Chainalysis says the on-chain activity tied to Grinex’s suspension points to more than a simple exchange breach. In its April 17 review, the blockchain intelligence firm examined the sanctioned platform after Grinex said a cyberattack had drained about 1 billion rubles, or roughly $13.7 million. The company’s conclusion was blunt: the movement of funds did not look consistent with a standard law-enforcement seizure, and it also raised doubts about whether the incident matched the pattern of a conventional outside hack.
Rather than relying on Grinex’s own account, Chainalysis reviewed the source and destination addresses published by the exchange. It found that the assets taken were largely fiat-backed stablecoins before being moved through a Tron-based decentralized exchange and converted into TRX. Chainalysis said that rapid conversion from stablecoins into a token that cannot be frozen is a familiar laundering tactic. The point is simple. Actors moving illicit funds often try to exit centralized stablecoins before an issuer can block them.
Fast swaps out of stablecoins drew Chainalysis scrutiny
That behavior, according to the firm, cuts against the idea of a typical Western enforcement action. In those cases, authorities can generally seek assistance from centralized stablecoin issuers to freeze assets. Here, the funds were quickly swapped away instead. Chainalysis said the pattern suggested an effort to avoid issuer intervention, not a process aligned with ordinary seizure mechanics.
The company described the rush out of stablecoins as a hallmark move by cybercriminals and other illicit actors trying to launder funds under time pressure. That does not settle attribution on its own. It does, however, leave the Grinex narrative under heavier scrutiny because the chain activity does not cleanly match the scenarios the exchange’s public explanation might imply.
Links to Garantex and A7A5 point to a wider structure
Chainalysis based its assessment on broader network ties as well. The decentralized exchange used in the swaps had previously acted as a liquidity source for hot wallets associated with Garantex, the sanctioned exchange that Chainalysis has already described as Grinex’s direct predecessor after international enforcement disrupted the earlier venue.
The review also connected Grinex to A7A5, a ruble-backed token issued by sanctioned Kyrgyzstani company Old Vector. Chainalysis said A7A5 was built for a narrow payments ecosystem linked to Russia and suited to cross-border settlement under sanctions pressure. That framing places Grinex inside a more coordinated operating environment rather than as an isolated exchange handling a one-off incident.
Funds remained in one address at publication time
At the time of publication, Chainalysis said the exfiltrated assets were still sitting in a single address, leaving an active trail for later forensic work. The firm also said it had labeled the relevant addresses across its products so customers could monitor downstream exposure as the funds move.
Its broader finding centered on what it called a “shadow crypto economy”. In that description, Grinex, Garantex, A7A5, and related services form an interconnected network built to keep value moving despite sanctions. Grinex’s shutdown, in that view, hit a key channel inside that system.

