Iran curtails crypto exchange hours following $90M hack
While the crypto markets have not been immune to geopolitical developments, the sector in Iran experienced a more direct effect last week with a politically motivated $90 million exchange hack, prompting the authorities to introduce an exchange curfew.
Blockchain analytics firm Chainalysis outlined on X on June 18 that Nobitex, Iran’s largest cryptocurrency exchange, had been hacked, with crypto assets to the value of $90 million having been drained from exchange-controlled wallets.

Weaponizing blockchain technology
The hack had the hallmark of a politically-motivated attack given that rather than the digital assets being stolen, they were sent to vanity addresses, customized blockchain addresses involving user-defined sequences of characters. The vanity addresses contained “politically charged messages” and in sending the funds to them, the funds were effectively burned as they’re now permanently inaccessible.
The firm stated:
”This incident highlights how crypto exploits aren’t always financially motivated. Bad actors can weaponize blockchain technology for geopolitical messaging, turning hacks into ideological statements rather than profit-driven crimes.”
Pro-Israel hacker group Gonjeshke Darande, also known as “Predatory Sparrow,” appears to have carried out the hack, given that on June 18, it outlined on X that it would release Nobitex’s source code together with other internal information related to the firm’s internal network, while confirming that it had conducted cyberattacks against the company. The group made the following assertion:
”The Nobitex exchange is at the heart of the [Iranian] regime’s efforts to finance terror worldwide, as well as being the regime’s favorite sanctions violation tool.”
Rafe Pilling, director of threat intelligence at Sophos, a British cybersecurity company, told The Guardian that Predatory Sparrow “bears all the hallmarks of a false persona used by a government-sponsored threat group to conduct disruptive operations against targets” linked to the Iranian government.
While Nobitex is estimated to have seven million users, an Open Source Intelligence (OSINT)-based investigation carried out in 2024 linked relatives of Ali Khamenei, Iran’s supreme leader, and other Iranian establishment figures to the crypto exchange.
Minimizing systemic risk
The cyber attack has prompted a response from the Iranian government. In a blog post, Chainalysis outlined that the Central Bank of Iran has instructed all domestic crypto exchange platforms to curtail their service hours to between 10 a.m. and 8 p.m.
The company speculated that this measure could be motivated by a desire to impose a higher level of oversight and control over the local crypto sector. However, it also suggested that it may be part of an attempt by the Iranian authorities to manage and minimize systemic risk.
In recent years, Iran has been subject to extensive international sanctions applied by various entities including the United States, the European Union and the United Nations. Those sanctions have had a significant impact upon the country’s economy, triggering high inflation and currency devaluation.
With that, crypto has been increasingly viewed by the authorities as a means to circumvent sanctions. Last December, the Iranian authorities appeared to be working towards regulating crypto, embracing the asset class in acknowledgement of its growing importance to the Iranian economy.
In February, Chainalysis reported that sanctioned entities worldwide had received $15.8 billion in crypto transactions in 2024.


