Connect with us

Crypto

From banks to blockchains: US opens new front in Iran sanctions

Published

on

From banks to blockchains: US opens new front in Iran sanctions

The US Treasury designated Nobitex alongside Wallex, Bitpin and Ramzinex and sanctioned senior figures connected to Nobitex, including chairman, co-founder and former chief executive Amir Hossein Rad.

According to the Treasury, Nobitex processed more than half of all Iranian digital asset inflows in 2025. Washington also accused it of facilitating transactions linked to the Islamic Revolutionary Guard Corps (IRGC), sanctions evasion, ransomware activity and the Central Bank of Iran’s access to hundreds of millions of dollars in stablecoins.

The sanctions therefore struck at part of the infrastructure that has allowed Iranian individuals, companies and state-linked actors to access international digital asset markets despite years of financial restrictions.

Crypto vs sanctions

Iran’s interest in cryptocurrency is not difficult to explain. Sanctions have sharply limited access to international banking networks, dollar transactions, trade finance and oil revenues. Digital assets do not eliminate these constraints but can provide alternative channels for moving value across borders.

Advertisement

Cryptocurrencies and stablecoins can help facilitate transactions, preserve value and maintain access to foreign markets. Stablecoins are particularly attractive because they reduce exposure to price volatility while still operating outside traditional correspondent banking networks.

Crypto mining has also become part of Iran’s sanctions-evasion toolkit. By using subsidized electricity to mine Bitcoin, Iran can effectively convert domestic energy resources into a globally transferable digital asset.

The strategy comes with costs. Mining places additional strain on Iran’s electricity grid and has been linked to power shortages and public frustration. Yet for a sanctioned economy, the logic remains compelling: when access to conventional finance is restricted, any mechanism capable of transforming local resources into internationally usable value becomes strategically important.

Hormuz and crypto

Cryptocurrency has also emerged in discussions surrounding the Strait of Hormuz, one of the world’s most important energy chokepoints.

Advertisement

Chainalysis reported recently that Iran intended to demand cryptocurrency payments from oil tankers seeking safe passage through the strait during periods of heightened tension. Whether such plans were fully implemented is less important than what they reveal about the potential role of digital assets in future geopolitical confrontations.

For Tehran, cryptocurrency offers several advantages in such scenarios. Payments can move rapidly across borders, avoid some traditional banking restrictions and reduce exposure to frozen accounts or conventional financial controls.

The prospect of crypto-based payments linked to maritime security demonstrates how digital assets could potentially be used not only to move money quietly but also to generate revenue during periods of geopolitical crisis.

The US Treasury has warned of sanctions risks associated with Iranian demands for transit-related payments through the Strait of Hormuz, including payments made through digital assets, fiat currency, offsets, swaps or other arrangements.

Blockchain evasion limits

Advertisement

Despite its advantages, cryptocurrency is not a magic shield against sanctions.

Blockchain transactions often leave traces that can be analyzed by firms such as Chainalysis and Elliptic or by government financial-intelligence agencies.

Once the United States designates a platform such as Nobitex, international exchanges, liquidity providers and counterparties face increased risks if they continue interacting with Iranian-linked wallets. This pushes activity toward smaller, less liquid and often riskier channels.

The sanctions also highlight another vulnerability. Treasury officials noted that Nobitex suffered a major hack in June 2025, underscoring the risks associated with relying on digital financial infrastructure.

Another area of interest is the role of the IRGC, which under Iran’s previous budget law was tasked with exporting roughly 700,000 barrels of crude oil per day—about half of the country’s exports at the time. The organization is also one of Iran’s largest infrastructure contractors.

Advertisement

While available data do not reveal where imported services originated or who ultimately benefited from them, the overlap illustrates the growing importance of non-traditional financial channels within Iran’s sanctioned economy.

Iran is likely to adapt. Activity may shift toward peer-to-peer trading, decentralized platforms, foreign intermediaries, stablecoin networks or new domestic exchanges. Yet each alternative carries costs, whether through reduced liquidity, greater compliance risks or increased exposure to future sanctions.

For Washington, the challenge is sustained enforcement. Sanctioning Nobitex will matter most if it is accompanied by international cooperation, improved blockchain intelligence, pressure on foreign exchanges and clear guidance for shipping firms, insurers and commodity traders.

