Iranian – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Mon, 01 Sep 2025 03:28:21 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 Iranian – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 Geopolitical Chaos Sends Iranian Crypto Flows Plummeting by Over 76% https://earlybirdsinvest.com/geopolitical-chaos-sends-iranian-crypto-flows-plummeting-by-over-76/ https://earlybirdsinvest.com/geopolitical-chaos-sends-iranian-crypto-flows-plummeting-by-over-76/#respond Mon, 01 Sep 2025 03:28:20 +0000 https://earlybirdsinvest.com/geopolitical-chaos-sends-iranian-crypto-flows-plummeting-by-over-76/

Cryptocurrency trading in Iran has slowed dramatically in 2025. A mix of geopolitical tensions, cyberattacks, and stricter regulations has rattled the previously booming market.

According to blockchain analytics firm TRM Labs, total cryptocurrency inflows into Iran from January through July 2025 reached roughly $3.7 billion, an 11% decline from the same period in 2024.

The contraction was particularly pronounced after April, as June inflows plunged more than 50% year-over-year. This was followed by an even steeper drop of over 76% in July.

Hack, War, and Wallet Freezes

Several geopolitical and security events weighed heavily on Iranian crypto markets, such as stalled nuclear talks with Israel, the outbreak of an armed conflict in June, a $90 million breach at Nobitex, and Tether’s blacklisting of an important Iranian-linked stablecoin address.

According to the TRM report, these shocks together shifted trader behavior, prompting capital outflows to overseas exchanges and increased use of alternative blockchains and stablecoins.

Despite the turbulence, Nobitex maintained its central role in Iran’s crypto ecosystem and handled more than 87% of all Iranian-linked transaction volume in 2025. Of the over $3 billion processed through the platform, approximately $2 billion moved via the Tron network, with heavy use of TRC-20 USDT and TRX.

This concentration offered efficiency for users but also amplified systemic risk, as demonstrated when the Predatory Sparrow group exploited vulnerabilities in Nobitex’s infrastructure during the height of the Iran-Israel hostilities.

Dual Priorities

The $90 million hack froze liquidity, slowed transaction processing, and temporarily pushed users toward smaller or higher-risk platforms, revealing not only operational weaknesses but also the regime’s “dual priorities” of enabling warrantless surveillance while maintaining selective privacy for VIP users. TRM Labs traced on-chain activity to IRGC-linked actors and sanctioned entities such as Gaza Now, underscoring the political dimensions of the attack.

The geopolitical escalation in June accelerated capital flight from domestic exchanges, as seen with the surge in outflows from Nobitex by more than 150% in the week leading up to the conflict, often moving to global exchanges with limited Know Your Customer (KYC) measures or to high-risk, no-KYC platforms.

The exodus was exacerbated in July when Tether froze 42 Iranian-linked addresses, many of which were tied to Nobitex and an IRGC-affiliated actor. The freeze disrupted longstanding transactional flows, which led Iranian users to move to alternative stablecoins such as DAI on the Polygon network.

Domestic influencers, government-aligned channels, and exchanges actively encouraged this migration, demonstrating both the adaptability of participants and the regime’s use of digital assets to bypass sanctions.

Meanwhile, Iran’s domestic regulatory environment continued to shift, with the Law on Taxation of Speculation and Profiteering enacted in August 2025, which imposed capital gains tax on crypto trading. While phased implementation is expected, the measure points to Tehran’s intent to formally regulate digital asset markets by bringing cryptocurrencies alongside gold, real estate, and forex in the regime’s tax framework.

Beyond capital markets, crypto remains a critical tool for Iran in procurement and sanctions evasion. Chinese resellers, for instance, supply drone components, AI hardware, and electrical equipment through crypto transactions, and a sophisticated underground KYC bypass industry supports these operations by providing forged identification documents for onboarding to international exchanges.

SPECIAL OFFER (Sponsored)

Binance Free $600 (CryptoPotato Exclusive): Use this link to register a new account and receive $600 exclusive welcome offer on Binance (full details).

LIMITED OFFER for CryptoPotato readers at Bybit: Use this link to register and open a $500 FREE position on any coin!

