Nobitex Hack pulls curtains on months of suspicious fund movements

2025/06/26 19:42

The recent hack on Nobitex, Iran’s largest crypto exchange, dealt a major blow to the country’s crypto industry, draining millions in user funds. But the breach may have revealed more than just security flaws, as troubling on-chain history raises questions over the platform’s operations.

According to BeInCrypto, an investigation by blockchain intelligence firm Global Ledger into the June 18 Nobitex hack has found that the platform may have been engaging in stealthy fund movements well before the cyberattack. 

Per the report, on-chain analysis has revealed a pattern of practices typically linked to money laundering, such as peelchains, one-use wallets, and systematic balance sweeps, deeply embedded in the exchange’s infrastructure.

The attack on Nobitex affected multiple chains, resulting in the loss of over $90 million in assets. Shortly after the breach, Nobitex moved 1,801 BTC (worth around $187 million) from exposed wallets to new addresses. While the exchange described this as a protective measure, the investigation shows similar movement patterns had been occurring quietly for months.

Hot Wallets, Cold Moves: Nobitex’s shady crypto shuffle

Since as far back as October 2024, Nobitex has been using a stealth tactic known as peelchains, a method where funds are gradually split and passed through intermediaries or one-time-use wallets. This technique is used to quietly move large amounts of crypto, while obscuring their trail and making them difficult to trace.

On multiple occasions, several hot wallets tied to Nobitex repeatedly passed exactly 30 BTC between addresses, often through one-time-use intermediaries. Funds in these flows were eventually sent to exchange addresses or, in some cases, destinations linked to illicit actors.

Additionally, the investigation traced funds moving in and out of a wallet cluster that behaved like a central mixing layer. Many of these wallets had a short lifespan and were used just once before being abandoned, suggesting an intentional scheme to avoid detection.

Further evidence shows that Nobitex’s “rescue wallet,” which was supposedly deployed after the hack to safeguard the remaining funds, was found to have been active for months prior, consistently receiving chipped-off funds. The exchange has also continued similar asset movements post-hack and is said to still hold substantial reserves.

Global Ledger’s findings now raise questions about Nobitex’s operational transparency, including possible ties to illicit activity such as money laundering.

Gonjeshke Darande, the pro-Israel hacker group that claimed responsibility for the attack, previously accused Nobitex of being Iran’s “favorite sanctions violation tool.” The group also cited this as a key reason for targeting the exchange, claiming it as part of a broader retaliation effort tied to the Israel-Iran conflict.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Eskom Grid Surges to 60.6%—Is South Africa Poised for Its Bitcoin Mining Plan?

Eskom Grid Surges to 60.6%—Is South Africa Poised for Its Bitcoin Mining Plan?

South Africa’s state-run power utility, Eskom, has posted a notable uptick in performance, marking a milestone in a long-struggling electricity supply system. According to a June 2025 electricity update by Minerals Council South Africa (MCSA), the utility’s Energy Availability Factor (EAF) hit an average of 60.6% for the month, the first time this year that Eskom surpassed the 60% mark. More critically, it comes just as Eskom begins to explore new frontiers, among them, Bitcoin mining. Source: Eskom & Minerals Council SA Eskom Sees Stability Gains Amid Winter Demand, But Long-Term Challenges Persist Eskom has shown signs of short-term recovery after years of persistent blackouts, failing infrastructure, and rising debt. The utility managed to avoid load-shedding through most of June and into July, marking a rare period of stability for the national grid. According to André Lourens, chief economist at MCSA, the improved performance reflects a combination of reduced maintenance, better plant output, and strategic use of emergency reserves. “Emergency reserves were sufficient and used strategically to balance the grid, even as the system came under pressure,” he said. Eskom’s Energy Availability Factor (EAF), a measure of plant readiness, typically improves in winter as maintenance is scaled back. In early June, the utility brought 2,500 MW of generation capacity back online ahead of a cold front, helping keep unplanned outages below the 15,000 MW threshold that often triggers Stage 2 load-shedding. Eskom’s Winter Outlook projects that if unplanned outages remain below 13,000 MW, the country can avoid blackouts altogether. Even in a less favorable scenario with 15,000 MW in outages , blackouts would be limited to 21 days over the 153-day winter season. The National Transmission Company South Africa (NTCSA) also released a 52-week forecast, indicating Eskom has adequate capacity to meet demand and reserve requirements through July 2026, even factoring in up to 17,200 MW in unplanned outages. Still, electricity production remains below pre-pandemic levels. Eskom is currently producing around 16,800 GWh per month, up from earlier in the year but still short of the 17,100 GWh monthly average in 2024 and far below the 19,000 GWh peak in 2019. Eskom 52-week outlook Source: Eskom & Minerals Council SA Lourens said output could edge slightly higher in July and August as winter demand peaks. Financially, the utility remains under pressure. Electricity sales have fallen 16% over the past decade, from 217.9 TWh in 2014 to 183.3 TWh in 2024. Revenue, however, has risen 115% over the same period, largely due to steep tariff increases. The average electricity price rose from R0.71 per kWh in 2014 to R2.12 in 2025. Despite falling demand and rising costs, Eskom’s workforce remains bloated. While employee numbers have dropped from 50,000 to 40,000 over the past decade, the World Bank estimates only 14,200 are needed. Labor costs have soared, increasing nearly tenfold since the 1990s. With R403 billion ($22.7 billion) in debt, Eskom is now exploring new revenue opportunities. CEO Dan Marokane recently suggested repurposing excess electricity to support energy-intensive sectors such as AI, data centers, and Bitcoin mining . Eskom Eyes Bitcoin Mining, AI as Part of Future Energy Strategy Amid Operational Setbacks Eskom is exploring Bitcoin mining and AI-driven data centers as potential solutions to utilize surplus generation capacity and stabilize its finances, according to CEO Dan Marokane. Speaking at the BizNews Conference earlier this month, Marokane said the utility is drawing lessons from the United States, where Bitcoin mining operations have contributed to grid flexibility by reducing power use during high-demand periods. 🚨 Eskom explores supporting Bitcoin mining, AI, and data centers as South Africa’s utility confronts falling electricity sales, debt, and renewable competition. #Eskom #BitcoinMining https://t.co/1iB479D9fg — Cryptonews.com (@cryptonews) July 1, 2025 Eskom is studying similar demand-response models, such as Texas-based Riot Platforms, which earned $32 million in 2023 by cutting power consumption during a heatwave. “There are exciting opportunities around AI and data centers, but also within the space of Bitcoin,” said Marokane. However, environmental concerns persist. A 2024 study in Nature Communications linked major U.S. mining facilities to air pollution across state lines, while their energy use surpassed that of Los Angeles. Although global Bitcoin mining is gradually shifting toward renewables, 52.4% as of the latest Cambridge report , natural gas remains the primary energy source, replacing coal. Eskom’s shift in strategy comes as it continues to struggle with unplanned outages and rising operating costs. From June 13 to 19, outages briefly surged to over 15,000 MW, forcing the utility to increase its use of expensive open-cycle gas turbines. Diesel spending has reached R4.51 billion so far this year—more than double the same period in 2024. The utility is also dealing with delays at the Koeberg Nuclear Power Station. The return of Unit 1 has been pushed back by at least a month after inspections revealed defects in four steam generator tubes. Eskom confirmed that the defects have been addressed in line with safety standards, following assistance from international specialists. Despite the setbacks, Marokane said Eskom must evolve. “The business has to reinvent itself and use part of this baseload in a way that can help it manage the remainder of its debt pile,” he said.
Share
CryptoNews2025/07/16 20:48