Nearly $100 million stolen: Iranian exchange Nobitex theft incident

2025/06/20 15:00

Author: Lisa & 23pds

Editor: Sherry

background

On June 18, 2025, the on-chain detective ZachXBT revealed that Iran’s largest crypto trading platform, Nobitex, was suspected of being hacked, involving abnormal transfers of large amounts of assets across multiple public chains.

Nearly $100 million stolen: Iranian exchange Nobitex theft incident

 (https://t.me/investigations)

SlowMist further confirmed that the affected assets in the incident included TRON, EVM and BTC networks, and the initial estimated loss was approximately US$81.7 million.

Nearly $100 million stolen: Iranian exchange Nobitex theft incident

 (https://x.com/slowmist_team/status/1935246606095593578)

Nobitex also issued an announcement confirming that some infrastructure and hot wallets had indeed suffered unauthorized access, but emphasized that user funds were safe.

Nearly $100 million stolen: Iranian exchange Nobitex theft incident

 (https://x.com/nobitexmarket/status/1935244739575480472)

It is worth noting that the attacker not only transferred the funds, but also actively transferred a large amount of assets to a specially designed destruction address. The value of the assets that were "burned" was nearly 100 million US dollars.

Nearly $100 million stolen: Iranian exchange Nobitex theft incident

 (https://x.com/GonjeshkeDarand/status/1935412212320891089)

Timeline

June 18

  • ZachXBT disclosed that the Iranian crypto exchange Nobitex was suspected of being hacked, and a large number of suspicious withdrawal transactions occurred on the TRON chain. SlowMist further confirmed that the attack involved multiple chains, and the initial estimated loss was about 81.7 million US dollars.
  • Nobitex said that the technical team detected illegal access to some infrastructure and hot wallets, and immediately cut off external interfaces and launched an investigation. The vast majority of assets stored in cold wallets were not affected, and the intrusion was limited to some hot wallets used for daily liquidity.
  • The hacker group Predatory Sparrow (Gonjeshke Darande) claimed responsibility for the attack and announced that it would release Nobitex source code and internal data within 24 hours.

Nearly $100 million stolen: Iranian exchange Nobitex theft incident

 (https://x.com/GonjeshkeDarand/status/1935231018937536681)

June 19

  • Nobitex released its fourth statement, saying that the platform has completely blocked external access to the server, and that the hot wallet transfer was "active migration made by the security team to protect funds." At the same time, the official confirmed that the stolen assets were transferred to some wallets with non-standard addresses composed of arbitrary characters, which were used to destroy user assets, totaling about $100 million.
  • The hacker group Predatory Sparrow (Gonjeshke Darande) claims to have burned about $90 million worth of crypto assets, calling it a "sanctions circumvention tool."
  • The hacker group Predatory Sparrow (Gonjeshke Darande) released the Nobitex source code.

Nearly $100 million stolen: Iranian exchange Nobitex theft incident

 (https://x.com/GonjeshkeDarand/status/1935593397156270534)

Source code information

According to the source code information released by the attacker, the folder information is as follows:

Nearly $100 million stolen: Iranian exchange Nobitex theft incident

Specifically, the following contents are involved:

Nearly $100 million stolen: Iranian exchange Nobitex theft incident

The core system of Nobitex is mainly written in Python and deployed and managed using K8s. Based on the known information, we speculate that the attacker may have broken through the operation and maintenance boundary and entered the intranet, which will not be analyzed here.

MistTrack Analysis

The attacker used multiple seemingly legitimate but uncontrollable "destruction addresses" to receive assets. Most of these addresses comply with the on-chain address format verification rules and can successfully receive assets, but once the funds are transferred in, they are permanently destroyed. At the same time, these addresses also contain emotional and provocative words, which are offensive. Some of the "destruction addresses" used by the attacker are as follows:

  • TKFuckiRGCTerroristsNoBiTEXy2r7mNX
  • 0xffFFfFFffFFffFfFffFFfFfFfFFFFfFfFFFFDead
  • 1FuckiRGCTerroristsNoBiTEXXXaAovLX
  • DFuckiRGCTerroristsNoBiTEXXWLW65t
  • FuckiRGCTerroristsNoBiTEXXXXXXXXXXXXXXXXXXX
  • UQABFuckIRGCTerroristsNOBITEX11111111111111111_jT
  • one19fuckterr0rfuckterr0rfuckterr0rxn7kj7u
  • rFuckiRGCTerroristsNoBiTEXypBrmUM

We used the on-chain anti-money laundering and tracking tool MistTrack for analysis, and the incomplete statistics of Nobitex’s losses are as follows:

Nearly $100 million stolen: Iranian exchange Nobitex theft incident

According to MistTrack analysis, the attacker completed 110,641 USDT transactions and 2,889 TRX transactions on TRON:

Nearly $100 million stolen: Iranian exchange Nobitex theft incident

The EVM chains stolen by the attacker mainly include BSC, Ethereum, Arbitrum, Polygon and Avalanche. In addition to the mainstream currencies of each ecosystem, they also include UNI, LINK, SHIB and other tokens.

