Crypto in Conflict: Sanctions Risk, DeFi Fundraising, and What Firms Must Know
A detailed analysis published by blockchain intelligence firm Elliptic maps cryptoasset activity on both sides of the Russia-Ukraine war and lands squarely on the desks of compliance officers, auditors, and the accounting firms advising virtual asset service providers (VASPs). The headline finding is stark: more than one in ten pro-Russian crypto donations originate from sources already flagged as illicit, creating live sanctions exposure for any platform that processes those funds without adequate screening. For teams building or reviewing AML controls, and for anyone relying on crypto accounting software to maintain an audit trail, this report is a practical stress-test of current frameworks.
What the Report Actually Covers
Elliptic drew on its own proprietary blockchain data to trace cryptoasset flows connected to both Ukrainian and pro-Russian fundraising activity from the period following Russia's full-scale invasion in February 2022. The scope is deliberately wide, covering humanitarian campaigns, military-support networks, sanctioned entities, and groups whose public communications have included material the report characterises as glorifying potential war crimes and crimes against humanity.
The Ukrainian fundraising picture
Blockchain technology proved highly effective as a fundraising rail on the Ukrainian side. The report puts total crypto donations at over $78 million. Bitcoin accounted for just 1% of that figure. The bulk moved through channels built on more recent infrastructure: DeFi protocols, non-fungible token campaigns, and decentralised autonomous organisations. NFT campaigns alone contributed close to $8 million, roughly 10% of the total. That scale demonstrates something compliance teams should already be modelling: DeFi and NFT flows are no longer niche. They are material fundraising vehicles that need to sit inside any credible AML and crypto bookkeeping software architecture.
The pro-Russian fundraising picture and its illicit taint
Pro-Russian entities, a category that includes fundraisers for the Russian military and affiliated militias, raised a reported $4.8 million in crypto donations. Efforts to replicate the Ukrainian model using NFTs and DeFi structures largely failed. What did not fail, however, was the flow of funds from already-tainted sources: the report finds that over 10% of pro-Russian donations trace to dark-web markets, sanctioned entities, or vendors linked to stolen payment card data. That proportion converts the pro-Russian fundraising ecosystem into a live sanctions-screening problem for every platform that may have touched those wallets.
Sanctions Exposure: What the Numbers Mean in Practice
A 10%-plus illicit-source rate is not an academic data point. Under both US OFAC rules and EU sanctions regulations, a VASP that processes a transaction where the counterparty wallet is linked to a designated entity faces potential strict-liability exposure, regardless of whether the platform knew about the link at the time. The obligation to know sits with the firm.
OFAC and EU sanctions mechanics
OFAC's framework requires US persons and entities to block transactions involving sanctioned parties and to report blocked property. The EU's sanctions regime, implemented across member states under Council regulations, imposes equivalent asset-freeze and reporting obligations. Neither framework makes an exception for amounts that appear small. A $500 donation routed through a wallet cluster connected to a sanctioned militia carries the same legal exposure as a large institutional transfer if the link can be established on-chain.
Why blockchain traceability matters here
Blockchain's permanent public ledger cuts both ways. It is the mechanism that allowed Elliptic to identify the illicit-source proportion in the first place, but it is also the mechanism that allows regulators and law-enforcement agencies to trace flows retrospectively. A VASP that processed a pro-Russian donation wallet in 2022 or 2023 may find that wallet cluster newly designated or newly traced to a sanctioned entity in 2026. Retrospective exposure of this kind is exactly why transaction-level records, not just onboarding KYC snapshots, need to be maintained and searchable inside whatever digital asset accounting software the firm operates.
DeFi, NFTs, and DAOs as Compliance Blind Spots
The Ukrainian fundraising data does something useful for compliance teams: it demonstrates empirically that DeFi protocols, NFT minting campaigns, and DAOs can mobilise tens of millions of dollars quickly and across borders. That same capability is neutral to the cause it serves. A DeFi protocol does not screen for the political affiliation of a liquidity provider. An NFT smart contract does not perform KYC on a buyer.
Regulatory trajectory in the US and EU
Both the US and the EU are moving to close the DeFi compliance gap, though at different speeds. In the US, the revised CLARITY Act has focused legislative attention on which DeFi operators are sufficiently decentralised to avoid broker-dealer classification and which are not. Operators that retain meaningful control face AML obligations under FinCEN rules. For context on how that legislation is developing, see our earlier coverage of what the revised CLARITY Act means for non-decentralised DeFi operators.
In the EU, the Markets in Crypto-Assets Regulation (MiCA) and the Transfer of Funds Regulation (TFR) together require travel-rule compliance for crypto transfers above threshold amounts, but DeFi sits in a stated regulatory grey zone that the European Commission has committed to revisiting. The Elliptic findings add political pressure to that review: if DeFi rails can move $78 million in a conflict context, regulators will not accept indefinite ambiguity about AML obligations.
NFTs: the $8 million data point firms cannot ignore
Nearly $8 million raised through NFT campaigns in a single conflict context is a data point that should inform how accounting firms classify NFT activity for their VASP clients. An NFT is not automatically a collectible with minimal financial crime risk. When NFT campaigns are used as fundraising vehicles, the underlying flows have the same AML profile as any other donation channel, including the need for source-of-funds checks on significant contributors and sanctions screening on wallet addresses involved in secondary-market transactions.
