Russia’s $96 Billion Crypto Laundering Successor Just Got Hacked—and Blames Western Spies

Grinex, the sanctioned exchange that replaced Garantex after a $96B laundering run, suspended operations after a $13M hack it blames on ‘Western Special Services.’

Grinex cryptocurrency exchange logo on dark web interface with hacker silhouette and Russian flag representing $13 million hack
  • Grinex, the Russia-linked crypto exchange that replaced the sanctioned Garantex, has suspended all operations after hackers stole over $13 million from user accounts.
  • The exchange blamed “Western Special Services” for the attack, claiming the breach showed sophistication “typically limited to state-backed entities.”
  • Garantex processed $96 billion before law enforcement shut it down in March 2025—and Grinex picked up right where it left off.

A sanctions-evasion machine that moved $96 billion through the global crypto system just learned what it feels like to get robbed. Grinex, the Russia-linked exchange that emerged as Garantex’s successor, announced Thursday it had been hacked for more than one billion rubles—roughly $13.7 million—and promptly suspended all trading and withdrawal services.

The exchange didn’t just blame anonymous hackers. In an official statement, Grinex alleged the attack bore hallmarks of “Western Special Services” and “unfriendly states,” claiming the technical evidence pointed to capabilities “typically limited to state-backed entities.” Whether that’s genuine attribution or a convenient narrative for an exchange already under Western sanctions is, at this point, anyone’s guess.

From Garantex to Grinex: The $96 Billion Pipeline

To understand why Grinex matters, you have to go back to Garantex. That exchange was sanctioned by OFAC in April 2022 and spent the next three years becoming one of the most active conduits for Russian sanctions evasion and ransomware laundering on the planet. From 2019 until international law enforcement shut it down in March 2025, Garantex processed a staggering $96 billion in transactions. When authorities finally pulled the plug, they froze $26 million—about 0.03% of what had already flowed through.

Investigators at TRM Labs identified Grinex as the likely successor shortly after Garantex went dark. The new exchange was promoted through Garantex-linked Telegram communities and showed “strong operational similarities,” including the same interface design and user migration patterns. Before its shutdown, Garantex had been transferring assets into A7A5, a ruble-linked stablecoin running on Ethereum and TRON—apparently designed to preserve liquidity while the old exchange wound down and the new one spun up.

Grinex says it has handed all collected evidence to law enforcement and that a criminal investigation is underway. The exchange framed the hack as “a new phase of destabilization involving coordinated cyber theft targeting Russian users.”

Whether Western intelligence agencies actually pulled off a $13 million heist against a sanctioned Russian crypto exchange—or whether Grinex just had terrible security and needed a geopolitical villain—is the kind of question that may never get a satisfying answer. What’s not in dispute: the pipeline that moved $96 billion is now offline, at least temporarily, and the users who trusted their rubles to a sanctions-evasion successor are learning that “state-backed” security works both ways.

Leave your vote