Skip to content

Risk operations

Crypto exchange sanctions: lessons for businesses

admin · 8/9/2026 · 12 min read

Global crypto payment network with one incoming route flagged for review

Recent actions against crypto exchanges linked to Iran and Russia show why businesses should screen incoming wallets, understand jurisdiction, and pause risky payments before acceptance.

A year that changed the sanctions conversation around crypto

For businesses that accept cryptocurrency, exchange risk is no longer a question reserved for banks and specialist compliance teams. Between August 2025 and August 2026, authorities in the United States, the United Kingdom, and the European Union announced actions involving exchanges and payment networks connected to Russia and Iran. The names were different, but the operational lesson was consistent: a crypto payment can carry risk from the service it passed through, even when the asset itself is widely used and the customer appears ordinary.

That does not mean every payment from a particular country is unlawful. It also does not mean an address becomes criminal merely because it has some connection to a named platform. Sanctions are imposed under specific legal regimes, their reach depends on jurisdiction and other legal connections, and blockchain exposure requires interpretation. A responsible business needs to distinguish those questions before accepting or rejecting funds.

This article reviews five significant developments from the past year, explains what the authorities actually announced, and turns the news into a practical incoming payment process. Information and links were checked on 9 August 2026.

First, these were not “worldwide sanctions”

Headlines often compress a complex action into a few words: an exchange was sanctioned. The missing question is by whom?

A United States designation creates obligations for United States persons and transactions within United States jurisdiction. Depending on the authority used, it can also expose some people and institutions outside the United States to secondary sanctions risk. United Kingdom restrictions apply under the United Kingdom regime. European Union measures operate under European Union law. The same exchange may be targeted by several jurisdictions, but that still is not the same as a single global prohibition.

For a business, the relevant analysis can include where the company is established, where its staff and customers are located, which financial institutions or service providers are involved, what currency and infrastructure are used, and whether a specific sanctions authority has wider consequences. This is why a blockchain risk report should support a sanctions process, not replace legal analysis or a current list check.

What happened during the past year

14 August 2025: the United States acted against Garantex, Grinex, and their network

The United States Treasury redesignated Garantex and designated Grinex, which it described as a successor exchange created by Garantex employees after earlier enforcement action. Treasury also targeted executives and associated companies in Russia and the Kyrgyz Republic. According to Treasury, Garantex had processed more than $100 million in transactions linked to illicit activity since 2019, while Grinex had facilitated billions of dollars in cryptocurrency transactions after its creation.

The announcement also described how customer deposits were moved toward the successor operation and how A7A5, a token backed by the ruble, was used in that transition. This matters because sanctions risk does not always remain attached to one familiar brand. Infrastructure, staff, customer balances, tokens, and wallet activity can migrate to a new entity.

Read the United States Treasury announcement and CoinDesk's independent coverage.

20 August 2025: the United Kingdom targeted Grinex, Meer, and A7A5 infrastructure

Six days later, the United Kingdom announced measures against financial and crypto networks it said Russia was using to circumvent sanctions through Kyrgyzstan. The action included the Grinex and Meer exchanges and infrastructure associated with A7A5. The United Kingdom government said the token had moved $9.3 billion on a dedicated exchange in four months.

This action shows how quickly the same network can attract attention in more than one jurisdiction. It also broadens the review question. A business should not look only for an old exchange name. It should consider related services, successor platforms, issuers, and payment rails identified in current intelligence.

Read the United Kingdom government announcement.

23 October 2025: the European Union expanded its focus on crypto providers

In its nineteenth package of measures concerning Russia, the European Union said recent activity showed increasing use of crypto to circumvent restrictions. It targeted the developer of A7A5, the Kyrgyz issuer of the token, and the operator of a platform where significant volumes of it were traded. The package also introduced restrictions involving crypto payment services.

The important point for risk teams is not that every ruble linked token or every platform in a third country is automatically prohibited. It is that enforcement can follow the wider service chain. An issuer, platform operator, exchange, bank, and related company may form parts of the same payment route, while each has a different legal identity and role.

Read the Council of the European Union announcement.

2 June 2026: the United States designated four Iranian exchanges

The United States Treasury designated Nobitex, Wallex, Bitpin, and Ramzinex. Treasury described Nobitex as Iran's largest digital asset exchange and said it processed more than half of Iranian digital asset inflows in 2025. It accused the exchanges of supporting sanctions evasion or processing activity linked to sanctioned Iranian institutions and the Islamic Revolutionary Guard Corps.

The June announcement was not the beginning of every United States restriction on Iranian crypto exchanges. On 1 May 2026, the Office of Foreign Assets Control stated that Iranian digital asset exchanges meet the regulatory definition of an Iranian financial institution and are blocked under the cited rules even if they do not appear by name on the Specially Designated Nationals list. The later action publicly named four exchanges and added specific designation grounds and associated individuals.

The legal detail is especially important here. In another FAQ, the Office of Foreign Assets Control stated that certain dealings by foreign financial institutions and other persons outside the United States with the four exchanges can create sanctions exposure under the authorities cited in the designation. That does not produce one automatic answer for every business or transaction, but it makes jurisdictional review essential rather than optional.

Read the United States Treasury announcement, OFAC FAQ 1250, OFAC FAQ 1257, Associated Press coverage, and Reuters coverage.

7 August 2026: the United States targeted Shelbit Exchange and Aban Tether

Two days before this article was checked, the United States Treasury announced another action involving crypto exchanges connected to Iran. It targeted Shelbit Exchange, which Treasury described as operating through a network of companies in Georgia, the United Arab Emirates, and Poland, as well as Iran based Aban Tether. Treasury alleged that Shelbit processed activity involving wallets attributed to the Islamic Revolutionary Guard Corps and that Aban Tether had handled transactions involving the four Iranian exchanges named in June.

