The $10.69 That Saved the World: What Really Happened During WannaCry
October 5, 2026 · 6 min read
On a Friday afternoon in May 2017, a twenty-two-year-old sat in his bedroom in a small English seaside town and, more or less by accident, saved the world from the worst of a global cyberattack — for the price of a cheap lunch.
His name is Marcus Hutchins, and that afternoon he was doing what he did most days: analyzing malware. A vicious new piece of ransomware was tearing across the planet, freezing hospitals across Britain's National Health Service, and Hutchins had grabbed a sample to pull apart. Digging through it, he noticed something strange. Before doing its damage, the malware kept trying to reach a particular web address — a long, nonsensical string of characters that nobody had registered. On a hunch, following a standard researcher's trick for tracking infections, he registered the domain himself. It cost $10.69. And in doing so, without at first grasping what he'd done, he flipped a hidden switch inside the malware that told it to stop spreading. Across the world, the attack ground to a halt.
That is the story of WannaCry in miniature: colossal stakes turning on tiny, almost accidental human moments. But to appreciate how astonishing that eleven-dollar save really was, you have to understand what Hutchins had actually stopped — and where it came from. Because the most dangerous part of WannaCry wasn't built by the criminals who unleashed it. It was built by the United States government.
A Weapon Escapes Its Makers
Somewhere in the machinery of the National Security Agency, years before that Friday, analysts found a flaw in a piece of software that runs on virtually every Windows computer on earth — the component Windows uses to share files and printers across a network. This is the kind of discovery an intelligence agency treasures: a reliable way into a huge fraction of the world's machines. And the NSA did what such agencies do with these discoveries. Instead of warning Microsoft so the flaw could be fixed and everyone protected, it kept the flaw secret and built it into a weapon, code-named EternalBlue.
Then the NSA lost it. In 2016 and 2017, a mysterious group calling itself the Shadow Brokers began dumping the agency's stolen cyber-arsenal onto the public internet, taunting the U.S. government in deliberately broken English as they went. In April 2017, they released EternalBlue itself — free, downloadable by anyone on earth. To this day we don't know for certain who the Shadow Brokers were; the leading theories point to a hostile nation-state or an insider, but the case has never been conclusively closed. What we do know is the effect. The most carefully guarded kind of weapon a country possesses — a working method for silently breaking into its enemies' computers — had just been handed, at no charge, to every criminal and opportunist on the internet.
Weeks later, someone picked it up. They wrapped the NSA's stolen exploit around a piece of ransomware, and the result was WannaCry. What made it so terrifyingly fast was that EternalBlue let it spread on its own — a self-propagating worm that jumped from one vulnerable computer to the next automatically, with no human clicking anything. Once loose, it didn't wait to be invited. It hunted. That's how it reached more than 150 countries and hundreds of thousands of machines in a single day, hitting Spanish telecoms, French car plants, Russian railways, German train stations, FedEx, Chinese universities, and — most consequentially — the hospitals of the NHS.
There's a lineage here that runs through everything I write about in the Digital Outlaws series: the slow, dangerous militarization of software, the transformation of secret flaws into national weapons. WannaCry is the moment that lineage arrived, without warning, on the screens of ordinary people. A weapon built by the American government to spy on its adversaries ended up locking the files of British nurses.
The Fix That Sat on the Shelf
Here is the detail that turns the WannaCry story from a thriller into a tragedy: it never should have worked.
When the NSA realized its tools were compromised, Microsoft was tipped off, and in March 2017 — two full months before the attack — the company issued a free security update that closed the exact hole EternalBlue relied on. Any computer that installed the patch was immune. The fix existed. It was available. It was sitting on the shelf.
And hundreds of thousands of organizations didn't install it. Not because they were reckless, but because patching at scale in the real world is genuinely hard. They were running old, out-of-support systems — Windows XP was still humming away inside hospitals, ATMs, factory floors, and medical devices years after Microsoft had stopped protecting it. They had life-critical equipment certified only for ancient software. They couldn't easily take hospital systems offline for the downtime that updates require. They were understaffed and underfunded, and they were operating on the oldest and most human instinct in technology: if it's working, don't touch it.
So when WannaCry came, it found a world full of doors that could have been bolted, for free, and it walked straight through them. This is the lesson at the heart of the whole story, and it's one I keep circling back to as someone who has spent a career building and maintaining systems: "just patch your systems" is simultaneously the entire answer and the lesson the world perpetually refuses to learn. WannaCry taught it in the most dramatic way imaginable — and years later, the same unpatched, legacy-laden, under-resourced conditions persist across hospitals, utilities, and governments everywhere. Which is exactly why ransomware kept working, and kept getting worse.
Why This Story Still Matters
WannaCry didn't hit its full potential, in the end — partly because of Hutchins' $10.69 kill switch, partly because a coincidental sanctions-style filter and the malware's own clumsiness limited it. Strangely, it was also a financial flop: it caused damage estimated in the billions but collected only around $140,000 in ransom, because its payment-and-decryption system barely worked. That failure as a "business" became one of the clues that pointed investigators away from an ordinary criminal crew and toward a nation-state, and the forensic trail — code shared with earlier attacks — led to North Korea's Lazarus Group, the same actor behind the Sony Pictures hack and the Bangladesh Bank heist. In late 2017 the U.S. and U.K. governments formally attributed WannaCry to North Korea.
And then there's the human coda that refuses to resolve into a fairy tale. Three months after Marcus Hutchins saved the world, the FBI arrested him at the Las Vegas airport — not for anything to do with WannaCry, but for banking malware he'd helped create years earlier, as a teenager. The accidental hero turned out to have a past. His case eventually ended with a guilty plea and a sentence of time served, no prison, a judge explicitly making room for both his wrongdoing and his redemption; he's since had a legitimate, respected security career. It's a messy, human story, and its refusal to offer a clean moral is exactly what makes it worth telling honestly.
That's why I wrote the book: to assemble the whole thing — the stolen weapon, the fragile world, the accidental hero, the nation-state behind it, and the ransomware epidemic it previewed — into one coherent narrative, explained in plain language, with the technology made clear and the human beings kept at the center. WannaCry was a warning, delivered as loudly as history ever delivers one: don't hoard weapons that can be stolen, don't build the world on foundations you refuse to maintain, and don't count on a kid with an eleven-dollar domain to save you next time. Most of that warning went unheeded. The full story of that one weekend in May — and why it still matters — is in the book.
WannaCry: The Ransomware That Held the World Hostage is available now in ebook from all major stores. It's part of Shane Larson's Digital Outlaws series.
New posts and releases, straight to your inbox. No spam, unsubscribe anytime.





