- calendar_today September 3, 2025
As Iran became the target of a destructive double-tap attack from the elusive hacker group Predatory Sparrow, also known by its Farsi name, a shadowy cyberwar escalated this week. In back-to-back operations, the group destroyed the top cryptocurrency exchange in the nation, Nobitex, and severely damaged Sepah Bank, a financial institution intimately connected to Iran’s military operations.
Predatory Sparrow has not always been quiet. Before, the group conducted well-publicized cyberattacks derailing trains, shutting down fuel systems, and even physically damaging industrial sites. But the deliberate destruction of financial assets on a scale hardly seen in cyberwarfare distinguishes this new campaign.
Blockchain analytics company Elliptic claims the hackers broke into Nobitex and destroyed more than $90 million worth of bitcoin. Not one of them stole it. Rather, they moved the money to “vanity addresses,” crypto wallets made especially to be unrecoverable. Every address expressed a message, including lines like “FuckIRGCterrorists,” so transforming the movement from financial sabotage into a political statement.
“The crypto they stole has essentially been burned,” co-founder Elliptic Tom Robinson remarked. The hackers obviously have political rather than financial motives.
In a statement sent to X, Predatory Sparrow claimed that Iran was able to evade international sanctions and fund organizations, including the Islamic Revolutionary Guard Corps (IRGC), Hamas, the Houthis, and Palestinian Islamic Jihad by means of funds provided by Nobitex. Elliptic verified that Nobitex had conducted business using wallets connected to approved companies.
The website of Nobitex has been offline since the attack. The company has not responded, thus users are left in uncertainty, wondering if their money is gone permanently.
Still, the assault did not stop there.
Within hours of the Nobitex takedown, Predatory Sparrow started another attack—this time on Sepah Bank, a big participant in Iran’s financial system. The group claimed to have totally erased internal bank data and uploaded files allegedly showing financial arrangements between Sepah Bank and the Iranian military.
“Caution: Associating with the regime’s instruments for evading sanctions and financing its ballistic missiles and nuclear program is bad for your long-term financial health,” the hackers advised. Who’s next?
The bank’s website went offline for a little while, but returned the next day. Still, the influence transcended simple digital presence.
Iranian cybersecurity specialist Hamid Kashfi, who now resides in Sweden, claimed to have heard from sources inside Iran that Sepah’s online banking and ATMs were still not working. Millions of average people are impacted. Individuals are unable to obtain their money. This is causing civilian suffering, not just attacking the government, he said.
Previously claiming responsibility for some of the most disruptive cyberattacks in Iranian history, Predatory Sparrow is They disabled thousands of gas station payment terminals, so paralyzing fuel distribution in 2021 and 2022 and closing Iran’s railway system. Their most infamous action, however, came in 2022 when they stole control systems from a steel plant and let molten steel spill over, igniting a fire almost certain to kill workers. They put a video of that attack online.
Although the group presents itself as a domestic Iranian resistance force, cybersecurity experts mostly agree they are supported—or even directly run—by Israeli military or intelligence operations. Among usual hacktivist groups, their capacity, coordination, and accuracy are unparalleled.
“This isn’t a ragtag team of hackers,” Google’s Mandiant threat intelligence team chief analyst John Hultquist said. “They are state-level players with the ability and knowledge to execute attacks few others could.”
Foreign governments and watchdogs have long been interested in Iran’s use of cryptocurrencies as a workaround for restrictions. Targeting Nobitex and Sepah Bank, Predatory Sparrow directly attacked two of the financial veins of the government, demonstrating that cyber tools can now be used not only for intelligence gathering but also for instantaneous economic disruption.
Predatory Sparrow also made clear in one last note, “Who’s next?” This operation might only be the start.






