The A7 Leaks: What $8 Billion in Stablecoin Flows Mean for Crypto Accounting and AML Compliance
A major leak of internal documents from the A7 group, the Russia-based sanctions-evasion network linked to sanctioned Moldovan fugitive Ilan Shor, has confirmed what compliance professionals have long suspected: stablecoins, ruble-backed tokens, and purpose-built activist-payment apps are now core infrastructure for circumventing Western financial controls. Blockchain analytics firm Elliptic, which analysed the leaked data, identified wallets connected to A7 and associated businesses that received $8 billion in stablecoin transactions over roughly 18 months. For accounting firms and CFOs operating crypto accounting software with any exposure to stablecoin flows or Russian-linked entities, this leak is not background noise. It is an active typology update.
Who Is Behind A7 and Why It Matters
Ilan Shor and the A7 Structure
Ilan Shor was convicted in 2017 in connection with the 2014 theft of $1 billion from three Moldovan banks. He subsequently fled to Israel and then to Russia, which granted him citizenship. The United States sanctioned him in 2022 for allegedly helping Russia undermine democratic elections in Moldova, including large-scale vote-buying for pro-Russia candidates and disinformation campaigns targeting the incumbent pro-Europe government.
After relocating to Russia, Shor founded the A7 group of companies in 2024. A7 specialises in helping Russian businesses bypass sanctions and conduct cross-border payments. Critically, A7 is 49% owned by Promsvyazbank (PSB), a Russian state-owned bank that serves the country's defence sector and was itself sanctioned for financing Russia's defence industry and facilitating sanctions evasion. The US designated A7 directly in August 2025. At a conference focused on Russian infrastructure in the Far East, Shor told President Putin that A7 had facilitated 7.5 trillion rubles, approximately $89 billion, in cross-border transactions over ten months, with more than half routed through Asian countries.
The Data Breach and Kyrgyz Routing
A cache of A7's internal documents was leaked in early September 2025. One slide in the leaked data, titled "Internal settlement scheme of Group A7", shows how payments originating in Russia are funnelled through a network of companies, primarily in Kyrgyzstan, a country with close financial and political ties to Moscow. The leak also reveals that Shor provided the President of Kyrgyzstan with a luxury jet through a chain of proxies, suggesting deep political relationships underpinning the financial network. The scheme uses a combination of cash, promissory notes, and cryptocurrency to move value across borders, with crypto playing an increasingly central role.
The Stablecoin Architecture: USDT and A7A5
Why Russian Actors Favour USDT
Tether's USDT has become the stablecoin of choice for Russian sanctions evasion for three compounding reasons. First, its price stability relative to the volatile ruble makes it practical for treasury management. Second, its broad acceptance across global exchanges and payment channels means it can settle cross-border obligations without touching the SWIFT network. Third, it is accessible even as domestic Russian banks lost their international correspondent banking relationships.
However, USDT's centralised structure is also a liability. Tether can freeze wallets on instruction from law enforcement. This vulnerability was demonstrated in March 2025 when the US Secret Service, using intelligence from Elliptic, forced Russian crypto exchange Garantex offline and froze 26 million USDT. Garantex had deployed sophisticated wallet obfuscation techniques to obscure its transaction graph, but Elliptic's analysis penetrated that structure and provided actionable intelligence to investigators.
A7A5: The Ruble-Backed Workaround
A7's response to the USDT freezing risk was to develop its own stablecoin. A7A5 is a ruble-backed token issued through Old Vector LLC, a Kyrgyz company, with each unit claimed to be backed 1:1 by ruble deposits held at PSB. Because A7A5 is not issued by a Western entity, it cannot be frozen by Tether or any other Western-controlled issuer. At the time of the leak, 41.6 billion A7A5 tokens were in circulation, carrying a stated value of approximately $496 million, with total transaction volume of $68 billion recorded to date.
The leaked chat logs reveal that A7 employees actively managed market liquidity for A7A5. In April 2025, employees discussed the need for market-making on crypto exchanges to support sufficient liquidity for those wishing to swap between A7A5 and USDT. Subsequently, A7 wallets sent at least $2 billion in USDT to exchanges to be sold for A7A5, seeding adoption of the ruble-backed token. PSB, Old Vector, and A7A5 now form an integrated sanctions-busting layer within the A7 group's payment infrastructure.
Crypto-Funded Election Interference in Moldova
The Taito App and Activist Payments
The leaks go beyond financial sanctions evasion and into political operations. Leaked chat logs show software developers working on a project called "Taito", an application designed to manage and pay a network of political activists in Moldova. Moldovan police announced in August 2025 that Taito was being used for illegal electoral financing and voter bribery. The timing matters: Moldova held parliamentary elections immediately after the leak became public, and Russia's strategic objective of preventing Moldova's integration with the European Union is explicit in the documents. Crypto payments provided the financial rails for this activist network precisely because they bypass the banking controls that would otherwise flag unusual cash movements before an election.
Wallet Switching and Breach Response
Elliptic's analysis indicates that Shor's businesses began switching their cryptocurrency wallet infrastructure around August 14, 2025, the same day that unusual activity was observed in wallets managing the A7A5 stablecoin. This timing suggests the network became aware of the breach and began rotating cryptographic keys and addresses to limit exposure. The $8 billion figure should therefore be treated as a lower bound: other wallets not yet identified may exist, and the rotation complicates attribution.
AML and Compliance Implications for Accounting Firms and CFOs
Updating Your Transaction Monitoring Typologies
The A7 leaks crystallise several typologies that should be reflected in any firm's AML risk framework when using crypto accounting software or digital asset accounting software for client work.
