Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Grinex Exchange Halts After .74M Cyber Heist Linked to Intelligence

Grinex Exchange Halts After $13.74M Cyber Heist Linked to Intelligence

Posted on April 18, 2026 By CWS

Grinex Exchange Suspends Operations Following Major Hack

The cryptocurrency exchange Grinex, based in Kyrgyzstan and previously sanctioned by the U.K. and U.S., has announced a halt in its operations. This decision follows a significant cyber attack resulting in the theft of around $13.74 million. The exchange has attributed this breach to Western intelligence agencies, suggesting a sophisticated level of involvement in the attack.

According to Grinex, the cyber assault was marked by advanced technological capabilities typically associated with state-level intelligence operations. The attack led to the loss of over 1 billion rubles in user funds, as stated in an official release. The exchange speculated that the motive was to damage Russia’s financial sovereignty.

Allegations of Intelligence Involvement

Grinex’s spokesperson revealed that the exchange had been targeted since its inception, with the recent breach representing a new escalation in cyber threats aimed at destabilizing the local financial landscape. The company, believed to be a rebranded version of Garantex, has faced sanctions due to links with illicit activities, including ransomware and darknet market operations.

The U.S. Treasury had previously sanctioned Garantex in 2022 and renewed these sanctions in 2025. Garantex allegedly facilitated over $100 million in illicit transactions. In response to sanctions, it reportedly transitioned its customer base to Grinex, utilizing a ruble-backed stablecoin called A7A5 to remain operational.

Blockchain Analysis and Further Developments

Reports from blockchain intelligence firms Elliptic and TRM Labs indicate that Grinex has been involved in significant financial activities with Rapira, a Georgian exchange, totaling over $72 million. The April 15 breach saw stolen assets moved to TRON and Ethereum blockchains, with the funds converted to assets like TRX or ETH to circumvent freezing by Tether.

TRM Labs identified approximately 70 addresses linked to the incident. It noted that TokenSpot, another Kyrgyzstan-based exchange possibly tied to Grinex, was also affected. TokenSpot temporarily suspended its services due to ‘technical maintenance’ on the day of the breach, resuming operations shortly after.

Implications and Future Outlook

The incident has prompted speculation about whether the hack was a genuine criminal exploit or a false flag operation orchestrated by Russia-linked insiders. Chainalysis highlighted the rapid conversion of stablecoins to evade asset freezing, a common laundering tactic.

The disruption of Grinex, a key player in Russian sanctions evasion infrastructure, raises questions about the future of such exchanges under heavy sanctions. The event underscores the ongoing challenges in regulating and securing the cryptocurrency landscape.

The Hacker News Tags:Blockchain, Cryptocurrency, cyber attack, Ethereum, Garantex, Grinex, money laundering, ruble-backed stablecoin, Sanctions, TRON, USDT

Post navigation

Previous Post: New Mirai Variant Targets TBK DVRs with CVE-2024-3721
Next Post: Fiverr Faces Data Breach Due to Cloudinary Misconfiguration

Related Posts

AI Tools in Malware, Botnets, GDI Flaws, Election Attacks & More AI Tools in Malware, Botnets, GDI Flaws, Election Attacks & More The Hacker News
WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More WhatsApp Worm, Critical CVEs, Oracle 0-Day, Ransomware Cartel & More The Hacker News
GoCaracal Malware Uses Ethereum for C2 Address Updates GoCaracal Malware Uses Ethereum for C2 Address Updates The Hacker News
Linux Rootkit and macOS Crypto Stealer Dominate Headlines Linux Rootkit and macOS Crypto Stealer Dominate Headlines The Hacker News
Google Sues 25 Chinese Entities Over BADBOX 2.0 Botnet Affecting 10M Android Devices Google Sues 25 Chinese Entities Over BADBOX 2.0 Botnet Affecting 10M Android Devices The Hacker News
Microsoft Unveils Tool to Detect AI Model Backdoors Microsoft Unveils Tool to Detect AI Model Backdoors The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark