I like cryptocurrencies, and I also work in information security and malware analysis. I acknowledge ransomware is a massive problem and that ransomware would be stupid to not use cryptocurrency. Technology isn't inherently good or bad; it just is what it is.
I think one of the main sources of the problem here is international law enforcement. The Russian government and security/law enforcement services have a pretty open agreement with cybercriminals: don't target Russian citizens and we won't impact your business. A lot of these organizations are now complementing the ransoms with harassment and blackmail, too, like threatening to release sensitive documents, directly harassing CEOs, etc. And some directly target health care facilities, knowing there'll be more urgency to pay up.
So if you're a Russian citizen, you have carte blanche to steal millions from people around the world, in an organizational structure that mostly resembles a kind of standard office job, with almost no anxiety that it'll ever come back to bite you (as long as you never travel outside of the country).
It reminds me a little of old-school naval piracy and privateering in many ways.
If you're in the US or UK or France or many other places and want to start a lucrative ransomware operation, there's a high chance you'll eventually get caught, so the risk of long-term imprisonment is enough to deter you even if easy millions may tempt you. If you have no moral qualms, great incentives, and nothing to deter you, the possibilities are limitless.
I'm not saying that all countries should extradite - just that they should at least make a good faith effort to cooperate with other countries' law enforcement and stop serious cybercrime like ransomware. Though I can understand why an "underdog" nation-state may want to have good relations with some talented criminals within their borders who they may be able to recruit or order around as needed.