Garantex: The Russian Exchange That Moved $96 Billion and Would Not Die
A Moscow cash desk for ransomware gangs and sanctions dodgers moved $96 billion, was shut by the US Secret Service, and reopened under a new name.
Key numbers
$96B+
Volume processed
2019-2025
Years open
$26M+
Frozen in takedown
Up to $5M
US reward offered
On the morning of 6 March 2025, customers of Garantex, a cryptocurrency exchange run out of Moscow, opened its website and found a law enforcement banner where the trading screen used to be. The US Secret Service had seized its web addresses. German and Finnish police had taken its servers. Tether, the company behind the most widely used digital dollar, had frozen the exchange's wallets. The next day, the US Justice Department unsealed criminal charges against two of the men who ran it.
The Justice Department put a number on what Garantex had done since April 2019: at least $96 billion in cryptocurrency transactions. Blockchain analytics firm Elliptic, which helped the investigation, said more than $60 billion of that moved after April 2022, when the US government had already blacklisted the exchange. For comparison, BTC-e, the Russian exchange closed by the US in 2017 and long treated as the benchmark for crypto money laundering, was accused of handling about $4 billion.
Garantex did not stay dead. Within days its customers were trading on a new exchange called Grinex, paid out in a new digital rouble called A7A5. Eighteen months later, governments are still adding the name to their sanctions lists. On 2 October 2026 Japan became the latest.

AI agents and automation
Could AI answer your customers from your own documents?
Assistants trained on your files, website and FAQs, with limits on what they can say. Fixed price before any work starts.
AI agents and automation
A cash desk with a Moscow address
A crypto exchange is the equivalent of a currency booth crossed with a stockbroker. Customers hand over ordinary money, roubles in this case, and get crypto in return, or the other way round. The most traded product on Garantex was USDT, a stablecoin issued by Tether: a digital token designed to always be worth one US dollar, like a casino chip that can be cashed anywhere in the world.
That made Garantex a door. According to the European Union, customers of Sberbank, T-Bank and Alfa-Bank, Russian banks under EU sanctions since 2014, could use it to turn roubles in their bank accounts into digital dollars, then turn those into other currencies abroad. Money that could no longer leave Russia through a bank could leave through Garantex.
The exchange was registered in Estonia as Garantex Europe OU, but the US Treasury said most of its work was done in Moscow and Saint Petersburg, including from Federation Tower, a Moscow skyscraper that also housed other sanctioned exchanges. In February 2022 Estonia's Financial Intelligence Unit revoked its licence after finding "critical" anti-money laundering failures and links to wallets used for crime. Garantex kept trading anyway.
Who used it
On 5 April 2022 the US Treasury's Office of Foreign Assets Control (OFAC), the department that keeps America's sanctions blacklist, added Garantex to that list. Any American person or business that dealt with it was now breaking US law. The Treasury said the exchange had handled more than $100 million linked to criminals and darknet markets, the hidden websites where drugs and stolen data are sold. That included about $6 million from Conti, a Russian-speaking ransomware gang, and about $2.6 million from Hydra, then the largest darknet drug market in the world. German police shut Hydra down the same day.
Ransomware is software that locks up a company's computers until the owner pays a ransom, usually in crypto. Conti's victims included Ireland's national health service, the HSE, in 2021, and the government of Costa Rica in 2022. The Treasury later named other ransomware groups whose money passed through Garantex: Black Basta, LockBit, NetWalker, Phoenix Cryptolocker and Ryuk. Elliptic said Garantex was also used to launder thefts attributed to North Korea's Lazarus Group.
The sanctions did not slow it. The Justice Department said Garantex changed its operating wallet addresses, the crypto equivalent of account numbers, every day, so that US exchanges could not recognise and block its payments. TRM Labs, another blockchain analytics firm, found that Garantex and Iran's Nobitex together accounted for more than 85% of crypto flowing to sanctioned entities and countries in 2024. In February 2025 the EU sanctioned Garantex too, the first time it had done that to a Russian crypto exchange.
The takedown
The end came over two days. On 6 March 2025 the Secret Service, acting on a seizure order from a judge in the Eastern District of Virginia, took the domains Garantex.org, Garantex.io and Garantex.academy. German and Finnish police seized the servers. US agents already had earlier copies of those servers, including customer and accounting records. More than $26 million was frozen, much of it in USDT that Tether blocked. Garantex announced it was suspending all operations.