]]>
https://earlybirdsinvest.com/geopolitical-chaos-sends-iranian-crypto-flows-plummeting-by-over-76/feed/ 0 56150
Iranian crypto flows fall 11% on Israel conflict, Nobitex hack: TRM Labs https://earlybirdsinvest.com/iranian-crypto-flows-fall-11-on-israel-conflict-nobitex-hack-trm-labs/ https://earlybirdsinvest.com/iranian-crypto-flows-fall-11-on-israel-conflict-nobitex-hack-trm-labs/#respond Wed, 27 Aug 2025 01:30:58 +0000 https://earlybirdsinvest.com/iranian-crypto-flows-fall-11-on-israel-conflict-nobitex-hack-trm-labs/

Flows into Iranian crypto trading platforms have fallen in 2025 due to a breakdown in nuclear negotiations with Israel, a $90 million hack on Iran’s largest crypto exchange, and a major stablecoin blacklisting, says blockchain analytics firm TRM Labs.

Iranian crypto flows hit $3.7 billion between January and July, an 11% decrease compared to the same period last year, with the worst drop off coming in June and July, TRM Labs said in a report on Tuesday.

“This downturn coincided with a breakdown in nuclear negotiations, a 12-day conflict with Israel beginning June 13, and widespread power outages in Iran — driven by a combination of Israeli kinetic and cyber operations, as well as regime-initiated shutdowns.”

Iran’s crypto flows started to sharply drop in June, just after the $90 million hack on Nobitex, which handles 87% of the country’s crypto transactions. 

Many Iranians rely on US dollar stablecoins as a store of value amid skyrocketing inflation and to skirt tough sanctions on the country, which has largely cut it off from the global economy.

Nobitex hack big contributor to Iran’s crypto shake-up

Confidence in Iran-based virtual asset service providers (VASPs) deteriorated following Nobitex’s security breach, which came at the hands of pro-Israel group Predatory Sparrow on June 18 — when tensions between Iran and Israel were at their peak.

While Nobitex continues to dominate Iran crypto transaction volume, the incident disrupted liquidity, slowed transaction processing and temporarily pushed users toward alternative platforms, TRM said.

Share of crypto transaction volume among Iranian VASPs between January and July. Source: TRM Labs

Heightened Iran-Israel tensions further amplified the outflows, which surged more than 150% in the worst week and a large percentage of that volume headed to high-risk foreign exchanges with little to no Know Your Customer checks, TRM said.

Tether’s blacklisting slowed flows

Stablecoin issuer Tether also carried out its largest-ever freeze of Iranian-linked funds, blacklisting 42 crypto addresses with Tether (USDT) balances on July 2.

The incident sparked a coordinated push from Iranian exchanges, influencers and state-backed channels for users to offload their TRON-based USDT balances — Iran’s most widely used network and token — and move funds into Dai (DAI) on Polygon.

Related: UAE reportedly holds $700M in mined Bitcoin: Arkham

Many everyday Iranians continue to turn to crypto as a hedge against inflation, TRM said, highlighting Iran’s strong reliance on stablecoins.

Iran continues to use crypto for political objectives

Iran is still relying on crypto to pay for sensitive goods from Chinese chip resellers, including hardware critical for artificial intelligence, drone components, and other electrical equipment — enabling it to effectively bypass sanctions, TRM noted.

It has also used crypto to fund espionage payments with foreign operatives, the crypto analytics firm added.

However, illicit crypto transactions in Iran still only account for less than 1% of total volume.

Magazine: Bitcoin is ‘funny internet money’ during a crisis: Tezos co-founder

]]> https://earlybirdsinvest.com/iranian-crypto-flows-fall-11-on-israel-conflict-nobitex-hack-trm-labs/feed/ 0 55297 U.S. warns of Iranian cyber threats on critical infrastructure https://earlybirdsinvest.com/u-s-warns-of-iranian-cyber-threats-on-critical-infrastructure/ https://earlybirdsinvest.com/u-s-warns-of-iranian-cyber-threats-on-critical-infrastructure/#respond Tue, 01 Jul 2025 09:27:41 +0000 https://earlybirdsinvest.com/u-s-warns-of-iranian-cyber-threats-on-critical-infrastructure/

Iranian hacker

U.S. cyber agencies, the FBI, and NSA issued an urgent warning today about potential cyberattacks from Iranian-affiliated hackers targeting U.S. critical infrastructure.

CISA says there are no indications of an ongoing campaign but urges critical infrastructure organizations and other potential targets to monitor their defense due to the current unrest in the Middle East and cyber attacks previously linked to Iran.

In a joint fact sheet, the cyber agencies warn that Defense Industrial Base (DIB) companies with ties to Israeli defense and research, are at increased risk at being targeted. Other organizations in critical infrastructure sectors, including energy, water, and healthcare, are also considered potential targets.

The advisory warns that Iranian threat actors are Iran are known to exploit unpatched vulnerabilities or utilize default passwords to gain breach systems. This was seen last year when IRGC-affiliated Iranian threat actors breached a Pennsylvania water facility in November 2023 by hacking into Unitronics programmable logic controllers (PLCs) exposed online. 

Iranian-affiliated hackers also work with or act as hacktivists, performing distributed denial-of-service (DDoS) attacks or defacing websites. These attacks are often conducted in conjunction with politically motivated messages, with the attackers promoting their activities on X and Telegram.

Iranian threat actors have also been observed utilizing ransomware or working as affiliates with Russian ransomware gangs, such as NoEscape, Ransomhouse, and ALPHV (also known as BlackCat). Many of these attacks were focused on Israeli companies, where they encrypted devices and leaked stolen data.

In some cases, the attackers used data wipers instead of ransomware to conduct destructive attacks on organizations.

Mitigating attacks

CISA, the DoD, the FBI, and the NSA are urging organizations to adopt the following best practices to protect against these threats:

  • Isolate OT and ICS systems from the public internet and restrict remote access.
  • Use strong, unique passwords for all online accounts and systems, changing all default account passwords.
  • Enable multi-factor authentication (MFA) for critical systems and authentication platforms.
  • Install all software updates, especially on internet-facing systems to fix known vulnerabilities.
  • Monitor networks and servers for unusual activity.
  • Develop and test incident response plans to make sure that all backups and recovery plans are working.

For more information, organizations can read CISA’s Iran Threat Overview and the FBI’s Iran Threat web pages.

Tines Needle

While cloud attacks may be growing more sophisticated, attackers still succeed with surprisingly simple techniques.

Drawing from Wiz’s detections across thousands of organizations, this report reveals 8 key techniques used by cloud-fluent threat actors.

]]>
https://earlybirdsinvest.com/u-s-warns-of-iranian-cyber-threats-on-critical-infrastructure/feed/ 0 45133
Iranian International Behind Robbinhood Ransomware Scheme Pleads Guilty – U.S. Department of Justice https://earlybirdsinvest.com/iranian-international-behind-robbinhood-ransomware-scheme-pleads-guilty-u-s-department-of-justice/ https://earlybirdsinvest.com/iranian-international-behind-robbinhood-ransomware-scheme-pleads-guilty-u-s-department-of-justice/#respond Thu, 29 May 2025 23:55:29 +0000 https://earlybirdsinvest.com/iranian-international-behind-robbinhood-ransomware-scheme-pleads-guilty-u-s-department-of-justice/

An Iranian man is pleading guilty to being the mastermind behind the Robbinhood ransomware scam.

According to a recent press release by the U.S. Department of Justice (DOJ), 37-year-old Sina Gholinejad of Iran has pleaded guilty to participating in a hack of multiple cities across the US, causing widespread disruption and tens of millions of dollars in losses.

Authorities say that in January 2019, Gholinejad and his co-conspirators gained and maintained illegal access to the victims’ computers, stealing sensitive data and uploading the Robbinhood malware, which in turn would take over a victim’s PC, encrypt its files, and attempt to extort crypto assets out of them in exchange for the release of the data.

Gholinejad and his team would then attempt to launder the stolen funds through crypto mixing services and chain-hopping and hide their identities using advanced methods.

As stated by Matthew R. Galeotti, Head of the Justice Department’s Criminal Division, in the press release,

“The ransomware attack against the City of Baltimore forced the city to take hundreds of computers offline and prevented the city from performing basic functions for months.

Gholinejad’s conviction reflects the Criminal Division’s commitment to bringing cybercriminals who target our cities, healthcare system, and businesses to justice no matter where they are located. There will be no impunity for these destructive attacks.”

Other cities affected included Greenville, North Carolina, as well as Yonkers, New York, and Gresham, Oregon.

Gholinejad is scheduled to be sentenced in August and could face a maximum penalty of up to 30 years behind bars.

Follow us on X, Facebook and Telegram

Don’t Miss a Beat – Subscribe to get email alerts delivered directly to your inbox

Check Price Action

Surf The Daily Hodl Mix

&nbsp

Disclaimer: Opinions expressed at The Daily Hodl are not investment advice. Investors should do their due diligence before making any high-risk investments in Bitcoin, cryptocurrency or digital assets. Please be advised that your transfers and trades are at your own risk, and any losses you may incur are your responsibility. The Daily Hodl does not recommend the buying or selling of any cryptocurrencies or digital assets, nor is The Daily Hodl an investment advisor. Please note that The Daily Hodl participates in affiliate marketing.

Featured Image: Shutterstock/ne2pi

]]>
https://earlybirdsinvest.com/iranian-international-behind-robbinhood-ransomware-scheme-pleads-guilty-u-s-department-of-justice/feed/ 0 39042