pro israel hackers target nobitex

Iranian crypto exchange Nobitex found itself in digital shambles on June 18, 2025, when pro-Israel hacking group Gonjeshke Darande (“Predatory Sparrow”) orchestrated a devastating $90 million attack against the platform.

Unlike typical crypto heists where thieves make off with the digital loot, this attack was purely political—the hackers weren’t after profit but aimed to destroy assets as a message amid escalating Israel-Iran tensions.

The attack targeted only Nobitex’s “hot wallets”—the online-connected crypto storage—while offline “cold storage” assets remained untouched. This targeting pattern aligns with established security measures that most centralized exchanges employ to protect the majority of user funds.

What made this hack particularly fascinating was the attackers’ technique: they sent stolen funds to specially crafted “vanity addresses” containing anti-IRGC slogans.

Think of these addresses as impossibly complex digital safes where the combination was deliberately forgotten after locking.

“Brute forcing” these vanity addresses is like trying to find a specific grain of sand on all Earth’s beaches—technically possible but practically impossible.

Once funds went in, they were effectively burned forever, rendering over $90 million in various cryptocurrencies, including Bitcoin and Dogecoin, permanently inaccessible.

Nobitex, serving approximately 7 million users as Iran’s largest exchange, quickly suspended their website and app access following the breach.

The company has publicly committed to compensating affected users through insurance and reserve funds, emphasizing transparency throughout the crisis.

Predatory Sparrow explicitly linked their attack to Iranian government activities, accusing Nobitex of facilitating regime financing and sanctions evasion.

The hack came just one day after the same group claimed responsibility for breaching Iran’s state-owned Bank Sepah, suggesting a coordinated campaign.

Cryptocurrency security experts agree this attack represents a new paradigm in politically motivated cyber warfare, where blockchain’s immutability becomes a weapon rather than a shield.

The investigation continues into how exactly the attackers gained access to Nobitex’s systems, but the message was clear: in modern digital conflict, sometimes destroying assets makes a louder statement than stealing them.

Blockchain analysis firm Elliptic has documented on-chain interactions between Nobitex and wallets associated with Hamas, Palestinian Islamic Jihad, and Houthis.

The hackers embedded specific phrases including “FiRGCTerrorists” into blockchain addresses as a powerful symbolic statement against the Iranian regime.

Leave a Reply
You May Also Like

UwU Lend’s $20M Nightmare – Flash Loan Oracle Manipulation Devastates Platform

Flash loans up to $4 billion manipulated oracles, devastating UwU Lend in a $23.7M heist. Even after repairs, the attacker struck again. DeFi’s worst fears materialized.

Top 5 DeFi Exploits in 2025 So Far (And What We Learned)

Despite $470M lost to DeFi exploits in 2025, security remains shockingly primitive. Even giants like Coinbase and Bybit fell victim while 80% of hacked protocols skipped basic audits.

North Korean Cyber Army Steals Record-Smashing $1.34B in 2024 Crypto Rampage

North Korea’s hackers hijacked $1.34 billion in crypto – a staggering 61% of all stolen funds this year. Their billion-dollar industry is growing while your digital assets remain vulnerable.

North Korean Hackers Dominate $2.5B Crypto Theft Epidemic in First Half 2025

North Korean hackers stole a staggering $2.5B in crypto in six months—funding nuclear programs while outperforming all other criminals. These state-backed thieves aren’t slowing down.