Skip to main content
AVOID.NET
← Nobitex June 2025 Hack (Predatory Sparrow)reviewed 2026-09-06 · 26 claims checked

Fact-check findings

What an automated fact-checker found when it re-read Nobitex June 2025 Hack (Predatory Sparrow) against the sources the page cites. Only the most recent review is shown.

Read this first

These findings are produced by an automated reviewer, and its results vary between runs: the same page, checked three times on the same day, came back with 15%, 20% and 34% of its claims disputed, mostly because each run extracted a different number of claims. Treat what follows as leads, not rulings.

“Disputed” means the reviewer could not reconcile the claim with the evidence it cited. It does not mean the claim is false. “Unverifiable” means no reachable source settled it either way.

Nothing here changes the page on its own. A proposed correction is applied only after a human moderator approves it; until then the page reads as it did when reviewed.

disputed

2 claims

The reviewer could not reconcile the claim with the evidence it cited. This is a lead, not a ruling that the claim is false.

  1. #7[disputed][awaiting moderator]in section: Fund Destruction via Vanity Addresses
    “'DFuckiRGCTerroristsNoBiTEXXXWLW65t' on an EVM chain”
    reviewer'DFuckiRGCTerroristsNoBiTEXXXWLW65t' is a vanity address on an EVM chainAddresses beginning with 'D' are the standard Dogecoin address format; EVM addresses are 42-character 0x-prefixed hex strings and cannot take this form. This appears to be a chain-mislabeling error in the page, not a citation problem.
    Proposed correction (not yet applied)
    'DFuckiRGCTerroristsNoBiTEXXXWLW65t' on Dogecoin
  2. #14[disputed][awaiting moderator]in section: Attacker Attribution: Predatory Sparrow
    “Elliptic has 'repeatedly linked' the group to Israeli operatives.”
    reviewerElliptic has 'repeatedly linked' Predatory Sparrow to Israeli operativesCould not find any source in which Elliptic makes or is quoted making this specific attribution claim about Predatory Sparrow's operators; the attribution appears in the record as a media/researcher consensus, not an Elliptic-specific finding as the page presents it in quotation marks.
    Proposed correction (not yet applied)
    Predatory Sparrow is widely believed, including by Israeli media, to be linked to Israeli government or military operatives, though Elliptic itself has not made this specific attribution.

unverifiable

1 claim

No source the reviewer could reach confirms or contradicts the claim.

  1. #24[unverifiable][awaiting moderator]in section: Geopolitical Context and Cyber Shadow War
    “Iran also temporarily reduced internet speeds and closed the Tehran Stock Exchange.”
    reviewerIran also temporarily reduced internet speeds and closed the Tehran Stock Exchange in the same periodThis is plausible given widely reported wartime internet restrictions in Iran during the broader June 2025 conflict, but could not be independently confirmed against a primary or clearly on-topic secondary source within this review.

partially supported

2 claims

The cited evidence supports part of the claim but not all of it.

  1. #19[partially supported][awaiting moderator]in section: Nobitex's Prior Alleged Illicit Finance Connections
    “Chainalysis confirmed that 'IRGC-affiliated ransomware actors' had leveraged Nobitex to cash out proceeds.”
    reviewerChainalysis confirmed IRGC-affiliated ransomware actors leveraged Nobitex to cash out proceedsThe substance (IRGC-linked ransomware actors used Nobitex to cash out) is corroborated, but the exact quoted phrase 'IRGC-affiliated ransomware actors' could not be located verbatim in the cited Chainalysis piece during this review; treated as a close paraphrase rather than a verified direct quote.
  2. #23[partially supported][awaiting moderator]in section: Geopolitical Context and Cyber Shadow War
    “Iran responded to the broader disruptions by ordering the Central Bank to instruct domestic crypto platforms to restrict operating hours, enhance cold-storage security protocols, and report large transfers in real-time.”
    reviewerIran's Central Bank instructed domestic crypto platforms to restrict operating hours and enhance cold-storage security following the attacksThe operating-hours restriction is well corroborated; the 'enhance cold-storage' and 'report large transfers in real-time' details could not be independently confirmed in the sources checked and are treated as plausible but not independently verified additions.

confirmed

21 claims

The cited evidence supports the claim as written.