Nearly $100 million stolen: Iranian exchange Nobitex theft incident

On Bitcoin, the attacker stole a total of 18.4716 BTC, or about 2,086 transactions.

Nearly $100 million stolen: Iranian exchange Nobitex theft incident

On Dogechain, the attacker stole a total of 39,409,954.5439 DOGE, approximately 34,081 transactions.

Nearly $100 million stolen: Iranian exchange Nobitex theft incident

On Solana, the attacker steals SOL, WIF, and RENDER:

Nearly $100 million stolen: Iranian exchange Nobitex theft incident

On TON, Harmony, and Ripple, the attacker stole 3,374.4 TON, 35,098,851.74 ONE, and 373,852.87 XRP respectively:

Nearly $100 million stolen: Iranian exchange Nobitex theft incident

MistTrack has added the relevant addresses to the malicious address database and will continue to pay attention to related chain trends.

Conclusion

The Nobitex incident once again reminds the industry that security is a whole. Platforms need to further strengthen security protection and adopt more advanced defense mechanisms, especially for platforms that use hot wallets for daily operations. SlowMist recommends:

  • Strictly isolate the permissions and access paths of cold and hot wallets, and regularly audit the hot wallet call permissions;
  • Use on-chain real-time monitoring systems (such as MistEye) to obtain comprehensive threat intelligence and dynamic security monitoring in a timely manner;
  • Cooperate with on-chain anti-money laundering systems (such as MistTrack) to promptly detect abnormal fund flows;
  • Strengthen emergency response mechanisms to ensure effective response within the golden window after an attack occurs.
  • The incident is still under investigation, and the SlowMist security team will continue to follow up and update the progress in a timely manner.
سلب مسئولیت: مقالات بازنشر شده در این سایت از پلتفرم‌ های عمومی جمع‌ آوری شده‌ اند و صرفاً برای اهداف اطلاع‌ رسانی ارائه می‌ شوند. این مطالب لزوماً بیانگر دیدگاه‌ های MEXC نیستند. کلیه حقوق متعلق به نویسندگان اصلی محتوا است. اگر معتقدید که محتوایی حقوق اشخاص ثالث را نقض می‌ کند، لطفاً برای حذف آن با آدرس ایمیل service@support.mexc.com تماس بگیرید. MEXC هیچگونه تضمینی در مورد دقت، کامل بودن یا به‌ روز بودن محتوای ارائه‌ شده نمی‌ دهد و مسئولیتی در قبال هرگونه اقدام بر اساس این اطلاعات ندارد. این محتوا مشاوره مالی، حقوقی یا حرفه‌ ای محسوب نمی‌ شود و نباید آن را به‌ عنوان توصیه یا تأیید از سوی MEXC تلقی کرد.
اشتراک گذاری مقاله

محتوای پیشنهادی

Kan dit technisch patroon de Dogecoin koers richting $0,31 brengen?

Kan dit technisch patroon de Dogecoin koers richting $0,31 brengen?