Accounting and Audit Implications
For accountants and auditors serving VASPs, the Elliptic report raises several concrete questions that should feature in any 2026 engagement planning or internal audit cycle.
Transaction-level record integrity
If a VASP client processed transactions involving wallets now identified as connected to sanctioned entities or dark-web markets, the firm needs to establish what records exist at the transaction level. Aggregate balances recorded in a general ledger are insufficient; you need the wallet address, the timestamp, the counterparty, and the blockchain transaction hash. Any crypto accounting software deployment that does not capture and retain these fields at the individual transaction level is operationally unfit for a sanctions-screening context.
Contingent liability disclosure
Where a VASP has processed transactions that may carry retrospective sanctions exposure, auditors and preparers need to assess whether a contingent liability disclosure is required under IFRS (IAS 37) or US GAAP (ASC 450). The threshold is whether an outflow is probable and can be reliably estimated. In a context where regulatory and law-enforcement scrutiny of conflict-linked wallets is active and ongoing, that threshold may be closer than firms assume.
Governance documentation for high-risk categories
Board-level governance documents, including AML risk assessments and the written policies required under FinCEN's programme rules and the EU's AMLD framework, should be reviewed to confirm that conflict-linked wallet clusters are explicitly addressed as a high-risk category. If the current documentation predates the period of significant conflict-linked activity, it likely needs updating. Auditors should treat the absence of this category as a control gap.
Prior-period exposure review
The report covers activity from 2022 onwards. Accounting firms with VASP clients should consider whether a targeted prior-period review of transaction records is warranted, using current blockchain intelligence data to test whether any processed wallets now carry a known illicit-source or sanctions designation. This is a proportionate step, not an exhaustive re-audit, but it provides a defensible record that the firm took reasonable steps when the risk intelligence became available. For a parallel example of how OFAC designations create retroactive accounting and compliance obligations, see our analysis of how the OFAC sanctions on Xinbi Guarantee affect crypto accounting workflows.
Practical Steps for Compliance and Finance Teams
The report does not prescribe a compliance response, but the data points toward several concrete actions.
Screening architecture
Wallet screening needs to operate at the transaction level, not just at onboarding. Blockchain intelligence feeds should be updated frequently enough to catch newly designated wallet clusters. Any digital asset accounting software used to record VASP transactions should log the screening outcome alongside the transaction record so that the audit trail is complete and self-contained.
DeFi and NFT policy coverage
AML policies that do not explicitly address DeFi protocol interactions and NFT campaigns leave a gap that regulators and auditors will identify. The Elliptic data makes the omission difficult to defend: these are documented, material fundraising channels with a demonstrated capacity for large-scale illicit-source exposure.
Staff training on conflict-linked typologies
Suspicious activity reporting requires staff to recognise patterns. Conflict-linked fundraising typologies, including the use of DAOs to pool donations, NFT drops as a cover for value transfer, and DeFi bridging to obscure fund origins, should be included in the next training cycle. FATF's guidance on virtual assets and the FinCEN SAR filing requirements for VASPs both provide a regulatory basis for expecting this coverage.
Frequently Asked Questions
Does the Elliptic report create any legal obligations for VASPs?
The report itself does not. Legal obligations arise from OFAC designations, EU Council regulations, and national AML legislation. The report's value is that it surfaces risk patterns and wallet-cluster data that VASPs can use to strengthen their screening. Ignoring that intelligence when it is publicly available could be relevant to a regulatory assessment of whether a firm took adequate steps.
What does "over 10% from illicit sources" mean for a VASP that accepted pro-Russian donations?
It means the statistical probability that any given pro-Russian donation wallet traces to a dark-web market, sanctioned entity, or stolen-card vendor is material, not negligible. A VASP that accepted such donations without transaction-level screening should treat this as a prompt to review its records and, if exposure is identified, consult legal counsel about voluntary disclosure obligations under applicable OFAC or EU sanctions rules.
Are NFT transactions subject to the same AML obligations as crypto transfers?
In most jurisdictions, yes, where a VASP facilitates the exchange or transfer of NFTs that qualify as virtual assets under local law. FATF's updated guidance on virtual assets explicitly includes NFTs that function as payment or investment instruments. Both US FinCEN rules and the EU's TFR apply to qualifying transfers. The specific classification depends on the NFT's characteristics and the platform's role in the transaction.
How should auditors treat conflict-linked wallet exposure in financial statements?
Under IAS 37 and ASC 450, a contingent liability should be disclosed where a potential outflow is probable and can be reasonably estimated, and noted where an outflow is possible but not probable. If a VASP has processed wallets with identified sanctions links and faces potential regulatory action, the auditor needs to assess whether either threshold is met, in consultation with the entity's legal advisers.
Does this report affect firms that only use crypto for treasury or payment purposes rather than operating as VASPs?
The direct AML obligations are lower for non-VASP corporates, but sanctions obligations apply to all US persons and EU entities regardless of their business model. A corporate treasury that holds crypto and transacts on-chain has an obligation not to deal with sanctioned counterparties. If the firm uses any blockchain-connected payment rail, it should confirm that its sanctions screening covers on-chain counterparties and not just traditional bank account details.
Source: Elliptic
