DeFi Intel

Grinex Exchange Wallet Drain (April 17, 2026)

Date
2026-04-17
Loss
$13.74M
Category
Exchange hack
Attack vector
Coordinated drain of dozens of exchange-controlled hot wallets on TRON and Ethereum (54 addresses disclosed by Grinex, roughly 70 identified by TRM Labs), with roughly $15M in USDT exfiltrated at around 12:00 UTC and immediately swapped into non-freezable TRX via the SunSwap DEX before consolidation at a single TRON address. No smart-contract exploit; the attacker held simultaneous signing capability over the exchange's wallet fleet, consistent with compromised key management or insider access.
Attribution
Contested. Grinex blamed the 'special services of unfriendly states' (Western intelligence) without publishing any technical evidence; TRM Labs assessed an external cyber operation as more likely than an exit scam, citing indiscriminate targeting of Grinex and the connected Kyrgyz exchange TokenSpot; Chainalysis flagged that the immediate USDT-to-TRX swap is inconsistent with a law-enforcement seizure and raised false-flag and insider hypotheses. No firm or agency has made a positive attribution.

Overview

At approximately 12:00 UTC on Wednesday, April 15, 2026, an attacker began draining the operational hot wallets of Grinex, the Kyrgyzstan-incorporated, Russia-linked cryptocurrency exchange that emerged in March 2025 as the de facto successor to the sanctioned and law-enforcement-dismantled Garantex. Grinex announced a suspension of operations on April 16 and had fully halted by April 17, claiming losses of more than 1 billion rubles, approximately $13.74M, though on-chain analysis by Elliptic and TRM Labs put the confirmed outflow closer to $15M in USDT across TRON and Ethereum. The exchange disclosed 54 attacker-linked addresses; TRM Labs identified roughly 70, plus four Ethereum addresses. The stolen USDT was swapped into TRX within minutes via the TRON-based DEX SunSwap, defeating any possibility of a Tether freeze, and consolidated into a single TRON address that came to hold about 45.9 million TRX, roughly $14.98M. The same consolidation address received under $5,000 from two addresses at TokenSpot, a Kyrgyz exchange with deep financial ties to the Garantex-Grinex network that went offline for 'technical work' the same day, suggesting a common attack vector. Grinex published no intrusion details but attributed the theft to the 'special services of unfriendly states,' framing it as an attack on Russia's financial sovereignty; no evidence was offered and Reuters could not verify the claim. TRM Labs assessed an external cyber operation as more likely than an exit scam, while Chainalysis noted the freeze-evading swap pattern is inconsistent with a law-enforcement confiscation and left open insider-theft and false-flag scenarios. Nothing was recovered: users of the OFAC-, UK-, and EU-sanctioned venue, many of whom had already had Garantex balances converted into the ruble stablecoin A7A5 after the March 2025 takedown, were locked out with no legal recourse, and weeks later the dormant funds began moving through mixers and cross-chain bridges toward major exchanges. The incident halted, at least temporarily, a venue that on-chain analysts measured at more than $16 billion in flows since March 2025, including $9.25 billion after its August 2025 OFAC designation.

Timeline of events

The theft was executed at approximately 12:00 UTC on Wednesday, April 15, 2026, when USDT began leaving Grinex-controlled hot wallets on TRON and Ethereum in a coordinated sequence; Elliptic's on-chain reconstruction timestamps roughly $15M in USDT moving at that hour. The same day, TokenSpot, a Kyrgyzstan-based exchange with extensive financial links to the Garantex-Grinex network, posted a notice citing 'technical work' and went offline. On April 16 Grinex publicly announced a suspension of operations, describing a large-scale cyberattack, claiming losses exceeding 1 billion rubles, and attributing the operation to the special services of unfriendly states; withdrawals were frozen and, per CoinDesk's reporting, access to the exchange's Moscow office was restricted while users were locked out of their funds. By April 17 the halt was total and the incident was being covered internationally, with Grinex disclosing a list of 54 attacker-linked addresses. Over the following days the blockchain-analytics response converged: Chainalysis published an analysis observing that the immediate swap of stolen stablecoins into TRX contradicted the exchange's state-seizure narrative; TRM Labs identified approximately 70 connected addresses, about 16 more than Grinex disclosed, documented the SunSwap conversions, and connected the sub-$5,000 TokenSpot theft to the same TRON consolidation address, which by publication held about 45.9 million TRX worth roughly $14.98M. The funds then sat dormant for weeks before beginning to move through mixers and cross-chain bridges toward major exchanges, with Chainalysis noting it was unclear whether the movement was the original attacker or an insider with access to the stolen wallets.

