Cracking Russia’s Shadow Banks: How the EU’s 21st Sanctions Package Hits Crypto Rails and the A7 Network (Again)

Cracking Russia’s Shadow Banks

What Changed on 23 July

On 23 July 2026, the Council of the EU ratified its 21st restrictive measures framework, imposing sanctions on 218 new targets – comprising 48 individuals and 170 entities – with a strategic emphasis on paralyzing Russia’s financial services and virtual asset sectors.

The escalation is defined by two structural shifts. First, comprehensive asset freezes and prohibitions on economic resources now encompass 94 Russian banks and major financial institutions, with transaction bans hitting 33 additional credit entities. Second, the EU has debuted a legal mechanism for a comprehensive third – country ban on crypto – asset services; this enables Brussels to interdict any transaction between EU operators and crypto providers facilitating Russian activity, irrespective of the provider’s legal domicile.

Crucially, these measures project enforcement far beyond Russian territory. The package targets a Kyrgyz bank linked to Russia’s SPFS messaging system, three additional non – Russian banks aiding circumvention, and 14 virtual asset service providers (VASPs) based in Georgia, Panama, the UAE, the Marshall Islands, Kyrgyzstan, and Belarus. Formally described as a reaction to strikes on civilian infrastructure, the Council intends for these actions to “further cripple Russia’s economy and war machine.”

Tightening the Screws on Financial Institutions

The core of this update involves granular designations of credit and financial institutions that sustain Russia’s domestic lending and state programs. While many listed banks are regional or sector – specific, they are unified by their role as “a substantial source of revenue” for the Russian Federation, thereby fueling the destabilization of Ukraine.

Entries from the Official Journal demonstrate the breadth of this financial blockade:

  • Joint Stock Company Bank 2050: A state – supported institution critical for SME financing initiatives championed by the Kremlin.
  • JSB Ak Bars Bank: A top – tier financial powerhouse deeply integrated into strategic state – backed lending sectors.
  • Renaissance Credit: A major Moscow retail lender and a key participant in the Central Bank’s digital ruble pilot project.

These designations effectively sever EU connectivity to vital segments of Russia’s credit chain. For investigators, the significance lies in these banks’ roles as market makers for sovereign debt and executors of state – mandated loan programs – essential components of the war economy.

Furthermore, the package targets non – bank entities – payment services and fintech firms – that provide the technical liquidity allowing sanctioned actors to bypass Western restrictions. This infrastructure represents a critical target for dismantling Russia’s alternative settlement centers.

Crypto and the A7 Network: From Shadow Channels to Explicit Targets

While virtual assets were previously viewed as a high – risk vector, the 21st package provides a precise tactical response. The Council has added four designations specifically targeting the cross – border A7 network and its expanding ties to Africa, while extending transaction bans to 14 crypto platforms across several global jurisdictions.

The A7 network serves as a Kremlin – endorsed financial corridor designed to evade oil caps and finance military procurement. Estimates suggest the network facilitated over $90 billion in 2025 – roughly half of Russia’s military budget – utilizing crypto rails and Kyrgyz banking hubs. The EU’s new third – country ban ensures that any platform acting as an A7 node is now a legitimate target for enforcement, regardless of where it is based.

This material shift means compliance risk no longer depends on a platform’s registration, but on its functional integration into evasion ecosystems. A cluster of platforms – including Rapira, Aifory Pro, and BitPapa – demonstrate how virtual asset services have evolved into parallel payment rails for sanctioned entities.

Rapira: Georgia - Registered, Moscow - Anchored

Rapira operates at the nexus of Georgian registration and a physical presence in Moscow, facilitating ruble – based trading with deep ties to sanctioned exchanges.

  • Corporate Profile: Incorporated in Georgia but maintains a Moscow office to facilitate domestic trading.
  • Transaction Exposure: Forensic analysis indicates over $72 million in direct transfers with the sanctioned Garantex exchange.
  • Network Links: Integrated with sanctioned Russian giants like Sberbank and VTB, Rapira serves as a textbook example of utilizing non – EU jurisdictions to access global liquidity.

