Pro-Israel Hackers Drain $90 Million from Iran’s Nobitex Exchange Amid Escalating Cyber

    By

    Triparna Baishnab

    Triparna Baishnab

    Pro-Israel hackers steal $90 million from Iran's Nobitex crypto exchange, burning funds in a political act amid rising tensions.

    Pro-Israel Hackers Drain $90 Million from Iran’s Nobitex Exchange Amid Escalating Cyber

    Quick Take

    Summary is AI generated, newsroom reviewed.

    • Pro-Israel hacker group Predatory Sparrow stole over $90 million from Iran's Nobitex exchange.

    • Stolen funds were transferred to inaccessible wallets with anti-IRGC messages.

    • The attack is part of a broader cyber campaign targeting Iranian infrastructure.

    • Cybersecurity experts link the group's activities to state-sponsored operations.

    Escalating Cyber Warfare: $90 Million Stolen from Nobitex

    On June 18, 2025, Iran’s largest cryptocurrency exchange, Nobitex, was targeted in a significant cyberattack. The pro-Israel hacker group Predatory Sparrow, also known as Gonjeshke Darande, claimed responsibility for the breach. The group accused Nobitex of facilitating Iran’s efforts to bypass international sanctions and finance militant activities.

    Blockchain analysis firms Elliptic and TRM Labs confirmed that over $90 million in cryptocurrencies, including Bitcoin, Ethereum, and Dogecoin, were siphoned from Nobitex’s wallets. However, in an unprecedented move, the hackers transferred the stolen funds to “vanity addresses”—cryptocurrency wallets designed to be inaccessible due to their complex cryptographic keys. These addresses contained anti-IRGC messages, effectively rendering the stolen assets irretrievable.

    Nobitex responded by suspending access to its platform, citing unauthorized access to its systems. The exchange has not yet issued a public statement regarding the incident. This attack is part of a broader pattern of cyber operations attributed to Predatory Sparrow, which has previously targeted Iranian infrastructure, including gas stations and industrial sites.

    Political Motives Behind the Attack

    The deliberate destruction of the stolen funds indicates that the primary objective was not financial gain but a political statement. By rendering the assets inaccessible, the hackers aimed to disrupt Iran’s financial operations and send a message regarding the country’s alleged support for militant groups. The attack underscores the increasing use of cyber warfare as a tool for geopolitical influence, particularly in the context of the ongoing Israel-Iran conflict.

    While the true identity and affiliations of Predatory Sparrow remain unconfirmed, cybersecurity experts suggest that the group’s operations bear the hallmarks of a state-sponsored cyber unit. The sophistication and scale of the attacks, coupled with their alignment with Israeli strategic interests, point to a well-resourced and organized threat actor.

    Google News Icon

    Follow us on Google News

    Get the latest crypto insights and updates.

    Follow