Grinex, the Exchange Linked to Sanctioned Garantex, Halts Trading and Blames a $13M "Western" Hack
Russian crypto exchange Grinex halted trading on October 1, claiming a roughly $13 million hack it blamed on "Western special services" — an unverified assertion made on its own Telegram channel.
Grinex, a Russian crypto exchange that regulators and researchers have tied to the sanctioned-and-seized Garantex, said it stopped trading after an alleged exploit drained more than 1 billion rubles — about $13 million. The claim came in a statement posted to the exchange's own Telegram channel on October 1, as reported by Decrypt (translated via Google), which also noted that the US has designated Russia's A7 Network as a transnational criminal organization.
Grinex described itself as "the leading cryptoruble exchange" handling settlements "between Russian businesses and citizens in digital assets," and attributed the loss to "Western special services." No on-chain evidence, exploited-contract address, or wallet trail was offered to support either the dollar figure or the attribution, and the amount rests entirely on the exchange's own account. Independent confirmation of the hack, its size, or who carried it out had not surfaced as of this writing.
The context matters. Grinex has been linked to Garantex, the exchange sanctioned by the US and later subject to enforcement action and seizure over its role in laundering illicit funds. An entity framing itself as a victim of foreign intelligence services — rather than naming an ordinary exploit, an insider, or operational failure — is making a politically convenient claim that is, by its nature, nearly impossible to check.
Key facts
- Who: Grinex, a Russian crypto exchange linked to the sanctioned and seized Garantex (Decrypt).
- What: Trading halted after an alleged exploit (Decrypt; Grinex Telegram statement).
- How much: More than 1 billion rubles, ~$13 million — figure sourced solely to Grinex (Decrypt, translating Grinex's Telegram).
- Grinex's attribution: "Western special services" — the exchange's own unverified claim (Grinex Telegram, via Decrypt).
- Related: The US has designated Russia's A7 Network as a transnational criminal organization; further specifics weren't detailed (Decrypt headline).
The real-world read
Treat Grinex's statement as what it is — a self-published claim from an interested party with a sanctions history, not established fact. Three things stand out. First, the $13 million and the "Western special services" line both originate from Grinex alone, on its own channel, with no corroborating data. Second, blaming foreign intelligence is a framing that casts a sanctioned-adjacent exchange as a geopolitical victim rather than addressing more mundane possibilities — a straightforward exploit, insider theft, or exit-style disruption — none of which Grinex rules out because none are mentioned. Third, the timing sits against a tightening enforcement backdrop, including the A7 Network designation; whether the two are connected is unknown and Grinex didn't say. The responsible read: a halt happened and a loss was claimed; the amount and the culprit remain unverified.
Opinion, and whose
Grinex's own position — that this was an attack by "Western special services" — is the only characterization on offer, and it is the exchange's, not a verified finding. No independent analyst assessment of the incident was available at this stage.
Sources
- Decrypt (Tier 2, reputable secondary), Oct 2, 2026 — reported the halt, the ~$13M/1-billion-ruble claim, the Garantex link, and the A7 Network designation; itself relaying Grinex's Google-translated Telegram statement.
- Grinex Telegram statement — the exchange's own account; an interested party's unverified marketing-adjacent claim, not independent confirmation.
Not financial advice.