← Back to Webthreepedia
WEBTHREEPEDIA RESEARCH

[MARKET UPDATE] Grinex Halts After $13.7M Hack, Ending $100B Pipeline

Zephyra|April 18, 2026|BPF
EXECUTIVE SUMMARY

Grinex, the Kyrgyzstan-registered cryptocurrency exchange that emerged as Garantex's operational successor in early 2025, suspended all operations on April 16, 2026, after reporting the theft of approximately $13.7 million in user funds. The exchange attributed the attack to "special services of ...

"Given the exchange's heavily sanctioned status, its restricted ecosystem, and the on-chain use of Garantex's preferred obfuscation techniques, it is worth considering if this incident could be a false flag attack." — Chainalysis, Blog Analysis (April 17, 2026)

Executive Summary

Grinex, the Kyrgyzstan-registered cryptocurrency exchange that emerged as Garantex's operational successor in early 2025, suspended all operations on April 16, 2026, after reporting the theft of approximately $13.7 million in user funds. The exchange attributed the attack to "special services of unfriendly states," a claim that on-chain forensics firms Chainalysis, Elliptic, and TRM Labs have not independently verified. TRM Labs identified roughly 70 wallet addresses connected to the incident — 16 more than Grinex publicly disclosed — and assessed the event as "more likely an external cyber operation rather than an exit scam."

The incident effectively shuts down a platform that, along with its predecessor Garantex, processed over $100 billion in transactions since its 2022 OFAC designation — more than 70% of which involved sanctioned entities and jurisdictions, according to TRM Labs. It also disrupts the infrastructure behind A7A5, a ruble-backed stablecoin that surpassed $100 billion in total transfers in under a year and served as Russia's primary crypto conduit for circumventing SWIFT exclusion. Three blockchain analytics firms flagged the possibility that the incident may not be what it appears, given on-chain patterns consistent with Garantex's own historical obfuscation methods.

Table of Contents

  1. The Attack: What the On-Chain Data Shows
  2. Garantex to Grinex: The Sanctions Evasion Pipeline
  3. The A7A5 Stablecoin: $100 Billion in Shadow Finance
  4. TokenSpot: The Third Node
  5. Attribution and the False Flag Question
  6. Implications for Crypto's Sanctions Enforcement Model
  7. Key Takeaways
  8. Conclusion
  9. Sources & References

The Attack: What the On-Chain Data Shows

At approximately 12:00 UTC on April 15, 2026, funds began moving out of Grinex-controlled wallets. The theft predominantly involved USDT on the TRON blockchain. According to Elliptic, the attacker converted stolen USDT to TRX via SunSwap on TRON, or to ETH on Ethereum, before consolidating proceeds. The conversion to non-freezable tokens — a standard technique for preventing Tether from executing emergency freezes — occurred rapidly.

TRM Labs traced approximately $14.98 million across both Grinex and a second exchange, TokenSpot, to a single consolidation address holding roughly 45.9 million TRX. TRM identified approximately 70 wallet addresses linked to the incident. Grinex disclosed 54 affected addresses publicly. Four Ethereum addresses associated with the incident remain under investigation, with fund destinations not yet determined.

Grinex announced the suspension of operations on April 16, 2026, stating that "digital forensic evidence and the nature of the attack point to an unprecedented level of resources and technological sophistication — capabilities typically available exclusively to the agencies of hostile states." The exchange also claimed its infrastructure had been "under attack since the beginning of operations."

Garantex to Grinex: The Sanctions Evasion Pipeline

Grinex's origins are inseparable from Garantex, the Moscow-headquartered exchange that OFAC first sanctioned on April 5, 2022, for facilitating transactions tied to ransomware groups Conti, Ryuk, and LockBit, and the Hydra darknet marketplace. According to the U.S. Treasury Department, Garantex processed over $100 million in transactions directly associated with illicit actors.

In March 2025, a multinational law enforcement operation involving the FBI, Europol, Dutch National Police, German Federal Criminal Police, Finnish National Bureau of Investigation, and Estonian National Criminal Police seized Garantex's web domains (garantex.org, garantex.io, garantex.academy) and froze $26 million in cryptocurrency. The DOJ unsealed indictments against administrators Aleksej Besciokov, a 46-year-old Lithuanian national, and Aleksandr Mira Serda, a 40-year-old Russian co-founder and chief commercial officer.

Grinex was incorporated in Kyrgyzstan in December 2024 — three months before the takedown. Telegram channels affiliated with Garantex promoted Grinex within days of the seizure, advertising "familiar functionality." OFAC sanctioned Grinex on August 14, 2025, along with Old Vector LLC, the issuer of the A7A5 stablecoin.

By the time of its suspension, Grinex had processed over $6 billion in total cryptoasset transactions, according to Elliptic. The exchange also maintained operational ties to Rapira, a Georgia-incorporated entity with a Moscow office, which conducted $72 million in direct cryptoasset trades with Grinex, according to The Hacker News.

The A7A5 Stablecoin: $100 Billion in Shadow Finance

The most consequential element of the Garantex-Grinex infrastructure is the A7A5 stablecoin, a digital asset pegged to the Russian ruble. A7A5 surpassed $100 billion in cumulative transaction value in under one year from its January 2025 launch, according to Elliptic data published in February 2026.

A7A5 is issued by Old Vector LLC, a Kyrgyzstan-based entity. Its parent company is A7 LLC, a Russian cross-border settlement platform. Ownership traces to two sanctioned parties: Ilan Shor, a convicted Moldovan fraudster sanctioned by the U.S. for undermining Moldovan elections, and Promsvyazbank (PSB), a Russian state-owned defense bank sanctioned for its role supporting Russia's military sector. A7A5 claims 1:1 ruble backing via PSB deposits.

Key metrics as of Elliptic's most recent data:

  • Circulation: ~42.5 billion A7A5 tokens ($547 million equivalent)
  • Accounts holding A7A5: 35,500 (up from 14,000 in July 2025)
  • Total distinct accounts transacting: 41,300 across ~250,000 transactions
  • Peak daily transfer volume: $1.5 billion (declined to ~$500 million daily)
  • Exchange volumes: $17.3 billion total — $11.2 billion in A7A5/ruble pairs, $6.1 billion in A7A5/USDT pairs
  • PSB card purchases through A7A5: $26 million
  • Digital promissory notes redeemed: 2,300 totaling $8.6 million

The token's functional purpose was to provide Russian users a "safe harbor" for accessing USDT liquidity while avoiding seizure risk. When Garantex was taken down in March 2025, former customers received A7A5 credits equivalent to their frozen balances, redeemable on Grinex. The stablecoin effectively replaced SWIFT as a cross-border settlement mechanism for users cut off from the international banking system following Russia's invasion of Ukraine.

U.S., U.K., and EU sanctions on A7A5 and Old Vector in August 2025 have slowed growth. Uniswap blocklisted the token in November 2025. DEX liquidity provision collapsed from $150 million daily in July 2025 to $0.5 million weekly by November 2025. No major new issuances have occurred since late July 2025.

TokenSpot: The Third Node

The April 15 attack also struck TokenSpot, a Kyrgyzstan-based exchange that TRM Labs assesses as "a likely front company for Garantex, based on on-chain analysis." TokenSpot lost under $5,000 in the incident but its operational connection to Grinex is significant.

TRM Labs data shows TokenSpot processed $4 billion in transactions between December 2023 and March 2026. Combined transfers between TokenSpot and the Garantex/Grinex ecosystem totaled $88 million, with TokenSpot receiving $12 million back from Grinex. TokenSpot also routed $257.5 million to the A7 network.

Two TokenSpot addresses were found routing funds to the same consolidation address used by the attacker for Grinex funds. Both TokenSpot addresses went offline on April 15, the same day as the Grinex attack, suggesting a single coordinated operation against both platforms. TRM also identified approximately $1 million in funds from a Houthi-linked wallet flowing through TokenSpot, indicating the platform's role extended beyond Russian sanctions evasion.

Attribution and the False Flag Question

Three major blockchain analytics firms have published analyses questioning Grinex's attribution claims.

Chainalysis noted that the on-chain laundering techniques used in the attack — specifically the rapid swapping from stablecoins to decentralized tokens to avoid freezing — are "a hallmark tactic of cybercriminals and illicit actors." The firm explicitly flagged the possibility of a false flag, noting the use of "Garantex's preferred obfuscation techniques."

TRM Labs stated it "has not independently verified" Grinex's attribution to Western intelligence services and assessed the incident as "more likely an external cyber operation rather than an exit scam," based on the indiscriminate targeting pattern across both Grinex and TokenSpot.

Elliptic observed that the stolen funds were "quickly swapped for a non-freezable token" and that the operational patterns were consistent with standard crypto-criminal laundering rather than state-level operations. No technical evidence or indicators supporting state attribution were provided by Grinex.