On 7 March the Justice Department unsealed an indictment, a formal set of criminal charges, against two men. Aleksej Besciokov, 46, a Lithuanian national living in Russia, is described as the exchange's main technical administrator, the man who kept its systems running and approved transactions. Aleksandr Mira Serda, 40, a Russian national living in the United Arab Emirates, is described as its co-founder and chief commercial officer. Both are charged with conspiracy to launder money, which carries up to 20 years in prison. Besciokov is also charged with conspiring to break US sanctions (up to 20 years) and running an unlicensed money transfer business (up to five). Neither has been convicted.
Four days later Besciokov was arrested in India. Kerala state police found him on 11 March 2025 in Varkala, a beach town where he had been on holiday with his wife and two daughters. His family had flown home the day before. He was taken to Delhi to face a US extradition request under India's Extradition Act of 1962. No public record shows he has yet been handed over to the United States. Mira Serda remains at large.
The same desk under a new name
Garantex had seen it coming. TRM Labs found that between 8 February and 1 March 2025, days before the raid, Garantex moved billions of A7A5 tokens to new addresses linked to Grinex, an exchange registered in Kyrgyzstan. A7A5 is a stablecoin tied to the rouble rather than the dollar. It was launched in early 2025 by A7, a payments company the US Treasury says is owned by the sanctioned Moldovan oligarch Ilan Shor and the Russian state bank Promsvyazbank, and issued by a Kyrgyz firm, Old Vector.
After the raid, the Treasury said, Garantex customers who had lost access to their money were paid back in A7A5 on Grinex. Same customers, same business, new name. Elliptic later counted more than $100 billion in A7A5 transfers in under a year, with Grinex the main place to trade it.
On 14 August 2025 the US sanctioned Grinex, A7 and its affiliates, and three Garantex executives: Sergey Mendeleev, Mira Serda and Pavel Karavatsky. The State Department offered up to $5 million for information leading to Mira Serda's arrest and up to $1 million for other Garantex leaders. Britain sanctioned Grinex and Old Vector six days later. The EU banned all dealings in A7A5 in October 2025.
In April 2026 Grinex itself stopped trading after what it called a cyberattack by "Western special services" that took around $13 million. Blockchain analysts at Elliptic and TRM Labs published no evidence of a state attacker, and the pattern looked more like the operators emptying the till, as CMZ reported at the time.
Still being chased
On 2 October 2026 Japan froze the assets of 33 organisations and nine individuals under its Foreign Exchange and Foreign Trade Act, and crypto news outlets reported that Garantex was one of them. The same package was Japan's first ever sanction on ships: 35 vessels in Russia's "shadow fleet", the ageing tankers that carry Russian oil around Western price limits. In practice the listing means no one under Japanese law may make payments or capital transactions with Garantex.
The exchange itself has been offline for 19 months, so the order freezes little that is still moving. Its value is the signal, and the pattern it confirms. Garantex was licensed and lost the licence, sanctioned and kept trading, raided and reopened. Each time, the same people moved the same customers to a new name faster than governments could add that name to a list.
The aftermath
Garantex has been offline since 6 March 2025. More than $26 million was frozen in the takedown, and the US Secret Service asked anyone whose money was laundered through the exchange to come forward as a possible claimant. Aleksej Besciokov was arrested in India on 11 March 2025 and taken into custody in Delhi pending extradition; no public record shows he has been transferred to the US. Aleksandr Mira Serda has not been arrested, and the State Department reward of up to $5 million stands. Both men are charged, not convicted. The business moved to Grinex and the rouble stablecoin A7A5, which together handled tens of billions of dollars before the US (August 2025), UK (August 2025) and EU (October 2025) sanctioned them. Grinex halted trading in April 2026 after a claimed hack. On 2 October 2026 Japan added Garantex to its asset-freeze list, according to crypto news reports of the package, alongside 32 other entities, nine individuals and 35 shadow fleet tankers.
What this teaches
- Losing a licence did not stop Garantex. Neither did US sanctions. Only seizing the servers and freezing the money did.
- A sanctioned exchange with a loyal customer base can be rebuilt under a new name within days, especially when the move is prepared in advance.
- Stablecoins cut both ways: Tether could freeze Garantex's digital dollars, so its operators built a digital rouble Tether could not touch.
- Sanctions lists move slower than the businesses on them. Japan listed Garantex 19 months after it went offline.

COMMENTS