Attack mechanism

This was not a smart-contract exploit or a protocol failure; it was a custody compromise. Whoever executed the drain possessed simultaneous signing capability over dozens of exchange-operated hot wallets on two separate blockchains, and used it in a single coordinated window. Grinex disclosed 54 compromised addresses holding predominantly USDT on TRON; TRM Labs' tracing expanded the cluster to roughly 70 addresses and identified four associated Ethereum addresses whose destinations remained under investigation. The signature move came immediately after exfiltration: the stolen USDT was swapped into TRX through SunSwap, a TRON-based decentralized exchange that Garantex-linked actors had used before, with a smaller Ethereum-side flow converted toward ETH. Converting a centrally-freezable stablecoin into a native, non-freezable asset within minutes eliminated Tether's ability to blacklist the proceeds, a countermeasure that had bitten this network before when Tether froze roughly $27M of Garantex-linked USDT during the March 2025 takedown. The proceeds were then consolidated into a single TRON address rather than being fanned out, an unusually tidy pattern that gave investigators one clean choke point to watch but also signaled an operator confident that no freeze could reach TRX. The parallel TokenSpot intrusion, which yielded under $5,000 routed to the same consolidation address from two addresses that went offline on April 15, indicates the attacker held access across both platforms simultaneously, consistent with a shared infrastructure compromise, shared key-management tooling, or an insider positioned across the connected exchanges.

Root cause analysis

The technical root cause is formally unverifiable because Grinex published no forensic detail: no intrusion vector, no malware indicators, no compromised-system inventory, and no named agency behind its state-attack claim. Three scenarios frame the analysis. First, an external cyber operation, criminal or political, that compromised the exchange's hot-wallet key material or internal signing service; TRM Labs assessed this as the more likely explanation, citing the indiscriminate targeting of two platforms and the modest total value, which fits an opportunistic intrusion better than a staged exit. Second, an insider theft or exit scam conducted under the cover of a hack; Chainalysis noted that the instant conversion of stablecoins to TRX is behavior consistent with evading issuer freezes rather than with any law-enforcement confiscation, which freezes assets rather than converting them, and observed that Russia has a well-documented history of false-flag framing. The venue's incentives, mounting sanctions pressure, shrinking operational footprint, and a clientele that cannot complain to any regulator, made the exit-scam hypothesis impossible to dismiss. Third, the operation Grinex itself alleged: a Western intelligence action against Russia's crypto rails, for which no technical evidence was produced and which Reuters could not verify. Beneath all three scenarios sits the same structural cause: a sanctioned exchange concentrating customer assets in operator-controlled hot wallets, with no external audit, no proof-of-reserves, no regulatory oversight, and total opacity as a business requirement. The opacity that enabled sanctions evasion also removed every control that would normally bound insider risk or compel honest disclosure.

Initial response and user impact

Grinex's response consisted of halting the platform rather than containing or remediating a breach in public view. Operations were suspended on April 16, withdrawals were frozen indefinitely, and users were told their funds were inaccessible pending an investigation whose findings were never published. CoinDesk reported that access to the Moscow office was restricted, cutting off the in-person service channel that had been a distinguishing feature of the Garantex-Grinex model since Garantex invited customers to face-to-face Moscow meetings after its own March 2025 takedown. There was no compensation plan, no proof-of-reserves, no bug bounty, and no negotiation channel; none of the standard exchange-incident playbook applies to a venue that is itself sanctioned by OFAC, the UK, and the EU. Users had no legal recourse in any jurisdiction: they could not file claims with a regulator overseeing the exchange, and many were using the platform precisely because it operated outside such systems. For Garantex veterans this was the second total freeze in thirteen months; after the March 2025 enforcement action froze their balances, customers had been issued A7A5, the ruble-backed stablecoin from Kyrgyz issuer Old Vector, as credits redeemable on Grinex, meaning the same clientele now watched the redemption venue for their previous loss go dark. External response came only from the analytics industry: Chainalysis labeled the attacker addresses in its products to alert exchanges and investigators, and TRM Labs and Elliptic published tracing that constrained Grinex's narrative within days. Tether had no window to act because the USDT was swapped out within minutes of the theft.

