Nearly $100 million stolen: Iranian exchange Nobitex theft incident

2025/06/20 15:00

Author: Lisa & 23pds

Editor: Sherry

background

On June 18, 2025, the on-chain detective ZachXBT revealed that Iran’s largest crypto trading platform, Nobitex, was suspected of being hacked, involving abnormal transfers of large amounts of assets across multiple public chains.

Nearly $100 million stolen: Iranian exchange Nobitex theft incident

 (https://t.me/investigations)

SlowMist further confirmed that the affected assets in the incident included TRON, EVM and BTC networks, and the initial estimated loss was approximately US$81.7 million.

Nearly $100 million stolen: Iranian exchange Nobitex theft incident

 (https://x.com/slowmist_team/status/1935246606095593578)

Nobitex also issued an announcement confirming that some infrastructure and hot wallets had indeed suffered unauthorized access, but emphasized that user funds were safe.

Nearly $100 million stolen: Iranian exchange Nobitex theft incident

 (https://x.com/nobitexmarket/status/1935244739575480472)

It is worth noting that the attacker not only transferred the funds, but also actively transferred a large amount of assets to a specially designed destruction address. The value of the assets that were "burned" was nearly 100 million US dollars.

Nearly $100 million stolen: Iranian exchange Nobitex theft incident

 (https://x.com/GonjeshkeDarand/status/1935412212320891089)

Timeline

June 18

  • ZachXBT disclosed that the Iranian crypto exchange Nobitex was suspected of being hacked, and a large number of suspicious withdrawal transactions occurred on the TRON chain. SlowMist further confirmed that the attack involved multiple chains, and the initial estimated loss was about 81.7 million US dollars.
  • Nobitex said that the technical team detected illegal access to some infrastructure and hot wallets, and immediately cut off external interfaces and launched an investigation. The vast majority of assets stored in cold wallets were not affected, and the intrusion was limited to some hot wallets used for daily liquidity.
  • The hacker group Predatory Sparrow (Gonjeshke Darande) claimed responsibility for the attack and announced that it would release Nobitex source code and internal data within 24 hours.

Nearly $100 million stolen: Iranian exchange Nobitex theft incident

 (https://x.com/GonjeshkeDarand/status/1935231018937536681)

June 19

  • Nobitex released its fourth statement, saying that the platform has completely blocked external access to the server, and that the hot wallet transfer was "active migration made by the security team to protect funds." At the same time, the official confirmed that the stolen assets were transferred to some wallets with non-standard addresses composed of arbitrary characters, which were used to destroy user assets, totaling about $100 million.
  • The hacker group Predatory Sparrow (Gonjeshke Darande) claims to have burned about $90 million worth of crypto assets, calling it a "sanctions circumvention tool."
  • The hacker group Predatory Sparrow (Gonjeshke Darande) released the Nobitex source code.

Nearly $100 million stolen: Iranian exchange Nobitex theft incident

 (https://x.com/GonjeshkeDarand/status/1935593397156270534)

Source code information

According to the source code information released by the attacker, the folder information is as follows:

Nearly $100 million stolen: Iranian exchange Nobitex theft incident

Specifically, the following contents are involved:

Nearly $100 million stolen: Iranian exchange Nobitex theft incident

The core system of Nobitex is mainly written in Python and deployed and managed using K8s. Based on the known information, we speculate that the attacker may have broken through the operation and maintenance boundary and entered the intranet, which will not be analyzed here.

MistTrack Analysis

The attacker used multiple seemingly legitimate but uncontrollable "destruction addresses" to receive assets. Most of these addresses comply with the on-chain address format verification rules and can successfully receive assets, but once the funds are transferred in, they are permanently destroyed. At the same time, these addresses also contain emotional and provocative words, which are offensive. Some of the "destruction addresses" used by the attacker are as follows:

  • TKFuckiRGCTerroristsNoBiTEXy2r7mNX
  • 0xffFFfFFffFFffFfFffFFfFfFfFFFFfFfFFFFDead
  • 1FuckiRGCTerroristsNoBiTEXXXaAovLX
  • DFuckiRGCTerroristsNoBiTEXXWLW65t
  • FuckiRGCTerroristsNoBiTEXXXXXXXXXXXXXXXXXXX
  • UQABFuckIRGCTerroristsNOBITEX11111111111111111_jT
  • one19fuckterr0rfuckterr0rfuckterr0rxn7kj7u
  • rFuckiRGCTerroristsNoBiTEXypBrmUM

We used the on-chain anti-money laundering and tracking tool MistTrack for analysis, and the incomplete statistics of Nobitex’s losses are as follows:

Nearly $100 million stolen: Iranian exchange Nobitex theft incident

According to MistTrack analysis, the attacker completed 110,641 USDT transactions and 2,889 TRX transactions on TRON:

Nearly $100 million stolen: Iranian exchange Nobitex theft incident

The EVM chains stolen by the attacker mainly include BSC, Ethereum, Arbitrum, Polygon and Avalanche. In addition to the mainstream currencies of each ecosystem, they also include UNI, LINK, SHIB and other tokens.

Nearly $100 million stolen: Iranian exchange Nobitex theft incident

On Bitcoin, the attacker stole a total of 18.4716 BTC, or about 2,086 transactions.

Nearly $100 million stolen: Iranian exchange Nobitex theft incident

On Dogechain, the attacker stole a total of 39,409,954.5439 DOGE, approximately 34,081 transactions.

