The sanctioned Russian cryptocurrency exchange Grinex has halted all operations following a sophisticated cyberattack that resulted in the theft of over $13.74 million (more than 1 billion rubles) in USDT stablecoins. The exchange has accused “hostile state-linked” foreign intelligence agencies of orchestrating the breach.
Key Details of the Attack
According to Grinex, the attack was unprecedented in scale and coordination. Hackers infiltrated user wallets, stealing USDT and then converting the funds into TRX tokens, which were consolidated into a single wallet address. Preliminary forensic analysis by the exchange indicates that the digital footprint of the attackers shows a level of coordination “typically associated with state-level actors.” Law enforcement authorities are now examining logs from 54 wallets linked to the incident.
Allegations of State Involvement
“From the very beginning, the exchange’s infrastructure has been under attack,” a Grinex spokesperson stated. “The exchange was placed on sanctions lists, crypto wallets faced targeted attacks, transactions were blocked. Now, attempts to destabilize the domestic financial system have reached a new height — direct asset theft.” The exchange explicitly claims the attack was a deliberate attempt to undermine Russian financial sovereignty and likely involved foreign intelligence services. While no specific country was named, the timing and nature of the attack point to geopolitical tensions surrounding sanctions on Russian financial entities.
Sanctions Background
Grinex operates as a ruble-to-crypto exchange for Russian businesses and individual investors. In 2025, it gained prominence by taking over the client base and infrastructure of Garantex, another sanctioned exchange that closed under Western regulatory pressure. This acquisition made Grinex a primary target for U.S. sanctions. Prior to the hack, the exchange claimed it had helped recover and return 2.5 billion rubles in digital assets previously frozen by Tether.
Aftermath and Investigation
Grinex has filed a formal criminal complaint and handed over technical logs and digital evidence to law enforcement agencies. However, the exchange has not announced a timeline for resuming services or a formal compensation plan for affected users. The platform remains offline, leaving customers unable to access their accounts or withdraw funds. Analysts warn that the incident highlights the growing cybersecurity and geopolitical risks faced by sanctioned cryptocurrency platforms. As Western governments continue to tighten restrictions on Russian crypto activity, exchanges like Grinex may become increasingly vulnerable to both cyberattacks and regulatory pressures.