Funds tracking and laundering

On-chain visibility was strong even as ground truth about the intrusion stayed dark. TRM Labs mapped approximately 70 attacker-connected addresses against the 54 Grinex disclosed, documented the USDT-to-TRX conversions through SunSwap, and identified the single TRON consolidation address that accumulated about 45.9 million TRX, roughly $14.98M at prevailing prices, along with four Ethereum-side addresses still being traced. The consolidation pattern initially favored defenders: one address holding nearly the entire proceeds is easy to monitor, and Chainalysis committed to tracking downstream TRX movement and any successor entities. The TokenSpot thread strengthened the external-operation reading: two TokenSpot addresses routed slightly under $5,000 to the same consolidation address, and TRM's broader mapping of TokenSpot showed how tightly it was woven into the network, with a combined $88 million transferred to Garantex and Grinex, more than $12 million received from Grinex, $257.5 million sent to the A7 network that issues A7A5, roughly $4 billion in volume between December 2023 and March 2026, and nearly $1 million received by a Houthi-linked wallet. After weeks of dormancy, the stolen assets began moving through mixers and cross-chain bridges toward major exchanges, a laundering escalation that reopened the insider question: Chainalysis stated it was unclear whether the movement was conducted by the original threat actors or by an insider with access to the stolen wallets. As of this writing, no exchange has publicly reported freezing deposits traced to the consolidation address, and none of the funds have been recovered.

Legal and regulatory aftermath

The hack triggered no new enforcement because everything around Grinex was already enforced. Garantex had been sanctioned by OFAC in April 2022 for laundering over $100 million linked to the Hydra darknet market and Conti ransomware; despite that designation it processed transactions on the order of $100 billion, with TRM estimating it accounted for 82% of all crypto volume associated with sanctioned entities worldwide, before a March 2025 operation by the US Secret Service and DOJ with German, Finnish, and Europol cooperation seized its domains and servers, Tether froze roughly $27M in linked USDT, and co-founder Aleksej Besciokov was arrested in Kerala, India, with fellow operator Aleksandr Mira Serda charged in a money-laundering conspiracy. Grinex, incorporated in Kyrgyzstan in December 2024 and live within weeks of the takedown, was designated by OFAC on August 14, 2025 alongside Garantex co-owners and related entities, with UK and EU actions in the same period. The April 2026 theft therefore produced a jurisdictional void: no regulator opened a recovery case, no exchange users could file claims, and Western agencies had no incentive to investigate a loss suffered by a sanctioned sanctions-evasion venue. The sharper regulatory lesson ran the other way: on-chain analysts measured more than $16 billion through Grinex since March 2025, including $9.25 billion after its OFAC designation, evidence that sanctions had slowed nothing, while a single day's key compromise halted the venue outright. Analysts nonetheless cautioned that the collapse would not dent Russian sanctions busting, pointing to the surviving A7A5 rails and adjacent infrastructure such as the Exved payment platform and MKAN Coin, and to the network's demonstrated rebrand capacity.

Industry implications

Grinex crystallized several dynamics. First, sanctioned exchanges are soft targets for everyone: they cannot buy reputable security services, cannot call law enforcement, and cannot pursue attackers, and after Nobitex's politically motivated June 2025 breach by Predatory Sparrow, the precedent exists for state-adjacent actors treating sanctioned venues as legitimate targets, which is precisely the ambiguity Grinex's unverified attribution exploited. Second, the incident showcased the verification asymmetry that now governs exchange incidents: the platform's own account was unauditable, but within days independent tracing by TRM Labs, Chainalysis, and Elliptic had fixed the address count, the swap path, the consolidation point, and the TokenSpot link, constraining what any narrative, state-attack or exit-scam, could claim. Third, the instant conversion of stolen stablecoins into native assets is now standard tradecraft; the window for issuer-level freezes is measured in minutes, which weakens the deterrent value of Tether's blacklist and pushes defense toward pre-positioned monitoring and exchange-side deposit screening. Fourth, the episode demonstrated the resilience of Russia's crypto sanctions-evasion stack: the Garantex-to-Grinex rebrand had already proven that designations displace rather than destroy such networks, and the hack is best understood as accelerating another migration, with A7A5 flows and successor venues continuing. Finally, it underlined the compounding risk borne by users of gray-market venues, who absorbed their second total freeze in thirteen months with no recourse, a warning relevant across every jurisdiction where users are pushed toward unregulated offshore platforms.

