After breaching Iran’s largest crypto exchange, the pro-Israel hacker group Gonjeshke Darande claimed to have destroyed more than $90 million in digital assets taken from Nobitex’s wallets.
In a June 18 update via X, the group said it had burned the funds across multiple blockchains using “vanity addresses” that contain no recoverable private keys, effectively rendering the assets permanently inaccessible.
This follows the high-profile exploit of Nobitex, in which over $90 million in Bitcoin $BTC $ETH $DOGE and other tokens were drained from hot wallets. The attackers had originally framed the breach as a direct response to Nobitex’s alleged role in helping the Iranian regime circumvent sanctions and fund terrorism.
The group, also known as Predatory Sparrow, tied the hack to ongoing military and cyber tensions between Iran and Israel, which intensified following Israeli airstrikes on Tehran’s nuclear sites days earlier. Blockchain security platforms like Chainalysis quickly confirmed that the stolen assets had not been transferred to mixers or exchanges, but rather to irretrievable addresses with inflammatory labels.
The attackers have also threatened to release the source code and internal infrastructure data of Nobitex, which could worsen the situation for Iran’s leading cryptocurrency platform, which has over 11 million users. Gonjeshke Darande warned that any assets left on the platform would be at risk if users did not withdraw immediately.
Despite having no financial motivation, the hack has far-reaching implications. The intentional destruction of more than $90 million worth of digital currency demonstrates how state-level conflicts have turned crypto infrastructure into a new battlefield.