Iranian crypto exchange Nobitex reportedly exploited for $73M: ZachXBT

4 hours ago

The Iranian crypto exchange’s wallets were exploited for astatine slightest $73 cardinal arsenic attackers utilized vanity addresses for the theft.

 ZachXBT

Iran-based cryptocurrency speech Nobitex appears to person been exploited for implicit $73 cardinal of integer assets, according to onchain researcher ZachXBT.

The attack, disclosed successful a June 18 Telegram post, allegedly drained astatine slightest $73 cardinal successful assets crossed the Tron web and Ethereum Virtual Machine (EVM)-compatible blockchains, though lone a information is confirmed lost.

ZachXBT spotted attackers utilizing a “vanity address” to exploit the protocol, which resulted successful “suspicious outflows” from aggregate Nobitex-linked wallets.

A vanity code refers to a nationalist wallet code with a specific, user-defined series of characters. The archetypal $49 cardinal was stolen done the code “TKFuckiRGCTerroristsNoBiTEXy2r7mNX.” The 2nd code utilized was “0xffFFfFFffFFffFfFffFFfFfFfFFFFfFfFFFFDead,” according to Tronscan.

Attacker wallet “KFucki.” Source: Tronscan

Related: Coinbase information leak could enactment users successful carnal danger: TechCrunch founder

The breach adds to a increasing database of crypto manufacture hacks successful 2025. More than $2.1 cardinal successful integer assets person been stolen truthful acold this year, according to blockchain information steadfast CertiK.

Source: CertiK

Hackers person besides switched from exploiting blockchain infrastructure to profiting from weaknesses successful quality behavior, according to Ronghui Gu, the co-founder of CertiK.

“The bulk of this $2.1 cardinal was caused by wallet compromises, cardinal mismanagement and operational issues,” Gu told Cointelegraph during the Chain Reaction regular X spaces show connected June 2.

Social engineering schemes similar address poisoning don’t necessitate immoderate hacking. Instead, attackers instrumentality victims into sending assets to fraudulent wallet addresses.

Related: Staked Ethereum hits 35M ETH precocious arsenic liquid proviso declines

This is simply a processing story, and further accusation volition beryllium added arsenic it becomes available.

View source