Crypto, Sanctions and War: How Russian Actors Funnel Digital Assets
Sanctioned Russian entities have raised millions of dollars in cryptocurrency to support military operations in Ukraine, routing funds through paramilitary donation campaigns, ransomware networks, cross-chain bridges, and Ponzi-adjacent schemes. A detailed analysis published by blockchain intelligence firm Elliptic documents the scale and sophistication of these efforts, and the findings carry direct compliance obligations for every virtual asset service provider (VASP), accounting firm, and corporate treasury that touches digital assets.
The Scale of Pro-Russian Crypto Fundraising
Elliptic's analysis, drawing on proprietary internal data, found that pro-Russian entities raising funds for Russian military operations and associated militias had collected approximately $4.8 million in crypto donations by the end of November 2022. Separately, around 50 distinct military fundraising campaigns were identified, each advertising dedicated crypto donation wallets and together accumulating roughly $3.2 million in digital assets.
Those numbers may look modest against the broader crypto market, but the compliance signal they carry is not modest at all. Many of these campaigns explicitly advertised methods for circumventing sanctions, some providing step-by-step guidance on making anonymous donations. Crucially, the routes they described were not always confined to unregulated dark-web infrastructure. Several strategies involved compliant, regulated virtual asset services, meaning that a licensed exchange or custodian could be the unwitting last link in a sanctions-violation chain.
Why Compliant Platforms Are Still at Risk
The assumption that a sanctions-designated wallet will simply be blocked at the point of deposit is increasingly outdated. Sanctioned actors are using mixing layers, peer-to-peer transfers, and cross-chain swaps to distance funds from their origin before they ever reach a regulated on-ramp or off-ramp. A VASP that screens only the immediate counterparty address, without tracing the upstream transaction graph, may pass a compliance audit on paper while still processing the proceeds of sanctioned activity.
Key Actors and the Methods They Used
The Elliptic report highlights several specific entities and individuals whose crypto activity illustrates the breadth of evasion techniques in play.
Task Force Rusich
Task Force Rusich, also known as DSHRG Rusich, is a paramilitary group with roots going back to 2009. Associated with far-right ideology and neo-Nazi symbolism, it has fought in Syria and Ukraine and is affiliated with the Wagner Group. The US, UK, EU, and Canada have all designated Rusich under sanctions regimes, including its leaders Alexey Yurevich Milchakov and Yan Igorevich Petrovskiy. Despite those designations, the group remained operationally active and publicly visible on social media throughout the period studied. It raised over $200,000 in crypto donations, demonstrating that SDN-list inclusion alone does not stop inbound digital asset flows if VASPs are not screening at the wallet level.
The Terricon Project and the NFT Angle
In April 2022 a pro-separatist website called "The Terricon Project" appeared and began soliciting crypto donations to procure military equipment. The project was openly backed by Alexander Zhuchkovsky, a supporter of the Russian Imperial Movement, itself a US-designated terrorist organisation. Zhuchkovsky was personally sanctioned by the US in June 2022. The project raised approximately $3,400 in crypto and also launched an NFT collection featuring coats of arms of Ukrainian cities claimed by Russia. The NFT marketplace that hosted the collection removed it before any sales completed. The episode is significant for compliance teams because it shows that the NFT layer, often treated as a separate and lower-risk product vertical, can be used to raise funds for sanctioned activity just as readily as a straightforward donation wallet.
Conti Ransomware and Cross-Chain Laundering
The Conti ransomware group publicly declared its support for the Russian government the day after the February 2022 invasion. A subsequent leak of more than 60,000 internal messages gave investigators an unusually detailed picture of the group's structure, its relationship with Russian security services, and its money-movement operations. Elliptic traced Conti's post-ransom laundering activity and found it involved substantial cross-chain transfers and asset swaps, including flows through the sanctioned crypto exchange Garantex and through the cross-chain bridge renBridge. Elliptic has separately documented that renBridge processed over $540 million in illicit cryptoassets. For compliance teams, the Conti case is a textbook illustration of why single-chain transaction monitoring is insufficient: the laundering trail deliberately hops between blockchains specifically to defeat linear screening.
