The pro-Israel hacking group “Predatory Sparrow” has executed a devastating cyberattack against Nobitex, Iran’s largest cryptocurrency exchange, stealing over $90 million in digital assets before deliberately destroying them in a politically motivated operation.
## The Attack Details
On June 18, 2025, hackers breached Nobitex’s security systems, prompting the exchange to report unauthorized access to their infrastructure and hot wallet at 2:24 AM EST the following day. The company immediately suspended all access and launched an internal investigation, while their website remained offline.
Predatory Sparrow quickly claimed responsibility through their social media account, threatening to release the company’s source code and internal data within 24 hours. The group positioned the attack as retaliation against what they described as Iran’s use of the exchange to finance terrorism and violate international sanctions.
## Crypto Burned, Not Stolen
In an unprecedented move, blockchain analysis firm Elliptic confirmed that the hackers didn’t keep the stolen cryptocurrency for profit. Instead, they transferred nearly all $90 million to specially created “vanity addresses” containing anti-Iranian Revolutionary Guard Corps (IRGC) messages like “F*ckIRGCterrorists.”
These vanity addresses are computationally impossible to access, meaning the hackers intentionally destroyed the funds rather than profiting from them. Creating such addresses requires enormous computational power, making recovery of the cryptocurrency impossible.
## Political Motivations
Elliptic’s investigation revealed connections between Nobitex and Iranian leadership, including ties to Supreme Leader Ali Khamenei’s relatives and IRGC-affiliated businesses. The exchange allegedly facilitated money movement from ransomware operations and helped sanctioned individuals circumvent international restrictions.
This attack followed Predatory Sparrow’s breach of Iran-controlled Bank Sepah just one day earlier, demonstrating a pattern of disruptive rather than financially motivated cyberattacks.
## Broader Context
These incidents occur as Iran increasingly isolates its internet infrastructure to protect against escalating cyberattacks. The attacks represent a new form of cyber warfare where hackers prioritize political disruption over financial gain, using cryptocurrency destruction as a weapon against state-sponsored activities.
The Nobitex breach highlights the growing intersection of cybersecurity, cryptocurrency, and geopolitical tensions in the digital age.
