Iran’s largest cryptocurrency exchange, Nobitex, suffered a politically motivated cyberattack in mid‑June 2025 that drained more than $90 million in digital assets from its hot wallets across multiple networks, including Bitcoin, EVM-compatible chains, Tron, and Ripple-related infrastructure. The pro‑Israel hacking group Gonjeshke Darande (also known as Predatory Sparrow) claimed responsibility, accusing Nobitex of helping the Iranian government evade Western sanctions and finance militant groups, and sent much of the stolen crypto to “burn” or vanity addresses carrying anti‑IRGC slogans, indicating the operation was aimed at inflicting damage and sending a political message rather than profiting. Within about a day of the exploit, the attackers escalated by publishing what they said was Nobitex’s full source code and internal infrastructure documentation on Telegram and other channels, exposing deployment configurations, privacy tooling, and wallet management scripts. Cybersecurity and blockchain analytics firms report that this leak effectively provides a blueprint of Nobitex’s systems, significantly increasing the risk that other actors could find new vulnerabilities and further compromise remaining user assets. Analysts frame the incident as a notable case of geopolitically driven cyber warfare in crypto, intertwining Israel–Iran tensions, sanctions evasion, and the security of centralized exchanges in high‑risk jurisdictions, and as a rare instance where an exchange hack doubles as both financial sabotage and intelligence exposure of a sanctioned country’s crypto infrastructure.

AI-generated background, compiled from web sources — not editorial content.

More coverage

Explore the topic

More on Bitcoin

Comments