Sanctioned Russian crypto-ruble exchange Grinex has suspended all operations after suffering a sophisticated cyberattack that led to the theft of over $13.74 million worth of Tether (USDT) stablecoins. The exchange, already under U.S. sanctions, accused 'hostile state' foreign intelligence agencies of orchestrating the breach, which targeted user wallets and drained more than 1 billion rubles in digital assets.
Key Takeaways
- Grinex halts operations after losing over 1 billion rubles (approximately $13.74 million) in USDT from user wallets due to a state-level hack.
- The exchange acquired Garantex in 2025, making it a primary target of current U.S. sanctions.
- Law enforcement is reviewing logs from 54 wallets as Grinex attempts to recover the stolen 13.74 million USDT, which was converted to TRX.
Allegations of State-Sponsored Intervention
Grinex, a Russia-based exchange facilitating crypto-to-ruble conversions for businesses and individual investors, says the unprecedented attack shows signs of coordination typical of nation-state actors. According to preliminary forensic data provided by the exchange, the attackers' digital footprint exhibited levels of sophistication and coordination that only state-level actors could achieve.
“Since its inception, the exchange's infrastructure has been under constant attack,” a Grinex spokesperson stated. “The exchange was placed on sanctions lists, crypto wallets were targeted, transactions were blocked. Now, the attempt to destabilize the domestic financial system has escalated to a new level — direct theft of assets.”
Grinex remains under U.S. and international sanctions aimed at isolating it from the global financial system. The exchange gained prominence in 2025 after taking over the client base and infrastructure of Garantex, another exchange that shut down under Western regulatory pressure.
According to Grinex, the exchange previously helped recover and return 2.5 billion rubles worth of digital assets that had been frozen by Tether, the issuer of USDT stablecoins. In the latest incident, the stolen funds were moved from dozens of individual wallets, converted into the TRX cryptocurrency, and consolidated into a single target address.
Russian Ruble Stablecoin Under EU Sanctions
The hack comes amid broader efforts by Western authorities to clamp down on Russian crypto financing. The European Union recently sanctioned A7A5, a ruble-backed stablecoin that has become a key tool for Russian crypto funding. The Grinex incident is likely to escalate tensions between Russia and the West over digital asset controls.
Grinex has filed a formal criminal complaint and handed over technical logs and digital evidence to law enforcement. No timeline for service restoration has been announced, nor has a formal compensation plan for users been established. Although the exchange remains offline, it insists these 'hostile actions' are part of a broader geopolitical campaign to restrict digital asset transfers within the Commonwealth of Independent States (CIS).

