NewsCryptoEU's 21st Sanctions Package Targets 14 Crypto Platforms Linked to Russia

EU's 21st Sanctions Package Targets 14 Crypto Platforms Linked to Russia

Author: CryptoDaily·

Key Takeaways

  • •The EU's 21st sanctions package prohibits EU persons and firms from transacting with 14 named crypto platforms across Georgia, Panama, the UAE, the Marshall Islands, Kyrgyzstan, and Belarus.
  • •Staggered entry-into-force dates apply, with three platforms blocked from 13 August 2026 and the remaining eleven from 23 August 2026.
  • •A new third-country ban mechanism created under Regulation (EU) 2026/1848 could allow the EU to prohibit all crypto-asset services to or from an entire jurisdiction if activated in the future.
  • •Four asset-freeze designations targeting the A7 cross-border payments network require immediate blocking of assets and control-and-ownership look-through beyond beneficiary name screening.
  • •The sanctions regime extends beyond front-end interfaces to DeFi, OTC, and P2P operators, with geofencing alone deemed insufficient for compliance.
EU's 21st Sanctions Package Targets 14 Crypto Platforms Linked to Russia

The European Union has significantly expanded its sanctions regime against Russia with the adoption of its 21st sanctions package on 23 July 2026, placing cryptocurrency service providers at the center of the new measures. The package introduces a transaction ban on 14 crypto-related platforms across six jurisdictions, alongside a new legal mechanism that could enable a future EU-wide prohibition on crypto-asset services from an entire third country.

Since Russia's full-scale invasion of Ukraine in February 2022, the EU has progressively tightened restrictions on Russian financial channels, cutting major banks from SWIFT and freezing central bank assets. Cryptocurrency emerged early as a circumvention vector, prompting the EU's 8th sanctions package in October 2022 to prohibit crypto-asset wallets and accounts for Russian nationals and residents. The 21st package escalates this trajectory from individual-level restrictions to platform-level bans, reflecting how designated exchanges and payment rails have continued to facilitate Russian cross-border flows.

According to the Council of the European Union, the 21st package adds 218 listings in total, comprising 48 individuals and 170 entities. For the first time, crypto-asset services are explicitly targeted with named designations and staggered compliance deadlines in August 2026.

Legal Framework and Key Provisions

The legal basis for the crypto-specific measures is set out in Regulation (EU) 2026/1848, published in the Official Journal. This regulation amends the relevant annexes and names each designated crypto service provider with specific entry-into-force dates. The Council's announcement confirms that the transaction ban has been widened to include 14 crypto-related service platforms that EU persons and companies must not transact with, directly or indirectly.

A notable innovation in this package is the creation of a mechanism allowing the EU to impose a full third-country ban on crypto-asset services. While not currently directed at any named country, the tool could, if activated, prohibit EU entities from providing or receiving crypto services to or from an entire jurisdiction. This mechanism arrives alongside the EU's Markets in Crypto-Assets (MiCA) regulation, which has been phasing in across 2024–2025 and gives EU authorities direct supervisory authority over crypto-asset service providers operating in the bloc.

The 14 Designated Crypto Platforms

The Official Journal names the 14 crypto-related services, some identified by brand name and others by their operating companies. The designations carry staggered entry-into-force dates in August 2026:

Entry into force 13 August 2026:

  • A7 Nigeria
  • A7 Africa
  • PilotFinance Ltd.

Entry into force 23 August 2026:

  • Rapira
  • Aifory Pro (Sooty Ltd.)
  • ABCeX (Nueva Cryptologia S.A.S DE C.V.)
  • WhiteBird
  • NoOnecrypto INC.
  • Tradex (Brightum LLC)
  • Monease Ltd
  • BitPapa
  • Exnode, Exnode Pay (Arvix)
  • HTX (HUOBI GLOBAL SA)
  • EXMO Ltd.

According to the Council's press release, these 14 platforms are tied to six jurisdictions: Georgia, Panama, the United Arab Emirates, the Marshall Islands, Kyrgyzstan, and Belarus. Several of these jurisdictions—particularly the UAE and Georgia—have been repeatedly identified by Western governments and blockchain analytics firms as corridors for Russian crypto activity following the displacement of traditional banking channels.

Once the entry-into-force dates are reached, EU persons and firms are prohibited from transacting with the listed services. This prohibition encompasses onboarding, payments, brokerage, market making, withdrawals routed through them, API connectivity, and marketing arrangements that could result in a prohibited service being delivered.

