Grinex, the Kyrgyzstan-registered cryptocurrency exchange that emerged as Garantex's operational successor in early 2025, suspended all operations on April 16, 2026, after reporting the theft of approximately $13.7 million in user funds. The exchange attributed the attack to "special services of ...
"Given the exchange's heavily sanctioned status, its restricted ecosystem, and the on-chain use of Garantex's preferred obfuscation techniques, it is worth considering if this incident could be a false flag attack." — Chainalysis, Blog Analysis (April 17, 2026)
Grinex, the Kyrgyzstan-registered cryptocurrency exchange that emerged as Garantex's operational successor in early 2025, suspended all operations on April 16, 2026, after reporting the theft of approximately $13.7 million in user funds. The exchange attributed the attack to "special services of unfriendly states," a claim that on-chain forensics firms Chainalysis, Elliptic, and TRM Labs have not independently verified. TRM Labs identified roughly 70 wallet addresses connected to the incident — 16 more than Grinex publicly disclosed — and assessed the event as "more likely an external cyber operation rather than an exit scam."
The incident effectively shuts down a platform that, along with its predecessor Garantex, processed over $100 billion in transactions since its 2022 OFAC designation — more than 70% of which involved sanctioned entities and jurisdictions, according to TRM Labs. It also disrupts the infrastructure behind A7A5, a ruble-backed stablecoin that surpassed $100 billion in total transfers in under a year and served as Russia's primary crypto conduit for circumventing SWIFT exclusion. Three blockchain analytics firms flagged the possibility that the incident may not be what it appears, given on-chain patterns consistent with Garantex's own historical obfuscation methods.
At approximately 12:00 UTC on April 15, 2026, funds began moving out of Grinex-controlled wallets. The theft predominantly involved USDT on the TRON blockchain. According to Elliptic, the attacker converted stolen USDT to TRX via SunSwap on TRON, or to ETH on Ethereum, before consolidating proceeds. The conversion to non-freezable tokens — a standard technique for preventing Tether from executing emergency freezes — occurred rapidly.
TRM Labs traced approximately $14.98 million across both Grinex and a second exchange, TokenSpot, to a single consolidation address holding roughly 45.9 million TRX. TRM identified approximately 70 wallet addresses linked to the incident. Grinex disclosed 54 affected addresses publicly. Four Ethereum addresses associated with the incident remain under investigation, with fund destinations not yet determined.
Grinex announced the suspension of operations on April 16, 2026, stating that "digital forensic evidence and the nature of the attack point to an unprecedented level of resources and technological sophistication — capabilities typically available exclusively to the agencies of hostile states." The exchange also claimed its infrastructure had been "under attack since the beginning of operations."
Grinex's origins are inseparable from Garantex, the Moscow-headquartered exchange that OFAC first sanctioned on April 5, 2022, for facilitating transactions tied to ransomware groups Conti, Ryuk, and LockBit, and the Hydra darknet marketplace. According to the U.S. Treasury Department, Garantex processed over $100 million in transactions directly associated with illicit actors.
In March 2025, a multinational law enforcement operation involving the FBI, Europol, Dutch National Police, German Federal Criminal Police, Finnish National Bureau of Investigation, and Estonian National Criminal Police seized Garantex's web domains (garantex.org, garantex.io, garantex.academy) and froze $26 million in cryptocurrency. The DOJ unsealed indictments against administrators Aleksej Besciokov, a 46-year-old Lithuanian national, and Aleksandr Mira Serda, a 40-year-old Russian co-founder and chief commercial officer.
Grinex was incorporated in Kyrgyzstan in December 2024 — three months before the takedown. Telegram channels affiliated with Garantex promoted Grinex within days of the seizure, advertising "familiar functionality." OFAC sanctioned Grinex on August 14, 2025, along with Old Vector LLC, the issuer of the A7A5 stablecoin.
By the time of its suspension, Grinex had processed over $6 billion in total cryptoasset transactions, according to Elliptic. The exchange also maintained operational ties to Rapira, a Georgia-incorporated entity with a Moscow office, which conducted $72 million in direct cryptoasset trades with Grinex, according to The Hacker News.
The most consequential element of the Garantex-Grinex infrastructure is the A7A5 stablecoin, a digital asset pegged to the Russian ruble. A7A5 surpassed $100 billion in cumulative transaction value in under one year from its January 2025 launch, according to Elliptic data published in February 2026.
A7A5 is issued by Old Vector LLC, a Kyrgyzstan-based entity. Its parent company is A7 LLC, a Russian cross-border settlement platform. Ownership traces to two sanctioned parties: Ilan Shor, a convicted Moldovan fraudster sanctioned by the U.S. for undermining Moldovan elections, and Promsvyazbank (PSB), a Russian state-owned defense bank sanctioned for its role supporting Russia's military sector. A7A5 claims 1:1 ruble backing via PSB deposits.
