Skip to content
← Back to newsNobitex Restores Services After $90 Million Cyberattack
Security

Nobitex Restores Services After $90 Million Cyberattack

By ToTo BugelmanNewcomer0 rep· 6/30/2025

Iranian crypto exchange Nobitex is gradually resuming operations after a significant $90 million exploit earlier in June, allegedly orchestrated by a pro-Israel group. The incident led to the destruction of stolen funds and the leak of the platform's source code, prompting a migration of user wallets.

 

Key Takeaways

  • Nobitex is slowly restoring services, initially for verified users only.

  • Withdrawal, deposit, and trading functionalities remain disabled but are expected to resume on June 30, subject to change.

  • The attack, claimed by Gonjeshke Darande, involved the destruction of stolen funds and the release of source code.

  • Nobitex has migrated user wallets, rendering deposits to old addresses invalid.

  • The exchange's CEO, Amir Rad, attributes the attack to the Israeli government, denying any state affiliation.

 

Nobitex Recovers After $90 Million Cyberattack

Nobitex, Iran's largest cryptocurrency exchange, has begun the process of restoring services following a substantial $90 million cyberattack. The breach, which occurred in early June, was claimed by a pro-Israel hacker group named Gonjeshke Darande. The group not only allegedly stole funds but also reportedly destroyed them and released portions of Nobitex's source code, compounding the damage.

 

Service Restoration and User Impact

Nobitex is progressively reopening its platform, starting with verified users. However, core functionalities such as withdrawals, deposits, and trading are still suspended. The exchange had previously indicated a target date of Monday, June 30, for the resumption of withdrawals, though this timeline is subject to revision. As a direct consequence of the security compromise, Nobitex has migrated all user wallets, meaning any deposits made to previous wallet addresses will no longer be valid.

 

Allegations and Geopolitical Context

The pro-Israel hacker group Gonjeshke Darande asserted responsibility for the attack, claiming to have destroyed the stolen funds and published parts of Nobitex's source code. TRM Labs, a blockchain intelligence firm, has speculated that information obtained from Nobitex might have been used by Israel to apprehend Iranian agents who received payments in cryptocurrency. Nobitex's CEO, Amir Rad, has publicly stated that the exchange's internal investigation points to the Israeli government's involvement in the breach. Rad emphasized that Nobitex is a private entity with no ties to the Iranian state or its military.

 

Nobitex's Market Dominance and Illicit Connections

Nobitex significantly outweighs other Iranian crypto exchanges in terms of activity, boasting $11 billion in total inflows compared to less than $7.5 billion for the next ten largest exchanges combined, according to Chainalysis. The research firm has also linked Nobitex to various illicit actors, including ransomware operators affiliated with the IRGC and sanctioned Russian crypto exchanges. The use of cryptocurrency in Iran, much like in Russia, is frequently associated with efforts to circumvent international monetary sanctions.

Sources

 

This article was created with support from AI-driven technology, drawing on multiple reputable sources. The final content has been thoroughly reviewed and edited by BlockzHub's editorial team to ensure accuracy, clarity, and coherence. Original reporting sources are credited whenever appropriate and as required. The opinions expressed in this article do not necessarily represent the official views or positions of BlockzHub. This article is intended for informational purposes only and should not be considered financial or professional advice. Investing involves risk, and you should consult a qualified financial advisor before making any investment decisions.

 

Discussion (0)

Sign in to join the discussion.

No comments yet. Be the first.