  1. #1[confirmed][no action needed]in the summary
    “On June 18, 2025, pro-Israel cyber group Gonjeshke Darande (Predatory Sparrow) breached Nobitex, Iran's largest cryptocurrency exchange, transferring over $90 million in user assets to computationally inaccessible vanity wallet addresses embedded with anti-IRGC political statements, effectively destroying the funds rather than stealing them.”
    reviewerOn June 18, 2025, Predatory Sparrow breached Nobitex and transferred over $90 million to computationally inaccessible vanity addresses embedded with anti-IRGC statementsWidely corroborated across Elliptic, Chainalysis, CNBC, NBC, Fortune, PBS reporting.
  2. #2[confirmed][no action needed]in the summary
    “The incident was followed within 24 hours by the public release of Nobitex's full source code, exposing internal privacy-evasion modules, hardcoded banking credentials, and alleged bypass logic for politically sensitive accounts.”
    reviewerThe source code release followed within roughly 24 hours of the fund-destruction eventJune 18 attack to June 19 leak is consistent with a ~24-hour gap; TRM Labs findings on the leak's content are independently confirmed.
  3. #3[confirmed][no action needed]in section: Incident Overview
    “Gonjeshke Darande — operating publicly under the name Predatory Sparrow — announced it had conducted a cyberattack against Nobitex, Iran's largest cryptocurrency exchange, with approximately 7 million registered users.”
    reviewerNobitex had approximately 7 million registered users at the time of the hackFigure matches contemporaneous June 2025 reporting; later figures reflect growth over time, not an error.
  4. #4[confirmed][no action needed]in section: Incident Overview
    “Independent analyst ZachXBT calculated at least $81.7 million lost across Ethereum and TRON-compatible networks.”
    reviewerZachXBT calculated at least $81.7 million lost across Ethereum and TRON-compatible networksIndependently corroborated by multiple outlets citing ZachXBT's on-chain figure.
  5. #5[confirmed][no action needed]in section: Incident Overview
    “The root cause was assessed by Chainalysis as compromised private keys controlling Nobitex hot wallets.”
    reviewerThe root cause was compromised private keys controlling Nobitex hot wallets, per ChainalysisConsistent across sources; no complex smart-contract exploit was involved.
  6. #6[confirmed][no action needed]in section: Fund Destruction via Vanity Addresses
    “Confirmed vanity address examples include '1FuckiRGCTerroristsNoBiTEXXXaAovLX' on Bitcoin, 'DFuckiRGCTerroristsNoBiTEXXXWLW65t' on an EVM chain, and 'TKFuckiRGCTerroristsNoBiTEXy2r7mNX' on TRON.”
    reviewerThe vanity address '1FuckiRGCTerroristsNoBiTEXXXaAovLX' (Bitcoin) and 'TKFuckiRGCTerroristsNoBiTEXy2r7mNX' (TRON) received destroyed fundsThe Bitcoin and TRON address strings are independently verified verbatim. This finding covers only those two addresses; the third address in the same sentence is disputed separately below.
  7. #8[confirmed][no action needed]in section: Fund Destruction via Vanity Addresses
    “Elliptic noted that generating vanity addresses with text strings of that length is 'computationally infeasible' — meaning the probability of a collision that would yield a matching private key is negligibly small.”
    reviewerGenerating vanity addresses of that length is 'computationally infeasible', per EllipticDirect quote confirmed in the cited Elliptic article.
  8. #9[confirmed][no action needed]in section: Fund Destruction via Vanity Addresses
    “An Elliptic researcher described the operation as 'more of a symbolic hack, as opposed to one where the intention is financial.'”
    reviewerAn Elliptic researcher described the operation as 'more of a symbolic hack, as opposed to one where the intention is financial'The exact phrase is corroborated in secondary reporting quoting Elliptic researchers.
  9. #10[confirmed][no action needed]in section: Source Code Leak
    “The group announced the leak with the statement: 'Time's up — full source code linked below. ASSETS LEFT IN NOBITEX ARE NOW ENTIRELY OUT IN THE OPEN.'”
    reviewerPredatory Sparrow announced the leak with 'Time's up — full source code linked below. ASSETS LEFT IN NOBITEX ARE NOW ENTIRELY OUT IN THE OPEN.'Quote independently confirmed in period reporting.
  10. #11[confirmed][no action needed]in section: Source Code Leak
    “TRM Labs conducted an analysis of the leaked codebase, finding a multi-layered hot and cold wallet architecture, hardcoded live API credentials for Iranian fiat payment platforms including Shetab, PAY.IR, Vandar, and IDPay, and privacy-evasion modules labeled 'owshen,' 'zpk,' and 'incentivized_mixer.'”
    reviewerTRM Labs found hardcoded live API credentials for Shetab, PAY.IR, Vandar, and IDPay, and privacy modules 'owshen', 'zpk', and 'incentivized_mixer'Directly verified against the primary cited source, word for word.
  11. #12[confirmed][no action needed]in section: Source Code Leak
    “Internal documentation titled 'Nobitex Privacy' explicitly outlined strategies to 'evade FinCEN and US Based Blockchain Intelligence company's detection tools,' according to TRM.”
    reviewerInternal documentation titled 'Nobitex Privacy' outlined strategies to 'evade FinCEN and US Based Blockchain Intelligence company's detection tools', per TRMExact quote match to primary source.
  12. #13[confirmed][no action needed]in section: Source Code Leak
    “TRM also identified VIP user pathways that allegedly bypassed standard compliance checks and master encryption keys stored in environment variables and plaintext credentials in development branches, which TRM assessed as likely facilitating the breach.”