Key metrics as of Elliptic's most recent data:
The token's functional purpose was to provide Russian users a "safe harbor" for accessing USDT liquidity while avoiding seizure risk. When Garantex was taken down in March 2025, former customers received A7A5 credits equivalent to their frozen balances, redeemable on Grinex. The stablecoin effectively replaced SWIFT as a cross-border settlement mechanism for users cut off from the international banking system following Russia's invasion of Ukraine.
U.S., U.K., and EU sanctions on A7A5 and Old Vector in August 2025 have slowed growth. Uniswap blocklisted the token in November 2025. DEX liquidity provision collapsed from $150 million daily in July 2025 to $0.5 million weekly by November 2025. No major new issuances have occurred since late July 2025.
The April 15 attack also struck TokenSpot, a Kyrgyzstan-based exchange that TRM Labs assesses as "a likely front company for Garantex, based on on-chain analysis." TokenSpot lost under $5,000 in the incident but its operational connection to Grinex is significant.
TRM Labs data shows TokenSpot processed $4 billion in transactions between December 2023 and March 2026. Combined transfers between TokenSpot and the Garantex/Grinex ecosystem totaled $88 million, with TokenSpot receiving $12 million back from Grinex. TokenSpot also routed $257.5 million to the A7 network.
Two TokenSpot addresses were found routing funds to the same consolidation address used by the attacker for Grinex funds. Both TokenSpot addresses went offline on April 15, the same day as the Grinex attack, suggesting a single coordinated operation against both platforms. TRM also identified approximately $1 million in funds from a Houthi-linked wallet flowing through TokenSpot, indicating the platform's role extended beyond Russian sanctions evasion.
Three major blockchain analytics firms have published analyses questioning Grinex's attribution claims.
Chainalysis noted that the on-chain laundering techniques used in the attack — specifically the rapid swapping from stablecoins to decentralized tokens to avoid freezing — are "a hallmark tactic of cybercriminals and illicit actors." The firm explicitly flagged the possibility of a false flag, noting the use of "Garantex's preferred obfuscation techniques."
TRM Labs stated it "has not independently verified" Grinex's attribution to Western intelligence services and assessed the incident as "more likely an external cyber operation rather than an exit scam," based on the indiscriminate targeting pattern across both Grinex and TokenSpot.
Elliptic observed that the stolen funds were "quickly swapped for a non-freezable token" and that the operational patterns were consistent with standard crypto-criminal laundering rather than state-level operations. No technical evidence or indicators supporting state attribution were provided by Grinex.
Grinex provided no forensic evidence, no indicators of compromise, and no technical attribution data. The exchange's sole evidence was the characterization that the attack showed "an unprecedented level of resources and technological sophistication." Independent analysts have not corroborated this claim.
The Grinex shutdown exposes both the limits and the partial effectiveness of the current sanctions enforcement approach against crypto-based evasion networks.
On one hand, the Garantex-Grinex cycle demonstrates that sanctioned entities can reconstitute within weeks. Grinex was incorporated in Kyrgyzstan three months before Garantex's takedown. The A7A5 stablecoin transferred $100 billion in under 12 months despite Garantex being sanctioned since 2022. The infrastructure migrated across jurisdictions — from Russia to Kyrgyzstan to Georgia — faster than enforcement action could follow.
On the other hand, sanctions pressure has degraded the ecosystem's operational capacity. A7A5 DEX liquidity dropped 99.7% from its July 2025 peak. No major new token issuances have occurred in nine months. The Grinex suspension — whether caused by external attack or internal factors — removes the primary trading venue. Tether's ability to freeze USDT on TRON proved sufficiently threatening that the attacker's first move was converting to non-freezable assets.
The episode underscores a structural tension: law enforcement seized Garantex's domains and databases in March 2025, but the operators had already pre-positioned successor infrastructure. OFAC sanctioned the successor five months later. The entity was operational for roughly 16 months total before this week's shutdown.
The Grinex suspension marks the second shutdown of a Garantex-linked exchange in 14 months. The first — Garantex's March 2025 domain seizure — was reversed within days through Grinex's launch. Whether the same reconstitution pattern repeats depends on enforcement speed. OFAC, the FBI, and Europol hold Garantex's customer databases, obtained during the 2025 takedown. The A7A5 token's infrastructure remains technically functional, though severely degraded by sanctions pressure.
The $13.7 million loss is small relative to the network's $100 billion throughput. The greater damage is operational: Grinex's suspension removes the primary fiat on-ramp for A7A5 and the most accessible sanctions evasion venue for Russian crypto users. The question now is whether a third successor exchange emerges, and how quickly.