For four years the European Union has treated crypto as a leak to be plugged — a side channel where a Russian entity locked out of the banking system might still shuffle value across a border. The bloc’s 21st sanctions package, adopted July 23, treats crypto platforms as something closer to accomplices. Fourteen of them are now named, banned, and, in the EU’s telling, complicit in keeping Moscow’s war economy liquid.
The package is the largest single round of Russia listings in four years, carrying 218 designations and reaching more than 100 banks and crypto operators, according to a breakdown published by blockchain-analytics firm Chainalysis. Most of the attention will go to the banking measures — asset freezes on 94 financial institutions, 33 more Russian lenders pushed off SWIFT, a frozen oil price cap of $44.10 a barrel through mid-2027. But the crypto provisions are where the EU is doing something it has not done before.
The named fourteen
The transaction ban now covers 14 crypto-asset service platforms operating out of six jurisdictions: Georgia, Panama, the United Arab Emirates, the Marshall Islands, Kyrgyzstan, and Belarus. The list, per the Council’s designations, includes Rapira, Aifory Pro (Sooty Ltd.), ABCeX, WhiteBird, NoOnecrypto, Tradex (Brightum LLC), Monease, BitPapa, Exnode and Exnode Pay, HTX (Huobi Global SA), EXMO, A7 Nigeria, A7 Africa, and PilotFinance.
The presence of HTX — one of the larger names in global exchange volume — signals that this is not a list confined to obscure over-the-counter desks. The common thread the Council draws is function, not size: each is accused of serving as a conduit for Russian entities moving funds around existing restrictions. From the moment the measure takes effect, EU persons and companies are prohibited from doing business with any of them.
That framing matters more than the individual names. The EU is no longer only sanctioning the Russian user of a platform; it is sanctioning the platform for letting the user through. A service that fails to keep designated parties out is, under this logic, a target in its own right.
A mechanism that reaches past its own borders
The genuinely novel piece is a legal instrument the package creates but has not yet fired: a full third-country ban on crypto-asset services. In plain terms, the EU has written itself the power to prohibit any transaction between an EU entity and any crypto provider based in a country that hosts services Russia uses for sanctions evasion — even providers that are not themselves designated.
The EU tested a narrower version of this idea against Belarus earlier in 2026. The 21st package generalizes it. If Brussels decides a given jurisdiction has become a haven for evasion infrastructure, it can, in principle, wall off that jurisdiction’s crypto sector from European counterparties wholesale. Chainalysis notes the mechanism remains unused for now, which is precisely what makes it a deterrent: the threat is the point.
For a crypto-asset service provider (CASP), the compliance calculus shifts accordingly. It is no longer enough to screen your own customers. If you operate in — or merely serve customers in — a country that later lands on the wrong side of this mechanism, you could lose access to EU business regardless of your own record. The bloc’s official sanctions framework already prohibits providing crypto-asset services to Russian persons; the new layer extends that exposure outward to the jurisdictions where evasion is suspected to live.
Why compliance teams should read the fine print
There is a quieter provision that will do a lot of work: the package extends the existing prohibition on Russian ownership of EU-registered crypto wallets, accounts, and custody arrangements to any type of crypto-asset service. What was once a custody-and-wallet rule now spans the full service stack — trading, transfers, staking infrastructure, orchestration layers. The surface area a European CASP has to police just grew.
Layered on top are the EU’s Transfer of Funds Regulation obligations, which can require enhanced due diligence when a European CASP interacts with a non-EU virtual-asset service provider. The combined effect is that transactions touching the six named jurisdictions — and any future third-country designation — now demand documentation a firm may not currently collect. The consolidated lists that CASPs are expected to screen against are maintained on the EU’s official sanctions map, and the designations from this package flow into that reference.
The Council paired the crypto measures with the usual machinery of a major package: 94 bank asset freezes, action against a Kyrgyz bank tied to Russia’s SPFS messaging system, 41 more shadow-fleet tankers, and 56 listings linked to Russia’s military-industrial base, 37 of them tied specifically to long-range drone production. Read together, the crypto listings are not a sideshow bolted onto a banking package. They are the EU declaring that digital-asset rails are now a first-class front in sanctions enforcement — and that the platforms running those rails will be held to the same standard as the banks.
For firms with any EU nexus, the practical takeaway is unglamorous but urgent: re-screen counterparties against the updated lists, map exposure to the six jurisdictions, and assume the third-country mechanism will eventually be used on someone. The EU spent four years treating crypto as a gap in the wall. This package is the bloc starting to build the wall out of the platforms themselves.
