February 2023 saw over $142.4 million in losses from crypto hacks and scams, marking a staggering 200% year-over-year increase according to a comprehensive report by De.Fi released on March 2, 2023. With Bitcoin hovering around $23,475 and Ethereum at $1,647, the recovering market has attracted renewed attention from both legitimate investors and sophisticated threat actors. Understanding the threat landscape and implementing robust security practices has never been more critical for cryptocurrency holders.
The Threat Landscape
The crypto security environment in early 2023 is characterized by increasingly sophisticated attack vectors that combine technical exploits with social engineering. The De.Fi report identified two major categories of attacks that dominated February: oracle manipulation and flash loan exploits. The BonqDAO incident on February 2 resulted in $120 million in losses when an attacker manipulated the protocol’s price oracle, artificially inflating the WALBT token price to mint over 100 million BEUR tokens before dumping them. Platypus Finance lost $8.5 million on February 16 through a flash loan attack that exploited weaknesses in the USP solvency check mechanism.
Beyond DeFi exploits, the phishing attack on The Sandbox disclosed on March 2 demonstrates how attackers are targeting the human layer. By compromising a single employee’s computer, the attacker gained access to user email addresses and sent fraudulent emails containing malware links disguised as a game feature called “PURELAND Access.” With over 350,000 active monthly users, the potential impact was enormous. These attacks succeed because they exploit trust rather than code vulnerabilities.
Core Principles
Effective crypto security rests on three fundamental principles: separation, verification, and minimal exposure. Separation means using different devices or browser profiles for crypto activities versus general internet use. Verification means never trusting a link or attachment without confirming its legitimacy through an independent channel. Minimal exposure means keeping only what you need for active transactions in hot wallets, with the bulk of holdings in cold storage.
The BonqDAO attack illustrates why these principles extend beyond individual behavior. Oracle manipulation attacks succeed because protocols rely on single price feeds or insufficiently decentralized data sources. Understanding how a protocol sources its price data, whether it uses time-weighted average prices, and whether it has circuit breakers for abnormal price movements should be part of every investor’s due diligence before committing funds.
Tooling and Setup
A robust crypto security setup should include hardware wallets such as Ledger or Trezor for storing significant holdings. These devices keep private keys offline and require physical confirmation of transactions, making remote theft virtually impossible. For daily trading and DeFi interactions, use a dedicated browser profile with only essential extensions installed. Consider using a separate email address exclusively for crypto accounts, and never reuse passwords across services.
Enable two-factor authentication on every crypto-related account, preferably using an authenticator app rather than SMS, which is vulnerable to SIM-swap attacks. The Sandbox incident demonstrated that even platforms with millions of users can have gaps in their internal security — the company only enforced universal 2FA after the breach occurred. If major platforms are lagging on security fundamentals, individual users must take responsibility for their own protection.
For DeFi participants, consider using transaction simulation tools that preview what a smart contract interaction will do before you sign it. Tools like Tenderly and PocketUniverse can help identify malicious contract interactions that could drain your wallet.
Ongoing Vigilance
Security is not a one-time setup but a continuous process. Regularly review your wallet approvals and revoke unnecessary token allowances using tools like Revoke.cash or Etherscan’s token approval checker. Monitor your wallets for unauthorized activity, and consider setting up alerts through blockchain monitoring services. Keep all software, including browser extensions and wallet firmware, updated to patch known vulnerabilities.
Stay informed about ongoing threats by following security researchers and platforms on social media. The crypto security community often identifies new attack patterns before they become widespread. When incidents like the BonqDAO or Platypus Finance exploits occur, take the time to understand how they worked and whether any protocols you use share similar vulnerabilities.
Final Takeaway
The $142.4 million lost in February 2023 with zero recovery is a harsh reminder that in cryptocurrency, you are your own bank — and your own security department. No protocol is too large to fail, no platform too popular to be breached, and no user too small to be targeted. Invest in your security setup with the same diligence you apply to your investment research. The tools and knowledge are available; the question is whether you will implement them before or after an incident affects you.
Disclaimer: This article is for informational purposes only and does not constitute financial or security advice. Always conduct your own research and consult with security professionals regarding your specific situation.
BonqDAO 120M loss because of one oracle. one. youd think after Mandi Maker every protocol would use at least three independent price feeds
Sven H. chainlink exists and protocols still roll their own oracle. its cheaper until you lose 120 million i guess
bonqdao losing $120m to oracle manipulation is wild. we solved this problem years ago and protocols still use single-source oracles
partially agree but flash loan + oracle attacks are getting more sophisticated too. platypus wasnt just another copy paste exploit
fair point on sophistication but the root cause is always the same: access control and oracle dependency. flash loans just amplify the blast radius
solved years ago and protocols still copy paste the same oracle setup. $120M says they won’t learn either
120M and bonqdao still hasnt recovered. wonder how many more oracles need to fail before single-source becomes unacceptable
the BonqDAO oracle manipulation for $120m is wild. youd think after DeFi summer people would learn but here we are still seeing the same attacks in 2026
BonqDAO losing 120M because one oracle got manipulated is still insane to me. a single price feed took down the whole protocol
rekt_archivist_ and they minted 100M BEUR before dumping. the attacker didnt even need to be sophisticated, just one weak oracle
BonqDAO losing 120M because one oracle got manipulated is still insane to me. a single price feed took down the whole protocol
200 percent YoY increase in hacks and people still click random links in discord. hard to feel bad at this point
200% YoY increase in hacks during a recovery period makes sense. rising prices bring out the predators. the $23k BTC mention takes me back though
the 200% increase in losses is mostly just activity picking back up. bears didnt hack, they just had less liquidity to steal
BonqDAO 120M to a single oracle manipulation and we are still having the multi-source oracle conversation years later. TWAP exists, use it
platypus lost 8.5M on the same flash loan vector that hit everyone else that month. copy paste codebases are the real vulnerability
the 142.4M figure is just what was reported. real losses including unreported rug pulls are probably 3x that
Marcus L. 142.4M reported but unreported rugs probably push it past 400M. february 2023 was brutal
bonqdao losing $120m to oracle manipulation is wild. we solved this problem years ago and protocols still use single-source oracles
oracle_watcher bonqdao used a single price source for WALBT. one manipulated feed and 120M gone. twap and multi-source oracles exist for exactly this reason
flash loan + oracle attacks are getting more sophisticated. platypus wasnt just another copy paste exploit, the attack vector is evolving
the 200% increase is mostly just activity picking back up. bears didnt hack, they just had more liquidity to steal
BonqDAO held 120M in value and used a single oracle for WALBT pricing. thats not a hack, thats negligence at the protocol level
Devon M. platypus was the same month with an 8.5M flash loan hit. two major protocols, same quarter, same oracle class of bug. twap exists for a reason
mev_fog_ Platypus and BonqDAO in the same month proved that oracle audits were box checking exercises. nobody actually stress tested the price feeds under flash loan conditions
200 percent YoY increase and the article still recommends hardware wallets and 2FA as the fix. those dont help when the protocol itself is fundamentally broken