On 7 February 2014 Mt. Gox stopped letting anyone take bitcoin out. The Tokyo exchange had begun as a site for trading Magic: The Gathering cards, its domain bought in January 2007; Jed McCaleb made it a bitcoin exchange in 2010 and sold it in 2011 to a French developer, Mark Karpelès. By early 2014 it handled most of the world's bitcoin trade. The notice said only that the company needed a clear technical view of its currency processes. On 10 February it named a cause — transaction malleability, a property of the protocol that let a transaction's identifier be altered after signing, so a completed transfer could be made to look as though it had never happened. Bitcoin lost about a fifth of its value in a day. The explanation was contested the same day: the Bitcoin Foundation's chief scientist, Gavin Andresen, answered that the currency was not at fault and that the trouble lay in the exchange's own customised wallet software, and a study by Christian Decker and Roger Wattenhofer that March found no widespread use of malleability attacks before Mt. Gox closed.

Statements followed on 17 and 20 February without a date for resuming withdrawals. Two bitcoin enthusiasts stood outside the Tokyo office with placards; on Mt. Gox's own order book the coin was trading at a fraction of what it fetched elsewhere, because a balance held there could not be moved. On 23 February Karpelès resigned from the board of the Bitcoin Foundation and the exchange's Twitter history was deleted. The next day trading was suspended and the site went blank. A document circulating that same day, presented as an internal crisis strategy draft, said the company was insolvent and that 744,408 bitcoin were missing, taken over several years without being noticed. Mt. Gox confirmed nothing; six other bitcoin companies published a joint statement distancing themselves from it.

On 28 February the company filed for civil rehabilitation at the Tokyo District Court, declaring liabilities of about 6.5 billion yen. It said roughly 750,000 customer bitcoin and about 100,000 of its own were gone — near enough seven per cent of every bitcoin then in existence, worth something in the region of $473 million at that week's prices. Karpelès, twenty-eight years old, appeared at a news conference in a suit rather than the T-shirt he was usually photographed in, bowed, apologised in Japanese and blamed what he described as a weakness in the system. On 20 March the trustee announced that 199,999.99 bitcoin had been found in an old-format wallet last used before June 2011, cutting the missing total to about 650,000.

Hindsight rearranged the story. In April 2015 WizSec's researchers, working from leaked transaction data, concluded that most or all of the missing coins had been drained from the hot wallet a little at a time from late 2011 — meaning the exchange had been insolvent for more than two years before it halted withdrawals. Karpelès was arrested on 1 August 2015 and, on 14 March 2019, convicted on one count of falsifying data to inflate holdings by $33.5 million; he got thirty months suspended for four years, and was acquitted of embezzlement. On 9 June 2023 American prosecutors charged two Russian nationals, Alexey Bilyuchenko and Aleksandr Verner, alleging they reached the server holding the exchange's wallets in about September 2011 and took at least 647,000 bitcoin, laundering them through BTC-e. The allegations remain untested.

Also that month · 21–25 February

The line that always ran

On 21 February Apple released iOS 7.0.6, and 6.1.6 for older devices, with a release note saying only that an attacker in a privileged network position might capture or modify data in sessions protected by SSL or TLS. Because the relevant code was published, researchers had the reason within a day. In Secure Transport's SSLVerifySignedServerKeyExchange function a line reading "goto fail;" appeared twice in succession beneath an unbraced if statement. C attaches such a conditional to one statement only, so the second jump ran every time, skipping the finalisation of the hash and the signature check that followed. The variable carrying the result held the status of a hash update instead, and verification could not fail: a certificate chain signed with the wrong private key, or not signed at all, was accepted. Adam Langley published his analysis and a test site on 22 February and confirmed that OS X 10.9.1 was affected too. It stayed unpatched, in public, until 10.9.2 shipped on 25 February. The flaw is CVE-2014-1266, and a compiler warning for unreachable code would have caught it.

Also that month · 12–19 February

A contractor, a crowdfunder, a campus

On 12 February Brian Krebs reported the route into Target, whose 2013 holiday card theft was still being counted: a malware-laced phishing email at Fazio Mechanical Services, a refrigeration contractor in Sharpsburg, Pennsylvania, sent at least two months before card data began moving. Sources put the malware at Citadel, a ZeuS descendant, though that was never confirmed; investigators said the firm had been relying on the free edition of Malwarebytes, which has no real-time protection and is licensed for personal use. Fazio called itself the victim of a sophisticated cyber attack operation; its access ran through Target's Ariba billing system and two vendor portals. Target would not comment. On 15 February Kickstarter posted a notice from its chief executive: law enforcement had warned it on the Wednesday night that intruders had taken usernames, email and postal addresses, telephone numbers and hashed passwords, though no card numbers, which it did not store in full. On 19 February the University of Maryland said 309,079 records had been taken — everyone issued a campus ID since 1998 — with names, dates of birth, university numbers and Social Security numbers, and nothing else.

