At least one more Russia-linked crypto exchange has been hit in the billion-ruble hack of the sanctioned Kyrgyzstan-registered Grinex, blockchain analyses showedAt least one more Russia-linked crypto exchange has been hit in the billion-ruble hack of the sanctioned Kyrgyzstan-registered Grinex, blockchain analyses showed

Russia-linked exchanges Grinex and TokenSpot targeted in suspected coordinated hack

2026/04/18 02:43
4 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

At least one more Russia-linked crypto exchange has been hit in the billion-ruble hack of the sanctioned Kyrgyzstan-registered Grinex, blockchain analyses showed.

Reports of the coinciding incidents sparked suspicions that the cyberattacks may have been coordinated and carried out by intelligence services rather than hacking groups.

Russia-linked exchanges Grinex and TokenSpot targeted in suspected coordinated hack

Kyrgyz crypto exchange TokenSpot also suffers breach

Russia has been allegedly using a number of cryptocurrency platforms incorporated in allied states like Kyrgyzstan to bypass financial restrictions imposed over its war in Ukraine.

The best known among them, the Grinex exchange, was hacked this week, losing well over a billion rubles’ worth of cryptocurrency, almost $15 million to be precise. And it wasn’t alone.

Blockchain forensics firms quickly tracked the stolen crypto, mostly USDT on Tron, which was eventually converted via the decentralized platform SunSwap to Tron tokens (TRX), nearly 46 million of them, and deposited to a single address.

According to a TRM Labs report, another Kyrgyz crypto trading service, TokenSpot, believed to be connected to Grinex, was also affected.

Its analysts found out that a smaller amount of digital money, less than $5,000 in value, was sent to the same consolidation wallet used in the big hack.

On Wednesday, the day Grinex halted trading, TokenSpot took to Telegram to inform users of an ongoing maintenance period, with operations resuming the following day, TRM said Thursday.

While Grinex identified 54 addresses associated with the attack, TRM Labs found another 16, some of which were also used to transfer funds from TokenSpot.

The latter is registered in Kyrgyzstan but serves predominantly Russian customers and supports ruble transactions, the business news outlet RBC reported on Friday.

In a Telegram post, the Russian company SHARD, a provider of anti-money laundering and know your customer services, remarked:

The Kyrgyzstan-based Grinex, successor of the Russian exchange Garantex, which was shut down in a U.S.-led effort last year, has an office in the same business center in Russia’s capital.

After registering the hack and suspending all operations, Grinex contacted law enforcement authorities and shared the collected data for further investigation.

The crypto trading venue alleged it had been “subjected to a large-scale cyberattack with indications of involvement by foreign intelligence agencies” and highlighted:

“According to preliminary data, the attack was coordinated with the aim of directly harming Russia’s financial sovereignty,” the exchange also said.

Was Grinex hit by regular hackers or Western spies?

Grinex’s assertion has not been supported by official statements so far, but it sparked discussions in the Russian crypto space, with views supporting both scenarios.

SHARD commented that the exchange’s actions seem motivated by a desire to protect funds from being blocked by the issuer.

When its predecessor, Garantex, was taken offline in early 2025, Tether froze $27 million worth of USDT on its platform.

“This indicates an economic rather than political nature of the target, and it is possible that the hack is not connected to foreign intelligence services,” the company elaborated.

AML specialists at CoinKit concluded that since the attackers emptied the exchange’s wallets in about five minutes, the attack was pre-planned and executed automatically.

The analysts said the scheme has been observed in most major exchange hacks in the past couple of years and does not require access to government resources.

“The nature of the transactions does not match the signature of elite hacker groups working for governments,” the BitOK compliance platform agreed.

However, it also noted that Grinex is sanctioned by the U.S., the EU, and the U.K., which turns it into a “legitimate target” for Western intelligence and pointed out:

The Russia-linked cryptocurrency exchange has processed over $93 billion in transactions using the ruble-pegged stablecoin A7A5.

Entities linked to the digital currencies, most notably the Kyrgyzstan-registered firm Old Vector, which is currently issuing it, are also sanctioned by the West.

Still letting the bank keep the best part? Watch our free video on being your own bank.

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

USD1 Genesis: 0 Fees + 12% APR

USD1 Genesis: 0 Fees + 12% APRUSD1 Genesis: 0 Fees + 12% APR

New users: stake for up to 600% APR. Limited time!