Sanctions · Plain English

Crypto exchange sanctions in 2026: what actually happens to your coins

2025 and 2026 have been the busiest two years on record for sanctions against crypto platforms. Here is what was actually designated, what "tainted coins" really means, and what to do if a deposit gets held.

21 Aug 2026·11 min read·← All postsفارسی
14platforms under the EU's newest transaction ban
23 Aug2026 — when most of those bans start
3 mowindow for EU users to apply to withdraw
<0.5%false-positive rate in the only independent audit

Why this suddenly matters

For most of crypto's history, sanctions were something that happened to other people. That changed. Over 2025 and 2026, regulators in the United States, the United Kingdom and the European Union designated a long list of exchanges, stablecoins and payment platforms — and, crucially, they started reaching the platforms ordinary people actually use.

The practical consequence is not that your coins get confiscated. It is that a deposit you were expecting to land in seconds sits in limbo, and nobody will tell you why. That experience is now common enough to have its own vocabulary, and most of what circulates about it online is wrong.

The short versionBeing near a sanctioned address on a blockchain is not the same as dealing with a sanctioned person. The rules turn on whether a sanctioned party has an interest in your specific property — not on how many transactions separate you from a bad address. But compliance software is configured by each company independently, and that is where most real-world problems come from.

What was actually designated in 2025–26

Two clusters dominate. One is Russia-linked; one is Iran-linked. Both matter because their users were, overwhelmingly, ordinary retail traders.

DateWhoWhat happened
Mar 2025GarantexInternational takedown, servers seized, Tether froze wallets. Note: this was a seizure, not a delisting — Garantex had been under US sanctions since 2022 and stayed on the list.
21 Mar 2025Tornado CashOFAC removed the sanctions, following a federal appeals court ruling. Still delisted today.
14 Aug 2025GrinexDesignated by OFAC as Garantex's successor. Garantex re-designated the same day under a second authority.
20 Aug 2025Grinex, Old Vector, TengricoinThe UK's largest crypto action of the year — it froze the A7A5 rouble-stablecoin ecosystem and its Kyrgyz banking rails. The UK had designated Garantex itself back in 2022, with crypto addresses named in the entry.
2 Jun 2026Nobitex, Wallex, Bitpin, RamzinexLargest US action to date against Iran's digital-asset sector. Treasury said Nobitex alone processed "more than 50 percent of all Iranian digital asset inflows in 2025."
23 Jul 2026EU 21st packageTransaction bans on 14 crypto-asset service providers, plus a new power to ban entire third countries.
7 Aug 2026Shelbit, Aban TetherFurther US designations covering exchange and laundering networks.
23 Aug 2026HTX, EXMO + 9 moreThe EU transaction bans take effect. Three others (A7 Nigeria, A7 Africa, PilotFinance) started 13 Aug.

The Russia-linked chain is worth understanding as a chain, because it explains why "just move to the successor platform" keeps failing. Garantex was sanctioned, then seized; Grinex emerged as its successor and was itself designated; the ruble-pegged stablecoin A7A5 that moved through that ecosystem became the next pressure point. Elliptic's research describes the end state plainly: "From late September 2025 onward, A7A5 users began to report that USDT obtained by swapping A7A5 was being frozen or flagged on receipt at global exchanges."

A correction worth making, because almost everyone gets it wrong. PM2BTC, Bitzlato and Huione Group are routinely described as "OFAC-sanctioned." They are not on the SDN list. They are FinCEN actions — a different agency under a different statute, with different consequences. Huione's final rule was published 16 Oct 2025 and took effect 17 Nov 2025, and FinCEN proposed amending its definition on 25 Jun 2026 to capture successor entities. If an article calls these three "OFAC-sanctioned," treat the rest of it with caution.

What are "tainted coins", exactly?

This is the single most-asked question on the topic, and it has been asked continuously since 2013. The honest answer is that "tainted" is not a legal status. No regulator maintains a list of dirty coins. What exists is analysis software that traces where a coin has been and assigns it a risk score — and the score depends entirely on which tracing method the software uses.

That is not a small detail. Researchers have compared the methods on real theft data, and the results are not remotely close. Under the aggressive methods — where any contact with bad funds contaminates everything downstream — Cambridge researchers found that running them on a couple of major 2014 thefts meant more than 90% of all active wallets were "tainted" by 2017. Under a stricter accounting method, the same thefts touch a tiny fraction of that.