India desk · February 2014

Pushed offshore, then emptied

India's bitcoin holders were on Mt. Gox because they had been pushed there. On 24 December 2013 the Reserve Bank of India issued a press release cautioning users, holders and traders of virtual currency; within days the Enforcement Directorate searched premises in Ahmedabad connected to buysellbitco.in, then one of India's largest trading platforms, and the domestic exchanges suspended operations. With nowhere to trade at home, Indians traded in Tokyo. Moneylife reported on 3 March 2014 that Indians held more than 35,000 bitcoin, worth over Rs 100 crore, and that Rs 10 crore to Rs 20 crore of it had been sitting on Mt. Gox when the site went dark. Sathvik Vishwanath, a founding member of the Bitcoin Alliance India, was among the few who spoke on record. Most of those who had lost money would not be named, the magazine reported, for fear of questions from tax authorities.

Nobody was obliged to tell anyone anything: no Indian exchange had to file a report, no regulator gathered the losses, and the rules of the day did not reach a company in Shibuya. What followed came slowly — the RBI's circular of 6 April 2018 barring banks from serving crypto firms, the Supreme Court setting it aside on 4 March 2020 as disproportionate, and the Finance Act 2022's flat thirty per cent tax on virtual digital assets from 1 April that year. The machinery for saying what had happened arrived with CERT-In's six-hour direction of 2022 and the DPDP Act of 2023. It was tested on 18 July 2024, when WazirX lost about $235 million from a wallet held under third-party custody, froze withdrawals and left Indian users in a restructuring for months.

AI Tech desk · February 2014

Nadella, Lucy and Project Tango

On 4 February 2014 Microsoft named Satya Nadella its third chief executive, with John W. Thompson taking the chairmanship and Bill Gates leaving it for a technology adviser's role; nothing in the announcement mentioned artificial intelligence, and the appointment would still shape the field more than anything else that month. Two days later IBM committed $100 million over ten years to Project Lucy, pointing Watson at healthcare, education, water and sanitation, mobility and agriculture across Africa, run from the laboratory it had opened in Nairobi and named for the Australopithecus afarensis fossil. On 20 February Google's Advanced Technology and Projects group unveiled Project Tango, a five-inch Android prototype with motion-tracking and depth cameras, presented as an exploration into giving mobile devices "a human-scale understanding of space and motion"; two hundred units went to vetted developers by 14 March. Tango was retired in March 2018 and its work folded into ARCore, and Nadella's Microsoft had by then become OpenAI's principal backer.

Digital Guard desk · February 2014

Seven Years Behind the Mask

Kaspersky Lab published its account of Careto — The Mask — on 10 February 2014: a Spanish-speaking group running since at least 2007, stopped only weeks earlier, with more than 380 unique victims in 31 countries, among them government institutions, embassies, oil and gas companies and activists. Backdoors existed for Windows, OS X and Linux; the toolkit took VPN configurations, SSH keys and encryption material. Costin Raiu, who ran the firm's research team, said the operational security was "not normal for cyber-criminal groups"; Kaspersky had noticed the campaign only because the attackers were exploiting an old flaw in its own products. On 13 February Bit9 merged with Carbon Black and raised $38.25 million, terms undisclosed — prevention buying detection, a year after Bit9's own signing certificate had been taken and used to sign malware; the combined company took the Carbon Black name and sold to VMware in 2019. The RSA Conference ran from 24 to 28 February short of speakers who had withdrawn over a reported NSA contract the company denied and Reuters stood by; they spoke at TrustyCon on the 27th.

⏳ Time capsule — February 2014

  • On 7 February the Winter Olympics opened in Sochi with a record 88 nations competing; one of five snowflakes failed to expand into an Olympic ring, an error the closing ceremony on 23 February re-enacted as a joke.
  • On 10 February Dong Nguyen withdrew Flappy Bird from the App Store and Google Play, two days after tweeting that he could not take it any more.
  • On 18 February the Lok Sabha passed the Andhra Pradesh Reorganisation Bill by voice vote and the Rajya Sabha followed on 20 February; five days earlier a member had used pepper spray in the chamber as the bill was introduced.
  • On 19 February Facebook announced it would buy WhatsApp for about $19 billion in cash, shares and restricted stock.
Where it stands today — 2026

Ten years to be paid

A decade on, February 2014 reads as the founding case of a genre. What it established was that an exchange can be empty for years while its books say otherwise, and that the people holding the balances will be the last to find out. Repayments to roughly 127,000 creditors began on 5 July 2024, ten years and four months on, in coins worth many times what they had been when they vanished — a windfall for those who waited, and none at all for those who had sold their claims to get something back sooner. The two men the United States accuses of taking the coins in 2011 have not stood trial. The shape repeats across this archive: Bitfinex in August 2016, FTX in November 2022, WazirX in July 2024.

The month's other stories aged into teaching material. The Apple bug is the standard illustration of why an unbraced conditional and an unread diff are a security matter, and the argument it began about who reads critical code was still running six weeks later, when Heartbleed was disclosed on 7 April 2014 from a flaw committed to OpenSSL on 31 December 2011. Target's refrigeration contractor became the shorthand for third-party risk. And on 27 February the Guardian published GCHQ's Optic Nerve, which had taken still images from Yahoo webcam sessions in bulk — about 1.8 million accounts in one six-month window, the internal assessments themselves estimating that between three and eleven per cent of what it caught was sexually explicit, from people who were the target of nothing.