logo

The Vanity Address Affair: The Iranian Crypto Exchange Hack

ID: 98417b99-e3da-5160-9fbf-88cac5007bb6

STIX ID: report--98417b99-e3da-5160-9fbf-88cac5007bb6

Feed Name: Tal Be'ery

Threat Score
70/100

Date Published: 2025-06-18

Date Updated: 2026-04-19

Author: Tal Be'ery

...
...

On June 18, the Iranian crypto exchange Nobitex was breached and approximately $50M was taken by the anti-Iranian group Gonjeshke Darande ("Predatory Sparrow"); the stolen funds were sent to a Tron vanity address embedding a political message. The report explains Tron address/vanity generation, shows the destination address encodes 19 bytes of attacker-controlled data, and concludes the address is likely a burner (no private key) indicating ideological motives rather than financial gain.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.