Connect met Like-minded Crypto Enthusiasts! Connect op Discord! Check onze Discord   Dogecoin is de afgelopen dagen rustig omhoog bewogen en staat dicht bij een belangrijk punt op de grafiek. Het gaat om een patroon dat technische analisten een symmetrische driehoek noemen. Hierbij worden de toppen steeds iets lager en de bodems juist iets hoger. Kan de Dogecoin koers hierdoor binnenkort verder oplopen? Wat zegt dit symmetrische patroon over de Dogecoin koers? De Dogecoin koers beweegt al weken binnen deze driehoek. De ruimte tussen steun en weerstand wordt steeds kleiner. Dit wijst op afnemend handelsvolume en een markt die wacht tot kopers of verkopers de overhand krijgen. Een symmetrische driehoek ontstaat vaak in perioden van consolidatie. In zo’n fase wisselen bulls en bears elkaar af zonder dat één van de twee de volledige controle heeft. Het patroon eindigt vrijwel altijd met een uitbraak omhoog of omlaag. Het moment waarop dat gebeurt komt dichterbij, omdat de driehoek steeds nauwer wordt. Volgens data analyses kan het verschil tussen de boven- en onderkant van dit patroon worden gebruikt om het mogelijke koersdoel na een uitbraak te berekenen. In dit geval wijst de projectie op een beweging van ongeveer 30% zodra de koers door de driehoek heen breekt. Dogecoin $DOGE is getting ready for a 30% price move! pic.twitter.com/3bcNzfg2yC — Ali (@ali_charts) August 23, 2025 Welke crypto nu kopen?Lees onze uitgebreide gids en leer welke crypto nu kopen verstandig kan zijn! Welke crypto nu kopen? Bitcoin beweegt rond de ATH en blijft voor veel beleggers een van de meest aantrekkelijke crypto’s, met relatief laag risico en een bewezen trackrecord. Recente uitspraken van Fed-voorzitter Jerome Powell, die Bitcoin “digitaal goud” noemde, versterkten het vertrouwen. Tegelijkertijd zorgden macro-economische ontwikkelingen en een sterke altcoin rally voor extra beweging op… Continue reading Kan dit technisch patroon de Dogecoin koers richting $0,31 brengen? document.addEventListener('DOMContentLoaded', function() { var screenWidth = window.innerWidth; var excerpts = document.querySelectorAll('.lees-ook-description'); excerpts.forEach(function(description) { var excerpt = description.getAttribute('data-description'); var wordLimit = screenWidth wordLimit) { var trimmedDescription = excerpt.split(' ').slice(0, wordLimit).join(' ') + '...'; description.textContent = trimmedDescription; } }); }); Belangrijke niveaus voor Dogecoin Voor traders zijn er duidelijke koersniveaus die in de gaten worden gehouden. De eerste ligt rond $0,25. Dit niveau fungeert als weerstand. Als de Dogecoin koers daarboven komt met stevig volume, dan kan de weg open liggen richting $0,31 tot $0,32. Dat zijn de niveaus die volgen uit de hoogte van de driehoek toegepast op het moment van de uitbraak. Aan de andere kant is er ook een steunpunt zichtbaar rond $0,22. Wanneer de koers daaronder zakt, neemt de kans toe dat Dogecoin terugvalt richting de regio van $0,19 tot $0,20. Deze zone fungeerde in eerdere handelsweken vaker als vangnet voor kopers. De prijsontwikkeling laat dus zien dat de munt zich in een beslissende fase bevindt. Welke richting de koers kiest, hangt af van het vermogen om één van deze niveaus overtuigend te doorbreken. Historische patronen van de DOGE koers De huidige situatie van Dogecoin lijkt op eerdere fases waarin de munt langere tijd in een driehoek bewoog. Ook toen volgden scherpe bewegingen zodra de koers de formatie doorbrak. In 2021 en 2023 waren er vergelijkbare patronen zichtbaar. Beide keren resulteerde dat in sterke rallies, maar ook in forse correcties toen het momentum afzwakte. Dat maakt duidelijk dat symmetrische driehoeken krachtige indicatoren kunnen zijn. Toch blijft de richting altijd afhankelijk van de daadwerkelijke uitbraak. De volatiliteit die erop volgt is vaak groot, omdat veel traders hun posities aanpassen zodra de koers de formatie verlaat. Het gebied rond $0,25 vormt dus de sleutel voor een mogelijk vervolg omhoog richting $0,31 tot $0,32. Zakt de koers juist onder $0,22, dan komt de regio rond $0,19 weer in beeld. Met het huidige patroon en de afnemende volumes is de kans groot dat deze beslissing binnenkort valt. Koop je crypto via Best Wallet Best wallet is een topklasse crypto wallet waarmee je anoniem crypto kan kopen. Met meer dan 60 chains gesupport kan je al je main crypto coins aanschaffen via Best Wallet. Best wallet - betrouwbare en anonieme wallet Best wallet - betrouwbare en anonieme wallet Meer dan 60 chains beschikbaar voor alle crypto Vroege toegang tot nieuwe projecten Hoge staking belongingen Lage transactiekosten Best wallet review Koop nu via Best Wallet Let op: cryptocurrency is een zeer volatiele en ongereguleerde investering. Doe je eigen onderzoek. Het bericht Kan dit technisch patroon de Dogecoin koers richting $0,31 brengen? is geschreven door Dirk van Haaster en verscheen als eerst op Bitcoinmagazine.nl.
اشتراک
Coinstats2025/08/25 05:16
اشتراک
ALL4 Mining: Best Free Bitcoin (BTC) Dogecoin (DOGE) Cloud Mining Platform Regulated in the UK

ALL4 Mining: Best Free Bitcoin (BTC) Dogecoin (DOGE) Cloud Mining Platform Regulated in the UK

