Crypto Chaos in Iran: Curfew Imposed on Exchanges After Major Nobitex Hack

Share this story:

Iran Imposes Curfew on Crypto Exchanges Following Nobitex Hack

June 19, 2025 – Tehran, Iran
In a significant response to a recent high-profile hack, the Iranian government has enacted a curfew on domestic cryptocurrency exchanges. This move comes in the wake of a politically motivated cyberattack on Nobitex, which is the country’s largest cryptocurrency trading platform.

Details of the Nobitex Hack

On June 18, 2025, Nobitex suffered a devastating breach that resulted in losses estimated to exceed $90 million. According to the blockchain analytics firm Chainalysis, the attackers managed to drain a variety of digital assets, including Bitcoin, Ethereum, Dogecoin, Ripple, Solana, Tron, and Ton, from Nobitex’s hot wallets. In a calculated effort to render the stolen assets irretrievable, they were sent to burner wallets, effectively destroying them.

Central Bank Regulations

In light of the attack, the Central Bank of Iran announced an operational curfew that restricts all local crypto exchanges to operating between the hours of 10 AM and 8 PM. Experts suggest that this curfew is part of broader efforts by the Iranian regime to exert control over its crypto market, which plays a crucial role in circumventing international sanctions imposed on the country.

“This operational curfew could signal increasing pressure on exchanges operating within Iran, as the regime attempts to manage systemic risk in a market that plays an outsized role in navigating around global sanctions,” Chainalysis detailed in their latest report.

Claim of Responsibility

The pro-Israel hacker group known as Gonjeshke Darande, or Predatory Sparrow, has claimed responsibility for the cyber attack. They described the operation as a tactical disruption aimed at Iran’s sanctioned financial infrastructure. In an unusual twist, the attackers distributed inflammatory labels to the wallets holding the stolen assets and threatened to release sensitive information about Nobitex unless users withdrew their funds.

Chainalysis confirmed that the majority of the stolen assets were directed towards blockchain addresses that carried anti-IRGC (Islamic Revolutionary Guard Corps) slogans. The hackers followed through by sending portions of the assets to known burn addresses, ensuring that the stolen funds could not be retrieved.

Implications for Iran’s Crypto Economy

Nobitex is not just the largest cryptocurrency exchange in Iran but also serves as a vital component of the country’s digital economy. Chainalysis reports that Nobitex has facilitated over $11 billion in transactions, significantly more than the next ten largest exchanges combined. This platform functions as the primary gateway for Iranians engaging with global markets, particularly as they are often barred from conventional financial systems due to sanctions.

Furthermore, Nobitex has been linked to various wallets tied to sanctioned individuals and entities, including those associated with ransomware operations and terrorist organizations, such as pro-Hamas media outlets.

Response from Nobitex

In the aftermath of the attack, Nobitex has assured its users that their assets remain secure in cold storage and that all hot wallets have been appropriately managed to prevent further breaches. The exchange has committed to covering the losses through its reserve fund and is taking proactive measures to strengthen its security protocols, including migrating funds to new offline wallets to protect against future threats.

As the situation continues to unfold, the implications of this incident on Iran’s cryptocurrency landscape and its broader financial ecosystem remain to be seen.


This event highlights the increasingly complex intersection of cybersecurity, finance, and geopolitics, underscoring the vulnerabilities that exist within the rapidly evolving world of cryptocurrency.

Share this story: