February 2023 has proven to be a brutal month for cryptocurrency security, with CertiK reporting $51.4 million lost across 70 attacks — an alarming 83.4% increase from January. As Bitcoin hovers around $24,188 and Ethereum trades at $1,643, the growing value of digital assets continues to attract increasingly sophisticated threat actors. For anyone holding or transacting in cryptocurrency, understanding and implementing robust security practices has never been more critical.
The Threat Landscape
The CertiK February 2023 monthly report paints a stark picture. Flash loan attacks reached a record high of 22 incidents in a single month, resulting in $15.9 million in losses — the highest number of aggregated flash loan attacks since 2021. Discord server compromises surged by 36%, with 49 servers hacked, targeting project communities where unsuspecting members are often lured into clicking malicious links.
Exit scams accounted for $11.4 million across 28 incidents, representing 23.2% of total February losses. The largest was the fRiENDSiES Ai NFT project, flagged by on-chain investigator ZachXBT, which accounted for 48% of confirmed exit scam losses. Meanwhile, the MyAlgo wallet hack on the Algorand blockchain resulted in $9.2 million stolen through an apparent private key compromise, though only $1.5 million has been recovered so far.
On February 22, CertiK Alert also flagged suspicious movement of previously stolen Gate.io funds on Ethereum, a reminder that stolen assets continue circulating through the ecosystem long after the initial breach.
Core Principles
Protecting your cryptocurrency holdings starts with understanding the fundamental security triad: custody, authentication, and vigilance. Custody means controlling your own private keys whenever possible. Not your keys, not your coins remains the most important maxim in cryptocurrency security.
Authentication requires implementing multi-factor authentication on every exchange account and wallet service. Hardware-based 2FA tokens, such as YubiKey, provide the strongest protection against phishing attacks. SMS-based 2FA, while better than nothing, is increasingly vulnerable to SIM-swapping attacks.
Vigilance means maintaining constant awareness of the attack vectors currently in play. The surge in Discord compromises means that even official-looking announcements in project communities should be verified through independent channels before clicking any links or connecting wallets.
Tooling and Setup
Hardware wallets remain the gold standard for cryptocurrency storage. Devices from Ledger and Trezor store private keys offline, requiring physical confirmation for every transaction. This makes remote attacks, including the clipper malware currently being distributed through fake ChatGPT applications, completely ineffective.
For daily trading activities, consider using a dedicated device or a secure browser profile exclusively for cryptocurrency transactions. Browser extensions like EAL or CryptoScamDB can identify known phishing sites in real-time. Password managers with built-in credential monitoring add another layer of defense.
Smart contract interaction should be limited to audited protocols. Before approving any token spend, verify the contract address through multiple sources. Tools like Token Approval Checker on Etherscan allow users to review and revoke unnecessary approvals that could be exploited later.
Ongoing Vigilance
Security is not a one-time setup but a continuous process. Regularly review wallet approvals and revoke access to protocols you no longer use. Monitor your wallets using blockchain explorers or portfolio trackers that alert you to unauthorized transactions.
Stay informed about current attack trends. With flash loan attacks at record levels, be cautious about providing liquidity to unaudited protocols. The 22 flash loan attacks in February alone demonstrate that attackers are becoming more proficient at exploiting price oracle vulnerabilities and reentrancy bugs.
Community hygiene matters as well. With 49 Discord servers compromised in February, verify any announcement through the project’s official Twitter account, website, or Telegram admin before interacting. Never click wallet-connect links shared in Discord channels, even from seemingly trusted moderators.
Final Takeaway
The $51.4 million lost in February 2023 underscores a harsh reality: cryptocurrency security is an arms race, and individual users are on the front lines. The tools and knowledge to protect yourself exist, but they require consistent application. Hardware wallets, multi-factor authentication, contract approval hygiene, and community awareness form the foundation of a robust defense. In an ecosystem where a single misclick can result in irreversible financial loss, investing time in security practices yields the highest returns of all.
Disclaimer: This article is for informational purposes only and does not constitute financial or security advice. Always conduct your own research and consult with security professionals regarding your specific situation.
83% increase from january to february and we still had bigger months ahead. 2023 was just a warmup
february was a warmup for what came after. the euler and Mixin hacks alone dwarfed everything from Q1
22 flash loan attacks in one month is wild. the barrier to entry for these keeps dropping as attack toolkits get shared around telegram groups
telegram groups sharing attack scripts for $50 a pop. the commoditization of exploits is what makes this era different from 2018
$50 for an attack script on telegram. the ROI on that must be insane for the script sellers since one successful exploit can net millions
flash loan attacks being commoditized is the real problem. you dont even need to understand the exploit anymore, just pay someone for the script
Hiroshi T. commoditized flash loans were bound to happen. the real question is why protocols still deploy AMM code without circuit breakers
Wei C. circuit breakers exist in tradfi for exactly this reason. defi protocols shipping without them is pure negligence at this point
$51.4M in february alone and fRiENDSiES accounted for 48% of exit scam losses. the NFT grift was in full swing
49 Discord servers hacked in one month. thats 1-2 per day. and those are just the reported ones
discord_mod_ 49 servers in february alone and most mods were volunteers with zero security training. the social engineering was embarrassingly easy
mod_sweat_ 49 discord servers with volunteer mods and zero opsec training. most of those hacks were just someone clicking a malicious nitro link
nosleep_99 fRiENDSiES taking 48% of exit scam losses is wild. an AI NFT project that was basically a render of sad faces. people really funded that
fRiENDSiES taking 48% of exit scam losses proves most diligence in NFT is pure vibes. zachXBT flagged it and people still aped
Tariq Bello the crazy part is ZachXBT flagged it and people still bought in for weeks after. at some point you cant protect people from their own greed
CertiK reporting 51.4M lost in February while selling audits to the same projects getting hacked. the irony of a security firm profiting off insecurity seems lost on everyone
certik_skep_ CertiK auditing projects that then get hacked is a conflict of interest nobody talks about. they profit from the audit and the post-mortem forensics
22 flash loan attacks in a single month. the tooling got so cheap anyone could rent one for $50 on Telegram. protocols shipping AMM code without circuit breakers in 2023 were basically negligent
Belay T. fRiENDSiES alone was 48% of exit scam losses. an AI NFT project flagged by ZachXBT and people still bought in for weeks. greed overrides due diligence every time
exit_sniffer_ ZachXBT flagged fRiENDSiES publicly and people still bought in for weeks. greed literally overrides free due diligence
Belay T. flash loan toolkits for 50 dollars on Telegram means the barrier to running an exploit is now lower than buying a video game. protocols without circuit breakers are sitting ducks
flash loan toolkits for 50 bucks on Telegram. the barrier to exploitation dropped below the cost of a nice dinner. insane ROI for attackers
49 discord servers hacked through volunteer mods clicking nitro scam links. the social engineering layer is where crypto security fails hardest and nobody invests in fixing it
discord_sec_void_ volunteer mods with zero opsec training guarding communities worth millions. the weakest link is always human
49 discord servers hacked in february and the lesson nobody learned was that volunteer mods are not a security model. projects with 8 figure treasuries running community ops on unpaid labor
49 discord servers hacked in february and the lesson nobody learned was that volunteer mods are not a security model. projects with 8 figure treasuries running community ops on unpaid labor
fRiENDSiES being 48% of exit scam losses is insane. AI NFTs were the most obvious grift of 2023 and people still aped after ZachXBT flagged it
fRiENDSiES being 48% of exit scam losses is insane. AI NFTs were the most obvious grift of 2023 and people still aped after ZachXBT flagged it