A7 Cross-Border Payments Network

The package also includes four asset-freeze designations tied to the cross-border A7 payments network. The Council highlighted these in its press release, noting that asset-freeze designations are more aggressive than transaction bans with specific firms. Freezes typically require immediate blocking of assets owned, held, or controlled by listed parties, along with reporting to relevant authorities.

This raises particular concern for payment service providers, OTC desks, and wallet operators that may send or receive funds through intermediaries using A7 rails. Compliance teams need to review treasury positions, customer balances, and partner wallets for any control or beneficial ownership links to designated A7 entities. As legal experts note, a clean beneficiary name does not necessarily clear a transfer—control and ownership look-through constitutes a separate compliance test.

The New Third-Country Ban Mechanism

The introduction of a mechanism to impose an EU-wide prohibition on crypto-asset services from a whole third country represents a significant policy development. While it does not automatically block entire jurisdictions at present, its existence changes the risk calculus for routing and partnerships involving non-EU hubs.

If activated, EU entities would need to geofence operations, unwind vendor contracts, and potentially exit liquidity pools or payment corridors. The Council explicitly flagged this new capability in its 21st package communications, with the legal basis established in Regulation (EU) 2026/1848. The tool mirrors the approach the EU has used in banking sanctions, where it cut entire Russian banks from correspondent networks rather than targeting individual transactions.

Implications for DeFi, OTC, and P2P Operations

The sanctions regime applies to persons and companies, not solely to front-end interfaces. EU persons operating decentralized exchange (DEX) front ends are expected to avoid facilitating prohibited transactions. Geofencing measures alone are not considered sufficient—operators may need to block RPC calls that resolve to listed platforms' custody or settlement layers and restrict features that would knowingly route orders to them.

For OTC desks, counterparty diligence requirements now extend to downstream settlement paths. If a counterparty clears or sources liquidity through a listed platform, interaction—even indirect—is prohibited.

P2P platforms that provide escrow, issue invoices, or enforce dispute resolution may be classified as service providers rather than bulletin boards under regulatory frameworks. If any component of their technology stack touches a listed entity, that connection must be severed.

Operational Compliance Requirements

VASPs and fintech companies operating in the EU face several immediate obligations:

  • Freeze onboarding and terminate API connectivity for listed services before the respective entry-into-force dates, logging changes and notifying affected users.
  • Update sanctions screening systems to ensure both brand and corporate names trigger blocks.
  • Map dependencies across wallet providers, liquidity aggregators, payment service providers, and OTC partners to identify second-order exposure.
  • Update contracts to include sanctions representations and termination rights upon designation.
  • Prepare customer support with public statements and procedures for handling withdrawals that would route to prohibited venues.
  • Engage banking partners early to ensure fiat rails are not flagged or de-risked during compliance transitions.

On user asset management, best practice involves providing a window for users to reroute funds to compliant destinations before the entry-into-force dates, after which transfers to listed platforms must be blocked with clear audit trails maintained for every attempt.

Sanctions screening should incorporate data from the Official Journal, including entity names and aliases. Blockchain analytics (KYT) rules should flag common routing patterns, such as withdrawal addresses that regularly fund wallets subsequently depositing into listed exchanges.

According to Chainalysis's blog post published on 24 July 2026, the EU's sanctions announcement underscores the growing intersection of crypto compliance and geopolitical enforcement.

Market Impact

In the short term, liquidity is expected to migrate rather than disappear entirely as market makers rotate connectivity away from named venues toward compliant hubs. This shift could widen spreads in certain trading pairs—particularly retail-heavy corridors and stablecoin bridges that relied on listed venues for off-hours liquidity—while tightening spreads where volume consolidates.

Retail users are likely to encounter increased KYC friction as they attempt withdrawals to now-blocked platforms. The A7 designations also raise the compliance cost of routing experiments outside mainstream correspondent networks, which may lead some fintechs to pause pilot corridors pending legal clarity.

The existence of the third-country ban mechanism, even if not yet activated, is expected to push many EU firms to reduce exposure to high-risk hubs preemptively. As noted in regulatory practice, authorities frequently introduce enforcement tools before deploying them at scale.

Verification and Legal References

The formal list of designated entities, legal text, and entry-into-force dates are available in Regulation (EU) 2026/1848. The policy overview is provided in the Council's press release dated 23 July 2026. EU firms are advised to consult both documents and seek written legal counsel for case-specific compliance questions.

Sanctions breaches in many EU member states carry strict liability, meaning intent is not a defense. Firms relying on aggregators that split orders across multiple venues are advised to demand detailed venue disclosure and include contractual rights to terminate for sanctions breaches.