Artificial Intelligence

US-sanctioned currency exchange says $15 million heist done by "unfriendly states"

Published byAIDaily Editorial Team
3 min read
Original source author: Dan Goodin

Grinex says needed hacking resources "available exclusively to ... unfriendly states."

Share:
US-sanctioned currency exchange says $15 million heist done by "unfriendly states"

Grinex says needed hacking resources “available exclusively to … unfriendly states.”

Grinex, a US-sanctioned cryptocurrency exchange registered in Kyrgyzstan, said it’s halting operations after experiencing a $13 million heist carried out by “western special services” hackers.

Researchers from TRM, which has confirmed the theft, put the value of stolen assets at $15 million after discovering roughly 70 drained addresses, about 16 more than Grinex reported. Neither TRM nor fellow blockchain research firm Elliptic has said how the attackers slipped past Grinex’s defenses. Grinex said it has been under almost constant attack attempts since incorporating 16 months ago. The latest attacks, it said, targeted Russian users of the exchange.

Damaging “Russia’s financial sovereignty”

“The digital footprints and nature of the attack indicate an unprecedented level of resources and technology available exclusively to the structures of unfriendly states,” Grinex said . “According to preliminary data, the attack was coordinated with the aim of causing direct damage to Russia’s financial sovereignty.”

“Due to the attack, the Grinex exchange is forced to suspend operations,” Grinex continued. “All available information has been transferred to law enforcement agencies. An application has been submitted to the location of the infrastructure to initiate a criminal case.”

TRM said that TokenSpot, a second Kyrgyzstan-based exchange, was also breached. Two of the exchange’s addresses sent funds to the same consolidation address used by the affected Grinex-linked wallets. What’s more, both exchanges became inoperable on Wednesday, suggesting they were hit by the same attacker.

TRM said TokenSpot was a front for Grinex, which the US Treasury Department sanctioned last year. The department’s Office of Foreign Assets Control said that Grinex, in turn, was a rebrand of Garantex, an exchange it had sanctioned in 2022 . The department said then that Ganantex had “directly facilitated notorious ransomware actors and other cybercriminals by processing over $100 million in transactions linked to illicit activities since 2019.” Last year’s sanctions against Grinex came a few months after TRM said that the exchange was likely a front for Ganantex.

TRM said Thursday that it couldn’t confirm Grinex’s claim that Western special services were behind the heist. TRM also said that the theft didn’t appear to be performed by insiders in an attempt to liquidate assets before abandoning the exchange.

“Based on the relatively low total value drained, the indiscriminate targeting of both large and small wallets across multiple platforms including TokenSpot—which has since resumed operations after claiming a technical issue—TRM assesses this incident was more likely an external cyber operation rather than an exit scam.”

Elliptic said that Grinex has “strong ties to Russia and is one of the largest exchanges for exchanging Russian rubles for cryptoassets.” To date, it has processed transactions totaling more than $6 billion.

“It is likely that Grinex has common ownership and management with Garantex and was established as a response to the sanctions imposed on Garantex,” Elliptic said. “Following the shutdown of Garantex, much of its liquidity and clients migrated to Grinex.”

The drained Grinex accounts, Elliptic said, had outgoing transactions totaling about $15 million in USDT, an ethereum-based stablecoin its backers say is pegged to the value of the US dollar. The funds were then sent to further accounts on the TRON or ethereum blockchains. The USDT was then converted to either the TRX or ETH currencies. That conversation allowed the attackers to avoid the risk of the stolen assets being frozen by Tether, the company that issues the USDT stablecoin.

Key takeaways

  • The attack on Grinex highlights the vulnerability of cryptocurrency exchanges and the need for robust security.
  • The connection between Grinex and Garantex underscores the importance of due diligence in choosing investment platforms.
  • The incident may impact user trust in exchanges, especially in regions with political tensions.

Editorial analysis

The recent breach of the Grinex exchange, resulting in a theft of approximately $15 million, raises significant questions about the security of cryptocurrency platforms, particularly in a context where regulation is still developing in many countries, including Brazil. The claim that the attack was carried out by 'Western special services' reflects a geopolitical narrative that may impact user perception and trust in cryptocurrency exchanges, especially those operating in regions with political tensions, such as Central Asia.

For the Brazilian tech sector, this situation serves as a warning about the need to bolster cybersecurity measures in cryptocurrency trading platforms. With the growth of the crypto asset market in Brazil, protection against cyberattacks must be a priority, especially considering that the country already faces challenges related to digital security. Grinex's experience can be a valuable case study for Brazilian exchanges, which should learn from the mistakes and vulnerabilities of their international peers.

Moreover, the connection between Grinex and Garantex, both sanctioned by the U.S. government, highlights the importance of rigorous due diligence in choosing investment platforms. A lack of transparency and the potential for involvement in illicit activities can harm not only investors but also the reputation of the cryptocurrency market as a whole. Brazil, which is in the process of regulating the sector, should consider these issues when formulating policies that promote a safe and trustworthy environment for investors.

What to watch for next is how cybersecurity authorities and regulatory agencies will respond to this incident. International collaboration may be necessary to address emerging threats and protect digital assets. Additionally, the response from Grinex and other affected exchanges may influence security practices across the sector, leading to greater awareness of the importance of data protection and transaction integrity in an increasingly complex digital environment.

What this coverage includes

  • Clear source attribution and link to the original publication.
  • Editorial framing about relevance, impact, and likely next developments.
  • Review for readability, context, and duplication before publication.

Original source:

Ars Technica AI

About this article

This article was curated and published by AIDaily as part of our editorial coverage of artificial intelligence developments. The content is based on the original source cited below, enriched with editorial context and analysis. Automated tools may assist with translation and initial structuring, but publication decisions, factual review, and contextual framing remain editorial responsibilities.

Learn more about our editorial process