Pro-Israeli group “Predatory Sparrow” destroyed $90-100 million in crypto assets on Iran’s largest exchange Nobitex through irreversible vanity addresses.
Attack targeted Iran’s sanction-evasion system, affecting 7 million users who rely on crypto to survive international financial restrictions and inflation.
This marks cryptocurrency’s weaponization in geopolitical conflicts, transforming digital assets from decentralized tools into instruments of state-level cyber warfare.
Israeli hackers destroy $100M in Iranian crypto assets through Nobitex exchange attack, marking new era of digital warfare where geopolitical conflicts transform cryptocurrency into weapons.
THE CORE EVENT: AN ATYPICAL “DIGITAL DESTRUCTION” OPERATION
On June 18, 2025, Iran’s largest cryptocurrency exchange Nobitex suffered an unprecedented attack. Unlike conventional hackers who steal assets, the pro-Israeli group “Predatory Sparrow” (Gonjeshke Darande) infiltrated the system and transferred $90-100 million worth of crypto assets. These assets included BTC, ETH, DOGE, and other major currencies.
Subsequently, attackers moved the funds into inaccessible “vanity addresses.” These addresses contained political slogans such as “F*ckIRGCterrorists.” Furthermore, generating the private keys would computationally require “billions of years.” As a result, the funds became permanently destroyed.
Nobitex immediately suspended all services and promised to compensate user losses using reserve funds. However, Iran’s domestic internet disruptions meant recovery would take 4-5 days. Consequently, this situation intensified public panic about the financial system.
ATTACK METHODS: INTERSECTION OF TECHNICAL VULNERABILITIES AND POLITICAL MOTIVES
Precisely Exploiting Access Control Vulnerabilities
Rather than directly robbing main wallets, hackers gained administrator access through phishing emails or internal infiltration. They then invaded Nobitex’s hot wallet system, which processes instant transactions online.
Next, attackers moved laterally through internal networks. They systematically transferred multi-chain assets and planted destruction addresses. Blockchain company Nominis observed that this deep penetration far exceeded typical hackers’ “vault robbery” methods.
Strategic Intent: Destruction Rather Than Profit
Political Declaration: Destroying funds aimed to send Iran a deterrent signal about “cutting sanction channels.”
Psychological Warfare Escalation: Hackers threatened to publish Nobitex source code and internal data within 24 hours. This move attempted to completely destroy the platform’s business reputation.
Geopolitical Connection: The action occurred five days after Israel’s airstrikes on Iranian nuclear facilities (June 13). This timing created “soft-hard coordination” with physical military operations.
WHY NOBITEX BECAME THE “BULLSEYE”
IRAN’S FINANCIAL LIFELINE
Sanction Evasion Core: Nobitex serves as a key tool for Iran’s government and Revolutionary Guard (IRGC) to bypass international sanctions. In 2024, together with Russia’s Garantex exchange, it processed 85% of cryptocurrency flowing to sanctioned entities.
National Essential Platform: Over 7 million Iranian users depend on the platform to combat inflation and financial blockades. The exchange even provides tutorials for “circumventing transfer restrictions.”
THE ATTACK’S CHAIN REACTION
Central Bank Emergency Response: Iran’s central bank restricted all domestic exchanges’ operating hours to daily 10:00-20:00. This measure aimed to reduce systemic risks.
Civilians as Hidden Victims: Many families view crypto assets as their “last insurance policy.” Therefore, platform shutdowns intensify survival pressures across the country.
NEW PARADIGMS IN CYBER WARFARE: FROM PARALYZING FACILITIES TO BURNING ASSETS
“Predatory Sparrow’s” State Background Suspicions
Although Israel hasn’t officially acknowledged connections, the organization’s characteristics strongly suggest state support:
Target Consistency: In 2021, they paralyzed Iran’s nationwide gas station system. In 2022, they burned steel plant facilities. All attacks consistently targeted strategic infrastructure.
Tactical Professionalization: Within two days, they consecutively attacked Iran’s state-owned Sepah Bank and Nobitex. This coordination simultaneously disrupted both traditional and digital finance.
Cryptocurrency Becomes the “Fifth Battlefield”
UN Secretary-General Guterres called for stopping “new forms of military escalation.” However, such attacks blur the boundaries of warfare responsibility. Security experts warn that cyber strikes targeting payment systems could potentially spread to third-party countries like Saudi Arabia and Turkey.
INDUSTRY REFLECTION: DUAL CRISIS OF SECURITY AND TRUST
Exchange Security Vulnerability Warnings
The Nobitex incident exposed industry-wide problems including loose access controls, missing internal monitoring, and delayed responses. For instance, the exchange failed to promptly isolate hot wallets when the attack began.
By 2025, exchange hacking losses have already exceeded $2.1 billion globally. However, politically motivated attacks of this scale remain unprecedented in the industry.
Crypto Ecosystem Under Geopolitical Coercion
Collapse of Decentralization Ideals: Sovereign conflicts are dragging cryptocurrency into “weaponization” scenarios. Compliant platforms now face increasing pressure to choose political sides.
Regulatory Lag Dilemma: Countries still lack effective judicial accountability mechanisms for on-chain attacks. As Elliptic analysts admitted: “Recovering these funds would require billions of years.”
CONCLUSION: THE ERA OF CODE AS BULLETS
When $90 million transformed into political declaration ashes on the blockchain, the Nobitex incident became more than just a security vulnerability case. Instead, it marked a crucial turning point in the digitization of geopolitical conflicts.
In modern wars where missiles interweave with code, cryptocurrency’s original “censorship-resistant” vision faces systematic destruction. Meanwhile, ordinary users become the most vulnerable pawns caught in this digital smoke.
How can the industry rebuild trust? Perhaps the answer lies not merely in advanced technology, but in whether humanity can maintain the fundamental boundaries of warfare.
〈Crypto Battlefield in Geopolitical Smoke: Israeli Hackers “Burn” Nearly $100 Million in Iranian Exchange Assets〉這篇文章最早發佈於《CoinRank》。