UK sanctions already designate Rapira for “supporting the Russian financial sector.” Its combination of ruble on – ramping and opaque P2P interfaces makes it a prime target for the EU’s new disruptive instruments.

Aifory Pro: Moscow - City Crypto Wallet Turned Sanctions Risk

Positioning itself as a compliant crypto wallet, Aifory Pro operates out of Moscow – City, offering a suite of financial services tailored to “Russian realities.”

On paper, its offerings include:

  • Retail & Business Services: Crypto storage, cross – border routing, and white – label AML modules.
  • Asset Coverage: Support for BTC, ETH, and stablecoins with fiat conversion into RUB, USD, and EUR.
  • Legal Positioning: Claims adherence to Russian AML standards while operating large – scale Moscow – based exchanges.

Despite its compliance facade, Aifory Pro is designated by the UK as a supporter of the Russian financial sector. It functions as a conduit for moving funds between domestic banks and foreign exchanges, illustrating the professionalization of the Kremlin’s crypto front – ends.

ABCEX: High - Volume Exchange Feeding Garantex

ABCeX (ABCEX) has gained notoriety for the sheer volume of its transactions and their heavy concentration on sanctioned platforms.

  • Volume: Estimates suggest the platform has processed at least $11 billion in virtual assets.
  • Counterparties: A significant portion of this volume flows directly to Garantex and Aifory Pro.
  • Risk Profile: ABCEX acts as a structural liquidity provider for entities supporting darknet and sanctioned infrastructure.

While not yet listed by name in the EU, ABCEX’s profile places it squarely within the new regulatory crosshairs. High – volume counterparties to sanctioned platforms are increasingly treated as de facto extensions of those entities.

Whitebird: Belarusian Legal Exchange Under Sanctions Spotlight

Whitebird, organized as White Bird CJSC, functions as a domestically registered cryptocurrency exchange within the Republic of Belarus and maintains residency in the High Technology Park (HTP). While Presidential Decree No. 8 and related legislative acts formally legalize virtual asset trading via HTP‑licensed hubs, Whitebird is frequently highlighted in local media as a primary legal gateway for liquidating digital assets through Belarusian bank cards.

The platform’s operational suite includes:

  • Diversified Trading: A combined exchange, swap, and ICO ecosystem supporting spot trading for major cryptocurrencies and tokenized instruments.
  • Banking Integration: Deep technical links with institutions such as Belarusbank and Alfa‑Bank, complemented by proprietary MasterCard‑branded crypto cards that facilitate the settlement of Russian bank card payments through regulated Belarusian infrastructure.
  • Regulatory Facade: Comprehensive KYC/AML protocols and tax reporting mechanisms designed to position the exchange as a compliant retail and SME retail on‑ramp.

This domestic legality has now encountered the severe reality of international restrictive measures. By mid‑May 2026, leading forensic providers such as Crystal began categorizing Whitebird‑linked liquidity as 100% sanctions‑risk, citing EU provisions that target the Belarusian crypto sector’s role in facilitating circumvention. For users, the shift is stark: a previously “legal” exchange is now treated as a sanctioned node, with historical wallet activity being flagged and interdicted by European financial services.

From an investigative standpoint, Whitebird exemplifies the friction inherent in the 21st sanctions package. While it remains a licensed entity under Belarusian law, its functional utility – specifically its card on‑ramps and cross‑border payment rails – places it directly within the EU’s new disruptive crosshairs aimed at dismantling Russia‑linked shadow financial channels.

Noones: P2P Marketplace as Sanctions Interface

Noones is a peer – to – peer marketplace that has become a significant on – ramp for Russian users seeking to evade sanctions.

  • P2P Structure: Facilitates direct trades using payment methods that are notoriously difficult to trace, such as local transfers and cash.
  • Geographic Reach: Markets heavily in emerging regions used by Russian actors to route around bank restrictions.

P2P platforms pose a unique challenge; they facilitate thousands of small transactions that collectively provide vital liquidity to sanctioned actors. The EU’s third – country ban remains the primary tool for interdicting these decentralized networks.

