On February 21, 2025, attackers drained roughly 401,000 ETH — about $1.5 billion — from Bybit's Ethereum cold wallet, the largest cryptocurrency theft on record and, by most reckonings, the largest single financial heist of any kind. What makes it a landmark isn't the number. It's the elegance of the deception. The attackers never broke into Bybit. They compromised a developer's machine at Safe{Wallet}, the multisig platform Bybit used, and injected malicious JavaScript into Safe's hosted signing interface — code that lay dormant until it recognised Bybit's specific transaction.
Then it did the cruelest thing software can do: it lied to the people watching. Bybit's multisig signers looked at their screens and saw a normal, expected transfer. They approved it. But the transaction they were actually signing quietly rewrote the cold wallet's smart-contract logic, handing control to the attackers. Every human in the loop did their job correctly. The interface between them and the truth had been poisoned. On February 26, the FBI attributed the theft to North Korea's TraderTraitor cluster (overlapping with the Lazarus Group) — the state whose treasury has a smash-and-grab department.
Bybit's response became the counter-example to the heist's horror. CEO Ben Zhou kept withdrawals open through a record surge of redemptions, and the exchange reported restoring 1:1 backing of customer assets within days via emergency loans and open-market ETH buys, then launched a bounty offering 10% of any recovered funds. By March 20, tracking by Bybit's own bounty programme and blockchain-analytics firms put roughly 86% of the stolen ETH as already converted to Bitcoin and scattered through mixers and bridges — the industrial money-laundering machine that makes DPRK crypto theft a strategic capability, not just a crime.
Black Basta's chat logs spill
On February 11, a persona called "ExploitWhispers" leaked roughly 200,000 internal chat messages from the Black Basta ransomware gang, drawn largely from its Matrix server — the leaker claiming it was punishment for the gang targeting Russian banks (a claim, as always, not a fact). Spanning September 2023 into 2024 and echoing the 2022 Conti leaks, the archive gave researchers a rare window into the gang's structure, internal feuds, tooling, and negotiation playbook. Nothing damages a criminal enterprise quite like its own group chat becoming public — a lesson that would visit LockBit three months later.
Three nations sanction LockBit's hosting
On February 11, the US, UK, and Australia jointly sanctioned Zservers, a Russia-based "bulletproof" hosting provider, for supplying attack infrastructure to LockBit — the US also designating two Russian administrators, and the UK sanctioning a UK front company, XHOST. The action targeted the unglamorous but essential layer of the ransomware economy: the landlords who knowingly rent servers to criminals. You can't always arrest the tenant, the strategy runs, but you can go after the building.
Angel One's AWS scare
On February 27, Angel One — one of India's largest retail stockbrokers, with a client base above 30 million — was alerted by a dark-web monitoring partner to a "data leakage post" and confirmed that some of its Amazon Web Services resources had been compromised. It disclosed the breach to the exchanges on February 28, saying it had immediately rotated AWS and application credentials and hired external experts. Angel One stated there was no impact on clients' securities, funds, or credentials, and — importantly — never published a count of affected customers, so any specific figure circulating from the threat actor's leak post remained an unverified claim. The market was less measured: the stock fell over 11% across the next two sessions to a 52-week low. For India's booming retail-investing platforms, February's lesson was that in a cloud-native brokerage, a misconfigured AWS resource is a market-moving event.
⏳ Time capsule — February 2025
- The Philadelphia Eagles beat the Kansas City Chiefs 40–22 in Super Bowl LIX on February 9, with Kendrick Lamar headlining the halftime show.
- On February 18, NASA briefly put asteroid 2024 YR4's 2032 impact odds at 3.1% — a record for its size — before new data dropped the risk to near zero within a week.
- On February 19, Microsoft unveiled Majorana 1, a chip it claimed used topological qubits — a claim some physicists immediately disputed.
- On February 28, Bitcoin fell below $80,000 for the first time since November 2024, capping a brutal post-Bybit crypto week.
Trust the tool, lose the treasury
The Bybit heist rewrote crypto security's threat model overnight: the danger was no longer just your own systems but every tool you trusted to interact with them, and "verify what you're actually signing" — through hardware wallets and transaction-simulation — became doctrine across the industry. Its $1.5 billion record still stood as the high-water mark against which April 2026's $293 million heist was measured. The supply-chain logic it demonstrated — poison the trusted interface, let honest people approve their own robbery — is the same pattern that ran through the year's OAuth-token and vendor-compromise attacks. February 2025 was the month the industry learned that the most dangerous lie is the one your own screen tells you.