Iran’s Mabna Institute, the hacking organization accused of stealing intellectual property for the Islamic Revolutionary Guard Corps, has been doing more than breaking into university servers. According to blockchain intelligence firm TRM Labs, roughly 30 crypto addresses tied to Mabna defendants received about $16.8 million in total inflows between January 2018 and August 2026, spanning Bitcoin, Ethereum, and TRON.
One person, 92% of the money
The most striking data point in the TRM Labs findings is how concentrated the flows were. Defendant Keyvan Fayaz controlled 10 of the scrutinized addresses, and those addresses alone accounted for roughly $15.5 million, or 92% of all inflows across the entire cluster.
A second defendant, Behzad Mesri, was associated with layered transactions that ultimately routed toward a centralized exchange deposit. The residual balance sitting across all 30 addresses at the time of analysis was approximately $202,662, meaning nearly all of the $16.8 million had already been moved or spent.
Who is the Mabna Institute and why does this matter now
Mabna was founded around 2013 in Tehran and spent years operating as what U.S. prosecutors describe as a cyber-mercenary outfit working on behalf of the IRGC. The group’s alleged resume includes compromising 144 U.S. universities, 178 foreign universities, and an array of private companies and government entities, siphoning more than 31 terabytes of data in the process.
The first federal indictment came in March 2018, charging nine defendants. The August 2026 superseding indictment from the Department of Justice added eight more names, bringing the total to 17 individuals facing charges related to cyber intrusions carried out on behalf of Iranian state interests.
The same week, on August 24, the U.S. Treasury Department designated five individuals connected to Mabna under what it called Operation Economic Outcast, invoking Executive Order 13902. That executive order explicitly identifies digital assets as a sanctionable sector, meaning entities that engage in significant Iran-related crypto activity now face secondary sanctions risk.
What exchanges and compliance teams should take from this
For crypto businesses, any address that touched the 30 flagged wallets, even indirectly through multiple hops, now carries elevated risk in transaction monitoring systems. The $16.8 million flowing through the network leaves a wide contamination radius for blockchain analytics exposure scoring.
Any exchange or OTC desk that processed transactions for addresses in Fayaz’s cluster between 2018 and 2026 may find itself fielding regulatory inquiries, given that his addresses accounted for the overwhelming majority of the cluster’s volume.
The TRON component of the address cluster is also notable. TRON-based stablecoins, particularly USDT, have become a preferred rail for moving value across jurisdictions with limited banking access, and the presence of TRON addresses alongside Bitcoin and Ethereum in a sanctions-adjacent context fits a pattern that U.S. authorities have flagged in multiple enforcement actions over the past two years.
With 17 defendants indicted, five sanctioned, and a forensic trail stretching back six years across three blockchains, the Mabna case is one of the more detailed public examples of how state-linked actors use crypto infrastructure and how regulators intend to respond when they do.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

12 hours ago
6







English (US) ·