Verdict and lessons

The verdict is a coordinated hot-wallet drain of roughly $13.74M by Grinex's own accounting and closer to $15M on-chain, executed by an actor with signing control over the exchange's wallet fleet on two chains, laundered through an immediate freeze-evading swap into TRX, and consolidated at a single address that has not been recovered. On the balance of published evidence, TRM Labs' assessment of an external cyber operation is the most defensible reading, given the simultaneous TokenSpot intrusion and the modest haul, but the insider and exit-scam hypotheses raised by Chainalysis cannot be excluded, and Grinex's Western-intelligence attribution remains an evidence-free claim that served the operator's political framing. The lessons are transferable well beyond sanctioned venues. Attribution without indicators is public relations, not forensics, and should be priced accordingly. On-chain analytics is now fast and authoritative enough to bound an incident narrative within days, and exchanges should assume their claims will be checked against the ledger. Hot-wallet key concentration without external audit remains the dominant kill vector for centralized venues of every legal status, and the Grinex drain joins Poloniex, CoinDCX, and Nobitex in a lineage of custody compromises that no contract audit could have prevented. Issuer freezes are a minutes-scale race that defenders usually lose, so monitoring and deposit screening at the off-ramps matter more than blacklists. And for users, a venue that exists to evade oversight offers no protection when the oversight-free custody model fails, as it did here for the second time in just over a year.

Recovery

None. The stolen funds were swapped to TRX before any issuer freeze was possible and consolidated at a single TRON address holding ~45.9 million TRX (~$14.98M); after weeks of dormancy they began moving through mixers and cross-chain bridges toward major exchanges, with Chainalysis unable to determine whether the original attacker or an insider was moving them. Grinex announced no compensation plan, published no investigation findings, and, as a sanctioned entity, had no law-enforcement recovery channel; no exchange has publicly reported freezing traced deposits.

Key lessons

  • Attribution claims without technical indicators are public relations; Grinex's Western-intelligence framing collapsed against on-chain evidence showing freeze-evasion behavior inconsistent with a state seizure
  • Independent on-chain forensics now bounds incident narratives within days; exchanges should assume every claim will be checked against the ledger
  • Concentrated hot-wallet signing capability without external audit remains the dominant kill vector for centralized exchanges of any legal status
  • Issuer-level stablecoin freezes are a minutes-scale race; post-theft swaps into native assets like TRX defeat blacklists, shifting defense to deposit screening at off-ramps
  • Venues built to evade oversight offer users no protection when the custody model fails; Garantex-Grinex clientele absorbed two total freezes in thirteen months with no recourse

Frequently asked questions

What happened in the Grinex Exchange Wallet Drain?

Grinex, the Kyrgyzstan-incorporated successor to the sanctioned Russian exchange Garantex, was drained of ~$13.74M (on-chain ~$15M in USDT) from dozens of hot wallets on TRON and Ethereum at ~12:00 UTC on April 15, 2026, halting all operations by April 17. The attacker swapped the USDT into non-freezable TRX via SunSwap within minutes and consolidated ~45.9M TRX (~$14.98M) at one address; the connected Kyrgyz exchange TokenSpot was hit in the same window. Grinex blamed 'special services of unfriendly states' with zero evidence; TRM Labs assessed an external cyber operation as more likely than an exit scam, while Chainalysis noted the freeze-evading swaps contradict a state-seizure story and left insider theft open. Nothing was recovered, users of the OFAC/UK/EU-sanctioned venue had no recourse, and the funds later moved through mixers and bridges toward major exchanges.

How much was lost?

Approximately $13.74M was lost on 2026-04-17.

How did the attack work?

Coordinated drain of dozens of exchange-controlled hot wallets on TRON and Ethereum (54 addresses disclosed by Grinex, roughly 70 identified by TRM Labs), with roughly $15M in USDT exfiltrated at around 12:00 UTC and immediately swapped into non-freezable TRX via the SunSwap DEX before consolidation at a single TRON address. No smart-contract exploit; the attacker held simultaneous signing capability over the exchange's wallet fleet, consistent with compromised key management or insider access.

Who was responsible?

Contested. Grinex blamed the 'special services of unfriendly states' (Western intelligence) without publishing any technical evidence; TRM Labs assessed an external cyber operation as more likely than an exit scam, citing indiscriminate targeting of Grinex and the connected Kyrgyz exchange TokenSpot; Chainalysis flagged that the immediate USDT-to-TRX swap is inconsistent with a law-enforcement seizure and raised false-flag and insider hypotheses. No firm or agency has made a positive attribution.

Were the funds recovered?

None. The stolen funds were swapped to TRX before any issuer freeze was possible and consolidated at a single TRON address holding ~45.9 million TRX (~$14.98M); after weeks of dormancy they began moving through mixers and cross-chain bridges toward major exchanges, with Chainalysis unable to determine whether the original attacker or an insider was moving them. Grinex announced no compensation plan, published no investigation findings, and, as a sanctioned entity, had no law-enforcement recovery channel; no exchange has publicly reported freezing traced deposits.

Related