The EU's 20th sanctions package, effective May 24, 2026, imposes a blanket prohibition on all transactions between EU-licensed crypto firms and any crypto-asset service provider or decentralized trading platform established in Russia or Belarus. Two days later, on May 26, the UK sanctioned 18 ent...
"If the Kremlin thinks it can evade our sanctions by hiding behind crypto networks and shadow financial systems, it is gravely mistaken." — Yvette Cooper, UK Foreign Secretary
The EU's 20th sanctions package, effective May 24, 2026, imposes a blanket prohibition on all transactions between EU-licensed crypto firms and any crypto-asset service provider or decentralized trading platform established in Russia or Belarus. Two days later, on May 26, the UK sanctioned 18 entities — including HTX (formerly Huobi) — for channeling an alleged $1.5 billion back to the Kremlin through flows tied to previously sanctioned exchanges Garantex and Grinex.
Together, these actions represent the most aggressive coordinated crypto-sanctions campaign in history. The EU has moved from targeting individual platforms (a strategy it now concedes failed due to rapid successor-entity migration) to jurisdictional ecosystem-wide controls that ban an entire country's crypto sector. The UK, in parallel, applied banking-style Regulation 17A measures to crypto exchanges for the first time, a tool previously reserved for sanctioned banks.
The enforcement surge responds to a documented 694% increase in crypto-facilitated sanctions evasion in 2025, driven primarily by Russia's A7A5 ruble-pegged stablecoin, which processed over $93 billion in its first ten months of operation, according to Chainalysis.
The Council of the European Union adopted the 20th package of sanctions against Russia on April 23, 2026, with crypto-specific measures taking effect on May 24. The package marks a structural shift in sanctions methodology. Previously, the EU designated individual entities — specific exchanges, specific wallets, specific tokens. The 20th package abandons that approach for a categorical sectoral prohibition.
As of May 24, every EU-licensed crypto firm is legally barred from transacting with any crypto-asset service provider established in Russia or Belarus, regardless of whether the individual platform has been specifically listed. The EU Council's reasoning, as documented in the regulation, is explicit: further individual listings would simply produce "new successor platforms," a direct reference to the Garantex-to-Grinex migration that proved individual designations inadequate.
Commissioner Maria Luís Albuquerque stated that the package "represents another decisive step in tackling sanctions evasion, targeting financial actors and infrastructure in third countries that enable circumvention," according to an EU Commission press release dated April 23, 2026.
The prohibition extends to decentralized trading platforms established in Russia, a notable jurisdictional claim. Although enforcement against decentralized protocols is operationally difficult, the legal prohibition creates liability for any EU-person or EU-licensed entity that knowingly facilitates access.
The 20th package adds two assets to Annex LIII of the EU sanctions framework: RUBx, a ruble-pegged stablecoin issued through Rosbank's settlement infrastructure, and the digital ruble, the Bank of Russia's central bank digital currency currently in extended pilot and scheduled for mass rollout in September 2026.
No other major jurisdiction has explicitly blacklisted a sovereign-issued stablecoin or pre-emptively banned a CBDC before launch. U.S. OFAC sanctions have targeted individual exchanges and tokens but have not named a stablecoin tied to a foreign state's banking system. The EU's action does both simultaneously.
The digital ruble listing is preemptive. Russia's planned September 2026 CBDC rollout would have created a potential circumvention channel if EU-licensed payment processors, exchanges, or custody providers had already integrated it. By listing it now, the EU forecloses any legal integration pathway months before launch.
RUBx and the digital ruble join A7A5, which was banned under the EU's 19th sanctions package in October 2025 — making three Russian-linked crypto assets now explicitly prohibited under EU law.
On May 26, two days after the EU's measures took effect, the UK's Foreign, Commonwealth and Development Office (FCDO) sanctioned 18 entities and individuals. The most significant target: Huobi Global S.A., the Panamanian entity that operates HTX, one of the world's largest crypto exchanges.
According to Bloomberg and UK government filings, HTX is suspected of channeling over $1.5 billion to Russia through flows from previously sanctioned entities including Grinex and Garantex. The UK government's sanctions notice alleges that HTX served as part of the "infrastructure" used by Russia to circumvent Western restrictions.
The UK applied Regulation 17A of its Russia sanctions regime to crypto exchanges for the first time. This tool — previously used exclusively against sanctioned banks — requires UK financial firms and crypto service providers to freeze funds, sever correspondent relationships, and trace transactions connected to designated entities.
Other sanctioned entities include Bitpapa IC FZC LLC, Exmo Exchange Limited (a crypto exchange popular among Russian-speaking traders), Aifory LLC, and Rapira Group LLC. According to Chainalysis, several of these entities are directly tied to the A7 payments network.
HTX responded by asserting that Huobi Global S.A. is a "distinct" entity from the online HTX exchange and that the designation "does not and should not have any impact" on its operations. The legal separation's practical significance remains untested.
The scale of crypto-facilitated sanctions evasion that precipitated these enforcement actions is documented in Chainalysis's 2026 Crypto Crime Report. In 2025, sanctioned entities received $104 billion in crypto — a 694% increase year-over-year. Total illicit addresses received at least $154 billion, up 162% from 2024.
The primary driver: A7A5, a ruble-pegged stablecoin launched by crypto company A7 in mid-2024. A7 is 49%-owned by Promsvyazbank (PSB), a Russian state-owned defense bank already sanctioned by the U.S. Treasury. A7A5 processed $93.3 billion in transactions within approximately ten months, according to Chainalysis. By January 2026, cumulative on-chain transaction volume had crossed $100 billion.
