On February 21, 2025, attackers drained roughly 401,000 ETH — about $1.5 billion — from Bybit's Ethereum cold wallet, the largest cryptocurrency theft on record and, by most reckonings, the largest single financial heist of any kind. What makes it a landmark isn't the number. It's the elegance of the deception. The attackers never broke into Bybit. They compromised a developer's machine at Safe{Wallet}, the multisig platform Bybit used, and injected malicious JavaScript into Safe's hosted signing interface — code that lay dormant until it recognised Bybit's specific transaction.

Then it did the cruelest thing software can do: it lied to the people watching. Bybit's multisig signers looked at their screens and saw a normal, expected transfer. They approved it. But the transaction they were actually signing quietly rewrote the cold wallet's smart-contract logic, handing control to the attackers. Every human in the loop did their job correctly. The interface between them and the truth had been poisoned. On February 26, the FBI attributed the theft to North Korea's TraderTraitor cluster (overlapping with the Lazarus Group) — the state whose treasury has a smash-and-grab department.

Bybit's response became the counter-example to the heist's horror. CEO Ben Zhou kept withdrawals open through a record surge of redemptions, and the exchange reported restoring 1:1 backing of customer assets within days via emergency loans and open-market ETH buys, then launched a bounty offering 10% of any recovered funds. By March 20, tracking by Bybit's own bounty programme and blockchain-analytics firms put roughly 86% of the stolen ETH as already converted to Bitcoin and scattered through mixers and bridges — the industrial money-laundering machine that makes DPRK crypto theft a strategic capability, not just a crime.

Also that month · The gang exposed

Black Basta's chat logs spill

On February 11, a persona called "ExploitWhispers" leaked roughly 200,000 internal chat messages from the Black Basta ransomware gang, drawn largely from its Matrix server — the leaker claiming it was punishment for the gang targeting Russian banks (a claim, as always, not a fact). Spanning September 2023 into 2024 and echoing the 2022 Conti leaks, the archive gave researchers a rare window into the gang's structure, internal feuds, tooling, and negotiation playbook. Nothing damages a criminal enterprise quite like its own group chat becoming public — a lesson that would visit LockBit three months later.

Also that month · Landlords of crime

Three nations sanction LockBit's hosting

On February 11, the US, UK, and Australia jointly sanctioned Zservers, a Russia-based "bulletproof" hosting provider, for supplying attack infrastructure to LockBit — the US also designating two Russian administrators, and the UK sanctioning a UK front company, XHOST. The action targeted the unglamorous but essential layer of the ransomware economy: the landlords who knowingly rent servers to criminals. You can't always arrest the tenant, the strategy runs, but you can go after the building.

India desk · February 2025

Angel One's AWS scare

On February 27, Angel One — one of India's largest retail stockbrokers, with a client base above 30 million — was alerted by a dark-web monitoring partner to a "data leakage post" and confirmed that some of its Amazon Web Services resources had been compromised. It disclosed the breach to the exchanges on February 28, saying it had immediately rotated AWS and application credentials and hired external experts. Angel One stated there was no impact on clients' securities, funds, or credentials, and — importantly — never published a count of affected customers, so any specific figure circulating from the threat actor's leak post remained an unverified claim. The market was less measured: the stock fell over 11% across the next two sessions to a 52-week low. For India's booming retail-investing platforms, February's lesson was that in a cloud-native brokerage, a misconfigured AWS resource is a market-moving event.

AI Tech desk · February 2025

The reasoning dial and the Paris split

Anthropic released Claude 3.7 Sonnet on 24 February 2025, calling it the first hybrid reasoning model — one system that could answer instantly or think in visible, extended steps, with the depth of that thinking exposed to the user as something close to a dial. Alongside it came Claude Code, a terminal tool for agentic coding, shipped quietly as a limited research preview; of the two, it proved the more consequential. OpenAI closed the month on 27 February with GPT-4.5, released as a research preview and described by the company as its largest model yet, pitched at conversation and nuance rather than reasoning — an experiment it withdrew from the API on 14 July 2025, less than five months later. Earlier, on 2 February, it had launched deep research, the agent that pushed multi-step web research into a consumer product. Between the two releases, the Paris AI Action Summit on 10 and 11 February ended with most participating governments signing a declaration on inclusive and sustainable AI and the United States and United Kingdom declining — Washington criticising over-regulation, London saying the text did not go far enough on governance and national security.

Digital Guard desk · February 2025

Sophos closes Secureworks; breakout time shrinks

Sophos completed its acquisition of Secureworks on 3 February 2025, an $859 million all-cash deal that took the Taegis XDR platform off Nasdaq and made Sophos, by its own account, the largest pure-play provider of managed detection and response — though the technical merger it promised took until September 2025, when Sophos Endpoint was finally integrated natively into Taegis. On 27 February, CrowdStrike's 2025 Global Threat Report put the average eCrime breakout time — the interval between initial access and lateral movement — at 48 minutes, with the fastest observed at 51 seconds, and found 79% of initial-access detections involved no malware at all; voice phishing rose 442% between the first and second halves of 2024. Palo Alto Networks, reporting on 13 February, beat estimates with revenue up 14% year on year to $2.3 billion and saw its shares fall regardless. Read together, the month described an industry built to catch files now facing intruders who brought none — and left with under an hour to notice.

⏳ Time capsule — February 2025

  • The Philadelphia Eagles beat the Kansas City Chiefs 40–22 in Super Bowl LIX on February 9, with Kendrick Lamar headlining the halftime show.
  • On February 18, NASA briefly put asteroid 2024 YR4's 2032 impact odds at 3.1% — a record for its size — before new data dropped the risk to near zero within a week.
  • On February 19, Microsoft unveiled Majorana 1, a chip it claimed used topological qubits — a claim some physicists immediately disputed.
  • On February 28, Bitcoin fell below $80,000 for the first time since November 2024, capping a brutal post-Bybit crypto week.
Where it stands today — 2026

Trust the tool, lose the treasury

The Bybit heist rewrote crypto security's threat model overnight: the danger was no longer just your own systems but every tool you trusted to interact with them, and "verify what you're actually signing" — through hardware wallets and transaction-simulation — became doctrine across the industry. Its $1.5 billion record still stood as the high-water mark against which April 2026's $293 million heist was measured. The supply-chain logic it demonstrated — poison the trusted interface, let honest people approve their own robbery — is the same pattern that ran through the year's OAuth-token and vendor-compromise attacks. February 2025 was the month the industry learned that the most dangerous lie is the one your own screen tells you.