EU's 21st Sanctions Package against Russia: What It Means for Crypto Compliance and Transaction Monitoring

5-Minute Read
Sep 7, 2026
Example H2
Example H3
Example H4
Example H5
Example H6
Share Article

On 25 August, the Council of the EU effected its 21st package of restrictive measures against Russia, the largest batch of individual listings in four years. Of the 218 total designations, 48 target individuals and 170 target entities, spanning energy, financial services, trade and, increasingly, crypto-asset infrastructure. For compliance teams at exchanges and other VASPs, the package is notable less for its scale than for a structural shift in how the EU is choosing to police sanctions evasion in crypto.

What the package actually does

The headline financial measures are considerable in their own right: asset freezes on 94 banks and major financial institutions, an extended transaction ban covering 33 further Russian credit and financial institutions, and a first-time designation of a Kyrgyz bank connected to the SPFS messaging system, alongside three other non-Russian banks, for sanctions circumvention.

The crypto provisions sit alongside these financial measures rather than as an afterthought. The 21st package introduces three distinct crypto-asset measures, each addressing a different route Russian-linked activity has used to reach crypto markets.

The first is a platform transaction ban. The Council extended its transaction ban to 14 crypto-related service platforms based in Georgia, Panama, the UAE, the Marshall Islands, Kyrgyzstan and Belarus, alongside four new designations tied to the cross-border A7 network, including its expanding links into Africa. None of these 14 platforms are Russian-domiciled. 

The second closes a domestic route. From 25 August 2026, Russian nationals and people living in Russia can no longer own or control, directly or indirectly, a crypto-asset business based in an EU member state, nor sit on its board or governing body. The restriction applies across all crypto-asset businesses in the EU, not just the wallet, account and custody services it previously covered.

The third is a country-level ban framework.  EU persons and entities will be prohibited from transacting, directly or indirectly, with any crypto-asset service provider or exchange platform established in a country the Council determines to be undermining Russian sanctions. No country has yet been listed under this mechanism, but its existence alone signals the EU's readiness to move from sanctioning named platforms one at a time to excluding an entire jurisdiction's crypto sector in one step.

This third measure is the one compliance teams should watch most closely. Individual designations are static and, however imperfect, screenable: a name goes on a list, and a CASP can check its counterparties against it. A jurisdiction-wide mechanism changes the calculus entirely. A platform with no current designation, registered in one of the six countries already named under the platform ban or in any country the Council later adds, becomes a source of latent exposure the moment the Council acts, with no individual listing required as a trigger.

Why the 14 platforms are harder to screen than they look

The platforms named in Annex XLV are not the kind of centralised, KYC-compliant exchanges that show up cleanly in sanctions screening feeds. Several operate as nested services inside larger exchanges, rotate deposit wallets on a routine basis and settle across multiple chains simultaneously. A single-address check, of the sort that satisfies a narrow reading of "screen the sanctions list", will miss most of the exposure these platforms actually carry.

The same is true of the A7 network and the A7A5 rouble-pegged stablecoin at its centre, issued through a Kyrgyzstan vehicle and circulating on both Tron and Ethereum with reserves tied to a Russian state-linked bank. A7A5 was the first crypto asset the EU banned by name, in an earlier package, and the network did not shut down when it did. Chainalysis has estimated the network has processed close to $120 billion to date. That figure alone should reframe how compliance teams think about "sanctioned asset" as a category: banning the token by name does not remove the token from circulation, it removes the excuse for not tracing it.

What this means for transaction monitoring in practice

Three implications follow directly from the structure of this package, rather than from any single designation within it.

Jurisdiction becomes a risk input in its own right, not just a KYC field. With the country-level ban framework now in place, even though no country has yet been listed under it, a CASP's exposure to Georgia, Panama, the UAE, the Marshall Islands, Kyrgyzstan and Belarus at the platform level is worth mapping now, before any future listing turns that exposure into an urgent remediation exercise.

Screening has to trace past the direct counterparty. Most of the exposure created by nested services, nominee wallets and nominally unaffiliated intermediaries sits one or two hops away from any address that appears on a sanctions list. Wallet clustering and entity attribution are what surface that link; a static address match does not.

Monitoring needs to operate at the token-contract level, across chains, rather than at the exchange level alone. A rouble-pegged stablecoin moving on Tron and settling on Ethereum is one exposure, not two, and a monitoring programme that only watches one chain is not watching the flow, only a fraction of it.

Nominis assessment

Nominis assesses that the third-country mechanism represents the most consequential structural change in this package, ahead of any individual designation. It signals that the Council is prepared to treat jurisdictions, not just entities, as the unit of sanctions enforcement in crypto, following a pattern already visible in the shift from the 20th to the 21st package. CASPs whose customer or counterparty base includes meaningful volume from the newly named jurisdictions should not wait for the next individual listing to reassess that exposure; the legal basis to expand the list already exists, and the criteria the Council has signalled it will apply (systematic failure to prevent circumvention) are jurisdictional judgements that can move faster than any individual due diligence cycle can track.

All research content and accompanying reports are provided for informational purposes only and should not be relied upon as professional advice. Accessing these materials does not create any professional relationship or duty of care. Readers are encouraged to consult appropriately qualified professionals for guidance. We uphold the highest standards of accuracy in all the information we provide. For any questions or feedback, please contact us at contact@nominis.io.