Original briefings. Zero spin.
Every story is an original briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.
Blockchain Analysts Trace $16.8 Million to Iranian Hacker Network as Treasury Names Crypto a Sanctionable Sector

Since the Justice Department unsealed its superseding indictment against 17 alleged Iranian hackers on August 18, blockchain investigators have been digging into where the money went. The answer, according to TRM Labs: at least $16.8 million, moved through 30 crypto addresses tied to Mabna Institute defendants between January 2018 and August 2026.
The firm's analysis, published August 24, found the money spread across Bitcoin, Ethereum, and TRON. But it wasn't evenly spread. Defendant Keyvan Fayaz alone controlled 10 of the 30 flagged addresses, and those addresses absorbed roughly $15.5 million, 92% of everything that moved through the entire network, according to TRM Labs.
A second defendant, Behzad Mesri, shows up in the TRM Labs data too, with transactions that were layered through multiple hops before landing at a centralized exchange deposit. Mesri was previously charged over the 2017 HBO breach, and Decrypt reported that prosecutors say he and five other defendants, Saeid Houshyar, Manouchehr Hashemloo, Fayaz, Saber Shahbazi Ballojeh, and Arman Kahzadian, tried to extort HBO for roughly $6 million in Bitcoin.
By the time TRM Labs ran its analysis, only about $202,662 remained sitting in the 30 addresses. The rest, more than $16.6 million, had already been moved out or spent.
The Treasury action behind the numbers
The crypto tracing didn't happen in isolation. On August 24, the Treasury Department launched what it called Operation Economic Outcast, a sweeping action that designated nearly 60 Iran-linked entities, individuals, and vessels, according to TRM Labs' own writeup of the Treasury action. Secretary of the Treasury Scott Bessent described it as an economic campaign meant to cut off the financial lifelines sustaining the Iranian regime.
Buried in that action were five sectoral sanctions determinations issued under Executive Order 13902, an order originally aimed at Iran's construction, mining, textiles, and other industries. Treasury added digital assets to that list on August 24. Any person or company anywhere, not just Iranians, doing significant business in Iran-related crypto now faces secondary sanctions exposure.
Five of the individuals named in the Treasury designations were also charged in the DOJ's August 18 indictment, and OFAC specifically listed 30 crypto addresses connected to them, the same 30 addresses TRM Labs analyzed. Four of those five individuals directly control the wallets Treasury flagged.
Who the DOJ says ran the operation
CyberScoop reported that the Mabna Institute was founded around 2013 by Gholamreza Rafatnejad and Ehsan Mohammadi, with the stated goal of helping Iranian universities and research organizations steal scientific work from abroad. The institute allegedly paid hackers-for-hire to do it.
The scale, according to the DOJ press release cited by CyberScoop, is staggering: more than 100,000 compromised professor email accounts worldwide, 8,000 compromised accounts across 144 U.S. universities and 178 foreign universities, and at least 31.5 terabytes of stolen data including academic journals, dissertations, and e-books. U.S. universities alone spent more than $3.4 billion trying to procure and protect that kind of data and intellectual property, the DOJ said.
Jamie McDonald, U.S. Attorney for the Southern District of New York, said the new indictment "reveal[s] the broader network allegedly behind a sweeping, state-sponsored campaign to steal research and intellectual property from American universities, businesses, and government institutions." FBI Cyber Division Assistant Director Brett Leatherman put it more bluntly, saying the defendants "built and profited from a sprawling hacking-for-hire operation."
The State Department's Rewards for Justice program is now offering up to $10 million for information leading to the location of five of the defendants, according to Decrypt.
What this means for crypto compliance
TRM Labs and Crypto Briefing both flag the same practical fallout: any exchange, OTC desk, or wallet that processed transactions touching the 30 flagged addresses between 2018 and 2026, even indirectly through several transaction hops, now carries elevated risk scoring in blockchain analytics systems. Given that Fayaz's cluster alone accounted for 92% of the volume, platforms that unknowingly handled his transactions face the most exposure.
This isn't the first Iran-related crypto crackdown this year. Decrypt noted that Treasury sanctioned four Iranian crypto exchanges, including Nobitex, in June, tying them to terrorist financing and sanctions evasion, and froze more than $131 million across four wallets linked to Iran's central bank and armed forces in July. Two more exchanges got hit with sanctions in August for allegedly laundering money for the IRGC.
What remains unresolved is how much of the $16.6 million already withdrawn from the flagged wallets can actually be recovered or frozen, since the funds moved through exchanges before the sanctions designation existed. TRM Labs did not identify which specific exchanges received the deposits, only that a residual balance of roughly $202,662 remains traceable on-chain today.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.