Read that againSame blockchain. Same theft. Same maths. One method says almost everyone is contaminated; another says almost nobody is. So when someone tells you your coins are tainted, the accurate response is: tainted according to which method, configured by whom?

The industry has quietly moved on from the word. Chainalysis, Elliptic and TRM now talk about "exposure" rather than taint, and they are explicit that distance matters. Elliptic states in print that hop distance is "not a strong indicator of risk." Chainalysis's own 2026 benchmark notes that indirect thresholds are typically 10 to 20 times more lenient than direct ones. TRM puts it most usefully: "Proximity to illicit activity is not participation."

Is being a few transactions away from a sanctioned address illegal?

No — and the framing itself is wrong. Sanctions rules attach to whether a blocked person holds an interest in the specific property. The word "indirect" in the regulations refers to interests held through an intermediary or a nominee. It does not mean "a few transactions away."

The clearest evidence for this is what regulators don't say. OFAC's own 28-page guidance for the virtual-currency industry does not contain the word "hop" even once. Neither does it use "taint", "downstream", or "degrees of separation." The much-cited 50 Percent Rule is also frequently misapplied here: it is a rule about who owns an entity, not a rule about tracing funds along a chain.

What does exist is commercial risk appetite. Analytics vendors sell tools; each customer configures its own thresholds. TRM has said publicly that it does not block anything itself and that "organizations using TRM configure their own settings and risk thresholds." That is why the same wallet can be fine at one venue and frozen at another.

What about unsolicited "dust" you never asked for?

Sometimes a tiny amount of crypto arrives from an address you have never interacted with. You cannot refuse it — there is no way to reject an incoming transaction. Occasionally it is a scam setup; occasionally it is someone deliberately trying to contaminate wallets.

OFAC addressed this exactly once, in an FAQ published after the Tornado Cash designation. Its position was that the regulations "would technically apply", but that it would not prioritise enforcement over late reporting where dust was the only connection, and that recipients could apply for a specific licence. Three caveats matter: the relief was narrow (it covered reporting timing, not the underlying rules), it was specific to that one case, and the FAQ has since been withdrawn from Treasury's live site. It is persuasive by analogy — not current authority.

The practical risk is not prosecution. It is an automated false positive. In March 2026 a trader on Hyperliquid received an unsolicited 0.000001 ETH — about two cents — from a flagged address. He did nothing. Three weeks later he was banned from the platform's front-end, despite a four-year history, more than 9,000 transactions and roughly $750,000 in volume. The platform's co-founder later confirmed it: "it looks like this was a false positive flag from an address poisoning attack."

Leaving dust alone is generally the sensible move. Spending it merges it with your other funds in the same transaction, which is exactly the link that clustering software looks for.

Why won't they tell you why your deposit is held?

This is the part that makes people angriest, and the explanation is genuinely reassuring once you know it.

When a financial institution files a suspicious-activity report, US law — 31 U.S.C. § 5318(g)(2)prohibits it from telling you that it has done so. Not "discourages". Prohibits. Institutions served with a subpoena for such a report must refuse to produce it. So the maddening non-answer you get is not a company being evasive; in many cases it is a company complying with a statute that forbids the explanation you are asking for.

It is also worth knowing what "blocked" means. Per OFAC's own guidance, blocked property is frozen, not seized, and "title to the blocked property remains with the blocked person." Ownership does not transfer to the government. And a hold is usually a review, not an accusation — the legal trigger for a report is that a firm "knows, suspects, or has reason to suspect", which is a deliberately low bar designed to catch things early.

How to check before you accept funds

Search behaviour on this topic has shifted noticeably: people used to ask "am I already tainted?" and now increasingly ask "how do I check before I accept?" That is the better question, and it is answerable.

  1. Screen the counterparty address first, not afterFree OFAC address checkers exist, and the SDN list itself is public and downloadable. For a P2P trade, checking takes under a minute and happens before you are committed.
  2. Be wary of platforms in the news for the wrong reasonsIf a venue has just been designated or is facing a transaction ban, funds routed through it are far more likely to be flagged on arrival somewhere else — regardless of who you are.
  3. Keep your own recordsThe second most-searched question on this topic is literally how to prove your coins are legitimate. Exchange statements, trade confirmations, invoices and payslips are what actually resolve a review. Keep them as you go; reconstructing them afterwards is painful.
  4. Don't consolidate dustLeave unsolicited small amounts untouched rather than sweeping them into your main balance.
  5. If funds are held, respond with documents, not argumentsReviews are closed by evidence of source of funds. Ask what specific documentation is needed and provide it in one go.