This case adds an important cross border lesson. A service may use one brand while operating through several legal entities in different countries. Screening only the customer's country or the address shown on an exchange website can miss the corporate and wallet relationships that matter to the payment.

Read the United States Treasury announcement and Reuters coverage.

The timeline at a glance

Date Authority Main crypto targets Operational lesson
14 August 2025 United States Garantex, Grinex, executives, and associated companies Risk can migrate from a disrupted exchange to a successor network.
20 August 2025 United Kingdom Grinex, Meer, and A7A5 infrastructure Several jurisdictions may target different parts of one payment system.
23 October 2025 European Union A7A5 developer, issuer, and a platform operator Review the wider service chain, not only the exchange brand.
2 June 2026 United States Nobitex, Wallex, Bitpin, and Ramzinex Some Iran related dealings can create risk beyond United States persons.
7 August 2026 United States Shelbit Exchange, Aban Tether, and related companies One exchange brand may operate through entities and wallets across several countries.

Why the sender's wallet matters

A customer may say that funds came from personal savings, an exchange account, or a trading counterparty. The blockchain address provides a separate evidence trail. It can show direct interaction with an identified service or a more distant connection through intermediate wallets.

That distinction matters. A direct transfer from an address associated with a designated exchange is not the same as a remote, low value path that passed through several services. Neither observation, on its own, proves who owns the wallet or whether a legal breach occurred. It does tell the business what needs to be reviewed before the payment is treated as cleared.

Waiting until funds have been pooled, converted, or paid onward makes the investigation harder. The payment team may lose the clean relationship between the customer, invoice, transaction hash, receiving address, and screening result. A short hold before acceptance creates room for a proportionate decision.

How Farona helps before you accept the payment

Farona turns available blockchain risk signals into a Farona score, one of five Farona risk levels, a plain language verdict, and supporting evidence. The result can help a business identify incoming wallets that deserve closer review without exposing users to raw provider risk levels.

1. Screen the actual sender address

Ask the payer for the sending wallet before the transfer where the payment flow allows it. If the transaction has already been broadcast, record the transaction hash and identify the relevant sending address on the correct network. Screening a customer name or an exchange name alone is not a substitute for reviewing the address involved in the payment.

2. Read the Farona level with the evidence

Use the Farona level for triage, then read why the result was assigned. Pay attention to the risk category, whether exposure is direct or indirect, its available size, and the number of intermediate steps. A label without transaction context can be too broad, while a score without supporting evidence can be too easy to misread.

3. Open the context that answers the next question

When the case needs more detail, available Farona report sections can add address labels, counterparties, transaction flows, wallet profile information, and other relevant context. Address labels may help identify known associations. Counterparties and flows may help show whether the payment appears to be an isolated connection or part of a wider pattern.

Additional data should have a purpose. Open the section that helps answer a defined question, such as whether the relationship is direct, which service appears in the path, or how material the exposure is.

4. Pause, escalate, or request evidence

If the result exceeds your policy threshold, keep the payment pending. Ask for information that fits the case, such as proof of source, account withdrawal records, the purpose of the transfer, or an explanation of the wallet relationship. High and Critical Farona results should normally receive documented human review before funds are credited or moved.

5. Check the applicable sanctions lists and law

Farona supports risk investigation. It is not a substitute for checking the official lists that apply to your business, applying ownership and control rules, or obtaining legal advice. Sanctions data and wallet intelligence can change, and some restrictions apply even when a specific address is not published on a list.

6. Preserve the decision record

Keep the customer or invoice reference, wallet address, network, transaction hash, report generation time, relevant findings, information requested, reviewer, and final action. A good record explains what was known when the decision was made and why the response followed company policy.

A practical incoming payment policy

A useful policy defines the response before a difficult payment arrives. The exact thresholds should reflect your jurisdiction, business model, transaction values, customer profile, and professional advice.

  • Routine review: Verify the network and wallet, retain the result, and proceed when the case falls within approved limits.
  • Enhanced review: Open relevant evidence, request source information, and obtain a second review when the result or context is unclear.
  • Pause and escalate: Do not credit or move funds when severe direct exposure, a material pattern, or a High or Critical result exceeds policy.
  • Decline or restrict: Follow the action required by applicable law and your policy when a prohibited party or unacceptable relationship is identified.
  • Review again: Generate a current assessment if material time passes or new wallet activity appears before the payment is finalized.

Common mistakes after a sanctions headline

  • Calling a national action global: Always name the authority and legal regime involved.
  • Blocking an entire nationality: Country, residence, exchange exposure, wallet ownership, and prohibited party status are different facts.
  • Searching only the old brand: Successor platforms and related infrastructure can emerge after enforcement.
  • Treating indirect exposure as direct dealing: State the transaction distance accurately and review the intermediaries.
  • Assuming an unlisted address is safe: Published lists are essential, but ownership, control, related addresses, and new intelligence can matter.
  • Letting automation make the legal conclusion: Screening should route decisions and preserve evidence. Qualified people remain responsible for the final action.

What businesses should take from these cases

The past year showed a clear pattern. Authorities are looking beyond a single exchange domain and following the infrastructure around tokens, successor platforms, companies, executives, and payment channels. The regulatory reach differs by jurisdiction, but the operational consequence is similar: businesses need to understand where an incoming payment came from before they treat it as available money.

Farona helps make that review faster and more consistent by turning blockchain signals into a structured Farona assessment and letting teams add context when the case justifies it. The safest process combines that evidence with current official sanctions lists, a defined escalation policy, customer information, and specialist advice when the legal position is uncertain.

This article is general information, not legal advice. Sanctions change quickly. Confirm the rules and official lists that apply to your organization before acting.

Sources and further reading

Related posts

More from the same category.