Share via:
- Updated on: September 21, 2026
Since the EU adopted its 20th package of sanctions against Russia, imposing a blanket prohibition on crypto-asset transactions with crypto-asset service providers established in Russia, the crypto compliance industry has been left with a hard question: what exactly counts as a “Russia-linked” service?
The package doesn’t spell out a clean list of disqualifying features. Some platforms have used that gap to adapt, not by giving up Russia-facing services, but by getting smarter about where they show them.
This is what Crystal Intelligence observed with a Russia-linked crypto card-and-cash-out platform we had been tracking as an unlicensed exchange. A routine re-check ahead of reclassifying the platform as sanctioned revealed something more nuanced than a simple removal of its Russia-facing services: the platform had changed who could see them.
For general users, RUB, SBP, and other Russia-related options had disappeared from the public website, but further testing showed that these services remained available to verified users with a Russian phone number and passport. Rather than removing the services, the platform had effectively placed them behind an identity-based access gate.
Key takeaways
The Russia-linked platform removed Russia-facing services from the general website view while they remained visible through its Telegram bot; on the website, RUB-related services were subsequently restricted to verified users with a Russian phone number and passport.
The shift from channel-splitting (hiding services in a bot) to identity-gating (hiding services behind nationality verification) makes a platform’s Russia exposure invisible to any reviewer who isn’t the customer it’s built for.
The EU’s 20th sanctions package doesn’t define a clean checklist for a “Russia-linked” crypto service, so Crystal treats an accumulation of behavioral signals as actionable evidence rather than waiting for a formal designation.
Crystal’s on-chain analysis found nearly $200 million in combined volume moving through the Russia-linked platform between March and September 2026, with 4.9% tied to high-risk categories.
The EU’s 21st sanctions package (July 2026) has since introduced a formal tool for exactly this kind of case, letting the EU block transactions with any crypto provider used by Russia, regardless of where it’s incorporated.
What did Crystal Intelligence find on the Russia-linked platform?
When we first reviewed the platform, its website openly advertised a set of Russia-facing services:
Russian SBP (Faster Payment System) top-up: RUB-denominated account top-ups and withdrawals via SBP, Russia’s domestic instant payment infrastructure, with 195 supported Russian banks as transfer sources, several of them under EU, US, or UK sanctions (Sberbank, Gazprombank, VTB Bank, Alfabank, PSB Bank, Sovcombank, RSHB, Novikombank, EvrofinanceMosnarbank, and Moscow Credit Bank among them).
Russian mobile phone top-up for MTS, Tele2, Yota, Megafon, and Beeline.
Cash-out in 24 European countries, plus SEPA and SWIFT transfers in EUR and USD.

Old website – Top-up menu for Virtual cards offering cryptocurrencies and SBP transfer. (accessed on June 17, 2026)

Old website – Send menu listing Steam, Mobile operators, Cryptocurrencies, SBP, Offline Cash, Card, and Corporate SEPA/SWIFT. (accessed on June 17, 2026)

Old website – SBP top-up screen with RUB amounts and a bank picker (Raiffeisen, Tinkoff, Alfabank, Sber, Gazprombank, PSB Bank). (accessed on June 17, 2026)
On a later check, the website’s “Send” and “Top-up” pages had been stripped back to cryptocurrency-only options. No SBP, no RUB, no Russian mobile operators, no mention of Russian banks. On paper, it looked like a platform that had cleaned up its exposure.

New website – Top-up menu now shows Cryptocurrencies only. (accessed on September 1, 2026)

New website – Send menu now leads with Send-to-client, Card, and Personal SEPA; SBP and mobile top-up are no longer listed as top-level options. (accessed on September 1, 2026)
Its Telegram bot told a different story. Walking through the bot’s own “Top-up” and “Send” menus, the SBP option was still live, still routing to a bank picker listing Raiffeisen, Tinkoff, Alfabank, Sber, Gazprombank, and PSB Bank, still quoting amounts in RUB. The “Send” flow still offered mobile-operator top-ups, with the operator list rendered in Cyrillic (МТС, Tele2, Yota, MegaFon, Beeline). A promoted ad inside the same bot, in Russian, offered a Mastercard-branded virtual card “for paying for foreign services and subscriptions.”

The platform’s Telegram bot – QR-code payment flow quoting amounts in rubles, alongside a Russian-language ad for a virtual card.

The platform’s Telegram bot – mobile top-up menu listing Russian operators in Cyrillic (МТС, Tele2, Yota, MegaFon, Beeline). (accessed on September 1, 2026)
In other words: the polished, public-facing website was scrubbed. The Telegram bot, harder to index, harder to archive at scale, and largely invisible to a casual compliance review, kept operating exactly as before.
How did the Russia-linked platform gate ruble services by nationality?
The pattern kept evolving. In a Telegram post from March 2026, the platform told its users:
“If the Russian ruble is your primary currency, make sure your profile has a Russian phone number (+7). This is what unlocks access to SBP, OpenBank, and all ruble-related features. If you already have an account, simply change your number in your profile settings. Your phone number determines which tools are available to you: a Russian number provides access to SBP and OpenBank, while a foreign number provides access to tools specific to your market, while all payout options remain available.”

