Pro-Israel hackers take $ 81m in crypto — but it’s not about money

Which Iranian crypto exchange was hacked in June 2025?
Iran-based Crypto Exchange Nobitex suffered a hack on June 18. Pro-Israel Hacker Group Gonjeshke Darande has accounted for responsibility for the $ 81-million Crypto robbery.
Blockchain security zachxbt alert the community within the same day of attack. According to the analyst, hackers exploited a hot purse failure In the crypto exchange to access and remove the purse.
Nobitex later confirmed that $ 81 million worth of cryptocurrencies, including Bitcoin (Btc), Ether (Eth), Tron (Trx), Solana (Sol) and dogecoin (Doge), stolen. The exchange only clarified that Hot wallets is affected by attack and cold wallets remain safe.
Meanwhile, pro-Israel Hacker Group Gonjeshke Darande (Predatory Sparrow) claimed the responsibility for attacking through social media accounts.
For those who follow the current events, the hack may seem more than another crypto attack and possibly tied to the conflict in Israel-Iran. And that assumption has some merits.
But before checking the goal behind the Nobitex Crypto hack, let’s look at the long conflict between Iran and Israel.
The history of the Iran-Israel conflict
When allies, the relationship between Iran and Israel took a U-turn after the Iran revolution in 1979. Under the new Iranian government, diplomatic relations between the two countries were completely broken.
Penalties play an important role in shaping this conflict. Iran has been under penalties led by the US for decades, mainly because of its nuclear program. This led Iran to actively support countries that oppose the US and its allies, such as Palestine and Lebanon.
Over time, the two countries viewed each other as threats. Iran View Israel as a source of unethical in the region. Meanwhile, Israel sees alliances in the Iran region and nuclear ambitions as existing concerns.
But Iran and Israel were restrained from direct confrontation most of the time. It has fuel a “shadow war” conducted on killings, support for proxy groups and cyberattacks, including crypto hacks.
However, the tension rose in 2025, and a direct conflict between the two countries exploded on June 13. As the countries exchanged missiles, the war also fiery the digital front.
Inside Nobitex Crypto Hack: What exactly happened?
As a heavy country, Iran has little ways to access global finances, and cryptocurrencies are one of them. Thus, cryptocurrencies stand as an essential element of the country’s financial infrastructure.
Nobitex is the largest Crypto exchange In Iran. According to Data Through the chainalysis, the exchange received more than $ 11 billion, a number greater than the combined flow of the next 10 largest exchanges in the country.
In addition, Nobitex is aware of the military and political connections of Iran. Previous investigations Link The platform at the Islamic Revolutionary Guard Corps (IRGC), high rank of Iran officials and US rays such as Hamas and Houthis.
It made a clear target.
At any rate, the onchain examination shows that money is not the motivation behind the attack; This is politics.
Gonjeshke Darande Hacker Group used Vanity addresses for crypto exploitation. A Vanity Address refers to a that -Customize Address of the purse that includes specifically selected characters. Creating one requires proportional time and energy in the number of customized characters.
The Pro-Israel Hacker team uses two vanity addresses that contain large amounts of customized characters and brought A message:
- Tkfuckirgterroristsnobitexy2r7mnx
- 0xFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF
Elliptic announced that responding to computational demand for the creation of such addresses is not possible, even for state -level actors. This means that Gonjeshke Darande does not hold the Private keys of these addresses, and they work as Burner addresses.
The owners stolen in Nobitex Crypto hack and sent to these addresses have gone forever. ETHERSCAN AND TRON BLOCKCHAIN Records Prove that the owners are not moved, that it is clearly a political crypto hack.
The following Nobitex Hack
Nobitex responded by moving a huge amount of BTC to new cold storage wallets.
It also issued a statement to the public and provided certainty to pay off the affected users by Insurance Fund and Nobitex’s own resources.
The incident forced Iran regulators to act as well. The central bank of Iran Working time is limited of domestic crypto exchanges until between 10 am and 8pm.
After claiming responsibility, Gonjeshke Darande pledged to leak Nobitex’s source code and encouraged users to transfer funds to the platform. The Crypto Hacker Group was also requested by an exchange shutdown.
While the demand was ignored, the source code was Na -Published on social media on June 19.
Crypto conflicts activated by Iran and Israel
Nobitex Crypto Hack is the latest incident in Iran and Israeli Crypto War. The Digital Shadow War has been on for years.
Since May 2021, the Israel National Bureau for Counter Terror Financing (NBCTF) has been Pag -segag Cryptocurrency from the accounts of proxy groups linked to Iran, such as Hamas. Around 190 accounts in Binance were frozen.
The NBCTF conducted assets Flree in 2023 also, freezing $ 1.7 million Crypto costs. These owners are linked to the Iranian military’s Quds Force and another proxy group, Hezbollah.
Both countries also use cryptocurrency as a tool to fund spies. In May 2025, Iran killed An individual who has been found guilty of detective for mossad. The individual has been reported to have received crypto payments, including BTC.
One month later, Israel’s authorities Arrested Three individual suspected detectives for Iran. Investigations revealed that at least two of these individuals were paid to crypto.
When crypto hacking becomes a war in cyber
Crypto hacks are often assumed to be financial financial. While that is the case with many individual incidents, state -related actors may conduct crypto hacks for political reasons as well.
The state sponsored by the state of North Korea Lazarus Group is a well -known example. The group has been linked to many high-profile crypto thefts, with funds reported used to supply the country’s weapons programs.
Lazaro is Related to $ 625-million Ronin Bridge Hack That happened in March 2022. The stolen funds were laundered by coin mixers to avoid penalties.
The group hacked another Blockchain bridge For the same year, Harmony’s Horizon Bridge. The total amount of stolen cryptocurrencies is around $ 100 million.
Lazarus is also behind The bybit hack That occurred in February 2025. The group went away with cryptocurrencies worth about $ 1.5 billion. Bybit Hack stands as the largest crypto hack until July 2025.
Crypto has become a war tactic In the ongoing conflict with Ukraine-Russia. In 2022, pro-Russian hackers used Mars stealer malware to target crypto wallets in Ukraine and Eastern Europe. These attacks were launched in the early stages of the war in Ukraine and aim to disrupt access to digital funds.