Crypto Hacks Drop to $26.5M in February Amid Security Gains

TheNewsCryptoPublished on 2026-03-02Last updated on 2026-03-02

Abstract

Crypto hacks and scams plummeted to a multi-year low in February, totaling approximately $26.5 million across 15 incidents. This represents a significant 69.2% decrease from January's $86 million in losses. The two largest attacks accounted for the majority: a $10 million price manipulation hack on YieldBlox’s lending pool and an $8.9 million private key exploit on IoTeX. Security firm PeckShield attributed the sharp decline to a lack of "mega-hacks" and a shift in focus due to market volatility. Analysts suggest capital is becoming more selective, rewarding protocols with stronger security, and that improved risk controls, audits, and AI-powered tools are contributing to a broader trend of enhanced crypto security.

Last month recorded the lowest level of crypto hacks and scams since March 2025, having $26.5 million stolen since February, as reported by the blockchain security company PeckShield.

Around 15 cases were reported in the month, in which two accounted for the majority of the losses, with the biggest accounting for the $10 million theft from YieldBlox’s DAO-managed lending pool through a price manipulation hack on February 21, as reported by PeckShield at X on March 1.

The second-biggest hack targeted the decentralised identity protocol IoTeX, which lost around $8.9 million to a private key exploit on Feb 21. In total, February indicates a 69.2% month-on-month fall from January, which listed more than $86 million in losses.

What Did the Spokesperson Mention?

A spokesperson from PeckShield mentioned that mega-hacks, like the $1.5 billion Bybit hack in February last year, did not inflate last month’s statistics, and market volatility resulted in a significant cooling period in exploit activity.

The spokesperson further mentioned that a sharp market correction in early February, having Bitcoin slip below $70,000, moved the focus of the industry toward institutional deleveraging and math-based sell-offs.

At the time of high-volatility periods, the tactical aim mostly shifts away from protocol exploits toward navigating market liquidity. Dominick John, a Kronos Research analyst, mentioned that the shift could also show tighter risk controls, stronger counterparty standards and amplified real-time monitoring over major venues.

He further went on, mentioning that Capital is shifting to become more selective, rewarding protocols with mature security frameworks. John mentioned losses could carry on to slip by the year as audits, monitoring, and institutional risk frameworks mature.

AI might also intensify the shift, backing automated code reviews, anomaly detection, and pre-deployment attack simulations to catch vulnerabilities earlier in the lifecycle. Crypto security is intensifying, and protocols are doubling down on audits, formal verification, and real-time monitoring.

Highlighted Crypto News Today:

Will AAVE Reset Monthly Momentum or Lose Steam and Remain in the Red?

TagsBybitCrypto AttackHack

Related Questions

QWhat was the total amount stolen in crypto hacks and scams in February, as reported by PeckShield?

A$26.5 million.

QWhich two major hacks accounted for the majority of the losses in February, and what were the amounts?

AThe $10 million theft from YieldBlox’s DAO-managed lending pool and the $8.9 million hack targeting the IoTeX protocol.

QWhat was the month-on-month percentage decrease in crypto losses from January to February?

AA 69.2% decrease.

QAccording to the spokesperson, what factor contributed to a significant cooling period in exploit activity?

AMarket volatility.

QHow might AI contribute to improving crypto security, as mentioned in the article?

ABy backing automated code reviews, anomaly detection, and pre-deployment attack simulations to catch vulnerabilities earlier.

Related Reads

Coldcard Hardware Wallet Hacked: 594 Bitcoin Withdrawn in 25 Minutes

The Coldcard hardware wallet has been compromised, with hackers stealing approximately 594.5 Bitcoin (~$40 million) from 500 addresses in just 25 minutes. The root cause was a critical software bug, undetected for five years, which disabled the device's secure chip for generating true random numbers. This led to the creation of private keys based on predictable data like the processor's serial number, drastically reducing cryptographic security. The attackers exploited this offline by brute-forcing possible seed phrases, finding active addresses on the public ledger, and signing transactions. Initially, Coinkite (Coldcard's maker) claimed only older models were at risk but later admitted all devices running the compromised firmware were vulnerable. CEO Rodolphe Novak (NVK) apologized but ruled out financial compensation for affected users. To secure funds, owners must urgently update their firmware to specific safe versions, generate a completely new seed phrase on the updated device, and transfer all assets to new addresses created with that new seed. While a BIP-39 passphrase can help, it does not replace this migration process. Other Coinkite products like TAPSIGNER were not affected. This incident underscores that even specialized hardware requires rigorous, independent code audits, especially for cryptographic functions. It parallels past failures, like a 2006 OpenSSL bug in Debian, and raises questions about whether automated code analysis can ever fully replace human scrutiny in critical security areas.

cryptonews.ru8m ago

Coldcard Hardware Wallet Hacked: 594 Bitcoin Withdrawn in 25 Minutes

cryptonews.ru8m ago

Trading

Spot
活动图片