Ponzi Schemes and Sanctioned Officials
The report also traces a longer-running thread connecting pro-Russian separatist officials in the Donetsk region to serial crypto fraud schemes. Senior officials in the self-proclaimed "Donetsk People's Republic" have been associated with Ponzi schemes including MMM Global, E-Dinar, PRIZM, Ouroboros, and OneCoin, the scheme linked to the now-notorious "Cryptoqueen" Ruja Ignatova. One official, Aleksey Muratov, is US-sanctioned partly because of his involvement in these frauds. The pattern matters because it shows that the same networks facilitating scam tokens are also connected to the broader Russia sanctions evasion ecosystem. Firms that have previously treated crypto fraud and geopolitical sanctions risk as distinct compliance workstreams may need to revisit that separation.
Accounting and Reporting Implications
The findings land squarely in the intersection of AML compliance and financial reporting obligations, and the two cannot be treated in isolation.
For Accounting Firms and Auditors
Under both US Generally Accepted Auditing Standards and the UK's Financial Reporting Council guidance, auditors are required to assess whether a client's digital asset holdings or transaction flows present sanctions exposure. Where a client uses crypto bookkeeping software or digital asset accounting software that records transactions at face value without sanctions attribution metadata, the auditor has limited visibility. Firms should now be asking clients to demonstrate that their transaction records include blockchain provenance data, not just on-chain amounts and timestamps. A crypto accounting software stack that cannot link a wallet address to a sanctions watchlist entry in real time creates an audit gap that is difficult to paper over with disclosure alone.
The Conti and renBridge findings are particularly relevant here. If a client's treasury received ransomware-adjacent funds that were later identified as having passed through a sanctioned exchange, the question of whether those receipts should have been recognised or immediately frozen becomes a live accounting issue. Under OFAC rules in the US, and equivalent regimes under the UK's Office of Financial Sanctions Implementation (OFSI) and EU Council Regulations, holding or processing funds connected to a designated entity is itself a potential violation, irrespective of whether the firm knew the ultimate source.
For CFOs and Corporate Treasuries
Any corporate treasury that holds bitcoin, stablecoins, or other digital assets as a balance sheet item needs to be able to demonstrate at period-end that those holdings are not subject to sanctions taint. That is not a theoretical concern: regulators on both sides of the Atlantic have signalled that they expect VASPs and their institutional clients to take a risk-based approach to transaction provenance, not simply a point-in-time wallet check. The Elliptic findings show that sanctioned actors are deliberately using compliant platforms as exit ramps, meaning the compliance burden is shifting further downstream to the recipient institution. CFOs who treat crypto treasury management as a pure treasury function, separated from the AML programme, are carrying unquantified regulatory risk on the balance sheet.
Good digital asset accounting software will tag incoming transactions with risk scores derived from blockchain analytics. Firms that are not yet receiving that data feed from their custody or exchange providers should treat its absence as a gap requiring immediate remediation, not a future roadmap item.
What the Sanctions Landscape Looks Like Now
Since the February 2022 invasion, the US (via OFAC), the UK (via OFSI), and the EU (via successive Council Regulations) have all expanded their Russia-related sanctions packages to explicitly address cryptoasset evasion. Reporting obligations under the Bank Secrecy Act in the US, the Proceeds of Crime Act 2002 in the UK, and the EU's Transfer of Funds Regulation all require regulated entities to file suspicious activity reports where crypto flows raise sanctions red flags. The Elliptic data suggests that a meaningful volume of transactions connected to designated entities was still reaching regulated platforms, which implies that current screening practices have gaps.
For more on how regulators are using blockchain analytics to close those gaps, see our earlier coverage of blockchain analytics and AML in practice. The EU's specific legislative response to terrorist and state-actor financing through digital assets is covered in our piece on EU regulation targeting terrorist financing through digital assets.
Practical Steps for Compliance and Finance Teams
The Elliptic findings point to several concrete actions that VASPs, accounting firms, and corporate finance teams should be taking now.
Upgrade Screening to Cover Cross-Chain Activity
Single-chain wallet screening is no longer adequate where sophisticated actors are using cross-chain bridges and asset swaps to obscure provenance. Any sanctions screening tool or crypto bookkeeping software integration should be capable of following a transaction across chains, not just validating the immediate counterparty address against a static watchlist.
Extend KYC Beyond the Initial Onboarding Check
Several of the individuals named in the Elliptic report were sanctioned after initial platform onboarding occurred. A KYC process that is purely event-driven (triggered only at account opening) will not catch mid-relationship designations. Ongoing monitoring against updated sanctions lists, with automated alerts tied to the digital asset accounting software or custody platform, is now a regulatory expectation in all three major jurisdictions covered here.
Treat NFT Fundraising as a High-Risk Product
The Terricon Project episode illustrates that NFT sales can be structured as disguised fundraising for sanctioned activity. Platforms and firms that facilitate NFT minting, sale, or custody should apply the same sanctions screening logic to NFT proceeds as they would to a straightforward crypto transfer.
Build a Ransomware Payment Protocol
Given the documented link between ransomware groups like Conti and sanctioned exchange infrastructure, any firm that might face a ransomware demand needs a pre-approved protocol. That protocol should include a mandatory OFAC/OFSI check before any payment is authorised, because paying a ransom to a sanctioned group is itself a sanctions violation regardless of the business necessity. See our Bitcoin ransomware response plan for a structured approach.
Frequently Asked Questions
Does our firm have a legal obligation to screen crypto transactions for Russia-related sanctions?
Yes, in all three major jurisdictions covered here. In the US, OFAC's Russia-related sanctions programmes apply to all US persons and entities, including those processing digital assets. The UK's OFSI and EU Council Regulations impose equivalent obligations on regulated firms. Failure to screen, and to file a suspicious activity report where red flags are identified, can result in civil or criminal penalties even where the firm had no actual knowledge of the sanctions connection.
What does "cross-chain" laundering mean in practice, and why does it matter for our screening tools?
Cross-chain laundering means moving funds from one blockchain to another using a bridge protocol or wrapped-asset mechanism, specifically to break the transaction trail that a single-chain analytics tool would follow. If your screening tool only checks Ethereum addresses against a sanctions list, it will not detect funds that originated on Bitcoin, were bridged to Ethereum via renBridge, and then arrived at your platform. Your digital asset accounting software and AML tooling must be able to trace funds across blockchains to be effective.
Are NFT proceeds subject to the same sanctions screening requirements as crypto transfers?
Regulators in the US and EU have both indicated that NFT transactions are within scope of existing AML and sanctions frameworks where they constitute a transfer of value. The Financial Action Task Force (FATF) guidance on virtual assets is explicit that the economic substance of a transaction, not its technical form, determines whether AML obligations apply. NFT fundraising campaigns linked to sanctioned entities should therefore be treated as high-risk activity requiring enhanced due diligence.
If we receive funds that were later traced to a sanctioned entity, what are our obligations?
Under OFAC rules, a US person who holds funds connected to a sanctioned entity is required to block those funds and report the blocked property to OFAC. OFSI and EU regulations contain comparable freeze-and-report requirements. The key point is that the obligation arises on discovery, not at the point of receipt. Firms should have a documented process for handling post-receipt sanctions alerts, including how the relevant amount is reflected in the financial statements pending regulatory resolution.
How should crypto accounting software handle transactions that are subsequently identified as sanctions-tainted?
Once a transaction is flagged as potentially connected to a sanctioned entity, the accounting treatment depends on the applicable legal determination. Until that determination is made, the funds should not be recognised as unrestricted revenue or available cash. Many firms treat blocked or disputed crypto balances as a contingent liability or restricted asset until regulators confirm the appropriate disposition. Your external auditor should be involved in this determination, and the disclosure in the financial statements should reflect the uncertainty explicitly.
Source: Elliptic
