pro israel hackers target nobitex

Iranian crypto exchange Nobitex found itself in digital shambles on June 18, 2025, when pro-Israel hacking group Gonjeshke Darande (“Predatory Sparrow”) orchestrated a devastating $90 million attack against the platform.

Unlike typical crypto heists where thieves make off with the digital loot, this attack was purely political—the hackers weren’t after profit but aimed to destroy assets as a message amid escalating Israel-Iran tensions.

The attack targeted only Nobitex’s “hot wallets”—the online-connected crypto storage—while offline “cold storage” assets remained untouched. This targeting pattern aligns with established security measures that most centralized exchanges employ to protect the majority of user funds.

What made this hack particularly fascinating was the attackers’ technique: they sent stolen funds to specially crafted “vanity addresses” containing anti-IRGC slogans.

Think of these addresses as impossibly complex digital safes where the combination was deliberately forgotten after locking.

“Brute forcing” these vanity addresses is like trying to find a specific grain of sand on all Earth’s beaches—technically possible but practically impossible.

Once funds went in, they were effectively burned forever, rendering over $90 million in various cryptocurrencies, including Bitcoin and Dogecoin, permanently inaccessible.

Nobitex, serving approximately 7 million users as Iran’s largest exchange, quickly suspended their website and app access following the breach.

The company has publicly committed to compensating affected users through insurance and reserve funds, emphasizing transparency throughout the crisis.

Predatory Sparrow explicitly linked their attack to Iranian government activities, accusing Nobitex of facilitating regime financing and sanctions evasion.

The hack came just one day after the same group claimed responsibility for breaching Iran’s state-owned Bank Sepah, suggesting a coordinated campaign.

Cryptocurrency security experts agree this attack represents a new paradigm in politically motivated cyber warfare, where blockchain’s immutability becomes a weapon rather than a shield.

The investigation continues into how exactly the attackers gained access to Nobitex’s systems, but the message was clear: in modern digital conflict, sometimes destroying assets makes a louder statement than stealing them.

Blockchain analysis firm Elliptic has documented on-chain interactions between Nobitex and wallets associated with Hamas, Palestinian Islamic Jihad, and Houthis.

The hackers embedded specific phrases including “FiRGCTerrorists” into blockchain addresses as a powerful symbolic statement against the Iranian regime.

Leave a Reply
You May Also Like

North Korean Cyber Army Steals Record-Smashing $1.34B in 2024 Crypto Rampage

North Korea’s hackers hijacked $1.34 billion in crypto – a staggering 61% of all stolen funds this year. Their billion-dollar industry is growing while your digital assets remain vulnerable.

State-Sponsored Lazarus Hackers Target Venus Protocol in Failed $13.5M Heist Attempt

North Korean hackers almost stole $13.5M from Venus Protocol through a clever phishing attack. Security teams recovered every cent while the crypto world held its breath.

Phemex Exchange Security Breach Exposes Platform Vulnerability to Hackers

$85 million vanished in under two hours: See how Phemex’s devastating breach across 16 blockchains exposes critical vulnerabilities even North Korea exploits. Your crypto might be next.

GMX Finalizes $44M Compensation Plan for GLP Holders After Hack

GMX rescues liquidity providers with $44M after hackers drained $42M through a cunning exploit. Can their compensation plan rebuild trust? Legitimate users will receive specialized GLV tokens.