Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    80% of Major SpaceX Investors Deal With Crypto
    80% of Major SpaceX Investors Deal With Crypto
    SEC Cancels Crypto Meeting Why Rulemaking Just Hit Another Wall
    SEC Cancels Crypto Meeting: Why Rulemaking Just Hit Another Wall
    Internet Computer (ICP) Tops Blockchain Transactions Chart: Here’s What It's Actually Doing
    Internet Computer (ICP) Tops Blockchain Transactions Chart: Here’s What It’s Actually Doing
    Ethereum’s Staking War Why EIP-8361 Has DeFi Leaders Fighting Back
    Ethereum’s Staking War: Why EIP-8361 Has DeFi Leaders Fighting Back
    Nothing Is 100% Safe in Crypto Bitcoin’s Coldcard Exploit and Growing Security Crisis 
    Nothing Is 100% Safe in Crypto: Bitcoin’s Coldcard Exploit and Growing Security Crisis 
  • Opinion
    OpinionShow More
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
    CLARITY Act The Bill Exists, the Deal Does Not, Trump Has to Wait
    CLARITY Act: The Bill Exists, the Deal Does Not, Trump Has to Wait
    The Execution Gap: Why the Next Breakthrough in Financial AI is Human Behavior
    The Execution Gap: Why the Next Breakthrough in Financial AI is Human Behavior
  • Learn
    • Explained
    • How To
    • Insights
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Industry

Grinex Hack: Russian Exchange Points Finger at West for $13M Crypto Heist

In the statement posted on its website and Telegram channel, the exchange accused "foreign special services" of unfriendly states of orchestrating the breach, stating that the digital footprints pointed to resources and technology available only to state-level actors.

Written By Gopal Solanky
Published 2026-04-17·Updated 4 months ago
Make The Crypto Times preferred on GoogleGoogle
Grinex Hack: Russian Exchange Points Finger at West for $13M Crypto Heist
Show AI Summary
Grinex accused “foreign special services” of hostile states of orchestrating the state-backed attack, framing it as an assault on Russia’s financial sovereignty amid the ongoing war in Ukraine and Western sanctions.
The Kyrgyzstan-registered crypto exchange suspended all operations after a sophisticated cyberattack drained over $13–15 million (1+ billion RUB) from user wallets, mostly TRC-20 USDT on Tron.
Widely seen as the rebranded successor to the sanctioned Garantex exchange, Grinex now faces uncertain recovery for users, with stolen funds consolidated into a single TRX wallet under active blockchain monitoring.

On April 16, 2026, Grinex—a Kyrgyzstan-registered cryptocurrency exchange heavily tied to Russia’s domestic crypto-ruble ecosystem—suddenly halted all trading, deposits, and withdrawals after suffering a major security breach. 

The exchange described the sophisticated cyberattack as state-sponsored, claiming to be carried out by “Western intelligence agencies,” that drained more than one billion rubles, roughly $13 to $15 million, from user funds.

In the statement posted on its website and Telegram channel, the exchange accused “foreign special services” of unfriendly states of orchestrating the breach, stating that the digital footprints pointed to resources and technology available only to state-level actors. 

Grinex framed the incident as a direct assault on Russia’s financial sovereignty, coming amid ongoing geopolitical tensions. The exchange claims that this is a “direct theft of assets from Russian citizens and companies using complex cyberattacks.”

Grinex Crypto Exchange Claims $1B Cyberattack on Russian Users
Source: grinex.io

“The nature of the attack indicates an unprecedented level of resources… aimed at directly harming Russia’s financial sovereignty,” the exchange said. It has suspended operations indefinitely and handed over details to Russian law enforcement. 

No independent evidence has surfaced to support the claim of state involvement, and Western governments have not commented. 

“From the very beginning, the exchange’s infrastructure has been subject to attacks,” a spokesperson from Grinex said. “We have documented systematic attempts to restrict the transfer of cryptocurrency outside the CIS: the exchange was placed on sanctions lists, crypto wallets were deliberately targeted, and transactions were blocked.” 

The Hack: What Was Taken and Where It Went

In its statement, Grinex published a list of roughly 54 drained wallets, mostly holding TRC-20 USDT on the Tron blockchain, along with a handful of Ethereum addresses. 

The largest single drains included wallets losing hundreds of thousands of dollars each. The exchange reported the total theft at about 13.74 million USDT, though blockchain analytics firm TRM Labs tracked flows closer to $15 million.

As of publishing, all the stolen USDT balance was swapped through various services and consolidated into TRX (Tron blockchain’s native token). The bulk ended up in a single identifiable wallet: TH9k…neKVa, which holds around 45.9 million TRX—equivalent to roughly $15 million at prevailing prices. 

The address remains publicly viewable on Tronscan, and the funds appear to have been laundered through rapid conversions to obscure the trail.

TRM Labs noted that a related Kyrgyzstan-based platform, TokenSpot, with deep on-chain connections to Grinex, also appears to have been hit in the same operation.

Users with balances on the platform now face an uncertain wait. Grinex has promised to cooperate with authorities, but in the opaque world of sanctioned crypto exchanges, full recovery is far from guaranteed.

