Grinex, a cryptocurrency exchange described as closely tied to Russia, has suspended operations after a large-scale hack drained about 1 billion rubles from the platform. The report values the loss at roughly $13 million to $15 million. Trading, withdrawals, and platform services have been halted, and no timeline for reopening has been announced.
The attack was reported around April 16. On-chain activity cited in the source shows that large amounts of funds, mainly USDT, were moved out of wallets linked to Grinex. The stolen assets were then routed across TRON and Ethereum through multiple layers, with part of the funds swapped into TRX and ETH. The pattern suggests an effort to reduce the risk of issuer freezes.
Blockchain investigators are tracking the stolen funds
The report says blockchain analytics firms Elliptic and Chainalysis are monitoring the movements tied to the hack. Their work is focused on tracing the destination of the stolen crypto, which has been described as a theft in the tens of millions of dollars. Public details remain limited at this stage, with the clearest information centered on wallet flows and asset conversions.
Grinex claims the attack targeted Russia’s “financial sovereignty”
In a statement posted on its official Telegram channel, Grinex said the operation showed a high level of technical capability and resources. The exchange claimed the attack carried signs of “hostile state intelligence agencies”, an accusation that pointed toward Western services in the source material.
Grinex said the incident was aimed at damaging Russia’s “financial sovereignty” and added that information had been handed over to law enforcement. No recovery schedule was included. For users, the immediate problem is simple: assets on the platform are not accessible while withdrawals and trading remain suspended.
Pressure grows because Grinex was seen as a Garantex successor
The breach has drawn attention because of Grinex’s position in the Russian crypto market. According to the source, industry participants have widely viewed it as the platform that absorbed liquidity and users after Garantex was shut down under joint sanctions from the United States, the United Kingdom, and the European Union.
Grinex was described as a key venue for ruble-to-crypto exchange services used by Russian users. That role gave it weight in cross-border payments and capital movement channels. Its sudden shutdown after the hack leaves those channels under heavier strain and locks many users out of their funds for an unspecified period.