The platform’s Telegram post, March 2026.
The restriction took effect by June 2026: when Crystal Intelligence investigators accessed the website on June 24, 2026, ruble services were still active. On September 1, 2026, we accessed the website again and found that ruble integration had disappeared. We confirmed this directly with the platform’s own customer service, who told us:
“Refilling your wallet with rubles is now only available to citizens of Russia who have a Russian phone number linked to their account and who have been verified using a valid Russian passport with a current registration stamp.”

The platform’s customer service chat, September 1, 2026.
Alongside this, the platform restructured its website again. It is no longer possible for a general visitor to browse the service menu and see what the platform offers at all, closing off the casual, unauthenticated view that a compliance analyst or journalist would normally rely on.
This is a materially different mechanism from the one documented above. On the platform’s website, ruble-related services are now gated behind a verified Russian phone number and passport, meaning that a general visitor will not see SBP, OpenBank, or ruble top-up options unless they meet those requirements.
The Telegram bot, however, appears to operate differently: during our review, SBP and other Russia-facing services remained visible without the same identity-based filtering. In practice, this creates two different access models: the website selectively reveals them to verified Russian users, while the Telegram bot continues to expose them through a less restricted channel. The services have not disappeared; their visibility depends on where and how the user accesses the platform.
Why does this matter for crypto compliance teams?
It would be easy to read this as a platform tidying up its marketing. We think it’s something else: a platform that understands where compliance teams and blockchain analytics firms actually look, and where they don’t.
Websites are the default surface for OSINT and compliance review because they’re easy to check, easy to screenshot, and easy to reference in a report. Telegram bots are transactional, transitory by nature, and require someone to actually walk through the interaction flow rather than just loading a page. If a platform wants to keep offering a sanctioned-adjacent service while staying invisible to regulators, media, and casual due diligence, moving that service into a chat interface is a rational way to do it. It doesn’t require shutting anything down. It just requires knowing that most reviewers won’t follow it there.
The Russia-linked platform’s later move takes that logic one step further: it no longer depends on a reviewer failing to follow the service into a bot. It depends on the reviewer not being the customer the service is built for.
This is a version of an old problem showing up in a new place: the compliance industry, ourselves included, has generally treated a platform’s website as its authoritative surface. That assumption is starting to look outdated.
Do compliance teams need one disqualifying fact to flag a platform?
No single feature proves a platform is Russia-linked. But when enough of them point the same way, the accumulation itself becomes the evidence, especially when a platform is structured to avoid one clean disqualifying fact.
That principle is relevant here. The EU’s 20th package does not give compliance teams a clear checklist for determining when a crypto service should be considered Russia-linked. It prohibits transactions with crypto-asset service providers established in Russia, but leaves harder judgment calls open, particularly for platforms that may be incorporated elsewhere while continuing to serve Russian users via domestic payment rails.
Our view is that this ambiguity shouldn’t lead to a wait-and-see posture. If a platform supports RUB top-ups through Russia’s domestic payment system, integrates a list of specifically Russian banks (several already under direct sanctions), markets to Russian speakers, and offers Russian mobile top-up as a core product, the accumulation of those signals is itself the evidence. It looks like a Russia-facing financial service because it is one, regardless of where its corporate registration sits on paper.
We recognize this is a judgment call that will draw disagreement, and that flagging a platform on the accumulation of behavioral indicators, rather than waiting for a named designation, carries real weight. But the alternative, treating each indicator in isolation and waiting for an unambiguous single disqualifying fact, means compliance is always reacting to sanctions evasion after the money has already moved.
Since Crystal’s review, the EU’s 21st sanctions package (July 2026) has moved in the same direction. It extends the transaction ban to 14 crypto-related platforms across six jurisdictions (Georgia, Panama, the UAE, the Marshall Islands, Kyrgyzstan, and Belarus), and it introduces a new mechanism that lets the EU block any transaction between an EU operator and a crypto provider used by Russia, wherever that provider is based. It doesn’t resolve the ambiguity in the 20th package outright, but it confirms the direction of travel: enforcement is moving toward the accumulation-of-behavior standard this piece argues for, not away from it. See Crystal’s earlier coverage of the 21st package for the full breakdown.
What does Crystal’s on-chain data show?
This isn’t just a marketing-page discrepancy. Crystal’s on-chain analysis of the Russia-linked platform for the period March 1 to September 1, 2026 shows:
$94,695,752 received / $96,468,298 sent
$9,329,612in high-risk exposure, 4.9% of combined volume
The largest high-risk categories: gambling ($6,748,999 received / $142,587 sent), and illegal-service counterparties ($88,231 received / $1,118,273 sent)

