Grinex hacked, suspends trading; $15M pause, with the blame pointing to a “hostile nation”

TRX0,23%
ETH3,4%

Grinex trading suspended

Grinex, a Kyrgyzstan-registered exchange with deep ties to the Russian crypto market, announced on Thursday that it would suspend withdrawals and trading after its wallet infrastructure was hit by a “large-scale cyberattack.” Blockchain analytics firm Elliptic estimates the attack stole about $15 million in USDT. In an official statement on its website, Grinex characterized the incident as organized crime that harms financial sovereignty, and said the attack techniques have the hallmarks of “hostile nation actor” capabilities.

On-chain flow of the stolen funds: USDT rapidly shifts to TRX and ETH to avoid Tether freezing

Stolen wallet address (Source: Grinex)

After being stolen, the USDT was quickly routed through intermediary addresses on the Tron and Ethereum networks and ultimately converted into TRX and ETH. Elliptic noted that the purpose of this conversion operation is likely to reduce the risk of funds being frozen by Tether—Tether has the technical capability to blacklist USDT addresses associated with illegal activity, preventing them from being used in subsequent circulation.

Grinex’s own disclosed on-chain data also confirms this flow: a related wallet identified by the exchange shows a balance of about 459 million TRX, worth more than $15 million, suggesting that the stolen assets had already been consolidated into a single address after the initial transfer.

The successor to Garantex: Grinex’s identity background and market position

It is widely believed in the market that Grinex is the successor to the sanctioned exchange Garantex. Garantex was sanctioned and shut down last year after U.S. authorities determined that it facilitated the flow of hundreds of millions of dollars in illegal funds related to ransomware and dark web markets. Within days after Garantex’s shutdown, its liquidity and users quickly migrated to alternative platforms such as Grinex.

Grinex key identity data

Exchange registration location: Kyrgyzstan, deeply linked to the Russian market

Relationship to the prior entity: widely recognized as the successor platform of the sanctioned Garantex

Market role: the primary venue for ruble-to-crypto trading

A7A5 stablecoin hub: the core circulation center for the ruble-backed stablecoin A7A5

Total A7A5 transaction volume: Elliptic estimates it has exceeded $100 billion

FAQ

Why is Grinex considered a successor to Garantex?

Within a few days after Garantex shut down, its users and liquidity clearly migrated to platforms such as Grinex. Grinex then took over from Garantex to become a core crypto trading venue for the Russian market, particularly by assuming the trading and circulation functions for ruble-to-crypto pairs and the stablecoin A7A5 backed by rubles. Its market positioning is highly aligned with Garantex.

Why would the stolen USDT be converted into TRX and ETH?

Tether has the technical capability to blacklist USDT addresses involved in illegal activity; once frozen, the USDT would be unable to make any transfers or trades. Converting USDT into TRX or ETH can effectively bypass this freezing mechanism because Tether’s blacklist feature does not apply to other cryptocurrencies, allowing the stolen funds to continue circulating.

Grinex calls its mastermind a “hostile nation”—is this allegation credible?

Grinex’s statement frames the attack as an organized action targeting Russia’s financial sovereignty, but it provides no specific technical attribution evidence. In the absence of a detailed technical analysis report, such allegations are difficult to independently verify. The term “hostile nation” currently has more of a political narrative character rather than being based on publicly available technical traceability conclusions.

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Related Articles

Economist Proposes National USD Stablecoin to Eliminate Currency Controls in Venezuela

Alejandro Grisanti, head of Ecoanalitica, proposed issuing a national USD stablecoin as part of a series of measures to lift currency controls in Venezuela. This system would complement the current auction system, allowing the excluded sector to receive dollars via blockchain rails. Key

Coinpedia12m ago

U.S. Treasury Issues General License 135 Authorizing Russian Crude Oil Transactions Through May 17

The U.S. Treasury's OFAC issued General License 135, permitting specific Russian energy transactions impacted by sanctions, allowing necessary deliveries and repairs for cargo loaded before April 17, with a deadline for completion by May 17.

GateNews1h ago

Sanctioned Exchange Grinex Hit by $13.7M Hack; Blames Foreign Intelligence Services

Grinex, a sanctioned crypto-ruble exchange, has halted operations due to a cyberattack that stole over $13.74 million in USDT. The attack is believed to involve state-level actors aiming to destabilize Russia's financial system. Grinex is cooperating with law enforcement but has no timeline for resuming services.

Coinpedia1h ago

Iran and U.S. Drafting Memorandum of Understanding for Permanent Peace Framework

An Iranian official announced that Iran and the U.S. are drafting a memorandum of understanding for a permanent peace agreement, with negotiations set in Pakistan and a 60-day follow-up timeframe.

GateNews2h ago

Iran's Parliament Speaker Says Trump's 7 Statements Are 'Entirely False'

Iran's Parliament Speaker, Mohammad Baqer Qalibaf, claimed that all statements made by U.S. President Donald Trump within an hour are "entirely false," without detailing which statements he meant.

GateNews2h ago

Trump Says Naval Blockade on Iran Will Continue Until Deal Is Completed

President Trump announced on social media that the naval blockade on Iran will persist until a complete deal is finalized, emphasizing that negotiations are nearly done and should be concluded swiftly.

GateNews11h ago
Comment
0/400
No comments