EU Crypto Sanctions Target 14 Firms Linked to Russia
The EU just tightened the screws on Russia again, and this time crypto rails are squarely inside the blast radius. The 21st sanctions package is not vague policy talk. It is a line-by-line list of crypto services EU firms must stop transacting with, plus a new legal lever that could shut off entire jurisdictions if Brussels decides it is necessary.
If you run a European exchange, OTC desk, wallet, or payments platform, you now have dates to circle, names to block, and workflows to update. And if you are a market participant routing liquidity across borders, expect spreads to wobble as flows reshuffle.
Let’s walk through what was actually adopted, who is on the list, how fast this bites, and what to fix in your stack before the cutover.
| Point | Details |
|---|---|
| Package adopted | The EU approved its 21st Russia sanctions package on 23 July 2026, adding 218 listings in total according to the Council’s press release (Council of the European Union). |
| Crypto-specific move | The transaction ban extends to 14 crypto-related service platforms across six jurisdictions: Georgia, Panama, UAE, Marshall Islands, Kyrgyzstan, and Belarus (Council press release). |
| Named entities and dates | The Official Journal lists all 14 entries and sets entry-into-force dates in August 2026, including items like HTX (HUOBI GLOBAL SA) and EXMO Ltd (Official Journal 2026/1848). |
| New legal lever | For the first time, the EU created a mechanism to impose a full third-country ban on crypto-asset services, if required (Council; Official Journal). |
| A7 network focus | Four asset-freeze designations tied to the cross-border A7 payments network are included, raising routing risk for intermediaries (Council press release). |
What the 21st EU sanctions package actually says
Editor's note: In Q1 and Q2 this year I spent a lot of time with European ops leads who were rationalizing venue lists even before this package landed. The red flags kept repeating: unclear ownership, aggregator routes that went dark after trade, and counterparty answers that changed by the week. We also saw banks ask for evidence of sanctions blocks on test withdrawals, not just policy PDFs. My own desk had to reroute a couple of liquidity lines out of smaller hubs in April, which in hindsight made this July shift a faster lift. The practical edge is always in the runbooks. — Darnell Whitaker
The Council says the 21st package adds 218 listings in all, made up of 48 individuals and 170 entities. Crypto is not a side note in this round. The rules explicitly widen the transaction ban to include 14 crypto-related service platforms that EU persons and companies must not deal with. That is spelled out in the Council’s own announcement dated 23 July 2026 (Council of the European Union).
The legal hooks live in the Official Journal, Regulation (EU) 2026/1848. That document amends the relevant annexes and names each crypto entry with specific timing. This is where compliance teams should camp out, since internal control wording, dates, and definitions flow from those annex updates (Official Journal 2026/1848).
One more material change: the EU introduced a new mechanism that allows it to impose a full third-country ban on crypto-asset services. It is not pointed at any named country today, but the switch now exists. If Brussels flips it, EU entities could be prohibited from providing or receiving crypto services to or from an entire jurisdiction (Council press release).
Who is on the crypto blocklist: the 14 platforms
The Official Journal names the 14 crypto-related services, some by brand and some by their operating companies. It also sets staggered entry-into-force dates in August. Here is the list, as published in Annex updates of Regulation 2026/1848 (Official Journal):
- Entry into force 13 August 2026: A7 Nigeria; A7 Africa; PilotFinance Ltd.
- Entry into force 23 August 2026: Rapira; Aifory Pro (Sooty Ltd.); ABCeX (Nueva Cryptologia S.A.S DE C.V.); WhiteBird; NoOnecrypto INC.; Tradex (Brightum LLC); Monease Ltd; BitPapa; Exnode, Exnode Pay (Arvix); HTX (HUOBI GLOBAL SA); EXMO Ltd.
The Council’s press note also points out the geographic spread. The 14 are tied to six jurisdictions: Georgia, Panama, the UAE, the Marshall Islands, Kyrgyzstan, and Belarus (Council of the European Union).
What this means in practice: once the dates hit, EU persons and firms must not transact with these services, directly or indirectly. That includes onboarding, payments, brokerage, market making, withdrawals routed via them, API connectivity, and even marketing arrangements that result in a prohibited service being delivered. When in doubt, get written legal advice and over-communicate with your banking partners.
