Sanctioned Exchange Grinex Halts Operations After $13.74 Million Theft

Sanctioned Exchange Grinex Halts Operations After $13.74 Million Theft

N
News Editor 01
2026-07-08 19:56:27
Grinex, a sanctioned crypto-ruble exchange, has suspended operations after losing about $13.74 million in USDT in a sophisticated cyberattack. The platform claims the incident may involve foreign intelligence actors, while law enforcement reviews wallet logs and digital evidence.
GrinexhackUSDTTRXsanctions

Grinex, a crypto-ruble exchange operating under U.S. sanctions, has suspended all services after a sophisticated cyberattack led to the theft of approximately $13.74 million in Tether. According to the exchange, the stolen amount exceeded 1 billion rubles, making the incident one of the most serious security breaches it has publicly reported.

The platform said the attackers moved funds out of dozens of personal wallets, converted the stolen assets into TRX, and consolidated them into a single destination address. As Grinex attempts to trace and potentially recover the funds, law enforcement authorities are reviewing technical records associated with 54 wallets. The exchange has also filed a formal criminal complaint and handed over digital evidence and system logs to investigators.

Claims of State-Level Involvement

What makes the case especially notable is Grinex’s assertion that the attack may have involved actors with capabilities normally associated with state-backed operations. The exchange described the breach as unprecedented and said preliminary forensic findings point to a level of coordination that, in its view, suggests the possible involvement of foreign intelligence agencies from what it called “hostile states.”

A company spokesperson said the incident should not be viewed as an isolated theft alone, but as part of a broader attempt to destabilize Russia’s domestic financial system and undermine its financial sovereignty. Grinex also stated that its infrastructure had been under pressure from the beginning, including targeted attacks on crypto wallets and blocked transactions, and argued that the latest theft represented a further escalation.

At this stage, however, those allegations remain the exchange’s own characterization of events. The source material does not indicate that outside investigators or independent forensic firms have publicly confirmed the claim of intelligence-linked involvement. That distinction is important, as attribution in cyber incidents often remains uncertain for extended periods.

Sanctions History and the Garantex Connection

The exchange’s sanctions status adds a broader geopolitical dimension to the story. Grinex remains subject to U.S. and international sanctions intended to isolate it from the global financial system. Its profile rose significantly in 2025, when it took over the customer base and infrastructure of Garantex, another exchange that had shut down under pressure from Western regulators.

That background has made Grinex a particularly visible target in discussions around sanctioned crypto infrastructure, Russian digital asset flows, and cross-border financial restrictions. In the exchange’s telling, the current attack is tied not only to criminal motives but also to a wider campaign aimed at restricting digital asset transfers within the Commonwealth of Independent States, or CIS. While that claim reflects Grinex’s own interpretation, it underscores how deeply the platform views the theft through a geopolitical lens.

Fund Flows, Recovery Efforts, and Operational Freeze

Grinex said the stolen Tether was taken from multiple user wallets before being converted into TRX and sent onward. The exchange is now seeking to track the path of those funds and support investigative efforts, though no timetable for recovery has been announced. Because the assets were moved across wallets and converted, the recovery process may depend on the availability of exchange records, blockchain analytics, and potential coordination with intermediaries or token issuers where applicable.

The company noted that it had previously helped recover and return digital assets worth 2.5 billion rubles that had been frozen by Tether. By highlighting that earlier case, Grinex appears to be signaling both familiarity with asset recovery processes and its desire to reassure users that some form of response is underway. Still, there is no indication that a comparable outcome is guaranteed in the present case.

For now, the exchange remains offline. Grinex has not provided a specific date for restoring services, nor has it announced a formal compensation framework for affected users. That leaves customers facing uncertainty on two fronts: whether operations will resume soon, and whether losses will ultimately be reimbursed.

Why the Incident Matters

The theft is significant not just because of its scale, but because it highlights several recurring risks in the digital asset sector at once: concentrated wallet exposure, the speed with which stablecoin holdings can be converted and moved, and the difficulties of attribution in high-profile cyber incidents. In Grinex’s case, those issues are amplified by sanctions, political sensitivities, and its role in the crypto-ruble exchange market.

The episode may also draw attention to how sanctioned platforms manage wallet security, forensic readiness, and post-incident communication. Grinex’s decision to suspend all operations suggests the exchange sees the breach as severe enough to warrant a full halt rather than a limited containment response. That, in turn, may affect confidence among users, counterparties, and observers following the broader evolution of Russian crypto market infrastructure.

At present, the verified facts remain relatively clear: $13.74 million in USDT was reportedly stolen, the assets were converted into TRX, investigators are reviewing records tied to 54 wallets, and Grinex has paused operations while pursuing legal and investigative channels. The broader allegations about foreign intelligence involvement and geopolitical motives remain part of the exchange’s stated position, but not yet independently established in the available reporting.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
400

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.