The United States does not need to stop every Iranian crypto transaction to have an effect. It only needs to make the system more expensive, more traceable, riskier and less attractive for counterparties.

The Nobitex case illustrates how financial warfare has moved from banks to blockchains. Digital assets have given Tehran greater flexibility under sanctions, but they have also created new vulnerabilities.

Advertisement

The more Iran relies on crypto infrastructure, the more that infrastructure becomes part of the sanctions battlefield.

Crypto

FBI arrests man accused of using Steam games to drain victims’ crypto wallets | TechCrunch

Published

on

FBI arrests man accused of using Steam games to drain victims’ crypto wallets | TechCrunch

U.S. prosecutors have accused a Florida man of uploading fake video games that contained malware to Steam, the popular PC games platform. Once victims downloaded and installed the games, the malware was designed to infect their computers, steal their passwords and other data, and drain their crypto wallets, according to a criminal complaint.

On Tuesday, the FBI arrested Zyaire Wilkins, a 21-year-old Florida resident and student. On Wednesday, prosecutors accused him and a number of unnamed co-conspirators of hacking crimes. Over the past two years, Wilkins and his partners allegedly published several malware-laden video games on Steam, including BlockBlasters, Dashverse, Lampy, Lunara, and PirateFi. Using that malware, says the FBI, Wilkins and his accomplices infected around 8,000 victims, and then hacked around 80 cryptocurrency wallets to steal at least $220,000 worth of crypto.

Wilkins and the others marketed their malicious video games on Discord, LinkedIn, and Telegram, according to the authorities.  

Wilkins’ lawyer did not respond to a request for comment. 

In March, the FBI announced that it was investigating a hacker suspected of using malware-embedded video games published on Steam to hack victims. In the announcement, the bureau called for people who downloaded the malicious games, which included those named in this week’s complaint, to come forward and provide evidence to aid the investigation. 

Advertisement

In the last year, Steam’s maker Valve has removed several video games from its platform after they were found to contain malware, including PirateFi. All the games were designed to look legitimate, to the point that players could install them and play them, but they all contained malware. 

After the FBI identified another person involved in the crimes, according to the complaint, federal agents interviewed them. The unnamed person said they worked with other people to raise money to launch and market the malicious games in return for sharing some of the stolen cryptocurrency. The FBI identified a specific crypto account involved in the scheme, and then traced cryptocurrency payments made with that account to buy several gift cards, including for Uber Eats. After subpoenaing Uber, the feds were able to see that the gift cards were linked to an account that made deliveries to Wilkins, who went by the nickname Sibel.eth online, according to the complaint. 

The feds then got a search warrant for Wilkins’ residence, where they seized his MacBook laptop, cellphones, other devices, and digital wallets. According to the complaint, he refused to speak or answer any questions.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

Advertisement
Continue Reading

Crypto

DeFi’s Newest Threat: How Malicious Liquidity Pools Are Trick-Quoting Ethereum and Polygon Users

Published

on

DeFi’s Newest Threat: How Malicious Liquidity Pools Are Trick-Quoting Ethereum and Polygon Users

Key Takeaways

A ‘Jekyll and Hyde’ Tactic

A newly uncovered class of malicious decentralized finance ( DeFi) liquidity pools is targeting the core infrastructure that cryptocurrency traders rely on to find the best prices, according to new research published July 16 by DeFi infrastructure firm Enso.

The company is calling the deceptive setups “toxic pools.” Unlike typical cryptocurrency hacks that drain funds directly from smart contracts, these pools are engineered to systematically trick transaction simulations. They return attractive, highly competitive price quotes when a crypto wallet or decentralized exchange ( DEX) aggregator runs a simulation, but they alter their behavior the moment the transaction is actually executed on the blockchain.

The result is a subtle, systemic drain: traders receive significantly worse execution prices than they were quoted, or their transactions fail, burning network fees in the process.

“Our investigation leads us to believe this is not simply another isolated smart contract exploit,” said Milos Costantini, co-founder and chief product officer at Enso. “The industry has spent years optimizing price discovery. Our findings suggest the next challenge is verifying execution integrity.”

According to Enso’s report, toxic pools exploit the off-chain “dry-run” simulations that wallets use to preview trades. The malicious contracts detect when they are running in a read-only simulation environment and return an artificially optimized price. Once the transaction is actually broadcast on-chain, the pool alters its mathematical logic to execute the trade at a degraded rate.

