Grinex, a Kyrgyzstan-based cryptocurrency exchange tied by investigators to the sanctioned Russian platform Garantex, suspended operations after attackers stole roughly $13.7 million to $15 million from user wallets. The exchange alleged the intrusion was carried out by actors linked to Western intelligence services and said it had filed a criminal complaint, but no public technical evidence was provided to support that attribution. Reporting says the stolen assets belonged largely to Russian users, and the incident disrupted a platform associated with crypto-ruble activity, including the ruble-backed stablecoin A7A5.
Blockchain analysis from TRM Labs and Elliptic found the stolen funds were moved across TRON and Ethereum, with large amounts of USDT on TRON swapped into TRX through SunSwap before being consolidated. TRM said it identified about 70 addresses linked to the theft, exceeding the 54 publicly disclosed by Grinex, and assessed that Kyrgyzstan-based TokenSpot was likely compromised in the same operation after two of its addresses sent funds to the same consolidation wallet and the exchange suffered an outage. Investigators said both exchanges are part of a broader Russian sanctions-evasion ecosystem connected to Garantex, Grinex, A7, and A7A5.

Track how attackers are adapting to this technology.
6 events from the most recent confirmed update back to the earliest known activity.
Chainalysis said the movement of stolen Grinex funds did not resemble a government seizure or Western intelligence operation, contradicting Grinex's public claims. Instead, it assessed the on-chain behavior as more consistent with an internal exit scam, noting use of a Tron-based DEX previously linked to Garantex wallet funding.
TRM Labs published analysis concluding that TokenSpot was likely also compromised in the same campaign that hit Grinex. The report tied both exchanges to a broader Russian sanctions-evasion ecosystem associated with Garantex, Grinex, A7, and the ruble-backed stablecoin A7A5.
Following the disclosure, blockchain analysts reported that the stolen assets were moved through TRON and Ethereum addresses and swapped into TRX and ETH, including via SunSwap. TRM Labs identified about 70 addresses linked to the theft, exceeding the 54 addresses Grinex publicly disclosed, and found the funds were largely consolidated into a single TRON address.
In its public response to the incident, Grinex claimed the attack was carried out by actors tied to 'unfriendly states' or Western intelligence services as part of an effort to undermine Russia's financial sovereignty. No public technical evidence was cited to substantiate this attribution.
On April 16, 2026, Grinex announced that a cyberattack stole roughly USD 13.7 million to USD 15 million in user funds. The exchange suspended operations and said it filed a criminal complaint over the theft.
On April 15, 2026, Kyrgyzstan-based exchange TokenSpot experienced an outage. TRM Labs later assessed that TokenSpot was likely hit in the same operation after two of its addresses sent funds to the same attacker consolidation address.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
13 references tracked. Mallory keeps watching after this page renders.
govinfosecurity.com
Open sourcebankinfosecurity.com
Open sourcehackread.com
Open sourceeurasianet.org
Open sourcebleepingcomputer.com
Open sourceelliptic.co
Open sourcetrmlabs.com
Open sourceincrypted.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.