Iran’s crypto exchange Nobitex begins phased reopening after $90M hack tied to pro-Israel group


13 recorded changes
Want your article here?
Promote with Leviathan News

13 recorded changes
Want your article here?
Promote with Leviathan NewsIranian cryptocurrency exchange Nobitex, the country’s largest digital asset trading platform, has begun a phased restoration of services following a June 18, 2025 exploit that resulted in the loss or destruction of over $90 million in crypto from its hot wallets. Blockchain analytics firms and security researchers attribute the incident to Gonjeshke Darande (also known as Predatory Sparrow), a pro‑Israel hacktivist group widely believed to be linked to Israeli state interests, which framed the operation as a politically motivated strike on Iran’s digital financial infrastructure rather than a profit‑seeking theft. On‑chain analysis indicates that the attackers sent the stolen assets to specially crafted “burner” or invalid addresses—many with messages targeting Iran’s Islamic Revolutionary Guard Corps (IRGC)—meaning the funds cannot be recovered and were effectively destroyed. In response, Nobitex suspended services, isolated affected infrastructure, and later announced a multi‑phase recovery plan to bring the exchange back online. The roadmap outlines staged reactivation: first, mandatory re‑authentication for all users via the web interface with most functions still disabled; second, restored account access for verified users; and finally, a gradual reopening of deposits, withdrawals, and trading, accompanied by a promised technical post‑mortem and additional security hardening, including expanded cold‑storage usage. The incident has had systemic implications inside Iran: Nobitex is a central venue for domestic crypto activity, and reports indicate that Iranian authorities, including the Central Bank of Iran, have tightened oversight of exchanges and in some cases restricted operating hours following the hack. The Nobitex exploit is now cited as a prominent example of geopolitically driven cyber operations in the crypto sector, illustrating how nation‑state and proxy actors can use on‑chain tools not only to steal funds but to erase them as a form of political and economic signaling.
AI-generated background, compiled from web sources — not editorial content.

Quillaudits ·

𝕏/@TheBlockCo ·

CoinTelegraph ·

humanityprotocol.notion.site ·

𝕏/@a16zcrypto ·

𝕏/@flipdazed ·

Quillaudits ·

𝕏/@TheBlockCo ·

CoinTelegraph ·

humanityprotocol.notion.site ·

𝕏/@a16zcrypto ·

𝕏/@flipdazed ·
🚀 Love DeFi? Ready to dive in and start earning $SQUID while making an impact?