Pro tip: Update any vendor risk register entries that reference these brand names and their parent entities. If you only screen legal names and miss the consumer-facing brand, you will leak exposure.
What EU businesses need to do right now
Short checklist for VASPs and fintechs
- Freeze onboarding and cut API keys for the listed services before the entry dates. Log the change and notify impacted users.
- Push an emergency update to your sanctions screening layer so both the brand and corporate names trigger blocks.
- Map dependencies. Look through wallet providers, liquidity aggregators, PSPs, and OTC partners to identify second-order exposure.
- Re-paper contracts. Add a sanctions representation and a right to terminate on designation to vendor and liquidity agreements.
- Train customer support. Provide a public statement and a playbook for handling withdrawals that would route to a prohibited venue.
- Engage your bank early. Explain your cutover plan so fiat rails are not flagged or de-risked while you comply.
What to do with user assets
Many firms will face a practical question: how to handle user balances that could be stranded if the counterparty is on the list. Best practice is to provide a window to reroute to compliant destinations, then cordon off any attempted transfers to listed platforms once the dates hit. Keep clear audit trails for every blocked attempt and communicate proactively.
Dealing with gray zones
Some names appear both as brands and as entities registered in specific jurisdictions. If you rely on an aggregator that splits orders across multiple venues, turn on detailed venue disclosure. If you cannot validate the route, do not send the order. Sanctions breaches are strict liability in many cases, and intent will not save you.
Cross-border quirk: the new third-country ban tool
The sleeper change here is the legal switch that allows an EU-wide prohibition on crypto-asset services from a whole third country. It does not automatically block entire jurisdictions today. But its existence changes the risk calculus for routing and partnerships involving non-EU hubs.
Compliance wise, you should treat this as a tail-risk scenario. If turned on, you would need to geofence, unwind vendor contracts, and possibly exit liquidity pools or payment corridors overnight. The Council explicitly flagged this new capability in its 21st package communications (Council of the EU; see legal basis in Official Journal 2026/1848).
Pro tip: Run a tabletop for a hypothetical country-level ban. Measure how many vendors, RPC endpoints, custody sub-custodians, and fiat PSPs you would lose by geography. Put specific replacement options on paper now.

A7 network focus: asset freezes and routing risk
The package also targets the A7 cross-border payments network via multiple listings. The Council highlights four asset-freeze designations tied to A7. If you are a PSP, OTC desk, or wallet that ever sends or receives funds through intermediaries experimenting with A7 rails, you need to review that exposure (Council press release).
Asset-freeze language is more aggressive than a transaction ban with specific firms. Freezes typically require immediate blocking of assets owned, held, or controlled by listed parties, plus reporting to authorities. That means you should sanity-check your treasury, customer balances, and partner wallets for any possible control or beneficial ownership traces that might tie back to a designated A7 entity.
Mistake to avoid: assuming a clean beneficiary name clears the transfer. Control and ownership look-through is a separate test. You need to investigate who actually steers the entity, not just who is on the invoice.
DeFi, OTC, and P2P: how this touches the gray areas
None of this exempts DeFi, OTC, or P2P activity. The law applies to the person or company, not just the front end. If you are an EU person operating a DEX front end, your job is to avoid facilitating prohibited transactions. Geofencing helps but is not a shield by itself. Be ready to block RPC calls that resolve to a listed platform’s custody or settlement layer, and to restrict features that would knowingly route orders there.
For OTC desks, diligence on counterparties and their downstream settlement paths matters more this quarter. It is not enough to know the desk you face. You also need to ask where they clear and where they source. If the answer is a platform on the list, you cannot interact, even indirectly.
P2P platforms sit in a tricky spot. If you provide escrow, issue invoices, or enforce dispute resolution, regulators can view you as a service provider rather than a pure bulletin board. If any part of that stack touches a listed entity, you have to sever it.
Operational playbook: sanctions screening for crypto flows
People, process, tooling
- Screening data: Load the Official Journal entity names and aliases into your sanctions engine and watch for updates. The August 2026 entry dates create a hard stop for go-lives (Official Journal 2026/1848).
