Crypto Losses From Hacks Dropped Big in February

by

|

Published

TLDR

  • Last year, ByBit was rocked by a $1.5 billion heist by North Korea’s Lazarus Group.
  • This year, depending on who you ask, crypto losses ranged from $25 to $50 million. That’s a big drop.
  • What happened? Better security, regulation, and faster responses from law enforcement. But users still need to be diligent. Phishing and pig butchering are now the scams of choice.

February 2026 was a relatively quiet month in crypto security — at least compared to the chaos of January. Total losses from hacks and scams came in at around $49.3 million, according to blockchain security firm NOMINIS, down sharply from the roughly $385 million they recorded the month prior. 

It’s worth noting that NOMINIS appears to track private wallet compromises as well as protocol hacks. That could explain the discrepancy between its numbers and those published by PeckShield. We’re pretty sure PS only tracks protocol exploits.

PeckShield, another security firm, tracked slightly different numbers ($26.5 million), but both agree on the big picture: February marked the lowest monthly loss total since March 2025.

So what happened? Was it better security? A market slowdown? A bit of both? Let’s get after it.

One Hack Drove Most of the Damage

February’s numbers are a little misleading at first glance. Strip out one single incident, and the month looks even calmer than the headline figure suggests.

On February 3rd, Solana-based DeFi platform Step Finance suffered a devastating breach. Attackers compromised devices belonging to the platform’s executive team, likely exposing private keys or enabling the approval of unauthorized transactions. 

The result? Around 261,854 SOL — worth approximately $30 million — was drained from project wallets. Step Finance recovered about $4.7 million, but the damage was done. The platform ultimately announced it would shut down, taking its affiliated projects, SolanaFloor and Remora Markets, with it.

That one incident alone accounted for more than 60% of all crypto losses in February.

The second-biggest hit came near the end of the month, when YieldBlox, a DeFi lending protocol, lost around $10.2 million after an attacker exploited weaknesses in the protocol’s asset valuation and collateral calculations. 

And on February 24th, the IoTeX ecosystem was hit for $4.4 million when attackers exploited flaws in cross-chain minting logic to mint unbacked tokens.

Aside from these three incidents, February’s losses were largely due to smaller attacks targeting individual users.

Regular People Were the Main Target

If February had a theme, it was this: attackers targeted everyday users, not just major protocols. And that is something we’re seeing across the board, guys. You have to be more diligent than ever. But now, instead of worrying about a rug pull, you need to be more concerned about your email and dating apps.

Phishing attacks, address-poisoning scams, and malicious transaction approvals recurred throughout the month. These aren’t high-tech exploits — they’re tricks designed to manipulate you into handing over access to your wallet.

Here’s a quick rundown of what that looked like in practice:

  • February 2nd: A victim sent $100,000 in USDT to a fake address that looked almost identical to the real one, differing only in a few middle characters.
  • February 10th: A user unknowingly signed a malicious transaction that gave an attacker permission to move $118,785 in BUSD out of their wallet.
  • February 17th: An address poisoning scam tricked a user into copying a scammer’s wallet address from their transaction history, resulting in a $599,714 loss.
  • February 18th: Two separate incidents — one phishing approval draining $337,069 in USDT, and another address poisoning scam costing a victim $157,000.
  • February 25th: Another phishing approval attack, this time resulting in $388,051 in losses.

None of these required sophisticated hacking skills. They all came down to one thing: getting the user to make a mistake. Instead of trying to hack the contract, bad actors are hacking the human.

Why Did Overall Losses Fall So Much?

A few factors likely contributed to the decline.

First, there were no “mega-hacks” in February. Compare this to February 2025, when the Bybit exchange was hit for a staggering $1.5 billion. When those monster events don’t happen, monthly totals look much healthier by comparison.

Second, Bitcoin dipped below $70,000 in early February, triggering a broader market correction. The high-volatility periods could be shifting attention away from protocol exploits. Unfortunately, that includes users and attackers. 

Third, security standards across the industry may genuinely be improving. Better audits, stronger risk controls, and improved real-time monitoring are all playing a role. 

The Bigger Picture – What It Means for Crypto Users

February’s numbers are a reminder that most crypto losses don’t happen because someone cracked an unbreakable code. They happen because people click on the wrong link, copy the wrong address, or sign a transaction without fully understanding what it does.

The good news? These risks are largely avoidable with a few simple habits:

  • Always double-check wallet addresses — the full address, not just the first and last few characters.
  • Use saved contacts or ENS names for wallets you send to regularly.
  • Read transaction prompts carefully before signing anything. If something asks for approval to spend your tokens, make sure you know exactly what you’re approving.
  • Be skeptical of unsolicited investment opportunities, especially ones that arrive through social media or dating apps.

Security researchers, law enforcement, and blockchain analytics firms are getting better at tracking and stopping crypto crime. But the most effective line of defense is still you. A bit of caution goes a long way.

Crypto Losses and Improving Security Moving Forward

February’s decline in crypto losses is genuinely positive news, even if one bad month doesn’t make a trend. The combination of improved security practices, smarter monitoring tools, and more active law enforcement is starting to show results.

That said, attackers are adapting too. The shift toward social engineering — manipulating users rather than exploiting code — means that technical security alone won’t cut it. Education matters just as much as encryption.

The safest crypto users aren’t necessarily the most technically sophisticated. They’re the ones who stay informed, stay skeptical, and take a second look before hitting send.

Disclaimer

This article is for educational and information purposes, and should not be considered financial advice. For more information visit our disclaimer page

About the Author

Countdown to next draw

days

hours

minutes

seconds