HomeSecurityPredatory Sparrow "hits" Iranian Nobitex - Crypto theft

Predatory Sparrow “hit” Iranian Nobitex – Crypto theft

One of the most high-profile cyberattacks of 2025 occurred on June 18, when the pro-Israel hacking group Predatory Sparrow claimed to have breached Iran’s largest cryptocurrency exchange , Nobitex , stealing over $90 million in digital assets. According to the group, the stolen crypto was burned in a show of political protest .

Predatory Sparrow Nobitex crypto

Nobitex confirmed the breach through a post on the X (formerly Twitter), emphasizing that unauthorized access was detected to parts of the company's infrastructure and hot wallet .

"Immediately after detection, all access was suspended and internal security teams are closely investigating the extent of the incident," the company added.

See also: The most common phishing scams for crypto users – How to recognize them

A few hours later, Predatory Sparrow claimed responsibility, warning that it intends to publish Nobitex's source code and sensitive internal data, which it obtained during the attack. The company's website remains down.

In a message to X, the hacking group stated: “After the IRGC’s ‘Bank Sepah’, it’s Nobitex’s turn. WARNING! In 24 hours, we will publish Nobitex’s source code and internal information from their internal network. Any assets left there after this point will be compromised..”.

«The Nobitex exchange is at the center of the regime’s efforts to finance terrorism worldwide, while also being the regime’s favorite tool for violating sanctions. We, “Gonjeshke Darande”, have carried out cyberattacks against Nobitex».

The extent of the financial damage confirmed by blockchain analysis firm Elliptic, according to which more than $90 million in cryptocurrencies were removed from Nobitex wallets and channeled to addresses controlled by the attackers.

See also: Crypto investment scams: 5 people guilty of money laundering

The hackers didn't keep the stolen crypto - they "burned" it

Despite the high value of the cryptocurrencies, the Predatory Sparrow group appears to have had no financial motive . Instead of attempting to monetize or transfer the stolen digital assets, the hackers sent them to vanity addresses — embedded with anti-Islamic Republic of Iran Guard Corps (IRGC) messages, such as “F*ckIRGCterrorists.”

According to Elliptic, these types of addresses require enormous computing power to generate with active private keys. The technique relies on brute force methods, which generate cryptographic key pairs in bulk until the desired message appears. However, Elliptic emphasizes that generating such extensive alphanumeric sequences, such as those used in the attack, is practically impossible, which means that the funds are permanently lost. It is clear that these addresses were created so that the assets were inaccessible — in essence, the cryptocurrencies were 'burned'.

Predatory Sparrow "hit" Iranian Nobitex - Crypto theft

Elliptic also claims that there are indications of Nobitex’s connection to the IRGC and circles close to the Iranian government. Previous investigations have also linked the exchange to relatives of Supreme Leader Ali Khamenei, businesses controlled by the IRGC, and individuals under international sanctions. In fact, there are suspicions that Nobitex has been used to transfer money related to ransomware attacks.

The Nobitex attack came just a day after the breach of Bank Sepah, another Iranian entity. In both cases, Predatory Sparrow was not financial gain, but to reputation and digital infrastructure Iran's.

See also: Paddle to pay $5 million for facilitating fraud

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

These attacks come at a time when Iran is trying to technologically isolate itself from the rest of the world, limiting access to the international Internet — an effort to reduce its exposure to cyberattacks that threaten its critical infrastructure.

The Predatory Sparrow are a prime example of how cybersecurity has evolved into a geopolitical battleground.

The fact that the hackers did not gain any financial benefit, but instead burned Nobitex's cryptocurrencies , in an irreversible manner, sends a clear message: "We do not care about your money. We aim to expose you and hurt you politically."

This differentiates Predatory Sparrow from typical cybercrime groups and brings it closer to hacktivist groups.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS