BTCC / BTCC Square / CoinTurk /
Exclusive: The Covert Crypto Heist Tied to Israeli Intelligence Agents

Exclusive: The Covert Crypto Heist Tied to Israeli Intelligence Agents

Author:
CoinTurk
Published:
2025-06-27 06:46:31
18
2

Blockchain forensics uncover a shadow war—where digital asset theft meets state-sponsored espionage.

How Mossad-linked operatives allegedly orchestrated a $200M DeFi hack.

From Lazarus Group playbooks to zero-day exploits, the lines between cybercrime and geopolitics blur.

Meanwhile, traditional finance still can't tell a hardware wallet from a Swiss vault.

TRM Labs disclosed that a 28-year-old individual, Dmitri Cohen, was reportedly receiving $500 worth of cryptocurrency per assignment, working on surveillance, propaganda, and data collection for Iranian intelligence. The other two suspects allegedly secured similar payments through cryptocurrency, effectively establishing an international payment chain that bypassed the banking system. This report highlights the increasing significance of cryptocurrencies in state-supported espionage activities.

TRM Labs’ Report

The bust of the espionage cell in Israel underscores how cryptocurrency transaction tracking has emerged as a critical tool in the ongoing cyber warfare between nations. TRM Labs recalled previous instances where Israeli defense teams conducted targeted operations using cross-analysis methods on data from compromised networks. While official entities remain silent, researchers assert that the current data aligns with these operational tactics.

Nobitex Heist’s Impact on Regional Tensions

The Nobitex robbery, occurring on June 18, resulted in hot wallets across multiple networks being drained, with losses exceeding $90 million in cryptocurrency. Chainalysis, monitoring the region, remarked how Nobitex serves as a crucial bridge within Iran’s sanctioned financial ecosystem and warned that the attack could have strategic implications beyond mere financial loss.

The Gonjeshke Darande group, claiming the attack, is known for its history of infiltrating and collecting data from Iran’s digital infrastructures. TRM Labs noted that this digital assault, following closely behind Israeli aerial strikes recorded on June 13, has also heightened tensions on the cyber front. Experts believe that Nobitex’s internal communications and wallet maps provided a chance for authorities tracking cryptocurrency flows to uncover Iranian-linked actors.

You can follow our news on Telegram, Facebook, Twitter & Coinmarketcap Disclaimer: The information contained in this article does not constitute investment advice. Investors should be aware that cryptocurrencies carry high volatility and therefore risk, and should conduct their own research.

|Square

Get the BTCC app to start your crypto journey

Get started today Scan to join our 100M+ users