For context, $93.3 billion is equivalent to approximately one-third of Russia's entire annual imports, according to Foreign Policy. Chainalysis identified an "A7A5 Instant Swapper" service that converts A7A5 tokens into mainstream dollar-pegged stablecoins (USDT, USDC) with minimal or no KYC checks, having processed more than $2.2 billion — effectively bridging sanctioned entities into the broader crypto economy.
A7A5's issuing entities are incorporated in Kyrgyzstan, while reserves are held at Promsvyazbank in Russia. This jurisdictional arbitrage — operating from a non-sanctioned Central Asian country while holding reserves at a sanctioned Russian bank — has been a core feature of the evasion infrastructure.
According to CoinDesk, A7A5's operators stated on May 24, 2026, that the stablecoin has a viable business "even if sanctions end," arguing that its cross-border settlement utility for Russian trade has standalone value.
The EU's shift to sectoral bans was directly informed by the Garantex precedent. In March 2025, the U.S. Secret Service, in partnership with German and Finnish law enforcement, seized Garantex's web domain and froze over $26 million in cryptocurrency.
Within weeks, Garantex's operators launched Grinex as a near-identical replacement, transferring customer deposits and continuing operations. OFAC designated Grinex in August 2025. On April 16, 2026, Grinex announced it had been the victim of a cyberattack — which it attributed to "Western special services" — resulting in the theft of approximately $13.7–15 million in user funds. The exchange subsequently suspended operations.
The Garantex-Grinex cycle demonstrated that targeting individual entities produces a pattern of seizure, reconstitution, re-designation, and repeat. The EU's 20th package addresses this by prohibiting the entire jurisdictional category rather than specific platforms within it.
According to Elliptic's analysis, several Russian-linked exchanges flagged as facilitating sanctioned flows — including Bitpapa, ABCeX, Rapira, and Aifory Pro — collectively processed billions of dollars, with significant flows routed through already-sanctioned exchanges.
The EU's sanctions enforcement now operates on top of the Markets in Crypto-Assets (MiCA) framework, which entered its final transitional phase ahead of the July 1, 2026, deadline. The interaction between MiCA and sanctions creates what compliance analysts describe as a dual-enforcement layer.
MiCA's Travel Rule (Regulation EU 2023/1113), enforceable since December 30, 2024, requires crypto-asset service providers (CASPs) to collect and transmit verified originator and beneficiary information with every crypto-asset transfer. The sanctions package adds a hard prohibition on top of these transparency requirements. A counterparty that an EU venue can now identify under MiCA is the same counterparty it is now legally forbidden from serving.
The compliance infrastructure required is substantial. France issued 14 enforcement notices in Q4 2025 alone. BaFin in Germany blocked access to six offshore exchange domains that targeted German users without CASP authorization.
The convergence of MiCA compliance and sanctions enforcement creates operational pressure that disproportionately affects smaller EU-licensed venues. Large exchanges can spread compliance costs via EU passporting across 27 member states. Smaller firms face consolidation pressure, as the cost of sanctions screening, on-chain monitoring, and travel rule compliance scales poorly below certain volume thresholds.
The practical compliance burden for EU-licensed exchanges is immediate and multi-layered:
Counterparty screening: All transaction counterparties must be checked against the newly expanded prohibition — not just against a list of designated entities, but against the jurisdictional origin of any crypto service provider. Exchanges must determine whether a counterparty is "established in Russia or Belarus," which requires more than wallet-address screening.
On-chain monitoring: Exchanges must implement or upgrade blockchain analytics capabilities to identify flows originating from or destined for Russian/Belarusian infrastructure, including A7A5 swapper services and successor platforms to Garantex/Grinex.
Customer risk scoring: Enhanced due diligence requirements for flows with any connection to sanctioned jurisdictions, including indirect exposure through intermediary wallets or mixers.
Reporting obligations: Faster reporting and cooperation in cross-border investigations, with EU financial intelligence units expecting real-time or near-real-time suspicious transaction reporting.
The timeline is compressed. The May 24 effective date gave exchanges one month from the April 23 adoption to implement systems capable of identifying and blocking an entire jurisdiction's crypto ecosystem — a task that, according to compliance industry sources, typically requires three to six months.
The EU and UK actions of May 24–26, 2026, mark an inflection point in the intersection of crypto regulation and geopolitical sanctions enforcement. The economic logic is straightforward: when individual designations fail because successor entities emerge within weeks, the rational enforcement response is to prohibit the entire jurisdictional category.
The scale of the underlying problem — $93.3 billion in A7A5 volume alone, within a broader $104 billion sanctions-evasion ecosystem — demonstrates that crypto-facilitated sanctions circumvention has moved from a theoretical risk to a documented, industrial-scale operation. The EU's response acknowledges this by treating crypto sanctions enforcement as a systemic-infrastructure problem rather than a platform-by-platform enforcement exercise.
For EU-licensed exchanges, the compliance implications are concrete and immediate. The one-month implementation window between adoption and effective date was shorter than industry-standard timelines. Exchanges that had already invested in MiCA Travel Rule compliance hold an advantage; those that had not face both sanctions liability and a rapidly approaching July 1 MiCA deadline.
The preemptive ban on Russia's digital ruble — months before its September 2026 launch — signals that regulators are now thinking forward about CBDC-based evasion channels rather than reacting to established patterns. Whether enforcement can keep pace with the next generation of evasion infrastructure remains an open question, but the regulatory framework is no longer playing catch-up with the last war.