered a fix for WannaCry.
Reality
He registered a domain as part of routine malware analysis and, by his own account, didn't anticipate it would function as a kill switch.
Myth
Stopping the kill switch domain ended all risk from WannaCry.
Reality
Researchers had to actively defend the domain from being knocked offline, and variants without the same kill switch continued to appear afterward.
Myth
Hutchins' story ended as a straightforward hero narrative.
Reality
He was arrested by the FBI just months later on charges related to malware he had authored years earlier, well before his WannaCry work.
Why would ransomware creators build in something that could stop their own attack?
If the goal was to spread as widely as possible and collect ransom payments, why include a mechanism that could shut the whole operation down?Most security researchers believe the domain check was intended as a sandbox-evasion technique — malware analysts often run suspicious code inside isolated testing environments that automatically respond to any web request the malware makes, so a piece of malware checking for an always-successful response can use that as a signal it's being watched and studied, and shut down to avoid giving away its full behavior. The attackers likely never expected the domain to go unregistered in the real world.
Keeping the internet safe meant keeping a random website online, indefinitely
Once researchers realized the domain functioned as a kill switch, they had to actively maintain and defend it against attacks trying to take it offline — because if the domain ever went down, every infected but not-yet-triggered machine could resume encrypting files.
It turned an accidental fix into an ongoing responsibility, with real consequences riding on a single domain registration staying active.
The hero's past caught up with him almost immediately
Hutchins spent his teenage years writing malware himself, including a banking trojan called Kronos, before turning toward legitimate security research. Just months after being celebrated worldwide for stopping WannaCry, U.S. authorities arrested him for exactly that earlier chapter of his life.
The NHS disruption
WannaCry's impact on the UK's National Health Service was severe enough that hospitals canceled appointments and diverted emergency patients, later estimated to have cost the NHS more than £92 million in disruption and recovery.
It's a stark illustration of how quickly a piece of malware exploiting an already-patched vulnerability can still cause enormous real-world harm when organizations haven't kept their systems updated.
So, who stopped it?
Marcus Hutchins, a British security researcher, stopped WannaCry's global spread by registering a domain referenced in the malware's code, activating an unintended kill switch.
A well-documented, widely confirmed account — corroborated by researchers, court records, and Hutchins' own public statements.
Major cybersecurity crises are often resolved by individuals, not institutions
WannaCry is a striking reminder that some of the most consequential moments in cybersecurity history have come down to a single researcher's attentiveness rather than a coordinated institutional response — a pattern that's shaped how the security community thinks about the value of independent research ever since.
The short version
- Marcus Hutchins, known online as MalwareTech, stopped WannaCry's global spread on May 12, 2017.
- He registered an unregistered domain referenced in the malware's code, activating an unintended kill switch.
- The kill switch was likely designed as a sandbox-evasion technique, not a deliberate public off switch.
- Hutchins was arrested by the FBI months later on charges related to malware he had authored years earlier.
Questions people ask
Where to go next
Can the dark web be hacked?
A related look at how security incidents and dark web infrastructure sometimes intersect.
Why do hackers use Tor?
How the anonymity tools connected to this world actually get used.
Is Bitcoin actually anonymous?
Relevant to how ransomware payments like WannaCry's are tracked.
Has the FBI ever run a dark web marketplace undercover?
Another case of law enforcement and security research colliding in unexpected ways.
What happens to seized dark web cryptocurrency?
What typically happens to ransom payments and other cryptocurrency once authorities get involved.
Ten dollars and a hunch
The single most consequential fix to a global cyberattack in recent memory cost less than a large pizza, and nobody involved knew that's what it was doing until it already had.
You now know
- Marcus Hutchins stopped WannaCry's global spread on May 12, 2017, by registering a domain referenced in the malware's code.
- The kill switch was likely a sandbox-evasion technique that backfired once discovered, not a deliberate off switch.
- Hutchins was arrested by the FBI months later on unrelated charges tied to earlier malware he had authored.
Safety note
Educational, not operational
This guide is educational. It does not provide instructions for illegal activity, evading law enforcement, buying prohibited goods, or attacking systems. Laws and risks vary by country, so stay within your local rules and avoid interacting with unknown services.
Common myth
Myth vs reality
Hutchins deliberately engineered a fix for WannaCry.
He registered a domain as part of routine malware analysis and, by his own account, didn't anticipate it would function as a kill switch.
FAQs
Questions people ask
Sources
Further reading
- The sinkhole that saved the internetTechCrunch
- Marcus Hutchins, who stopped WannaCry's spread, avoids prison timeCyberScoop
Glossary
Terms in this guide
Continue learning