ALL4 Mining, a UK-regulated free cloud mining platform offering mining services for Bitcoin, Ripple, Dogecoin and many more, is pleased to announce the launch of its new mobile app. This timely launch enables users to access and manage their cloud mining investments anytime, anywhere, further democratizing cryptocurrency mining. Key highlights of the mobile app launch: Seamless mobile mining: The new mobile app provides a user-friendly interface to easily monitor mining contracts, track daily earnings, and manage investments. Enhanced security: Built with top-tier security measures from McAfee® and Cloudflare®, the app ensures your digital assets are protected wherever you are. Instant rewards: New users who sign up through the app receive an instant $15 sign-up bonus and can earn $0.6 per day just for logging in. Diverse contract options: From one-day contracts starting at $15 to long-term investments, users can choose from a variety of mining plans to suit different budgets and goals. Convenient settlement: The platform accepts more than 10 cryptocurrencies (such as DOGE, BTC, ETH, LTC, USDC, USDT, BNB, BCH, SOL, XRP) for settlement 24/7 reliability: With 100% uptime and 24/7 technical support, the mobile app guarantees you uninterrupted access to mining operations. About ALL4 Mining ALL4 Mining is a fast-growing digital asset mining service provider and a global leader in cloud mining services. The company was founded in 2019 and is headquartered in London, UK. After years of development, the company currently has more than 200 mining farms around the world, members in more than 200 countries and regions, and enjoys the trust of more than 9 million users worldwide. We believe that everyone should benefit from cloud mining and become a leader in the cloud mining industry. ALL4 Mining is committed to building a safe, compliant, transparent, clean, green, low-carbon, and environmentally friendly infrastructure power grid, providing a variety of stable and intelligent data processing service solutions for global customers. With a growing global mining network, ALL4 Mining provides institutional clients and digital asset enthusiasts with a more efficient mining experience. “The cryptocurrency market is expected to grow rapidly – ​​experts predict that by 2026, Bitcoin will reach $150,000, Litecoin will reach $1,000, Dogecoin will break the $1 mark, and XRP will soar to $10 – so the launch of our mobile app is timely,” said an ALL4 Mining spokesperson. “We are committed to making cloud mining convenient and secure, and our mobile solution will be a game-changer for users who seek flexibility and efficiency.” Simple steps to start cloud mining with ALL4 Mining Step 1: Choose ALL4 Mining as your provider: ALL4 Mining’s mining method is simple and straightforward, and users only need a minimum deposit to start mining. The platform ensures that everyone can participate by providing daily returns on mining contracts and flexible withdrawal methods. Step 2: Register an account: Visit the ALL4 Mining official website all4mining.com , create an account using your email address, log in to access the dashboard and start mining immediately. Step 3: Purchase a mining contract: ALL4 Mining offers a variety of contract options to suit different budgets and goals. Users can choose from the following options: BTC basic computing power: investment amount: $100, contract period: 2 days, daily income of $4.0, expiration income: $100 + $8 LTC [classic computing power contract]: investment amount: $600, contract period: 6 days, daily income of $7.26, expiration income: $600 + $43.56 BTC [classic computing power contract]: investment amount: $3,000, contract period: 20 days, daily income of $42.9, expiration income: $3,000 + $858 DOGE [classic computing power contract]: investment amount: $5,000, contract period: 30 days, daily income of $75, expiration income: $5,000 + $2,250 BTC [advanced computing power contract]: investment amount: $10,000, contract period: 40 days, daily income of $166, expiration income: $10,000 + $6,640 BTC [advanced computing power contract]: investment amount: 50,000 USD, contract period: 48 days, daily income: USD 910, maturity income: USD 50,000 + USD 43,680 BTC [Super Computing Power Contract]: Investment amount: USD 150,000, contract period: 50 days, daily income: USD 2,925, maturity income: USD 150,000 + USD 146,250 After purchasing the contract, the profit will be automatically credited to your account the next day. When the account balance reaches $100, you can choose to withdraw to your digital currency wallet, or continue to purchase contracts to get more profits. Get Started Now Join the cloud mining revolution by visiting the official website https://all4mining.com/ or downloading the ALL4 Mining mobile app today . With this new mobile app, managing your cryptocurrency investments will become easier and safer than ever before. Contact: Email: info@all4mining.com Website: all4mining.com Disclaimer: The information provided in this press release is not a solicitation for investment, nor is it intended as investment advice, financial advice, or trading advice. It is strongly recommended you practice due diligence, including consultation with a professional financial advisor, before investing in or trading cryptocurrency and securities.
اشتراک
CryptoNews2025/06/21 00:40
اشتراک