Nearly $100 million stolen: Iranian exchange Nobitex theft incident

On Solana, the attacker steals SOL, WIF, and RENDER:

Nearly $100 million stolen: Iranian exchange Nobitex theft incident

On TON, Harmony, and Ripple, the attacker stole 3,374.4 TON, 35,098,851.74 ONE, and 373,852.87 XRP respectively:

Nearly $100 million stolen: Iranian exchange Nobitex theft incident

MistTrack has added the relevant addresses to the malicious address database and will continue to pay attention to related chain trends.

Conclusion

The Nobitex incident once again reminds the industry that security is a whole. Platforms need to further strengthen security protection and adopt more advanced defense mechanisms, especially for platforms that use hot wallets for daily operations. SlowMist recommends:

  • Strictly isolate the permissions and access paths of cold and hot wallets, and regularly audit the hot wallet call permissions;
  • Use on-chain real-time monitoring systems (such as MistEye) to obtain comprehensive threat intelligence and dynamic security monitoring in a timely manner;
  • Cooperate with on-chain anti-money laundering systems (such as MistTrack) to promptly detect abnormal fund flows;
  • Strengthen emergency response mechanisms to ensure effective response within the golden window after an attack occurs.
  • The incident is still under investigation, and the SlowMist security team will continue to follow up and update the progress in a timely manner.
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

XRP Sparks Heated Discussions in the Market, SIX MINING Ushers in the Era of High Returns of $8,600

XRP Sparks Heated Discussions in the Market, SIX MINING Ushers in the Era of High Returns of $8,600

At the end of July 2025, as the cryptocurrency market showed renewed strength, XRP surged, drawing fresh attention from global investors. Now in August, XRP continues to position itself as a key strategic asset for holders, maintaining strong momentum as interest in cross-border payment solutions rises. Today, investors are using SIX MINING ‘s cloud mining platform to open a lucrative path to earning $8,600 a day. Three steps to make $8,600 a day: 1. Create a SIX MINING account for free ( you can get $0.64 for free every day you log in ). 2. Browse the contracts and make payments ( the following are examples of popular contracts on the platform. Profit settlement supports XRP ). Project Amount Cycle Total revenue Iceriver KAS KS7 Lite $100 2Days $100+$7.2 Canaan’s Avalon Miner A14 $1000 10Days $1000+$133 Antminer S21 XP $3000 15Days $3000+$666 HOST ANTMINER S19 XP Hyd $5000 20Days $5000+$1540 StrongU STU-U6 $30000 35Days $30000+$18480 ANTSPACE HD54.01 $200000 50Days $200000+$204000 By activating the contract, users can obtain stable income every day and easily achieve the daily target of $8,600. As the price of XRP rises, using the platform to include XRP in settlement income provides investors with a dual source of income. 3. Earn XRP mining income Why XRP? XRP as a strategic currency: the upward trend has been established. Current market data shows that XRP prices continue to rise, and many analysts believe that its long-term target price may exceed $5. Ripple’s joining the global payment network provides XRP holders with an excellent market opportunity. Although XRP itself does not rely on traditional mining mechanisms, its value can be unlocked in new ways through the revenue contracts of cloud computing platforms. SIX MINING: An Effective Channel to Release the Potential of XRP As a new generation of digital asset mining service provider, cloud mining platform SIX MINING provides efficient, safe, environmentally friendly and convenient mining solutions to global users. Highlights of the SIX MINING platform include: Free trial period: New users can get $12 trial credit upon registration, which can be used directly for mining contract experience. Free cloud computing capacity: Users do not need to purchase hardware or bear maintenance costs. Clean energy operation: Create a low-carbon mining system to help the green crypto economy. Flexible contract options, providing contract amounts of different terms: The contract amount can be configured between $100 and $200,000. Transparent income model: Real-time dashboard monitors daily income, and mobile applications easily manage assets. Bank-level fund management, SSL encryption and DDoS protection fully guarantee the security of user assets. 24/7 customer service: The platform provides 24/7 support to answer user questions and provide technical support to improve the overall experience. Summary: XRP Value Rises – SIX MINING Helps Investors Seize Opportunities As blockchain infrastructure and mainstream finance become more integrated, the value of XRP is expected to continue to grow. Thanks to the flexible contract mechanism and transparent mining revenue mechanism of the SIX MINING cloud mining platform, users can not only quickly participate in the blockchain ecosystem but also obtain stable revenue without hardware or expertise. With proper use, your revenue will grow from $0 to $8,600. In the future, cryptocurrency will not only be an investment, but also a channel for participation and value creation. Choose XRP, use SIX MINING, and make every asset work for you. Please visit the official website for more information and start your journey to earn $8,600 a day: https://sixmining.com/
Share
CryptoNews2025/08/09 20:00
Next week's macro outlook: Fed's September rate cut expectations face ultimate judgment

Next week's macro outlook: Fed's September rate cut expectations face ultimate judgment

PANews reported on August 9th that while this week's economic data was light, some data clearly indicated slowing demand. While US labor productivity remained strong, slowing economic activity and rising
Share
PANews2025/08/09 20:29
CryptoPunks changes ownership again, with Ribbit Capital as the financial backer behind the scenes. Can it usher in new development opportunities?

CryptoPunks changes ownership again, with Ribbit Capital as the financial backer behind the scenes. Can it usher in new development opportunities?

Cryptopunks need a permanent home to pass on.
Share
PANews2025/05/14 18:14