    reviewerTRM identified VIP bypass pathways and master encryption keys/plaintext credentials in environment variables and dev branchesConfirmed against primary source; page's causal framing ('likely facilitating the breach') is a reasonable paraphrase of TRM's own security-weakness framing.
  13. #15[confirmed][no action needed]in section: Attacker Attribution: Predatory Sparrow
    “it claimed responsibility for disabling a significant portion of Iran's fuel distribution network in 2021 and again in December 2023”
    reviewerPredatory Sparrow disabled a significant portion of Iran's fuel distribution network in 2021 and again in December 2023Note the group also separately attacked Iran's railway system in July 2021, which the page does not mention in this sentence; that omission is not an inaccuracy.
  14. #16[confirmed][no action needed]in section: Attacker Attribution: Predatory Sparrow
    “it caused a major fire at the Khouzestan steel mill in June 2022 by hijacking industrial control systems and spilling a vat of molten steel”
    reviewerPredatory Sparrow caused a major fire at the Khouzestan steel mill in June 2022 by hijacking industrial control systems and spilling molten steelDate and description consistent across sources.
  15. #17[confirmed][no action needed]in section: Attacker Attribution: Predatory Sparrow
    “Predatory Sparrow's stated justification for the Nobitex attack was that 'these cyberattacks are the result of Nobitex being a key regime tool for financing terrorism and violating sanctions.'”
    reviewerPredatory Sparrow's stated justification was 'these cyberattacks are the result of Nobitex being a key regime tool for financing terrorism and violating sanctions'Direct quote confirmed verbatim.
  16. #18[confirmed][no action needed]in section: Nobitex's Prior Alleged Illicit Finance Connections
    “Elliptic reported wallet-level interactions between Nobitex-controlled infrastructure and addresses associated with Hamas, Palestinian Islamic Jihad, Yemen's Houthis, DPRK-affiliated hacking groups, Syrian-based actors, and the Russian exchange Garantex (which was sanctioned by OFAC).”
    reviewerElliptic reported wallet-level interactions between Nobitex and addresses associated with Hamas, Palestinian Islamic Jihad, Houthis, DPRK-affiliated hackers, Syrian actors, and GarantexFull list of six named actors/groups corroborated across the cited Elliptic report and secondary press coverage of it.
  17. #20[confirmed][no action needed]in section: Nobitex's Prior Alleged Illicit Finance Connections
    “Elliptic's open-source investigation identified major shareholders including Seyed Mohammad Baqer Kharazi, described as a relative of Iran's Supreme Leader and a known associate of Mohsen Rezaee Mirqaed, a founding commander of the IRGC.”
    reviewerSeyed Mohammad Baqer Kharazi, a major Nobitex shareholder, is described as a relative of Iran's Supreme Leader and associate of IRGC founding commander Mohsen Rezaee MirqaedDirectly verified word-for-word against the primary source.
  18. #21[confirmed][no action needed]in section: Nobitex's Prior Alleged Illicit Finance Connections
    “On June 2, 2026 — approximately one year after the hack — OFAC formally sanctioned Nobitex along with three other Iranian exchanges (Wallex, Bitpin, and Ramzinex), citing sanctions evasion, terrorist financing, and support for the Iranian regime. OFAC designated four Nobitex executives: chairman and former CEO Amir Hossein Rad, current CEO Seyed Ali Khoee, and co-founders Seyed Mohammad Ali Aghamir and Seyed Mohammad Aghamir.”
    reviewerOn June 2, 2026, OFAC sanctioned Nobitex, Wallex, Bitpin, and Ramzinex, and designated four Nobitex executives: Amir Hossein Rad, Seyed Ali Khoee, Seyed Mohammad Ali Aghamir, and Seyed Mohammad AghamirConfirmed verbatim against the Chainalysis source cited on the page; note that other secondary outlets transliterate the co-founders' surname differently (Kharrazi vs. Aghamir), which is a known naming inconsistency in coverage of this action rather than a factual dispute about who was sanctioned.
  19. #22[confirmed][no action needed]in section: Nobitex's Prior Alleged Illicit Finance Connections
    “The four sanctioned exchanges had collectively sent or received cryptoasset transactions totaling at least $40 billion, and Nobitex alone accounted for over 50% of all Iranian digital asset inflows in the prior year, according to Elliptic.”
    reviewerThe four sanctioned exchanges collectively sent/received at least $40 billion in cryptoasset transactions, and Nobitex alone accounted for over 50% of Iranian digital asset inflows in the prior yearBoth figures independently corroborated.
  20. #25[confirmed][no action needed]in section: Attacker Attribution: Predatory Sparrow
    “it attacked Bank Sepah on June 17, 2025, disrupting payment and fuel systems, one day before the Nobitex operation”
    reviewerThe Bank Sepah attack occurred on June 17, 2025, one day before the Nobitex operationDate confirmed.
  21. #26[confirmed][no action needed]in the timeline
    “OFAC formally designates Nobitex and three other Iranian exchanges (Wallex, Bitpin, Ramzinex) for sanctions evasion, terrorist financing, and regime support. Four Nobitex executives are individually designated.”
    reviewerTimeline: OFAC formally designates Nobitex and three other Iranian exchanges on 2026-06-02Timeline date field matches confirmed sanction date.
How this fits together. The reviewer reads the published page and its cited sources and records one finding per claim. A human moderator decides whether each proposed correction is applied; those decisions, and the score changes they cause, appear in the audit log. Earlier review runs are not shown here; only the latest reflects the page as it stands.