2026-06-06 is live. RBL, certificate, and uptime monitoring — now in public beta.

News

Sanctioned Grinex Exchange Halts Operations After $13.74M Breach It Blames on Western Intelligence


Grinex, an exchange incorporated in Kyrgyzstan and placed under sanctions by both the U.K. and the U.S. last year, announced it is suspending trading and other services following what it describes as a major cyber intrusion that resulted in the loss of $13.74 million.

The company characterized the incident as a sophisticated, large-scale attack bearing indicators commonly associated with foreign intelligence services and said the theft involved more than 1 billion rubles of customers’ funds.

In a statement published on its site, Grinex argued that forensic traces and the technical profile of the breach point to resources and capabilities usually available only to state-backed actors, and that early findings imply the operation aimed specifically to harm Russia’s financial sovereignty. A company spokesperson added that the platform’s infrastructure has faced attacks since its inception, and that the recent incident represents a step up intended to unsettle the domestic financial system.

Investigators and analysts believe Grinex is effectively a relaunch of Garantex, a crypto venue sanctioned by the U.S. Treasury in April 2022 for facilitating money laundering connected to ransomware groups and darknet markets such as Conti and Hydra. The Treasury broadened those measures in August 2025 after alleging Garantex processed more than $100 million in illicit activity and continued to enable laundering.

According to the Treasury and blockchain intelligence companies Elliptic and TRM Labs, Garantex shifted its customer base onto Grinex following the sanctions and kept operating by relying on a ruble-pegged stablecoin known as A7A5.

A report from Elliptic published in February also flagged Rapira - an exchange incorporated in Georgia with an office in Moscow - as having conducted direct cryptoasset flows to and from Grinex exceeding $72 million, underscoring how platforms with Russian connections continue to facilitate efforts to evade sanctions.

Elliptic’s timeline places the Grinex theft on April 15, 2026 at about 12:00 UTC, and says the stolen balances were forwarded to additional addresses on the TRON and Ethereum networks. The firm noted the USDT was quickly swapped for assets such as TRX or ETH, a conversion step taken to reduce the risk of the seized stablecoins being frozen by Tether.

TRM Labs reported roughly 70 addresses tied to the episode and observed that TokenSpot - a Kyrgyzstan-based exchange likely acting as a front for Grinex - was impacted at the same time. On the day of the breach TokenSpot posted a Telegram notice citing technical maintenance and then announced on April 16 that full services had resumed. TRM estimates the attacker took under $5,000 from TokenSpot; those funds were moved through two TokenSpot-controlled addresses into the same consolidation wallet used by addresses linked to Grinex.

Chainalysis’ breakdown of the events highlighted that the stablecoins were rapidly exchanged for tokens that are harder to freeze, calling this pattern of swift conversion a common laundering tactic employed by malicious actors seeking to move proceeds before custodians or issuers can intervene.

Chainalysis also urged caution in interpreting the incident, noting that because of Grinex’s heavy sanctioning, its constrained ecosystem, and the on-chain obfuscation methods previously associated with Garantex, the possibility of a staged or false-flag operation cannot be ruled out. Whether the disruption stems from an independent criminal intrusion or a coordinated internal operation tied to Russia-linked actors, the outage deals a substantial setback to the network of services that have been used to circumvent sanctions.

First published on April 19, 2026.
Last updated on April 25, 2026.