How good is the software making these decisions?

Better than the panic suggests, and worse than the marketing suggests — in a specific direction that is worth knowing.

The only independent academic audit to test attribution against ground truth (recovered from seized servers) was published at a leading security conference in 2025. It found accuracy ranging from 24.54% to 94.85% across three services, with false positives under 0.5%. The important nuance is the direction of the errors: these systems rarely mislabel innocent addresses, but they systematically under-detect — and coverage was weakest for mixing services specifically, which is precisely the category that generates indirect-exposure alerts.

There is also a hard technical ceiling nobody can engineer around. Once funds enter an exchange, they are pooled with everyone else's. As Chainalysis itself has explained, "only the exchange itself knows which deposits and withdrawals are associated with specific customers." A deposit address belongs to the exchange, not to you — which is why tracing "through" a platform is guesswork from the outside.

If you hold funds on a platform facing a ban

Where a platform is subject to an EU transaction ban rather than a full asset freeze, there is normally a time-boxed process for getting out: eligible EU, EEA and Swiss users can apply for authorisation to withdraw funds or close their accounts, but only within three months of the ban taking effect. Windows like this are easy to miss and do not reopen.

If that applies to you, act on it early rather than at the deadline — applications take time to process, and the platform itself may be dealing with a surge of the same requests.

Questions people actually ask

What are tainted coins, exactly?

There is no official list of tainted coins and no legal status called "tainted". The term describes a risk score produced by blockchain-analysis software that traces where a coin has been. Different tracing methods give wildly different answers on the same data, so the meaningful question is always which method was used and who configured it.

How do I prove my coins are legitimate?

With records, not arguments. Exchange statements, trade confirmations, invoices, contracts and payslips showing how you acquired the funds are what close a compliance review. Keep them as you go — reconstructing a paper trail after a hold is much harder.

Can an exchange freeze my account over suspicious bitcoins?

An exchange can place a hold while it reviews a deposit, and the legal trigger is low by design — a firm needs only to suspect, or have reason to suspect, that something warrants a look. A hold is a review, not an accusation, and blocked property remains yours: it is frozen, not seized.

Why won't the exchange tell me why my deposit is held?

Often because it legally cannot. Where a suspicious-activity report has been filed, US law prohibits the institution from telling you it has done so, and it must refuse even a subpoena for it. The unhelpful answer you get is frequently a statute at work rather than a company being evasive.

I received crypto I never asked for. Am I in trouble?

Almost certainly not in a legal sense — you cannot refuse an incoming transaction, and the one time OFAC addressed unsolicited dust it said it would not prioritise enforcement in that situation and that recipients could apply for a licence. The realistic risk is an automated false positive at a platform, which has happened over amounts as small as two cents. Leaving dust untouched is the safer choice.

How many transactions away from a sanctioned address is too many?

There is no such number, and no regulator has published one. Sanctions rules turn on whether a sanctioned party has an interest in your specific property, not on distance along a chain — OFAC's own crypto guidance never uses the concept. Each company sets its own thresholds, which is why the same wallet can be fine at one venue and flagged at another.

Do exchanges consider all coins that went through a sanctioned platform tainted?

Not automatically. Analytics vendors themselves say distance matters and that proximity to illicit activity is not participation, and published benchmarks show indirect exposure is treated far more leniently than direct exposure. In practice, funds coming straight out of a platform that has just been designated do attract more scrutiny than funds several steps removed.

What happens to my money if a platform I use gets banned?

A transaction ban is not the same as an asset freeze. Where a ban applies, there is usually a limited window — three months in the EU's current framework — for eligible users to apply for authorisation to withdraw funds or close their account. These windows do not reopen, so applying early matters.

Got a question about your own account?Every case is different, and you don't have to guess on your own. Check the Terms, or just ask Sam AI — 24/7, in your language, and the answer is specific to your situation.
Ask Sam AI

This article is general information about publicly announced sanctions measures, not legal advice. Rules change, and how they apply depends on your own circumstances — see the Terms of Service or ask Sam AI. Dates and designations described here are as published by the relevant authorities as of 21 August 2026.