T
iTokenly

Nobitex hack — June 2025

Verified — 6 sourcesLast checked August 1, 2026

Incident facts

Date of incident
Target typeCentralised exchange
Loss$90,000,000Published estimates range $81,700,000 to $90,000,000Price at time of incident
MethodPrivate key compromiseattackers reached internal infrastructure and hot wallet signing keys, then swept the hot wallets to unspendable vanity addresses rather than to addresses they controlled
ChainsMultiple chains, Ethereum, Tron, Bitcoin, Solana, TON
Attributed toGonjeshke Darande (Predatory Sparrow)Confirmed
OutcomeUnresolved

What happened

Nobitex, Iran's largest cryptocurrency exchange, said on 18 June 2025 that it had identified unauthorised access to parts of its infrastructure, affecting its internal communication systems and a portion of its hot wallets. The website and app went offline the same day.

The group Gonjeshke Darande, known in English as Predatory Sparrow, claimed responsibility, saying Nobitex sat at the centre of the Iranian government's terror financing and sanctions evasion. The claim came a day after the same group said it had attacked the state-owned Bank Sepah, causing widespread ATM outages, and days after Israeli strikes on Iran began. The group also pledged to publish Nobitex's source code and internal technical documentation. Israel has not officially confirmed involvement.

Elliptic traced over $90 million out of Nobitex wallets, a figure broadly matched by TRM Labs and Chainalysis and by on-chain records reviewed by reporters. The independent analyst ZachXBT counted at least $81.7 million across Ethereum and Tron-compatible networks alone. Assets moved included bitcoin, ether, dogecoin, tron, XRP, solana, TON and tether.

The funds were not taken for profit. They were sent to vanity addresses spelling out anti-IRGC slogans on Tron and Ethereum. Producing addresses with text strings that long by brute force is computationally infeasible, so the attackers cannot hold the corresponding private keys, and Elliptic concluded the funds were effectively burned to send a political message. Nothing is recoverable. Nobitex restored access in stages from 29 June 2025, beginning with spot wallets for verified users. On 2 June 2026 the US Treasury sanctioned Nobitex itself, along with Wallex, Bitpin and Ramzinex and four Nobitex-linked individuals, under a counterterrorism designation citing IRGC and ransomware links.

Law enforcement

No arrests or charges. Gonjeshke Darande / Predatory Sparrow publicly claimed the operation and is widely described in reporting as Israel-linked, but no government has formally claimed or attributed it. Separately, on 2 June 2026 OFAC designated Nobitex, the victim, along with Wallex, Bitpin and Ramzinex and four individuals connected to Nobitex, under Executive Order 13224 counterterrorism authority; that action targets the exchange, not the attackers, and does not reference this hack.

Sources

  1. EllipticOn-chain · retrieved 2026-08-01
  2. TechCrunchSecondary · retrieved 2026-08-01
  3. Crypto BriefingSecondary · retrieved 2026-08-01
  4. crypto.newsSecondary · retrieved 2026-08-01
  5. Finance MagnatesSecondary · retrieved 2026-08-01
  6. EllipticOn-chain · retrieved 2026-08-01

Cite this

This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.

iTokenly Hack Registry, "Nobitex hack — June 2025", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/nobitex
https://itokenly.com/hacks/nobitex

Permalinks never change. If an entry is renamed, the old address keeps working.

Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.