The platform’s on-chain exposure by category, March 1 – September 1, 2026. Source: Crystal Intelligence.
A platform moving nearly $200 million in combined volume, with a meaningful share tied to high-risk categories, while actively managing which of its ruble and SBP services are visible to outside reviewers, is not a marginal case. It’s a live illustration of why compliance frameworks built around website-level review are no longer sufficient on their own.
How can compliance teams close this gap?
This case points to a structural gap, not a one-off. Platforms are getting more sophisticated about compartmentalizing risk between public-facing and private-facing channels, and compliance methodology needs to catch up. Here’s where to start:
1. Treat every channel as a surface, not just the website.
Telegram bots, in-app flows, WhatsApp catalogs, and mobile apps are functionally part of a platform’s product surface and need to be reviewed with the same rigor as its website, walked through step by step, not just glanced at.
2. Archive continuously, not once.
A single snapshot taken during onboarding or initial review has a shelf life measured in days, as this case shows. Effective OSINT for this kind of typology means periodic re-checks of the same platform across its different channels, with every version preserved, not just the most recent one.
3. Capture evidence that can’t be quietly edited away.
Screenshots with visible timestamps, archived pages (via tools like the Wayback Machine where the platform is indexed), and session recordings for interactive flows like bots and apps all matter, because platforms that scrub a website can and do rely on the fact that yesterday’s version is no longer visible to anyone checking today. Blockchain analytics platforms should be able to supply proof of evidence regarding the designation.
4. Cross-reference off-chain claims against on-chain behavior.
A scrubbed website doesn’t change what’s happening on-chain. Pairing evidence of advertised services with the platform’s actual transaction volume and counterparty exposure turns a marketing discrepancy into a substantiated risk finding.
5. Build typology awareness, not just designation-matching.
Waiting for a named sanctions listing before acting cedes the initiative to platforms that are actively designed to stay one step ahead of formal designation. A documented pattern of sectoral indicators, RUB/SBP integration, Russian-bank rails, Russian-targeted marketing, is itself actionable intelligence.
Frequently asked questions
What does the EU’s 20th sanctions package say about crypto platforms in Russia?
The EU’s 20th sanctions package bans crypto-asset transactions with crypto-asset service providers established in Russia. It doesn’t list every feature that makes a platform “Russia-linked,” which leaves room for platforms incorporated elsewhere to keep serving Russian users via domestic payment rails.
What is channel-splitting in crypto sanctions evasion?
Channel-splitting is when a platform removes a sanctioned-adjacent service from its public website, where compliance reviewers typically look, while keeping that same service live on a harder-to-monitor channel like a Telegram bot. The Russia-linked platform in this case study did this by stripping RUB and SBP options from its website while leaving them fully functional in its bot.
What is identity-gating, and how is it different from channel-splitting?
Identity-gating restricts access based on characteristics of the user rather than simply hiding a service on a different channel. On the Russia-linked platform’s website, ruble top-ups and related services were gated behind a Russian phone number and passport, making them invisible to general visitors. The Telegram bot operated differently during our review: SBP and other Russia-facing services remained visible without the same identity-based filtering.
Can compliance teams flag a platform as Russia-linked without a formal sanctions designation?
Yes. Crystal’s view is that an accumulation of behavioral signals, RUB/SBP integration, sanctioned Russian-bank rails, Russian-targeted marketing, and Russian mobile top-up, is itself actionable evidence. Waiting for a single disqualifying fact or a named designation means compliance is always reacting after funds have already moved.
What did the EU’s 21st sanctions package change for crypto compliance?
Adopted in July 2026, the 21st package extends the transaction ban to 14 crypto-related platforms across six jurisdictions and introduces a new mechanism letting the EU block any transaction between an EU operator and a crypto provider used by Russia, wherever that provider is incorporated. It moves EU enforcement further toward the accumulation-of-behavior standard, this case illustrates.
How can compliance teams detect platforms that hide services behind identity verification?
Treat every channel, not just the website, as part of the platform’s product surface; re-check platforms continuously rather than once; capture time-stamped, archived evidence; and cross-reference any advertised services against the platform’s actual on-chain transaction volume.
Conclusion
Sanctions evasion doesn’t always look like a shell company or a fake jurisdiction. Sometimes it looks like a platform quietly deciding which version of itself to show which audience. As enforcement frameworks like the EU’s 20th package put pressure on Russia-facing crypto services, we expect to see more of this kind of channel-splitting behavior, not less, and the Russia-linked platform’s own shift from splitting by channel to gating by verified nationality within the space of months shows how quickly that sophistication curve moves. The compliance response has to be to look everywhere a platform actually operates, not just where it’s easiest to look, and to account for who the platform lets look.
If your team is weighing platforms like this one, Crystal’s investigations hub tracks similar sanctions-evasion and typology cases as they develop. And if you want to see how Crystal helps compliance teams monitor, investigate, and prove this kind of risk directly, request a Crystal Expert demo.