Tradex.by and Monease: Belarusian and Fintech Links

Tradex.by serves as a Belarus – registered platform for Russian and Belarusian clients, operating at the fringes of financial oversight.

  • Belarus Link: The EU package mirrors Russia – specific restrictions to address Belarus’s involvement in the conflict.
  • Crypto Integration: These platforms provide alternative rails for moving funds when traditional channels are severed.

Similarly, Monease utilizes hybrid fintech models to blur the lines between traditional banking and crypto. For investigators, this confirms that virtual asset risk is inseparable from broader payment – service risk within Russian financial flows.

BitPapa: OFAC - Designated P2P Hub for Darknet and Banks

Bitpapa, sanctioned by both the US and UK, exemplifies the convergence of darknet flows, ransomware, and sanctioned banking into a single high – risk channel.

  • OFAC Designation: Sanctioned in early 2024 for facilitating Russian sanctions evasion.
  • Darknet Links: Processed millions for Hydra Market, the world’s largest darknet platform.
  • Bank Exposure: Facilitates virtual currency transactions with major sanctioned institutions like Sberbank.

Bitpapa is a primary node in the A7 network’s war economy infrastructure. The EU’s move to enable third – country bans creates a clear legal path to mirror the aggressive actions taken by the US and UK against such hubs.

Exnode: Infrastructure Node in Russia - Linked Crypto Routing

Exnode acts as an architectural player, providing the underlying technical and liquidity services required by Russia – linked platforms.

  • Role: Focuses on routing and technical integration for exchanges within the A7 ecosystem.
  • Risk: While less visible than retail brands, these nodes are vital to the resilience of Russia’s crypto infrastructure.

Forensic investigators must look beyond brand – name exchanges to target the behind – the – scenes aggregators that serve the war economy. The EU’s 21st package is specifically designed to reach these entities.

HTX (Huobi) and EXMO: Global Exchanges Under Regional Scrutiny

HTX and EXMO are global exchanges with significant exposure to Russian – linked financial flows.

  • HTX: Designated by the UK for providing economic resources to the Russian financial sector; suspected of channeling billions back to the Kremlin.
  • EXMO: Listed as a supporter of the Russian financial sector due to its popularity among Russian – speaking traders and its role in the A7 network.

As G7 nations tighten the net around A7 network exchanges, EU compliance officers must recognize that dealing with HTX and EXMO may soon be incompatible with their regulatory obligations.

A7A5 and the A7 Network: Structural Macro - Risk

A7A5 represents the internal nodes of the A7 network, a system functioning as a shadow correspondent – banking infrastructure.

  • Scale: Throughput is estimated at $90 billion annually, financing nearly half of Russia’s military spending.
  • Mechanics: Blends Kyrgyz banking with crypto rails to route funds for oil and procurement.

For investigators, the takeaway is clear: A7 is not just a cluster of exchanges, but a sophisticated, sanctions – resistant payment stack. The 21st EU package provides the first explicit set of tools intended to dismantle this parallel financial system.

The Investigative Perspective (CAT Analysis)

Viewed through a forensic lens, the EU’s 21st restrictive measures framework establishes three critical strategic shifts of immediate consequence to our investigative mandates:

  1. Erosion of the Crypto‑Traditional Binary: By simultaneously designating nearly 100 banks and deploying targeted virtual asset instruments, the Council has effectively merged traditional and crypto rails into a singular, integrated war‑financing ecosystem. Compliance frameworks must now treat these sectors as a unified monitoring front.
  2. Projecting Jurisdictional Reach: The package aggressively internationalizes enforcement, interdicting Kyrgyz nodes linked to the SPFS system and platforms across Georgia, the UAE, and Panama. This tactical pivot acknowledges that the Kremlin’s most vital payment corridors are anchored in third‑country intermediaries rather than Moscow.
  3. Codification of Platform‑Specific Risk: The debut of a third‑country ban on crypto services transforms high‑volume providers like Rapira, Bitpapa, and HTX from mere “risk vectors” into potential subjects of comprehensive EU transaction interdiction.

