Elliptic Says Iran's Nobitex Was Hit in $90 Million Hack — What We Know About the Attack

 

Nobitex cryptocurrency exchange hack and Iran geopolitical cyberattack

By CoinAINews Staff

A major cryptocurrency hack targeting Iran's largest exchange, Nobitex, has raised fresh questions about digital assets, sanctions, and the murky world of geopolitical cyberwarfare.

The June 2025 attack saw more than $90 million in cryptocurrency moved from Nobitex-controlled wallets to addresses controlled by the attackers, according to blockchain analytics firm Elliptic. The funds were subsequently sent to addresses designed to make the assets effectively inaccessible.

The incident quickly became politically charged because the hacking group that claimed responsibility, known as Predatory Sparrow, or Gonjeshke Darande, has been widely described by researchers and media outlets as pro-Israel or Israel-linked.

But there is an important distinction that should not be lost in the headlines.

The available public evidence does not establish that the Iranian government carried out the hack — a distinction that is often lost in sensational headlines.

Instead, the available evidence points toward an attack on an Iranian exchange by a group that claimed it was targeting Nobitex because of the platform's alleged connections to Iran's financial system.

That distinction matters, particularly as Nobitex has since faced growing scrutiny from U.S. authorities.


What Happened to Nobitex?

The attack took place on June 18, 2025, during a period of rapidly escalating tensions between Israel and Iran.

Elliptic's analysis found that more than $90 million worth of cryptoassets moved from Nobitex wallets to addresses controlled by the attackers.

Rather than attempting to quietly launder the funds, the attackers sent the cryptocurrency to what are commonly known as vanity addresses — blockchain addresses created with specific words or messages embedded in them.

The result was unusual.

The attackers effectively destroyed access to the stolen cryptocurrency instead of treating it like a conventional theft.

Reuters reported that roughly $90 million in crypto was transferred to hacker-controlled wallets and rendered inaccessible.

That made the incident look less like a conventional financial crime and more like a political statement carried out through cryptocurrency infrastructure.


Who Was Behind the Attack?

This is where the story becomes more complicated.

The group that claimed responsibility was Predatory Sparrow, also known by its Persian name Gonjeshke Darande.

The group has previously claimed responsibility for cyberattacks against Iranian infrastructure and financial institutions.

In the Nobitex incident, the attackers accused the exchange of helping the Iranian government evade sanctions and support hostile activities.

Elliptic described the attackers as a pro-Israel group, while Reuters reported that Predatory Sparrow was reportedly linked to Israel.

However, that does not mean the Israeli government has officially acknowledged responsibility for the attack.

That distinction is important when reporting the incident.

Attributing the hack to a specific government requires stronger evidence than simply establishing the identity or affiliations claimed by a hacking group.

So the most defensible description is that Predatory Sparrow claimed responsibility and has been widely linked to Israel, rather than saying that Israel officially carried out the attack.


Why Was Nobitex Targeted?

Nobitex sits at the center of Iran's cryptocurrency ecosystem.

The exchange is widely described as Iran's largest cryptocurrency platform and an important gateway between Iranian users and global digital-asset markets.

That position makes Nobitex strategically significant.

Blockchain analytics firms have previously identified transactions involving Nobitex and wallets associated with sanctioned Iranian entities and groups.

Elliptic has also investigated Nobitex's role in Iran's digital-asset ecosystem and reported connections involving activity that raised sanctions-evasion and illicit-finance concerns.

The exchange, however, has denied having direct government connections and has argued that illicit activity could occur through its platform without management knowledge.

That means the question is not simply whether Nobitex processed transactions connected to sanctioned entities.

The bigger question is what those transactions say about the role of the exchange inside Iran's wider financial system.


U.S. Sanctions Added Another Layer to the Story

The Nobitex controversy did not end with the 2025 hack.

In June 2026, the U.S. Treasury Department sanctioned Nobitex, accusing the exchange of providing significant support to the Iranian regime and facilitating transactions connected to sanctions evasion and the Islamic Revolutionary Guard Corps.

The Treasury said Nobitex processed more than half of Iranian digital-asset inflows in 2025 and described the platform as a tool that allowed Iranian regime insiders to access international cryptocurrency markets.

Treasury also sanctioned Nobitex's CEO and two individuals it identified as controlling figures connected to the exchange.

Those sanctions are significant because they provide an official U.S. government assessment of Nobitex's role in Iran's financial infrastructure.

But they still should not be confused with proof that Iran was responsible for the 2025 hack.

Those are two separate claims.


The $90 Million Wasn't a Typical Crypto Heist

One of the strangest aspects of the Nobitex attack was what happened to the stolen cryptocurrency.

Normally, hackers who steal digital assets attempt to move the funds through mixers, bridges, exchanges or multiple wallets before converting them into other assets or fiat currency.

That did not happen here.

Instead, the attackers transferred the funds to addresses that made them effectively unspendable.

Elliptic identified more than $90 million moving from Nobitex wallets to attacker-controlled addresses.

The apparent objective was therefore not simply to make money.