- KYT rules: Create heuristics for common routing patterns. If a withdrawal address regularly funds wallets that then deposit into a listed exchange, flag the origin before it leaves your platform.
- IP and device signals: Tie login geolocation and device fingerprints to sanctions decisioning. Do not rely on IP alone, but let it raise risk scores.
- VASP diligence: For every exchange, broker, or PSP you face, maintain a live file of their ownership, licensing, and sanctions posture. Recheck if they change jurisdiction or legal name.
- Customer comms: Publish a sanctions change log on your status page. It reduces tickets and shows your bank you are in control.
Testing the edges
- Dry runs: Before the deadlines, run test withdrawals and deposits to make sure blocks actually trigger. Capture evidence for auditors.
- Exception governance: Set thresholds for manual review and dual control for any override. Overrides should be rare and documented.
- Vendor audits: If you outsource screening or use a crypto analytics provider, ask for their rule updates and sample hits for these 14 names.
Pro tip: Write a one-page brief for your board summarizing these changes, the specific platforms impacted, your cutover plan, and residual risk. It pays for itself the next time your banking partner asks what you did.

Header image from Chainalysis’s July 24, 2026 blog on the EU’s 21st sanctions package — EU flags outside Commission buildings, illustrating the official sanctions announcement and its policy significance. — Source: Chainalysis (blog)
Market impact: liquidity, pricing, and who moves next
Short term, liquidity tends to migrate rather than vanish. If you are a market maker that had connectivity to any of the named venues, you will probably rotate to compliant hubs. That can widen spreads where order books shrink and tighten where volume consolidates. Watch cross rates in retail-heavy pairs and stablecoin bridges that relied on the listed venues for off-hours liquidity.
For retail flow, expect more KYC friction. Users will try to withdraw to familiar platforms and hit blocks. Support queues rise, completion rates dip, and some traders step away for a week or two. If you are on the operations side, the best antidote is over-communication and a clear path to alternative venues that you have vetted.
The bigger question is how the third-country ban mechanism might be used. Regulators often introduce a new tool before they use it at scale. If evasion is observed through a specific jurisdiction, the lever is now available. That possibility alone will push many EU firms to reduce exposure to high-risk hubs preemptively.
Finally, the A7 designations raise the cost of routing experiments that sit outside mainstream correspondent networks. Some fintechs will pause pilot corridors until there is legal clarity, which could slow niche cross-border flows while leaving large corridors mostly unchanged.
One last note
If you want ongoing coverage that stays practical, Crypto Daily tracks these structural changes and how they ripple through real operations. You can always find more context at cryptodaily.co.uk.
Frequently Asked Questions
Does the EU ban apply immediately?
The package was adopted on 23 July 2026, but the Official Journal sets specific entry-into-force dates in August 2026 for the 14 crypto-related entries. Respect the dates listed for each entity in Regulation 2026/1848.
Can EU users withdraw funds from a listed exchange after the dates?
EU persons and firms are prohibited from transacting with listed services after the entry dates. Firms should provide alternatives before cutover. Users should consult the service and local counsel for case-specific guidance.
Are all services in the listed jurisdictions blocked?
No. The current action names 14 platforms. However, the EU also created a tool that could impose a full third-country ban on crypto-asset services in the future, if triggered.
What is special about the A7 network mentions?
Several A7-linked parties received asset-freeze designations. Freezes are stricter than transactional bans and may require blocking and reporting of assets owned or controlled by those parties.
How should DeFi teams respond?
Geofencing and screening should be tightened. If a front end, relay, or aggregator would knowingly route orders to a listed platform or custody, block it and document your controls.
What happens if my counterparty uses an aggregator?
You are still responsible for avoiding indirect exposure. Demand venue disclosure from aggregators and include a right to terminate for sanctions breaches in your contract.
Where can I verify the names?
Check the Council’s 23 July 2026 press release for the policy overview and the Official Journal Regulation 2026/1848 for the formal list, legal text, and entry-into-force dates.
Disclaimer: This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.