On June 18, 2025, a hacktivist group calling itself Predatory Sparrow launched a coordinated breach of Iranian crypto exchange Nobitex, siphoning off more than $90 million worth of digital assets. In the days leading up to the exploit, the group had already targeted Bank Sepah (June 17), signaling a swift, politically charged operation that culminated in a bold on-chain statement. Funds were routed through vanity addresses emblazoned with “F*ckIRGCterrorists,” making clear that this was as much about protest as profit.
Top 5 Largest Stolen Transactions
(see table)
Key Insight: Stablecoins (USDT) accounted for the two largest individual hits, totaling over $8 million in just two transfers.
Stolen-Assets Distribution by Currency
(see chart above)
Predatory Sparrow’s use of custom addresses containing “F*ckIRGCterrorists” unmistakably transforms this hack into a form of digital protest. Vanity addresses—typically vanity vanity for prestige or brand—here become shouting postcards aimed directly at Iran’s Islamic Revolutionary Guard Corps. By permanently etching this message on the blockchain, the group has ensured their political critique will endure so long as the transactions remain on-chain.
Nobitex, Iran’s largest domestic crypto exchange, has faced allegations of facilitating transactions for IRGC-linked entities and OFAC-sanctioned operatives:
“Crypto exchanges must assume they’re geopolitical targets,” says Jane Hu, senior analyst at SecureChain. “No platform is immune to state-sponsored or ideologically driven attacks. Layered defenses—especially for sanctioned jurisdictions—are critical.”
“OFAC compliance isn’t just a checkbox,” notes compliance specialist Marcus Lee. “Real-time sanctions screening, outbound transaction limits, and rigorous KYC/AML can deter misuse and reduce liability.”
“Vanity hacks raise the stakes,” adds geopolitical consultant Dr. Leila Azimi. “When attackers broadcast a political message on-chain, they’re forcing regulators and exchanges to treat incidents not as isolated thefts but as acts of digital protest—blurring lines between crime and activism.”
The Predatory Sparrow breach of Nobitex underscores evolving threats at the nexus of crypto, sanctions, and geopolitics. To strengthen resilience:
By embracing stronger technical controls, sharper compliance measures, and an acute awareness of geopolitical risk, the crypto ecosystem can better weather—and deter—these high-stakes, hybrid cyber-activist campaigns.
350+ COMPLIANCE & DIGITAL ASSET TEAMS TRUST US