Grinex provided no forensic evidence, no indicators of compromise, and no technical attribution data. The exchange's sole evidence was the characterization that the attack showed "an unprecedented level of resources and technological sophistication." Independent analysts have not corroborated this claim.

Implications for Crypto's Sanctions Enforcement Model

The Grinex shutdown exposes both the limits and the partial effectiveness of the current sanctions enforcement approach against crypto-based evasion networks.

On one hand, the Garantex-Grinex cycle demonstrates that sanctioned entities can reconstitute within weeks. Grinex was incorporated in Kyrgyzstan three months before Garantex's takedown. The A7A5 stablecoin transferred $100 billion in under 12 months despite Garantex being sanctioned since 2022. The infrastructure migrated across jurisdictions — from Russia to Kyrgyzstan to Georgia — faster than enforcement action could follow.

On the other hand, sanctions pressure has degraded the ecosystem's operational capacity. A7A5 DEX liquidity dropped 99.7% from its July 2025 peak. No major new token issuances have occurred in nine months. The Grinex suspension — whether caused by external attack or internal factors — removes the primary trading venue. Tether's ability to freeze USDT on TRON proved sufficiently threatening that the attacker's first move was converting to non-freezable assets.

The episode underscores a structural tension: law enforcement seized Garantex's domains and databases in March 2025, but the operators had already pre-positioned successor infrastructure. OFAC sanctioned the successor five months later. The entity was operational for roughly 16 months total before this week's shutdown.

Key Takeaways

  • Grinex, successor to sanctioned exchange Garantex, suspended operations April 16, 2026, after a $13.7 million theft affecting at least 70 wallet addresses across TRON and Ethereum.
  • The Garantex-Grinex network processed over $100 billion in transactions since 2022, with more than 70% involving sanctioned entities, according to TRM Labs.
  • The A7A5 ruble-backed stablecoin, central to Russian sanctions evasion, surpassed $100 billion in transfers in under one year, with 42.5 billion tokens ($547 million) in circulation.
  • Three blockchain analytics firms — Chainalysis, Elliptic, and TRM Labs — have not verified Grinex's claim that "Western intelligence" was responsible. Chainalysis flagged the possibility of a false flag.
  • TokenSpot, assessed as a likely Garantex front company, was hit by the same attacker on the same day, losing under $5,000 but exposing $4 billion in cumulative transaction volume and $88 million in direct flows with Grinex.
  • Sanctions pressure degraded but did not eliminate the network: A7A5 DEX liquidity fell 99.7% from peak, but the token still processes ~$500 million daily.

Conclusion

The Grinex suspension marks the second shutdown of a Garantex-linked exchange in 14 months. The first — Garantex's March 2025 domain seizure — was reversed within days through Grinex's launch. Whether the same reconstitution pattern repeats depends on enforcement speed. OFAC, the FBI, and Europol hold Garantex's customer databases, obtained during the 2025 takedown. The A7A5 token's infrastructure remains technically functional, though severely degraded by sanctions pressure.

The $13.7 million loss is small relative to the network's $100 billion throughput. The greater damage is operational: Grinex's suspension removes the primary fiat on-ramp for A7A5 and the most accessible sanctions evasion venue for Russian crypto users. The question now is whether a third successor exchange emerges, and how quickly.

Sources & References

  1. Chainalysis — Sanctioned Russia-Linked Exchange Grinex Suspends Operations — On-chain analysis of attack patterns and false flag assessment
  2. Elliptic — Sanctioned Russia-linked crypto exchange Grinex halts operations — Technical analysis of fund flows and A7A5 connection
  3. TRM Labs — Sanctioned Russian Exchange Grinex and Kyrgyzstani Exchange TokenSpot Hit in USD 15 Million Theft — Wallet tracing, TokenSpot connection, and 70-address analysis
  4. CoinDesk — Russia-linked Grinex exchange halts operations after $13 million 'state-backed' hack — News report with Grinex attribution claims
  5. The Hacker News — $13.74M Hack Shuts Down Sanctioned Grinex Exchange After Intelligence Claims — Technical details and Rapira connection
  6. Elliptic — A7A5: The ruble-backed stablecoin crosses $100 billion in transactions — Comprehensive A7A5 metrics and ownership analysis
  7. U.S. Department of Justice — Garantex Cryptocurrency Exchange Disrupted in International Operation — March 2025 takedown details and indictments
  8. U.S. Treasury Department — Treasury Sanctions Cryptocurrency Exchange and Network — August 2025 OFAC sanctions on Grinex, A7A5, and Old Vector