Kyrgyzstani Exchange TokenSpot Determined to Be Front Company for Sanctioned Russian Exchange Grinex
TRM User Conference
Which mission will you select?
Key takeaways
- TokenSpot, an exchange based in Kyrgyzstan, and Grinex, an EU, UK, and US-sanctioned Russian exchange, are registered as separate companies but share onchain infrastructure in the way that services run by a single operator do
- After an April 2026 incident, Grinex publicly listed as its own an address that had collected USD 146.3 million from 126 TokenSpot deposit addresses
- Six TRON addresses are attributed to both exchanges, and a single collection address gathers leftover TRX fee balances from both of them
- TokenSpot sent USD 269.2 million to Grinex and Garantex after the UK designated each exchange, and received USD 285.7 million from them over the same periods
- A person reported in 2024 as TokenSpot's director also directed a payments company whose domain uses the same staging subdomains as the A7A5 token's website
{{horizontal-line}}
TokenSpot, a cryptocurrency exchange based in Kyrgyzstan, shares deposit, collection, and fee-funding addresses on TRON with Grinex, the sanctioned Russian exchange that TRM Labs has identified as a likely rebrand of Garantex. TRM assesses with high confidence that the two exchanges, though separate legal entities, run on shared wallet infrastructure and function as parts of the same operation.
On April 16, 2026, Grinex said it had been hacked. About USD 15 million was taken from Grinex and about USD 5,000 from TokenSpot, according to TRM's analysis at the time. Grinex then published a list of addresses it said were affected. One of them collected deposits for TokenSpot. That disclosure strengthens TRM's earlier assessment that TokenSpot likely functions as a front company.
TRM assesses that TokenSpot operates as a front company for Grinex, giving the sanctioned exchange a second, separately registered route for moving funds.
Who TokenSpot and Grinex are
The UK designated Garantex on May 4, 2022. After law enforcement took Garantex down in March 2025, Grinex emerged as its likely successor, and the US Treasury's Office of Foreign Assets Control (OFAC) designated Grinex on August 14, 2025. The UK designated Grinex LLC six days later, on August 20, 2025. TRM has documented how both exchanges connect to the A7 network and the A7A5 token in a deep dive on sanctions evasion networks, in The A7 Leaks, and in earlier work on Russian use of Kyrgyzstan's crypto sector.
TRM's earliest record of TokenSpot's onchain activity is December 8, 2023. Through September 27, 2026, its TRON addresses received USD 3.54 billion and sent USD 3.14 billion. A7, Grinex, and Garantex are TokenSpot's three largest external counterparties. Together they account for 30% of its outgoing volume and 10% of its incoming volume.
Grinex listed a TokenSpot aggregator as its own
Exchanges typically give each customer a separate deposit address, then sweep the funds from those addresses into a central address, known as a deposit aggregator. On TRON, a new address has to be activated before it can be used, which means someone pays its first TRX fee. A service activates its own deposit addresses.
After the April 2026 incident, Grinex published a list of its affected addresses on Telegram. One of them, TA8vyBg93KXaiQXV22WWXTB9hz3caN81DE, was active from February 5 to July 29, 2026 and received USD 268.9 million. Of that, USD 146.3 million came from 126 TokenSpot deposit addresses. At least two of those deposit addresses were activated by THdTnfgmUxt654qFGcPYDgFpVvZxDL3o5u, an address TRM has independently verified as TokenSpot's. These addresses had also had all their funds swept into THdTnfgmUxt654qFGcPYDgFpVvZxDL3o5u while it was still active. This shows that several TokenSpot addresses also behaved as Grinex addresses, including one claimed by Grinex as its own.

Another USD 116.3 million came from three addresses attributed to both TokenSpot and Grinex. Addresses attributed only to Grinex sent USD 1.9 million.

The address Grinex described as its own was collecting TokenSpot customer deposits. TRM assesses that Grinex and TokenSpot were using the same aggregator, which places funds from both exchanges in one address. This means TokenSpot’s funds comingled with sanctioned exchange Grinex’s. This presents a compliance and regulatory issue, as funds withdrawn from TokenSpot via TA8vyBg93KXaiQXV22WWXTB9hz3caN81DE are mixed with funds from an exchange sanctioned by the EU, US, and UK. TA8vyBg93KXaiQXV22WWXTB9hz3caN81DE was active from February 2, 2026 to May 20, 2026, and processed USD 269 million in outgoing transactions. The entirety of this sum is a mixture of sanctioned funds with funds from TokenSpot.
TokenSpot and Grinex share exclusive TRX fee collection address
TokenSpot and Grinex also share a fee-collection address. Every transfer on TRON requires a fee paid in TRX, the network's native token, so services top up their addresses with TRX and later sweep the unused TRX back to a single address. That address is a TRX reservoir. TWqeMbv3EJtJhmKYUTodT7BmG9fcQRjwor received leftover TRX from both TokenSpot and Grinex addresses between April 23 and July 8, 2026. Services send leftover TRX to an address they control, so TokenSpot and Grinex addresses using the same one is consistent with common ownership or shared control. In the transfers mapped in Figure 3, 711 TokenSpot addresses and 58 Grinex addresses sent their final TRX to this address.

