Crime

UK Targets Cryptomus, Heleket, TokenSpot in New Russian Sanctions

Summary

  • The UK’s latest sanctions target the broader infrastructure supporting Russia’s wartime economy. The UK designated crypto payment processors Cryptomus and Heleket, which operate under parent company Xeltox Enterprises Ltd., as well as Kyrgyzstani exchange TokenSpot CJSC. The package also targets actors across Russia’s energy sector, military supply chains, and financial system.
  • Cryptomus and Heleket have emerged as major payment hubs for illicit activity. Chainalysis had been tracking both services before their designation and found that they received funds from thousands of illicit counterparties. Together, they received more illicit funds across tracked categories than the mixers in our dataset and the number of illicit counterparties surged to more than 900 in a single month in late 2025.
  • TokenSpot is closely connected to the A7A5 sanctions-evasion network. Chainalysis analysis shows funds from TokenSpot along with Grinex and Meer converging on the same HTX deposit address, which received more than $308 million. These services also have connections to the A7A5 instant swapper and other addresses linked to the broader network.

On October 8, the United Kingdom’s (UK) Foreign, Commonwealth & Development Office (FCDO) designated 38 entities for their roles in financing Russia’s wartime economy, supporting its military-industrial base, and facilitating sanctions evasion.

Among those designated are crypto payment processors Cryptomus and Heleket, which both operate under a parent company Xeltox Enterprises LTD, and Kyrgyzstani exchange TokenSpot CJSC (Tokenspot).

These designations bring renewed attention to services Chainalysis has already been tracking. We have previously linked Cryptomus and Heleket to a range of illicit activity. Our analysis reveals the breadth of their illicit exposure, with both services receiving funds from a wide range of criminal actors, including scam operators, fraud shops, and organized criminal networks.

TokenSpot, meanwhile, is part of a Kyrgyzstan-based sanctions evasion network with ties to the A7A5 token and its administrators, which Chainalysis has tracked since the Kyrgyzstani exchanges Grinex and Meer.kg were sanctioned in August 2025.

Tracing the illicit ecosystem around Cryptomus and Heleket

Our analysis shows that both Cryptomus and Heleket have received funds from more than 15,000 illicit actors spanning every category of illicit activity we track.

As the chart above illustrates, both services have received funds linked to some of the most significant actor categories across today’s illicit ecosystem. For example, funds from the $1.4 billion Bybit exploit attributed to North Korea’s Lazarus Group ultimately reached both services indirectly. And proceeds from ransomware groups such as Black Basta and illicit marketplaces such as Xinbi Guarantee have flowed through the services.

Some illicit actors appear to maintain accounts on both services to distribute activity across multiple services and reduce their reliance on any single provider. The services have been the payment rails of choice for a number of malicious cyber infrastructure vendors as well, spanning bulletproof hosting, proxy services, malware and DDoS as-a- service providers, including several now designated entities such as Zservers, Stark Industries, First VPN, and Aeza Group.

In October 2025, Canada’s financial intelligence unit, FINTRAC, hit Cryptomus with a record CAD 177 million penalty for AML/CFT violations. This penalty, combined with our on-chain findings, point to a persistent pattern of weak controls that has allowed illicit actors to use these services at scale.

 

As the above chart shows, Cryptomus and Heleket exceed all mixing services that we track in terms of funds received by illicit actors operating in the following categories — scams, sanctioned jurisdictions, escort services, terrorist financing, and EU 20th sanctions package category.

Mixers are designed to obscure where funds come from, making their illicit finance risks well known. Cryptomus and Heleket, by contrast, presented themselves ostensibly as legitimate payment processors, albeit with lax compliance standards. Yet these two services received more funds from illicit actors than all tracked mixers combined across these categories. Their reach shows how payment services with minimal identity verification can facilitate laundering at a scale that rivals or exceeds services built to conceal transactions.

The presence of EU sanctions package exposure before UK designation indicates that these services were already transacting with entities sanctioned by European authorities.

Cryptomus and Heleket’s illicit actor activity has also grown steadily since 2022, with a surge in late 2025 to more than 900 in a single month.

 

This surge is likely driven in part by the takedown of other illicit-friendly services, such as the 2025 dismantling of the Russian crypto exchange Garantex. Our data show that many users already had accounts on both Garantex and Cryptomus or Heleket simultaneously. This suggests they may have simply shifted their primary activity to Cryptomus or Heleket after losing access to Garantex.

(The spike may also partly reflect new sanctions designations. When authorities designate an entity, its past transactions can begin counting toward a service’s illicit counterparties, even if those transactions occurred months or years earlier.)

Cryptomus has also promoted its services directly on criminal forums, positioning itself as a way for illicit actors to move and convert cryptocurrency. For example, Cryptomus advertised on BHF, a Russian-language dark web forum, as well as Nulled, a major cybercrime forum that had more than 10 million users at its peak. In these advertisements, Cryptomus promoted “anonymous” crypto payments and conversion without requiring KYC or KYB, making the service particularly attractive to users seeking to operate outside traditional financial controls.

This is a Cryptomus advertisement (translated from the original Russian) on BHF, a Russian-language cybercrime forum.
This is an advertisement for Cryptomus on Nulled Forum.

 

Inside TokenSpot, Grinex, and the A7A5 Network

Multiple pieces of evidence tie TokenSpot directly to a broader network of Kyrgyzstani crypto exchanges already sanctioned for facilitating Russian sanctions evasion.

A side-by-side comparison of Meer, which was sanctioned by OSFI in August 2025 for being a key facilitator of A7A5 trades, and TokenSpot reveals near-identical website designs. Both sites are Russian-language crypto-fiat exchanges, with matching layouts, visual assets, and value propositions. Meer markets itself as a “cryptocurrency exchange” for crypto-fiat pairs. TokenSpot advertises “cryptocurrency for business growth,” offering ruble-denominated crypto purchases for individuals and legal entities. The shared template strongly suggests common operators or infrastructure behind both services.

The Chainalysis Reactor graph below shows TokenSpot, Grinex, and Meer funneling downstream funds into the same HTX deposit address, which received over $308 million.

The graph reveals connections to addresses included in a leak of the Ilan Shor-affiliated company AnyKey LLC and the A7A5 instant swapper, a service that allows users to trade ruble-backed A7A5 tokens for dollar-backed stablecoins.

Intermediary wallets sit between several of these entities and the HTX deposit address, but the convergence point is clear: funds from all three Kyrgyzstani exchanges flowed to the same destination. HTX (formerly Huobi) was sanctioned by the UK in May for channeling over $1.5 billion to Russia through flows from previously sanctioned entities.

Russia’s oil and military supply chains also targeted

The designations extend well beyond crypto as well, targeting several of the industries and supply chains that underpin Russia’s wartime economy.

The UK sanctioned Russian oil companies Zarubezhneft and INK Capital, bringing its sanctions coverage to more than 90% of Russia’s total oil production capacity, and the Russian bank Stolichny Kredit. It also designated twelve shadow fleet tankers, bringing the total number of sanctioned vessels to more than 600.

The new sanctions also target the supply chains supporting Russia’s military-industrial base. Seventeen individuals and entities involved in importing machine tools, electronics, and materials used in ballistic missile and drone production were sanctioned.

Crypto is increasingly helping to finance these supply chains and procurement networks. For example, we tracked earlier this year how drone procurement networks of state-backed actors used open crowdfunding campaigns to fundraise via crypto. In one case, a collection of pro-Russia volunteer and paramilitary organizations were able to raise over $8.3 million in crypto to purchase drones as well as other military equipment.

These latest designations highlight how crypto intersects with the wider networks that enable sanctions evasion and support Russia’s wider financial and military efforts. Tracking these connections helps reveal how illicit actors adapt as authorities disrupt established channels.

As always, Chainalysis will continue to monitor these networks and the services that enable them as they evolve.

This website contains links to third-party sites that are not under the control of Chainalysis, Inc. or its affiliates (collectively “Chainalysis”). Access to such information does not imply association with, endorsement of, approval of, or recommendation by Chainalysis of the site or its operators, and Chainalysis is not responsible for the products, services, or other content hosted therein.

This material is for informational purposes only, and is not intended to provide legal, tax, financial, or investment advice. Recipients should consult their own advisors before making these types of decisions. Chainalysis has no responsibility or liability for any decision made or any other acts or omissions in connection with Recipient’s use of this material.

Chainalysis does not guarantee or warrant the accuracy, completeness, timeliness, suitability or validity of the information in this report and will not be responsible for any claim attributable to errors, omissions, or other inaccuracies of any part of such material.