Sanctioned Russian Crypto Exchange Grinex Loses $13.7M in Hack, Blames Foreign Intelligence Agencies

Sanctioned Russian Crypto Exchange Grinex Loses $13.7M in Hack, Blames Foreign Intelligence Agencies

N
News Editor 01
2026-07-08 19:58:17
Grinex, a US-sanctioned Russian crypto ruble exchange, suspended operations after a sophisticated cyberattack stole over $13.74 million worth of USDT. The exchange alleges involvement of hostile foreign intelligence agencies and has filed a criminal complaint.
cryptocurrencyhacksanctionsRussiaGrinex

The sanctioned Russian cryptocurrency exchange Grinex, which facilitates ruble-to-crypto trading for businesses and individual investors, has suspended all operations following a sophisticated cyberattack. The security breach resulted in the theft of approximately $13.74 million (over 1 billion rubles) worth of USDT stablecoins, marking the most severe asset loss in the exchange's history.

Attack Details and Fund Flow

According to Grinex's preliminary forensic analysis, the attackers first penetrated dozens of individual user wallets, transferred large amounts of USDT, converted them into TRX (Tron blockchain tokens), and finally consolidated all funds into a single target address. The digital footprint exhibited a level of coordination typically associated with state-sponsored actors. The stolen amount includes 13.74 million USDT, equivalent to more than 1 billion Russian rubles at the time of the incident.

Allegations of State Involvement

Grinex's official statement strongly suggested the involvement of foreign intelligence agencies from a "hostile nation." A spokesperson stated: "From the very beginning, the exchange’s infrastructure has been under constant attack. The exchange was blacklisted, crypto wallets were targeted, transactions were blocked. Now, attempts to destabilize the domestic financial system have escalated to a new level — direct asset theft." This accusation elevates the incident from a common cybercrime to a geopolitical maneuver.

Sanctions Background: Garantex Acquisition

Grinex has long been under U.S. and EU financial sanctions. In 2025, it gained notoriety by taking over the client base and infrastructure of Garantex, another Russian exchange that shut down under Western regulatory pressure. This "bailout" made Grinex a primary target for international sanctions enforcement. Previously, the exchange had assisted in recovering and returning 2.5 billion rubles worth of digital assets that had been frozen by USDT issuer Tether. The current hack further complicates its position.

Legal Actions and Uncertain Future

Grinex has filed a formal criminal complaint with law enforcement and submitted technical logs and digital evidence. Authorities are currently examining transaction logs from 54 wallets linked to the attack. However, the exchange has not announced a timeline for resuming services nor a formal compensation plan for affected users. It maintains that these "hostile actions" are part of a broader geopolitical effort to restrict digital asset transfers within the Commonwealth of Independent States (CIS). Industry analysts warn that this attack could further destabilize Russia's crypto market and intensify Western crackdowns on Russian crypto financial infrastructure.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.