TL;DR: On April 15, 2026, Grinex, a Kyrgyzstan-based crypto exchange that took over operations from the sanctioned Russian exchange Garantex, lost approximately $13.7 million (over 1 billion rubles) in a cyberattack. Roughly $15 million in USDT was drained from user wallets and rapidly converted to TRX and ETH to avoid Tether freezing the funds. Grinex blamed “Western intelligence agencies,” claiming the attack showed “an unprecedented level of resources and technology accessible only to entities of hostile states.” They provided zero evidence. The exchange shut down permanently. Blockchain analysts at Elliptic and Chainalysis are tracking the stolen funds but haven’t confirmed any state involvement.
$13.7 Million Gone in Hours
At approximately 12:00 UTC on April 15, attackers drained user wallets on Grinex, stealing roughly $15 million in USDT stablecoins. The stolen funds moved fast, converted to TRX on the TRON network and ETH on Ethereum within hours. That conversion matters: Tether can freeze USDT held in specific wallets, but once it’s swapped for TRX or ETH, it’s gone.[1]
Blockchain security firm Elliptic identified approximately 70 addresses connected to the incident. The pattern, rapid swap from freezable stablecoins to non-freezable tokens across multiple chains, is standard crypto laundering. Not exactly “unprecedented state-level resources.”[2]
By April 16, Grinex announced it was halting all operations and filed a criminal complaint with local law enforcement in Kyrgyzstan.
The “Western Spies Did It” Claim
Grinex’s statement read like a press release from the Kremlin. The attack bore “hallmarks of foreign intelligence agency involvement,” the exchange said, with “capabilities typically available exclusively to agencies of hostile states.” The breach was “coordinated with the aim of directly harming Russia’s financial sovereignty.”[3]
Evidence provided: none.
No indicators of compromise. No technical analysis. No specific agency named. Just the claim that the hack was too sophisticated for criminals, so it must have been a government.
Analysts aren’t buying it. Elliptic noted that the operation “could be a false flag attack” given the exchange’s sanctioned status and criminal connections.[2] The attack pattern, draining hot wallets, rapid token swaps across chains, matches dozens of exchange hacks carried out by ordinary criminal groups and North Korean state hackers alike. There’s nothing about this that requires a CIA budget.
Garantex to Grinex: Same Operation, New Domain
Understanding Grinex requires knowing what Garantex was. And what Garantex was, according to the U.S. Treasury, was a laundromat.
The U.S. Treasury sanctioned Garantex in April 2022 for processing over $100 million in transactions linked to ransomware payments and darknet marketplace operations. The exchange kept running. In August 2025, Treasury renewed sanctions after finding even more illicit transactions.[4]
Then came the takedown. On March 6, 2025, the U.S. Secret Service, working with German and Finnish law enforcement, seized Garantex’s web domains (garantex.org, garantex.io, garantex.academy) and froze over $26 million in cryptocurrency. The EU had separately sanctioned Garantex for connections to sanctioned Russian banks including Sberbank, T-Bank, and Alfa-Bank.[5]
On March 7, the DOJ unsealed indictments against two Garantex administrators: Aleksandr Mira Serda and Aleksej Besciokov. Besciokov, a Lithuanian national, was arrested in India on March 12.[6]
So Garantex was sanctioned, seized, and its admins were being arrested. Problem solved?
Not even close. Grinex appeared almost immediately, absorbing Garantex’s client base and infrastructure. The exchange helped return over 2.5 billion rubles in previously frozen cryptocurrency to Russian users. Same people, same operations, new name. Elliptic confirmed the organizations likely share ownership and management structures.[2]
Why This Matters for Surveillance
Whether Western intelligence actually hacked Grinex is almost beside the point. What matters is the pattern this fits into.
Governments are increasingly using offensive cyber operations against financial infrastructure they consider hostile. The FBI’s Operation Masquerade disrupted a Russian GRU network of 18,000 hijacked routers in early April. The Secret Service seized Garantex domains and froze $26 million in crypto. Five Eyes intelligence sharing agreements increasingly cover cryptocurrency tracking.[7]
The surveillance infrastructure that enables this works both directions. The same blockchain analysis tools that Chainalysis sells to the FBI and IRS are the ones tracking Grinex’s stolen funds right now. The same SIGINT capabilities that let the NSA monitor foreign communications could, theoretically, be turned toward disrupting sanctioned financial networks.
Grinex claiming “Western spies” is convenient propaganda. But the broader reality, that state actors on all sides are conducting offensive operations against each other’s financial infrastructure, is well-documented. The question isn’t whether it happens. It’s who’s watching and who gets to decide what counts as a legitimate target.
Russian Users Holding the Bag
The stolen funds came from wallets belonging to Russian users who were using Grinex for crypto-ruble exchange operations. These are people who were already in a precarious position, using a sanctioned platform because legitimate international exchanges won’t serve them, or because they needed to move money outside Russia’s increasingly controlled financial system.[1]
Now their money is gone, the exchange is shut down, and the operator is blaming foreign governments instead of explaining how user funds weren’t properly secured. Grinex was collecting ruble deposits and holding crypto on behalf of users who had no recourse under international law if something went wrong.
Something went wrong.
What to Watch
- Fund tracking. Elliptic and Chainalysis are both monitoring the stolen funds across TRON and Ethereum. If the money moves to a known exchange or mixer, that will tell us a lot about who took it.
- Garantex 3.0. History says whoever ran Garantex-turned-Grinex will try again. Watch for a new exchange absorbing the client base within weeks.
- State attribution. If this was actually a government operation, leaks or official statements may surface. The U.S. has occasionally acknowledged offensive cyber operations after the fact, as with Stuxnet.
- Sanctions enforcement. The Grinex saga shows how hard it is to actually kill a sanctioned crypto operation. Seize the domain, arrest the admins, and the operation just rebrands.
The Bottom Line
A sanctioned crypto exchange with deep ties to Russian money laundering got hacked and blamed Western intelligence. Maybe they’re right. Maybe an insider ran off with the funds. Maybe it was a criminal group that saw an easy target, a sanctioned exchange that can’t exactly call the SEC when things go sideways.
What we know for sure: $13.7 million is gone, the exchange is dead, and Russian users who trusted a sanctioned platform with their money just learned why that’s a bad bet. And somewhere, the people who ran Garantex and then Grinex are probably already picking out a new domain name.
References
- The Hacker News , $13.74M Hack Shuts Down Sanctioned Grinex Exchange After Intelligence Claims (April 17, 2026)
- Elliptic , Sanctioned Russia-Linked Crypto Exchange Grinex Halts Operations Following Alleged Hack
- Security Affairs , Kyrgyzstan-based Crypto Exchange Grinex Shuts Down After $13.7M Cyber Heist
- U.S. Treasury , Treasury Sanctions Cryptocurrency Exchange Enabling Sanctions Evasion
- U.S. Secret Service , Seizes Russian Cryptocurrency Exchange Websites (March 6, 2025)
- TechCrunch , Garantex Administrator Arrested in India at Request of US Authorities (March 12, 2025)
- Krebs on Security , Russia Hacked Routers to Steal Microsoft Office Tokens (April 2026)