Advertisement

To remain hidden from security systems, these pools alternate between honest and malicious states, rendering static code scanners and historical reputation filters ineffective. This bait-and-switch design degrades the user experience and drains user funds through failed transactions. In one case study, a manipulated Curve pool triggered more than 37,000 reverted trades, forcing users to burn nearly $30,000 in gas fees.

Attackers are also exploiting next-generation, modular exchange architectures. On Polygon, a malicious “hook” — a smart contract plugin used in platforms like Uniswap v4 — lured routing systems with fake rates before triggering a 99.1% transaction failure rate.

Findings From On-Chain Forensic Analysis

The research, which spanned roughly two months of on-chain forensic analysis, combined historical archive- node data, transaction trace analysis and smart contract inspections. Enso engineers, with support from contacts at major DeFi protocols Curve Finance and Oku, identified active toxic pools operating across both the Ethereum and Polygon blockchains.

In one documented case study on Ethereum, a manipulated Curve pool processed more than 129,000 swaps. While the pool appeared to be the optimal route, it delivered worse execution than quoted, leading to approximately $225,000 in overstated quotes.

Furthermore, Enso’s team identified multiple blockchain oracle contracts deployed by the same operator to support additional pools, indicating the tactic is likely more widespread than the two documented cases and could represent an emerging template for on-chain extraction.

Advertisement

The findings present a direct challenge to the user-facing layer of the DeFi ecosystem. Popular wallets, consumer-facing interfaces and aggregators depend heavily on automated simulations to guarantee the “best path” for a user’s trade.

Enso’s report highlights that if routing infrastructure cannot distinguish between a legitimate quote and a manipulated one, front-ends will continue to steer users toward these traps. This creates potential legal and financial liability risks for wallet providers and interface operators who promise “best execution” but routinely deliver toxic routes.

In response to the threat, Enso announced it has updated its execution-protection product, Enso Shield, to include dedicated toxic-pool detection. The security tool is designed to bypass standard simulation methods by analyzing live on-chain context, monitoring quote history and using transaction traces to spot execution discrepancies.

Rather than blaming individual decentralized exchanges, Enso has called on the wider cryptocurrency industry to conduct further research into the manipulation of transaction simulations.

“If transaction simulations can be manipulated while real execution tells a different story,” Costantini said, “we need better ways to verify what users actually receive.”

Advertisement
Continue Reading

Crypto

New law protects consumers from cryptocurrency kiosk/ATM fraud | Maui Now

Published

on

New law protects consumers from cryptocurrency kiosk/ATM fraud | Maui Now

July 16, 2026, 5:00 AM HST

Cryptocurrency kiosk/ATM. PC: AARP

Starting Oct. 1, cryptocurrency kiosk/ATMs that accept deposits will no longer be allowed in Hawai’i as a new consumer protection law takes effect.

Hawai’i is now the 35th state to enact a law to protect consumers from losing money in scams involving cryptocurrency kiosk/ATMs and is the first state to ban kiosks that accept deposits. Four other states have completely banned these machines. Other states have imposed transaction limits, mandated refunds for fraud, increased warning signs, required printed receipts and passed other consumer safeguards.

Advertisement

“The use of cryptocurrency kiosks in scams was increasing exponentially in Hawai’i and across the nation. Last year, the FBI said Hawai’i consumers reported losing $3.85 million through fraud involving cryptocurrency kioks. That’s nearly four times the amount reported lost in 2024,” said Keali’i Lopez, AARP Hawai‘i state director. “That’s why AARP fought hard to pass Act 224. We’re grateful to our advocacy volunteers and others who shared fraud stories, testified, called and sent letters and emails to help pass the law. We’re also thankful to lawmakers who acted decisively to protect consumers.”

The FBI said kupuna were especially vulnerable to cryptocurrency kiosk/ATM fraud and accounted for the majority of the losses. The machines look like bank ATMS and could be found in grocery stores, convenience stores, pharmacies, gas stations and other locations.

“Fraudsters use cryptocurrency kiosks like a getaway car in a bank robbery,” Lopez said. “They convince consumers through romance scams, by posing as an IRS agent or other official, or through a technology scam, to take money out of their banks and deposit it in the cryptocurrency kiosk and once the money is put into a scammer’s cryptocurrency wallet, it is gone.”

Advertisement
Continue Reading
Advertisement

Trending