- Ruble-pegged or non-Western stablecoins: A7A5 demonstrates that purpose-built stablecoins can be engineered specifically to avoid Western freezing mechanisms. Any token pegged to a sanctioned currency and issued through a non-FATF-compliant jurisdiction warrants enhanced due diligence.
- High-volume USDT flows through Central Asian intermediaries: The Kyrgyz routing structure is now a documented typology. Firms should review whether their screening tools flag indirect exposure to Kyrgyz-domiciled entities in stablecoin payment chains.
- Treasury chat-log evidence: The leak shows that ordinary employee chat logs can constitute transaction evidence. Firms advising clients on crypto treasury operations should ensure those clients understand that internal communications referencing wallet addresses are discoverable.
- Wallet rotation as an evasion signal: Rapid, coordinated switching of multiple wallets across a network, particularly around a known enforcement event, is now a documented red flag. Transaction monitoring rules should be calibrated to detect cluster-level address rotation.
Accounting Treatment and Record-Keeping Obligations
For firms using crypto bookkeeping software to account for stablecoin flows on behalf of clients, the A7 leaks reinforce several practical obligations. First, the existence of ruble-backed tokens like A7A5 raises the question of how to classify and value non-dollar-pegged stablecoins on the balance sheet, particularly where the backing asset is itself held in a sanctioned institution. Under both IFRS and US GAAP, the fair value of a stablecoin depends on the quality and liquidity of its backing, and PSB-backed deposits are not equivalent to US dollar bank deposits for impairment assessment purposes.
Second, sanctions screening is not purely a compliance function. When a client's counterparty is later identified as a sanctioned entity, the accounting records must be reviewed for any transactions that may need to be unwound, reported to the relevant authority, or written off. Firms should ensure their crypto accounting software can produce audit-ready transaction histories at the wallet and counterparty level, not just the token level.
Third, the PSB ownership stake in A7 illustrates how state ownership can create indirect sanctions exposure. A corporate client with a supply-chain or payment relationship touching any PSB affiliate should now reassess that exposure in light of the A7 designation.
For more context on how AI-driven tools are being applied to detect patterns of this kind, see our coverage of how AI is reshaping crypto crime detection for accounting firms. And for the regulatory backdrop on Russia's own domestic crypto policy, our earlier analysis of Russia's approved crypto trading list and what it means for compliance teams provides useful context.
What Firms Should Do Now
Immediate Steps Across Audit, Advisory, and Treasury Functions
Compliance leads and CFOs should treat the A7 designations as live screening data, not historical context. The specific actions to take before your next client review cycle are:
- Run A7, Old Vector LLC, Promsvyazbank, and A7A5 through your sanctions screening tools and update watchlists to reflect the August 2025 US designation of A7.
- Request that your digital asset accounting software provider confirms whether A7-linked wallet addresses are included in its blockchain analytics data feeds. If not, escalate to your primary blockchain analytics vendor directly.
- Review any client with cross-border payment activity routed through Kyrgyzstan or other Central Asian jurisdictions for indirect exposure to the A7 network.
- Check whether your transaction monitoring rules for stablecoin flows distinguish between USDT (issued by a Western-controlled entity) and non-Western ruble-pegged tokens. If they do not, this is a gap.
- For clients holding or transacting in stablecoins backed by non-dollar assets, ensure your balance sheet valuations account for the credit quality of the backing institution, not just the 1:1 peg claim.
Frequently Asked Questions
What is A7 and why was it sanctioned?
A7 is a group of companies founded in Russia in 2024 by Ilan Shor, a sanctioned Moldovan fugitive convicted in connection with a large-scale Moldovan bank fraud. A7 specialises in helping Russian businesses conduct cross-border payments that bypass Western sanctions. The US designated A7 in August 2025. It is 49% owned by Promsvyazbank, a Russian state bank that is itself under US sanctions for financing Russia's defence sector.
What is A7A5 and how does it differ from USDT?
A7A5 is a ruble-backed stablecoin issued by Old Vector LLC, a Kyrgyz company linked to A7. Each token is claimed to be backed 1:1 by ruble deposits held at Promsvyazbank. Unlike USDT, which is issued by a Western entity and can be frozen by Tether on instruction from law enforcement, A7A5 is designed to be outside the reach of Western asset-freezing mechanisms. At the time of the leak, 41.6 billion tokens were in circulation with a stated value of approximately $496 million.
How should accounting firms classify a ruble-backed stablecoin on the balance sheet?
Under both IFRS and US GAAP, the fair value of any stablecoin depends on the quality of its backing. A token backed by ruble deposits at a sanctioned bank cannot be treated as a dollar-equivalent instrument. Firms should assess the credit risk of the backing institution, apply appropriate impairment considerations, and document their valuation methodology carefully. This is distinct from how you would classify USDT or USDC backed by liquid US dollar assets.
What transaction monitoring red flags does the A7 network generate?
The A7 typology includes: high-volume USDT flows routed through Kyrgyz-domiciled entities; coordinated, rapid wallet address rotation across a network following an enforcement event; market-making activity in non-Western ruble-pegged stablecoins on crypto exchanges; and cross-border payment flows explicitly structured to avoid SWIFT. Firms should review whether their existing AML rules cover these patterns and update them if not.
Does FATF guidance cover ruble-backed stablecoins issued in non-member jurisdictions?
FATF's existing guidance on virtual assets and virtual asset service providers applies to tokens regardless of the currency they are pegged to, but enforcement depends on the jurisdiction of the issuer and the VASP involved. Kyrgyzstan is a FATF-Eurasia Group member, but compliance with FATF standards varies. Firms operating in US or EU jurisdictions must apply their own sanctions and AML obligations regardless of where the token is issued. The existence of A7A5 highlights a regulatory gap that Western authorities are likely to address in upcoming guidance updates.
Source: Elliptic