A third party draining both exchanges into one address would produce a similar link. The address received about USD 25,000 in total across 1,126 incoming transfers, an average of roughly USD 22 per transfer, and what it collects is small TRX balances left after fees. Those amounts match routine fee management and are too small to represent a theft from two exchanges that moved hundreds of millions of dollars. Based on this, TRM assesses it is unlikely that a third party drained both exchanges into one address.
The April 2026 incident hit both exchanges together
On April 15, 2026, at 13:02 UTC, Grinex announced a "technical break" and said deposits, withdrawals, and its website were temporarily unavailable (Telegram). At 13:27 UTC, 25 minutes later, TokenSpot told customers it was carrying out "technical work" and that deposits and withdrawals might be unstable (Telegram). On April 16, Grinex announced a cyberattack and published its list of affected addresses. Among the addresses that were affected by the hack were two TokenSpot addresses. Grinex did not list these addresses in their disclosure of the incident, and, based on current TRM attribution, no other exchanges were affected by this hack. These overlapping ‘technical’ announcements, in addition to the exfiltration of funds from two TokenSpot addresses as part of a cyber attack targeting Grinex, suggest common control between Grinex and TokenSpot.
TokenSpot sent over USD 950 million to Grinex, Garantex, and A7
TokenSpot sent Grinex USD 164.8 million in total. It also sent USD 109.7 million to Garantex after the US, the UK, and the EU sanctioned that exchange. Flows in the other direction are similar in size. TokenSpot received USD 132.3 million from Grinex after August 20, 2025, out of USD 152.1 million in total, and USD 153.4 million from Garantex.
A7 is TokenSpot's largest external counterparty. TokenSpot sent A7 USD 679.5 million and received USD 48.5 million from it. It also sent USD 26.5 million to A7A5 and received USD 7.7 million.

A shared director links TokenSpot to A7A5's web infrastructure
Melis Batyrbekovich Umarhodjaev was director of both TokenSpot and Tsunami Payments, a Kyrgyz payments company, according to June 2024 reports by Kaktus and Aqparat that cite the Kyrgyz Justice Ministry. As of September 2026, the Justice Ministry registry no longer lists him.
Tsunami Payments' domain, tsunamipayment.kg, and the A7A5 token's domain, a7a5.ai, use the same set of staging subdomains: account-api-stage, account-stage, internal-stage, and kyc-stage, according to public DNS records on dnsdumpster.com.


How compliance teams can screen for this exposure
Compliance teams that screen for Grinex exposure can apply the same treatment to TokenSpot addresses. Screening on the Grinex name alone will miss funds that pass through the aggregator and fee-collection addresses in the table below. Teams with TokenSpot exposure can review counterparty activity since August 20, 2025, when the UK designated Grinex LLC, and check those addresses against their transaction history.
Addresses referenced in this analysis

{{horizontal-line}}
Frequently asked questions (FAQs)
1. What is TokenSpot?
TokenSpot is a cryptocurrency exchange based in Kyrgyzstan. Its TRON addresses received USD 3.54 billion and sent USD 3.14 billion between December 8, 2023 and September 27, 2026.
2. How is TokenSpot connected to Grinex?
The two exchanges share a deposit aggregator that Grinex publicly listed as its own, six addresses attributed to both, and a TRX collection address that gathers fee balances from both. TRM assesses with high confidence that they are operated in common.
3. Is Grinex sanctioned?
Yes. OFAC designated Grinex on August 14, 2025, and the UK designated Grinex LLC on August 20, 2025. The UK designated Garantex, Grinex's likely predecessor, on May 4, 2022.
4. How much did TokenSpot move with Grinex and Garantex after they were sanctioned?
TokenSpot sent USD 269.2 million to the two exchanges and received USD 285.7 million from them after their UK designation dates.
5. What is the connection between TokenSpot and A7A5?
According to June 2024 reports citing the Kyrgyz Justice Ministry, TokenSpot's director also directed Tsunami Payments. Tsunami Payments' domain and the A7A5 token's domain use the same staging subdomains in public DNS records. TokenSpot also sent USD 26.5 million directly to A7A5.




















