AMLRadar
AMLRadar
← Back to Blog
Compliance5 August 2026·6 min read

EU's 21st Sanctions Package Names 14 Crypto Platforms — And Gives Itself Power to Ban Entire Countries

The EU adopted its 21st Russia sanctions package on July 23, effective August 23. It designates 14 crypto platforms and creates a new authority to ban all crypto dealings with an entire third country. Here is what CASPs and EMIs should check before it takes effect — and why the screening tool matters less than the data feeding it.


On July 23, the Council of the EU adopted its 21st sanctions package against Russia. It takes effect on August 23, and for compliance teams at CASPs, EMIs, and banks with crypto exposure, two parts of it deserve attention now — not in three weeks.

The first is a list of 14 newly designated crypto platforms. The second is quieter but more consequential: a new legal mechanism that lets the EU ban all crypto dealings with an entire country, not just named entities within it. No country has been designated yet. That is exactly why compliance teams should be looking at this today.

The 14 platforms

The package designates: A7 Nigeria, A7 Africa, Afory Pro, ABCeX, Bitpapa, Encode, EXMO Ltd., HTX, Monease Ltd., NoOnecrypto INC., Pilot Finance Ltd., Rapira, Tradex, and WhiteBird — platforms based in Georgia, Panama, the UAE, the Marshall Islands, Kyrgyzstan, Belarus, and Nigeria. From August 23, EU VASPs and financial institutions are prohibited from any dealing with these entities.

Three of these names will look familiar if you follow UK sanctions activity: HTX, Bitpapa, and EXMO were already designated by the UK in a package earlier this year. This EU listing brings the two jurisdictions' lists closer into alignment — useful if you operate under both regimes, since a gap between UK and EU designations has historically been one of the easier things for a sanctioned platform to route around.

A7 Nigeria and A7 Africa are also worth flagging specifically if you've been tracking the A7 network — the group behind the A7A5 ruble-pegged stablecoin we've written about before. These two entities extend that same network's footprint into African jurisdictions, which tracks with what A7 has reportedly been doing on the ground: opening offices in Nigeria and Zimbabwe, with Togo mentioned as a possible next step. If your screening program already flags A7A5 exposure, this is the next chapter of the same story, not a new one.

The part with no list yet

The more structurally important change in this package doesn't name a single new entity. It creates a legal basis for the EU to designate an entire third country as having systematically and persistently failed to prevent crypto services from being used to evade Russia sanctions — and, once designated, to prohibit all dealings with every crypto platform located there, regardless of whether that specific platform has done anything wrong.

The EU has not used this power yet. It has said, in effect, that it hopes the mere existence of the authority discourages countries — Kyrgyzstan was mentioned explicitly — from continuing to host platforms that facilitate evasion. There's no immediate obligation on EU firms today.

But "no obligation today" is not the same as "nothing to do today." A jurisdiction-wide ban, if and when it lands, will not come with a grace period long enough to unwind existing counterparty relationships cleanly. The firms that will handle a future designation calmly are the ones that already know, before it happens, how much of their customer and counterparty base touches Georgia, Panama, the UAE, the Marshall Islands, Kyrgyzstan, Belarus, and Nigeria — the seven jurisdictions this package's named platforms are based in, and the most likely candidates if this authority is ever used.

That's a mapping exercise you can run this month, not a control you need to build by August 23. It's also exactly the kind of forward-looking documentation an MLRO wants on file before a supervisor asks whether the risk was assessed in advance or only after the fact.

Why the screening tool matters less than the data behind it

Here's something worth being direct about, because it's easy to assume a sanctions screening platform "just has" every new designation the moment it's announced. It doesn't — not automatically, and not for every source.

OFAC publishes wallet addresses directly alongside its designations, which is why US sanctions tend to show up in crypto screening tools quickly and completely. The EU Consolidated Sanctions List works differently: it lists entities by name, not by blockchain address, as we've covered before. That means a platform being added to an EU list on August 23 will very likely appear in a CASP registry or entity screen — but it won't automatically produce a wallet address to check a transaction against, unless the EU starts publishing addresses alongside future packages, which it has not historically done.

This isn't a criticism of any one screening provider. It's a structural fact about how EU sanctions data is published, and it means every compliance program relying on automated screening — ours included — is only as current as the pipeline feeding it. In preparing this article, we audited our own sync process end to end and found our EU sanctions feed had gone unscheduled since its initial build in June — a gap in our own automation, not in the underlying source, and one we've now closed. It's a useful reminder for any team running automated compliance tooling: the sync running is not the same question as the sync running and delivering current data. Both are worth checking, not just at setup, but on a recurring basis.

What to check before August 23

  • Run the 14 names against your existing customer and counterparty base, not just new onboarding. A platform designated today may have touched your systems months ago.
  • Map your exposure to the seven named jurisdictions — Georgia, Panama, UAE, Marshall Islands, Kyrgyzstan, Belarus, Nigeria — even without a country-wide designation in place. This is the review the EU is explicitly telling firms to start now.
  • If you operate under both UK and EU regimes, reconcile the two lists. The overlap on HTX, Bitpapa, and EXMO is a good prompt to check whether your screening covers both sources or just one.
  • Ask your screening provider — or yourself, if you run this in-house — when the EU source last actually synced, not just whether the job is scheduled. A green status check and a current dataset are not the same thing.

How AML Radar covers this

The AML Radar CASP Registry tracks platform-level designations and registration status across jurisdictions, independent of whether a wallet address has been published for a given entity. The Wallet Screener checks addresses against OFAC, EU, and UK sources as each source actually publishes them, and every check is logged to the MLRO Audit Trail with a timestamp — so if a supervisor asks what your exposure to these seven jurisdictions looked like before a country-wide ban existed, the review is already on record, not reconstructed after the fact.

Conclusion

The 14 named platforms are the visible part of this package. The third-country ban authority is the part that should shape what your compliance team does between now and August 23 — not because it applies yet, but because the firms that map their exposure before it's mandatory are the ones who won't be scrambling if it is.

Try the AML Radar CASP Registry and Wallet Screener — free to start.


This article is for informational purposes only and does not constitute legal advice. Always consult a qualified compliance professional for guidance specific to your jurisdiction and business.

Ready to screen a wallet address?

Use AMLRadar's free screener to check any crypto address against OFAC, EU, and UK sanctions lists instantly.

Try the Screener