What the UK designated
On 8 October 2026, the UK designated the crypto payment processors Cryptomus and Heleket under its Russia sanctions regime. They were among three crypto exchanges and two payment platforms named in a 38-designation package that also targeted Russian oil companies and shadow fleet tankers. The Office of Financial Sanctions Implementation (OFSI), part of HM Treasury, now enforces the asset freeze, and roughly 7.5 million wallet addresses attributed to the two processors fall within scope.
Nominis first flagged this activity in 2024. The designation confirms what our data showed at the time.
It also raises a harder question for regulators and industry alike: why did it take two years, and what would shorten that gap next time?

What the on-chain data showed in 2024
In 2024, Nominis presented research on UK and Canadian exposure to illicit crypto activity, with Cryptomus as a central case study. Nominis assesses that the processor carried heavy flows tied to Russia sanctions evasion and steady exposure to darknet markets throughout that period.
None of this required privileged access. The signals sat on public ledgers, readable by any firm screening its counterparties.
The Heleket pivot: new name, same flows
When pressure built on Cryptomus, the activity moved next door. Heleket began operating in January 2025, and its hot wallets received their first liquidity from Garantex on 16 January. A month later, Cryptomus introduced mandatory identity checks, and its on-chain volume fell from USD 153 million in January to USD 86 million in March, according to figures reported by The Crypto Times.
Nominis assesses that the same counterparties and flow patterns reappeared on Heleket.
The lesson for screening is simple. A rebrand changes the logo, not the behaviour, so attribution has to follow the flows.
Why two years is too long
Around two years passed between the first private-sector warnings and a UK designation. Throughout that time, UK firms had no legal trigger to freeze, only their own risk-based judgement.
What compliance teams should do now
A designation is the end of the story for regulators. For your exposure, it should be the end of a story you already knew.
- Look back, not only forward. Re-screen historical activity for direct and indirect exposure to Cryptomus and Heleket, and report suspected breaches to OFSI. Its July 2025 assessment explicitly urged retrospective reviews.
- Watch for the next rebrand. Researchers have already linked Heleket to a card business now operated by Mirocard. Monitor shared liquidity sources and migrating counterparties, not only listed addresses.
- Join the conversation. Firms with on-chain findings should take them to the existing public-private channels. The faster that evidence travels, the shorter the next gap.
All research content and accompanying reports are provided for informational purposes only and should not be relied upon as professional advice. Accessing these materials does not create any professional relationship or duty of care. Readers are encouraged to consult appropriately qualified professionals for guidance. We uphold the highest standards of accuracy in all the information we provide. For any questions or feedback, please contact us at contact@nominis.io.