Actionable Takeaway

In light of the EU’s 21st framework and corresponding G7 escalations, our clients must recognize that Russia‑linked virtual asset rails and the A7 network now constitute a primary risk frontier, demanding the same investigative rigor as direct correspondent banking exposure. We recommend three immediate strategic imperatives:

  1. Establish rigorous counterparty screening protocols. Any nexus to platforms such as Rapira, Aifory Pro, ABCEX, Whitebird, Noones, Tradex.by, Monease, Bitpapa, Exnode, HTX, or EXMO must trigger immediate enhanced due diligence, as these A7‑linked nodes function as parallel settlement centers for the war economy.
  2. Operationalize forensic blockchain tracing. Compliance teams should deploy analytical tools to interdict exposure to sanctioned entities like Garantex/Grinex and Hydra‑linked clusters, aligning internal risk logic with the EU’s expansive new third‑country service prohibitions.
  3. Formulate rapid de‑risking contingencies. With Brussels now empowered to impose comprehensive transaction bans on crypto providers aiding the Kremlin, institutions must maintain predefined playbooks for the swift termination of high‑risk relationships without compromising broader operational continuity.

Sources

    1. 21st package of sanctions: EU hits Russian energy, financial services and crypto hard
    2. Elliptic: Forensic Analysis of Russia‑Linked Virtual Asset Evasion
    3. TRM Labs: UK Designations of Huobi, Exmo, and Bitpapa Node Network
    4. Official Journal: UK Russia Sanctions Designations (26 May 2026 Update)
    5. HM Treasury: Statutory Sanctions Notice (Regime: Russia)
    6. OCCRP: Dismantling the Russian Crypto Evasion Infrastructure
    7. Ukrinform: Vlasiuk on the Disruption of Kremlin Crypto Channels
    8. PISM: Strategic Countermeasures Against Circumvention via Virtual Assets
    9. Aying License: The EU 21st Package and the 11‑Platform Prohibition
    10. The Hacker News: US Treasury Designates Russian Exchange Trio
    11. Virtual Routes: Ransomware and Sanctions Tracker (Bitpapa & TOEP)
    12. AML Network Watchdog: Bitpapa Laundering Risk Profile
    13. Aifory Pro: Virtual Asset Settlement Infrastructure
    14. VC.ru: Deep Dive into the Aifory Pro Moscow Wallet Ecosystem
    15. ASCN.ai: Forensic Profile of the Whitebird Legal Exchange
    16. Finprosvet: Functional Review of the Whitebird Ecosystem
    17. Finstore.by: White Bird CJSC Institutional Residency Data
    18. Blockchain Belarus: Whitebird Platform Architecture
    19. KV.by: Legal Mechanisms for Virtual Asset Acquisition in Belarus
    20. Forklog: Whitebird Operational Mechanics for Regional Users
    21. VC.ru: Investigative Tracking of Sanctions Impact on Whitebird
    22. VC.ru: EU AML Provisions and Whitebird Interdiction Reports
    23. VC.ru: Assessing Systemic Risk Exposure for the Whitebird Exchange
    24. Digital Brief: Regulated Virtual Asset Liquidation in Belarus (2025)
    25. Exchange Review: Technical Deployment of Whitebird Infrastructure
    26. 1.ru: Assessing Regional Crypto Rails and Sanctions Escalation (RU)
    27. 1.ru: Cross‑Border Impact of EU Restrictive Measures (EN Translation)
What do you think?
Leave a Reply

Your email address will not be published. Required fields are marked *

Insights

More Related Articles

FATF’s 7th Virtual Asset Update: Criminals Outpace Regulators As Travel Rule Stalls In Practice

Author: Yury Serov

July 17, 2026

The Misunderstood Tool in Every Investigator’s Catalogue

Author: Yury Serov

July 10, 2026

FATF’s Fraud Roadmap 26-28: Three Minutes, 20 Hours and the New Test for AML Effectiveness

Author: Yury Serov

July 3, 2026