🎯 LOT Newcomer Limited-Time Airdrop is Live!
Individual users can earn up to 1,000 LOT — share from a total prize pool of 1,000,000 LOT!
🏃 Join now: https://www.gate.com/campaigns/1294
Complete deposit and trading tasks to receive random LOT airdrops. Exclusive Alpha trading task await!🎯 LOT Newcomer Limited-Time Airdrop is Live!
Individual users can earn up to 1,000 LOT — share from a total prize pool of 1,000,000 LOT!
🏃 Join now: https://www.gate.com/campaigns/1294
Complete deposit and trading tasks to receive random LOT airdrops. Exclusive Alpha trading task await!
Loss of approximately 100 million USD! Analysis of funds from the theft incident at Iran's largest exchange Nobitex.
Written by: Beosin
On June 18, Iran's largest crypto exchange Nobitex announced that it had suffered a hacker attack, resulting in losses of approximately $100 million, involving various crypto assets including BTC, ETH, Doge, XRP, SOL, TRX, and Ton. An organization named "Gonjeshke Darande," which is pro-Israel, has claimed responsibility for the attack and characterized it as a strike against Iran's crypto infrastructure. The Beosin security team promptly analyzed the incident and tracked the funds, sharing the results as follows:
Flow of Stolen Funds
This attack incident involves multiple blockchain networks. Through Beosin Trace analysis, the confirmed attacker addresses are as follows:
TRON Network: TKFuckiRGCTerroristsNoBiTEXy2r7mNX
Ethereum network: 0xffFFfFFffFFffFfFffFFfFfFfFFFFfFfFFFFDead
BTC Network: 1FuckiRGCTerroristsNoBiTEXXXaAovLX
Solana Network: FuckiRGCTerroristsNoBiTEXXXXXXXXXXXXXXXXXXXXXXXXX
Ripple network: rFuckiRGCTerroristsNoBiTEXypBrmUM
TON Network: UQABFuckIRGCTerroristsNOBITEX1111111111111111_jT
Harmony Network: one19fuckterr0rfuckterr0rfuckterr0rxn7kj7u
Dogecoin Network: DFuckiRGCTerroristsNoBiTEXXXWLW65t
Among them, 23,531 TRX and 49,439,310 USDT were stolen from the TRON network, with a total loss of about $49.45 million.
Beosin Trace Capital Flow Diagram
The Ethereum network was hacked, resulting in the theft of 939,556 USDT, 262.87 ETH, and various tokens from the Ethereum ecosystem (UNI, AXS, PEPE, MASK, MEME, AAVE, etc.), with a total loss amounting to approximately 8.2 million dollars. Below are the main flows of the stolen assets from the Ethereum network:
Beosin Trace Fund Flow Diagram
The Bitcoin network was hacked, resulting in the theft of 18.47 BTC, with a loss amount of approximately 1.93 million USD. Below is the flow of the stolen funds from the BTC network:
Beosin Trace Capital Flow Chart
The RIpple network was hacked, resulting in the theft of 373,852 XRP, with a loss amount of approximately 800,000 USD:
Beosin Trace Fund Flow Chart
The Solana network was hacked, losing 173 SOL, 336,067 WIF, and 31,954 RENDER, with a total loss of approximately 400,000 USD:
Beosin KYT Fund Flow Chart
The Dogecoin network was hacked, losing 39,409,954 Doge, with a loss of approximately 6.7 million USD, while the Harmony and TON networks lost a total of about 400,000 USD. Currently, more addresses related to the attacker are still under investigation and confirmation. Beosin Trace and KYT have added the confirmed attacker-related addresses to the blacklist and will continue to monitor them.
Nobitex Response Measures
After the attack, Nobitex immediately issued a public statement indicating that most of the exchange's Crypto Assets are still stored in secure cold wallets and were not affected. Additionally, Nobitex has taken measures to isolate the attacked systems and enhance its security posture to reduce the risk of similar attacks in the future.
According to media reports, due to the occurrence of this attack incident, the Central Bank of Iran has instructed all domestic crypto asset exchanges to limit their operating hours between 10 AM and 8 PM, implementing stricter regulatory measures on the related exchanges.
Summary
Nobitex is not only the largest crypto exchange in Iran but also a key hub in Iran's heavily sanctioned crypto ecosystem, providing access to the global market for users who cannot access traditional finance. This attack incident highlights the inherent conflict between the borderless nature of crypto assets and national geopolitics, and again demonstrates the urgent need for ongoing blockchain intelligence and on-chain and off-chain risk analysis in the crypto ecosystem.