Skip to main content
AVOID.NET

Grinex

avoid.net/grinex2/100·100% conf.
[AI-DRAFTED · AWAITING VERIFICATION][src:defillama]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·4wZ7yu…jsYo

Summary

Grinex is a Kyrgyzstan-registered cryptocurrency exchange widely assessed by blockchain intelligence firms and U.S. regulators as a direct successor to Garantex, a sanctioned Russian exchange seized in March 2025. Grinex was formally sanctioned by OFAC in August 2025 for facilitating billions in cryptocurrency transactions linked to ransomware groups, darknet markets, and Russian sanctions evasion. In April 2026, the exchange suspended operations following a reported $13.7 million hack it attributed to Western intelligence agencies — a claim for which no technical evidence was presented and which analysts have suggested may mask an internal exit scam.

Connected Entities

3 entities · 60 linked investigations
Relationships
  • A7A5 Stablecoin / Old Vectormentioned withEthereum(70%)
  • A7A5 Stablecoin / Old Vectormentioned withGrinex(70%)
  • Grinexmentioned withEthereum(60%)
  • Grinexmentioned withA7A5 Stablecoin / Old Vector(80%)
Have evidence about Grinex?
0
Accepted
2
Under review
0
Rejected / revoked

Community submissions

  • Under reviewincriminating[WAYBACK]9/18/2026, 10:13:30 PM

    Elliptic report confirming Grinex suspension following April 2026 hack, alleged Western attribution, and user fund loss from the sanctioned exchange

    avoid-scout

  • Under reviewincriminating[WAYBACK]8/21/2026, 11:08:24 AM

    On April 16, 2026, Grinex — the OFAC-sanctioned Russian exchange built by former Garantex staff — announced it was hacked for ~$15 million (1 billion+ rubles) in user funds, blaming 'Western Special Services.' The exchange subsequently suspended all operations. TRM Labs and Chainalysis both published analyses confirming Grinex had continued processing sanctioned-entity flows after its August 2025 OFAC designation, making the exchange a double-status entity: actively evading sanctions until the hack forced it offline. Grinex co-processed with Kyrgyzstani exchange TokenSpot in the same event.

    avoid-scout

Timeline(13 events)

5 April 2022

OFAC sanctions Garantex for processing over $100 million in illicit transactions, including ransomware payments from Conti, LockBit, and Ryuk, and Hydra darknet market flows.

9 December 2024

Grinex and Meer Exchange domain registrations both occur on the same date, suggesting synchronized infrastructure deployment in anticipation of enforcement action against Garantex.

2025

On-chain analysis later reveals Garantex wallets began moving funds into A7A5 stablecoin as early as January 2025 — weeks before the Garantex takedown.

6 March 2025

Multinational law enforcement action led by the U.S. Secret Service seizes Garantex domains and freezes approximately $26 million in cryptocurrency.

7 March 2025

DOJ unseals indictments against Garantex executives Aleksandr Mira Serda and Aleksej Besciokov. Besciokov is subsequently arrested in India.

7 March 2025

Garantex Telegram channels begin promoting Grinex as a 'new platform with familiar functionality,' transferring Garantex customer deposits to Grinex via the A7A5 stablecoin mechanism.

14 August 2025

OFAC formally designates Grinex as an SDN, along with Garantex co-founders Sergey Mendeleev, Aleksandr Mira Serda, and Pavel Karavatsky, and six associated companies. The A7A5 stablecoin network is also sanctioned.

20 August 2025

UK Office of Financial Sanctions Implementation (OFSI) sanctions Grinex.

September 2025

ICIJ publishes investigation confirming Garantex/Grinex operational continuity despite international sanctions.

23 October 2025

European Commission includes Grinex in its 19th package of Russia sanctions.

16 April 2026

Grinex announces a cyberattack resulting in the theft of over 1 billion rubles (approximately $13.7–$15 million) in user funds, attributing the breach to Western intelligence agencies.

16 April 2026

Grinex suspends all operations. On-chain analysts at Chainalysis, Elliptic, and TRM Labs track stolen USDT being converted to TRX and ETH via SunSwap DEX. TRM Labs identifies a simultaneous hack at TokenSpot exchange.

17 April 2026

Blockchain analysts publish findings raising questions about whether the breach was an external hack or an internal exit scam, noting that fund movement patterns resemble criminal laundering rather than state-actor behavior.

Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (1 event). 22 of 22 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 5/4/2026, 2:54:17 AM

last updated: 8/29/2026, 9:21:01 AM

4 views

avoid.net — verified advice for a post-truth world