Share this article

Iran's Nobitex Source Code Exposed Day After Hackers Steal Tokens Across Bitcoin, EVM, Ripple Networks

The pro-Israel group Gonjeshke Darande follows through on its threats, publishing the full exchange code and security files, thereby placing the remaining Nobitex assets at risk.

Updated Jun 19, 2025, 1:04 p.m. Published Jun 19, 2025, 10:34 a.m.
hacker
Pro-Israel hacker group Gonjeshke Darande released the source code for Iran's Nobitex crypto exchange(Unsplash)

What to know:

  • The pro-Israel hacker group Gonjeshke Darande released the full source code of Iranian crypto exchange Nobitex after conducting a $100 million exploit.
  • The leak exposes users' assets to potential theft because the public code dismantles the platform's back-end security.
  • Nobitex said it plans to restore services within five days despite internet disruptions in Iran.

The pro-Israel hacker collective Gonjeshke Darande released the full source code of Iranian crypto exchange Nobitex, just a day after orchestrating a $100 million exploit across multiple blockchains as the war between the two countries nears the end of its first week.

The move raised fresh concerns for users who have not yet withdrawn their assets from the platform because the code makes it extremely easy for nefarious actors to access and exploit.

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the Crypto Daybook Americas Newsletter today. See all newsletters

Israel attacked military and nuclear sites in Iran on Friday saying it had to take action to prevent its enemy, which has vowed to wipe the Jewish state off the map, attaining nuclear weapons. Iran responded with ballistic missile launches targeting the entire country, sending millions into shelters at short notice.

In an X post on Thursday, the hacker group, whose name is Farsi for Predatory Sparrow, wrote: “Time’s up – full source code linked below. ASSETS LEFT IN NOBITEX ARE NOW ENTIRELY OUT IN THE OPEN.”

Loading...

The leak included blockchain scripts, internal privacy settings and a list of servers, effectively dismantling the exchange’s back-end security.

The source code dump follows through on threats issued a day earlier, when Gonjeshke Darande claimed responsibility for the hack and promised to release internal data.

The group accused Nobitex of aiding Iran in circumventing international sanctions and called the platform the “regime’s favorite sanctions violation tool.”

Over $90 million in tokens from Bitcoin, EVM, Ripple, Dogecoin, Solana and other networks were deliberately sent to burner addresses, making recovery unlikely.

Blockchain data shows that funds were moved to provocatively named wallets, such as “1FuckiRGCTerroristsNoBiTEXXXaAovLX” and “DFuckiRGCTerroristsNoBiTEXXXWLW65t,” suggesting the use of brute-force-generated vanity addresses that the attackers do not hold private keys for. The IRCG, or Islamic Revolutionary Guard Corps, is an powerful and influential branch of the Iranian military.

Nobitex responded on Thursday, stating that no additional losses occurred after the leak and that it plans to begin restoring services within five days, although ongoing internet disruptions in Iran may delay the recovery.

More For You

Protocol Research: GoPlus Security

GP Basic Image

What to know:

  • As of October 2025, GoPlus has generated $4.7M in total revenue across its product lines. The GoPlus App is the primary revenue driver, contributing $2.5M (approx. 53%), followed by the SafeToken Protocol at $1.7M.
  • GoPlus Intelligence's Token Security API averaged 717 million monthly calls year-to-date in 2025 , with a peak of nearly 1 billion calls in February 2025. Total blockchain-level requests, including transaction simulations, averaged an additional 350 million per month.
  • Since its January 2025 launch , the $GPS token has registered over $5B in total spot volume and $10B in derivatives volume in 2025. Monthly spot volume peaked in March 2025 at over $1.1B , while derivatives volume peaked the same month at over $4B.

More For You

SGX's Crypto Futures Draw New Liquidity, Not Diverted Cash, Exchange Boss Says

The letters SGX, the exchanges logo, standing on a wall.

Institutions are pursuing cash-and-carry arbitrage, not outright bullish plays, Syn said.

What to know:

  • SGX's bitcoin and ether perpetual futures are building liquidity incrementally, Michael Syn, president of the Singapore exchange, said.
  • Institutions are pursuing cash-and-carry arbitrage, not outright bullish plays, he added.
  • The exchange's regulated perpetual futures offer improved risk-management practices, avoiding the high-leverage auto-liquidations common in unregulated markets.