The attackers wanted the transaction itself to become a public message.

That is one reason the Nobitex incident has attracted so much attention from cybersecurity and blockchain analysts.


What Blockchain Data Can — and Cannot — Prove

Blockchain investigations can provide an unusually detailed picture of where cryptocurrency moves.

Analysts can track wallet balances, transaction times, token movements and destination addresses.

But blockchain data generally cannot identify the real-world person sitting behind a wallet address by itself.

That distinction is particularly important in politically sensitive cyberattacks.

Blockchain analysis can establish that funds moved from a Nobitex wallet to a particular address.

It can establish the approximate value involved.

It can sometimes connect wallets to previously identified entities.

But determining who physically controlled the attacker infrastructure can require additional evidence from cybersecurity investigations, intelligence agencies, seized infrastructure or other sources.

That is why claims about the identity of a state actor should be treated carefully.


Why the Nobitex Hack Matters for Crypto

The attack highlights a growing problem for cryptocurrency exchanges operating in politically sensitive environments.

Crypto transactions are global by design.

A user in one country can send digital assets to another country within minutes, without using the traditional banking system.

That can make cryptocurrency valuable for legitimate users in countries with restricted access to international financial markets.

At the same time, the same infrastructure can be used for sanctions evasion, illicit finance and state-linked activity.

Nobitex sits directly inside that tension.

For ordinary Iranian users, the exchange can function as an important gateway to digital assets.

For governments and regulators, however, the same platform can represent a potential channel for moving money around international restrictions.

That makes a large Iranian exchange an obvious strategic target during a geopolitical conflict.


The Bigger Cyberwar Behind the Hack

The Nobitex attack also fits into a much broader pattern of cyber operations connected to the Iran-Israel conflict.

Predatory Sparrow has previously claimed responsibility for attacks targeting Iranian infrastructure.

Reuters reported that the Nobitex incident occurred shortly after another cyberattack targeting Iran's Bank Sepah.

That timing reinforced the perception that the Nobitex hack was part of a wider campaign rather than an isolated cryptocurrency theft.

For the crypto industry, this creates a difficult reality.

A cryptocurrency exchange can become a target not only because of the value of the assets it controls, but also because of its role in a country's financial infrastructure.


What Investors Should Take From the Incident

The Nobitex hack offers several lessons for cryptocurrency investors and exchanges.

First, custody matters.

Cryptocurrency held in a centralized exchange wallet ultimately depends on the exchange's security infrastructure.

Second, geopolitical risk can affect crypto infrastructure.

An exchange operating in a heavily sanctioned or politically isolated country can face risks that have little to do with normal market volatility.

Third, on-chain transparency cuts both ways.

Blockchain transactions can be tracked publicly, making it possible for researchers to reconstruct large hacks. But that transparency does not automatically reveal who controls every wallet.

Finally, investors should be careful with headlines that turn an attribution into a certainty.

There is a meaningful difference between:

"A pro-Israel hacking group claimed responsibility."

and:

"Israel hacked the exchange."

The first statement reflects the available reporting. The second requires evidence that has not been publicly established.


So, Was Iran Behind the Hack?

Based on the evidence publicly available, there is no solid basis for saying that Iran was behind the Nobitex hack.

The available evidence points in the opposite direction: Nobitex was the target, while Predatory Sparrow claimed responsibility for the attack. Elliptic independently traced more than $90 million in crypto from Nobitex wallets to attacker-controlled addresses.

At the same time, there is substantial reporting and U.S. government action concerning Nobitex's alleged connections to Iran's financial and sanctions-evasion infrastructure. Reuters reported in 2026 that Nobitex had processed transactions involving sanctioned Iranian entities, while the U.S. Treasury later sanctioned the exchange.

Those facts help explain why Nobitex may have been targeted, but they do not establish that Iran conducted the attack.

That distinction is crucial — and it is the difference between reporting facts and spreading speculation.


The Bottom Line

The Nobitex hack was far more than a typical cryptocurrency theft.

More than $90 million in digital assets was moved from the Iranian exchange to attacker-controlled addresses, according to Elliptic. The funds were then effectively destroyed rather than quietly cashed out.

The group that claimed responsibility, Predatory Sparrow, has been widely described as pro-Israel or Israel-linked. But public evidence does not establish that the Israeli government officially ordered or carried out the attack.

At the same time, Nobitex's role in Iran's financial ecosystem has come under increasing scrutiny. In 2026, the U.S. Treasury sanctioned the exchange, alleging that it helped the Iranian regime and sanctioned entities move funds and evade restrictions.

The result is a story where the target, the attackers and the geopolitical context are all important — but they should not be conflated.

For the cryptocurrency industry, the Nobitex incident is another reminder that digital assets are increasingly intertwined with geopolitics.

And when a major crypto exchange becomes part of a cyberwar, the blockchain can become not just a financial network, but also another battlefield in a long-running geopolitical conflict.


CoinAINews provides independent coverage of cryptocurrency, blockchain, technology and financial markets. This article is for informational purposes only and does not constitute financial advice.

 

Post a Comment

0 Comments