One of the most high-profile cyberattacks of 2025 occurred on June 18, when the pro-Israel hacking group Predatory Sparrow claimed to have breached Iran’s largest cryptocurrency exchange , Nobitex , stealing over $90 million in digital assets. According to the group, the stolen crypto was burned in a show of political protest .

Nobitex confirmed the breach through a post on the X (formerly Twitter), emphasizing that unauthorized access was detected to parts of the company's infrastructure and hot wallet .
"Immediately after detection, all access was suspended and internal security teams are closely investigating the extent of the incident," the company added.
See also: The most common phishing scams for crypto users – How to recognize them
A few hours later, Predatory Sparrow claimed responsibility, warning that it intends to publish Nobitex's source code and sensitive internal data, which it obtained during the attack. The company's website remains down.
In a message to X, the hacking group stated: “After the IRGC’s ‘Bank Sepah’, it’s Nobitex’s turn. WARNING! In 24 hours, we will publish Nobitex’s source code and internal information from their internal network. Any assets left there after this point will be compromised..”.
«The Nobitex exchange is at the center of the regime’s efforts to finance terrorism worldwide, while also being the regime’s favorite tool for violating sanctions. We, “Gonjeshke Darande”, have carried out cyberattacks against Nobitex».
The extent of the financial damage confirmed by blockchain analysis firm Elliptic, according to which more than $90 million in cryptocurrencies were removed from Nobitex wallets and channeled to addresses controlled by the attackers.
See also: Crypto investment scams: 5 people guilty of money laundering
The hackers didn't keep the stolen crypto - they "burned" it
Despite the high value of the cryptocurrencies, the Predatory Sparrow group appears to have had no financial motive . Instead of attempting to monetize or transfer the stolen digital assets, the hackers sent them to vanity addresses — embedded with anti-Islamic Republic of Iran Guard Corps (IRGC) messages, such as “F*ckIRGCterrorists.”
According to Elliptic, these types of addresses require enormous computing power to generate with active private keys. The technique relies on brute force methods, which generate cryptographic key pairs in bulk until the desired message appears. However, Elliptic emphasizes that generating such extensive alphanumeric sequences, such as those used in the attack, is practically impossible, which means that the funds are permanently lost. It is clear that these addresses were created so that the assets were inaccessible — in essence, the cryptocurrencies were 'burned'.

Elliptic also claims that there are indications of Nobitex’s connection to the IRGC and circles close to the Iranian government. Previous investigations have also linked the exchange to relatives of Supreme Leader Ali Khamenei, businesses controlled by the IRGC, and individuals under international sanctions. In fact, there are suspicions that Nobitex has been used to transfer money related to ransomware attacks.
The Nobitex attack came just a day after the breach of Bank Sepah, another Iranian entity. In both cases, Predatory Sparrow was not financial gain, but to reputation and digital infrastructure Iran's.
See also: Paddle to pay $5 million for facilitating fraud
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
These attacks come at a time when Iran is trying to technologically isolate itself from the rest of the world, limiting access to the international Internet — an effort to reduce its exposure to cyberattacks that threaten its critical infrastructure.
The Predatory Sparrow are a prime example of how cybersecurity has evolved into a geopolitical battleground.
The fact that the hackers did not gain any financial benefit, but instead burned Nobitex's cryptocurrencies , in an irreversible manner, sends a clear message: "We do not care about your money. We aim to expose you and hurt you politically."
This differentiates Predatory Sparrow from typical cybercrime groups and brings it closer to hacktivist groups.
Source: www.bleepingcomputer.com
