By CoinAINews Staff
A major cryptocurrency hack targeting Iran's largest
exchange, Nobitex, has raised fresh questions about digital assets, sanctions,
and the murky world of geopolitical cyberwarfare.
The June 2025 attack saw more than $90 million in
cryptocurrency moved from Nobitex-controlled wallets to addresses controlled by
the attackers, according to blockchain analytics firm Elliptic. The funds
were subsequently sent to addresses designed to make the assets effectively
inaccessible.
The incident quickly became politically charged because the
hacking group that claimed responsibility, known as Predatory Sparrow,
or Gonjeshke Darande, has been widely described by researchers and media
outlets as pro-Israel or Israel-linked.
But there is an important distinction that should not be
lost in the headlines.
The available public evidence does not establish that the
Iranian government carried out the hack — a distinction that is often lost in
sensational headlines.
Instead, the available evidence points toward an attack on
an Iranian exchange by a group that claimed it was targeting Nobitex because of
the platform's alleged connections to Iran's financial system.
That distinction matters, particularly as Nobitex has since
faced growing scrutiny from U.S. authorities.
What Happened to Nobitex?
The attack took place on June 18, 2025, during a
period of rapidly escalating tensions between Israel and Iran.
Elliptic's analysis found that more than $90 million
worth of cryptoassets moved from Nobitex wallets to addresses controlled by
the attackers.
Rather than attempting to quietly launder the funds, the
attackers sent the cryptocurrency to what are commonly known as vanity
addresses — blockchain addresses created with specific words or messages
embedded in them.
The result was unusual.
The attackers effectively destroyed access to the stolen
cryptocurrency instead of treating it like a conventional theft.
Reuters reported that roughly $90 million in crypto was
transferred to hacker-controlled wallets and rendered inaccessible.
That made the incident look less like a conventional
financial crime and more like a political statement carried out through
cryptocurrency infrastructure.
Who Was Behind the Attack?
This is where the story becomes more complicated.
The group that claimed responsibility was Predatory
Sparrow, also known by its Persian name Gonjeshke Darande.
The group has previously claimed responsibility for
cyberattacks against Iranian infrastructure and financial institutions.
In the Nobitex incident, the attackers accused the exchange
of helping the Iranian government evade sanctions and support hostile
activities.
Elliptic described the attackers as a pro-Israel group,
while Reuters reported that Predatory Sparrow was reportedly linked to Israel.
However, that does not mean the Israeli government
has officially acknowledged responsibility for the attack.
That distinction is important when reporting the incident.
Attributing the hack to a specific government requires
stronger evidence than simply establishing the identity or affiliations claimed
by a hacking group.
So the most defensible description is that Predatory
Sparrow claimed responsibility and has been widely linked to Israel, rather
than saying that Israel officially carried out the attack.
Why Was Nobitex Targeted?
Nobitex sits at the center of Iran's cryptocurrency
ecosystem.
The exchange is widely described as Iran's largest
cryptocurrency platform and an important gateway between Iranian users and
global digital-asset markets.
That position makes Nobitex strategically significant.
Blockchain analytics firms have previously identified
transactions involving Nobitex and wallets associated with sanctioned Iranian
entities and groups.
Elliptic has also investigated Nobitex's role in Iran's
digital-asset ecosystem and reported connections involving activity that raised
sanctions-evasion and illicit-finance concerns.
The exchange, however, has denied having direct government
connections and has argued that illicit activity could occur through its
platform without management knowledge.
That means the question is not simply whether Nobitex
processed transactions connected to sanctioned entities.
The bigger question is what those transactions say about
the role of the exchange inside Iran's wider financial system.
U.S. Sanctions Added Another Layer to the Story
The Nobitex controversy did not end with the 2025 hack.
In June 2026, the U.S. Treasury Department sanctioned
Nobitex, accusing the exchange of providing significant support to the Iranian
regime and facilitating transactions connected to sanctions evasion and the
Islamic Revolutionary Guard Corps.
The Treasury said Nobitex processed more than half of
Iranian digital-asset inflows in 2025 and described the platform as a tool that
allowed Iranian regime insiders to access international cryptocurrency markets.
Treasury also sanctioned Nobitex's CEO and two individuals
it identified as controlling figures connected to the exchange.
Those sanctions are significant because they provide an
official U.S. government assessment of Nobitex's role in Iran's financial
infrastructure.
But they still should not be confused with proof that Iran
was responsible for the 2025 hack.
Those are two separate claims.
The $90 Million Wasn't a Typical Crypto Heist
One of the strangest aspects of the Nobitex attack was what
happened to the stolen cryptocurrency.
Normally, hackers who steal digital assets attempt to move
the funds through mixers, bridges, exchanges or multiple wallets before
converting them into other assets or fiat currency.
That did not happen here.
Instead, the attackers transferred the funds to addresses
that made them effectively unspendable.
Elliptic identified more than $90 million moving from
Nobitex wallets to attacker-controlled addresses.
The apparent objective was therefore not simply to make
money.
The attackers wanted the transaction itself to become a
public message.
That is one reason the Nobitex incident has attracted so
much attention from cybersecurity and blockchain analysts.
What Blockchain Data Can — and Cannot — Prove
Blockchain investigations can provide an unusually detailed
picture of where cryptocurrency moves.
Analysts can track wallet balances, transaction times, token
movements and destination addresses.
But blockchain data generally cannot identify the real-world
person sitting behind a wallet address by itself.
That distinction is particularly important in politically
sensitive cyberattacks.
Blockchain analysis can establish that funds moved from a
Nobitex wallet to a particular address.
It can establish the approximate value involved.
It can sometimes connect wallets to previously identified
entities.
But determining who physically controlled the attacker
infrastructure can require additional evidence from cybersecurity
investigations, intelligence agencies, seized infrastructure or other sources.
That is why claims about the identity of a state actor
should be treated carefully.
Why the Nobitex Hack Matters for Crypto
The attack highlights a growing problem for cryptocurrency
exchanges operating in politically sensitive environments.
Crypto transactions are global by design.
A user in one country can send digital assets to another
country within minutes, without using the traditional banking system.
That can make cryptocurrency valuable for legitimate users
in countries with restricted access to international financial markets.
At the same time, the same infrastructure can be used for
sanctions evasion, illicit finance and state-linked activity.
Nobitex sits directly inside that tension.
For ordinary Iranian users, the exchange can function as an
important gateway to digital assets.
For governments and regulators, however, the same platform
can represent a potential channel for moving money around international
restrictions.
That makes a large Iranian exchange an obvious strategic
target during a geopolitical conflict.
The Bigger Cyberwar Behind the Hack
The Nobitex attack also fits into a much broader pattern of
cyber operations connected to the Iran-Israel conflict.
Predatory Sparrow has previously claimed responsibility for
attacks targeting Iranian infrastructure.
Reuters reported that the Nobitex incident occurred shortly
after another cyberattack targeting Iran's Bank Sepah.
That timing reinforced the perception that the Nobitex hack
was part of a wider campaign rather than an isolated cryptocurrency theft.
For the crypto industry, this creates a difficult reality.
A cryptocurrency exchange can become a target not only
because of the value of the assets it controls, but also because of its role in
a country's financial infrastructure.
What Investors Should Take From the Incident
The Nobitex hack offers several lessons for cryptocurrency
investors and exchanges.
First, custody matters.
Cryptocurrency held in a centralized exchange wallet
ultimately depends on the exchange's security infrastructure.
Second, geopolitical risk can affect crypto
infrastructure.
An exchange operating in a heavily sanctioned or politically
isolated country can face risks that have little to do with normal market
volatility.
Third, on-chain transparency cuts both ways.
Blockchain transactions can be tracked publicly, making it
possible for researchers to reconstruct large hacks. But that transparency does
not automatically reveal who controls every wallet.
Finally, investors should be careful with headlines that
turn an attribution into a certainty.
There is a meaningful difference between:
"A pro-Israel hacking group claimed
responsibility."
and:
"Israel hacked the exchange."
The first statement reflects the available reporting. The
second requires evidence that has not been publicly established.
So, Was Iran Behind the Hack?
Based on the evidence publicly available, there is no
solid basis for saying that Iran was behind the Nobitex hack.
The available evidence points in the opposite direction:
Nobitex was the target, while Predatory Sparrow claimed responsibility for the
attack. Elliptic independently traced more than $90 million in crypto from
Nobitex wallets to attacker-controlled addresses.
At the same time, there is substantial reporting and U.S.
government action concerning Nobitex's alleged connections to Iran's financial
and sanctions-evasion infrastructure. Reuters reported in 2026 that Nobitex had
processed transactions involving sanctioned Iranian entities, while the U.S.
Treasury later sanctioned the exchange.
Those facts help explain why Nobitex may have been
targeted, but they do not establish that Iran conducted the attack.
That distinction is crucial — and it is the difference
between reporting facts and spreading speculation.
The Bottom Line
The Nobitex hack was far more than a typical cryptocurrency
theft.
More than $90 million in digital assets was moved
from the Iranian exchange to attacker-controlled addresses, according to
Elliptic. The funds were then effectively destroyed rather than quietly cashed
out.
The group that claimed responsibility, Predatory Sparrow,
has been widely described as pro-Israel or Israel-linked. But public evidence
does not establish that the Israeli government officially ordered or carried
out the attack.
At the same time, Nobitex's role in Iran's financial
ecosystem has come under increasing scrutiny. In 2026, the U.S. Treasury
sanctioned the exchange, alleging that it helped the Iranian regime and
sanctioned entities move funds and evade restrictions.
The result is a story where the target, the attackers and
the geopolitical context are all important — but they should not be conflated.
For the cryptocurrency industry, the Nobitex incident is
another reminder that digital assets are increasingly intertwined with
geopolitics.
And when a major crypto exchange becomes part of a cyberwar,
the blockchain can become not just a financial network, but also another
battlefield in a long-running geopolitical conflict.
CoinAINews provides independent coverage of
cryptocurrency, blockchain, technology and financial markets. This article is
for informational purposes only and does not constitute financial advice.

0 Comments