Claims of a state-backed attack in the shadow of war

Grinex’s accusation carries a familiar ring in the context of Russia’s war with Ukraine, now entering its fifth year. The exchange portrayed the hack as part of a broader campaign by “hostile states” to undermine Russia’s ability to conduct business outside the traditional SWIFT system and Western-controlled finance. 

“From the very beginning, the exchange’s infrastructure has been subject to attacks,” Grinex spokesperson said, citing prior sanctions listings, blocked wallets, and restrictions on moving crypto outside the CIS—a loose regional alliance of 9 post-Soviet countries, including Russia, Belarus, Kazakhstan, Kyrgyzstan, and others.

This narrative fits neatly into Moscow’s longstanding claims that Western powers use sanctions and covert operations to wage economic war against Russia. 

While state actors certainly possess advanced cyber capabilities, exchange hacks are also common among sophisticated criminal groups looking to cash out quickly. No public forensic evidence has yet linked the attack to any specific intelligence agency, Western or otherwise. Even Reuters and other outlets noted they could not independently verify the claim.

The timing, however, is notable. Grinex positioned itself as a vital lifeline for Russian firms navigating sanctions imposed since the full-scale invasion of Ukraine in 2022. By facilitating P2P trades, USDT settlements, and even a ruble-pegged token called A7A5, it helped keep some cross-border and domestic flows alive when traditional banking channels tightened.

From Garantex to Grinex: A history of sanctions evasion

Grinex didn’t emerge in a vacuum. It is widely viewed by Western authorities and blockchain intelligence firms as the direct successor to Garantex, a Moscow-based exchange sanctioned by the U.S. Treasury’s OFAC in 2022 for processing over $100 million in ransomware payments and other illicit funds. 

During its runtime, Garantex became a go-to platform for cybercriminals, including groups linked to Conti, LockBit, and others.

In March 2025, U.S., German, and Finnish authorities disrupted Garantex in a coordinated operation, seizing its domain and freezing millions in crypto. Indictments followed against key figures. Almost immediately, user funds and liquidity shifted to Grinex, which replicated much of Garantex’s interface and even helped “recover” balances via the A7A5 stablecoin.

The U.S. Treasury sanctioned Grinex itself in August 2025, along with several associated companies and executives, explicitly calling it a sanctions-evasion vehicle created by Garantex insiders. Despite the designations, the platform continued operating, serving Russian-speaking users and businesses seeking alternatives to frozen banking channels.

Its business model focused on low fees, fast ruble-crypto conversions, and regional offices inside Russia—all while emphasizing its purported licensing under CIS rules. Critics, however, saw it as another chapter in a persistent cat-and-mouse game: when one door closes, another opens under a slightly different name.

What Happens Next?

For now, the site displays a maintenance notice detailing the hack and listing the stolen wallets. Trading remains frozen. Russian authorities have reportedly opened a criminal case, but the cross-border nature of crypto—combined with international sanctions—complicates any recovery effort.

Blockchain watchers continue to monitor the consolidation wallet. If the funds move again or get tumbled through mixers, tracing will grow even harder.

The incident underscores the double-edged sword of crypto in sanctioned economies: a tool for resilience that also attracts both criminals and sophisticated adversaries. Whether this was a criminal heist, a state operation, or something in between may never be fully known outside classified circles.

What is clear is that users who parked funds on Grinex—drawn by promises of easy ruble-crypto access in a restricted financial environment—are once again reminded of an old truth in this space: not your keys, not your coins. Especially when the platform itself sits at the volatile intersection of geopolitics, sanctions, and high-stakes cyber warfare. 

Also read: Circle Faces Lawsuit Over Inefficient Response to $280M Exploit

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

TAGGED:Crypto ExchangeCrypto HackRussia
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Latest News

Fake DeFiLlama App Removed After Security Test Drains Crypto Wallet
Fake DeFiLlama App Removed After Security Test Drains Crypto Wallet
Bitcoin ETFs Lose $390M as Solana Funds Buck Broader Crypto Outflows
Bitcoin ETFs Lose $390M as Solana Funds Buck Broader Crypto Outflows
CZ Warns Bitcoin Scarcity Could Put Whole Coins Beyond Millionaires
CZ Warns Bitcoin Scarcity Could Put Whole Coins Beyond Millionaires
80% of Major SpaceX Investors Deal With Crypto
80% of Major SpaceX Investors Deal With Crypto
Why Is IREN Stock Up 50% Since Its Late-July Low
Why Is IREN Stock Up 50% Since Its Late-July Low?

Find Us on Socials

You may also like

Coldcard Attackers Likely Used Unrestricted AI Models, Galaxy Says

Coldcard Attackers Likely Used Unrestricted AI Models, Galaxy Says

SOL Goes Live on XRP Ledger as Axelar Brings Solana to XRPL

SOL Goes Live on XRP Ledger as Axelar Brings Solana to XRPL

Cboe Files With SEC to List 3x Bitcoin and Ether ETFs

Cboe Files With SEC to List 3x Bitcoin and Ether ETFs

Lido Calls for Deeper Review Before EIP-8363 Advances

Lido Calls for Deeper Review Before EIP-8363 Advances

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Videos
Glossary

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information