On October 8, the United Kingdom’s Foreign, Commonwealth & Development Office designated 38 entities for supporting Russia’s military-industrial base and facilitating sanctions evasion. The package specifically targets crypto payment processors Cryptomus and Heleket, which operate under parent company Xeltox Enterprises Ltd., as well as the Kyrgyzstani exchange TokenSpot CJSC. These designations expand the UK’s regulatory framework to address infrastructure enabling illicit financial flows.
Chainalysis data indicates that Cryptomus and Heleket received funds from more than 15,000 illicit actors, including scam operators and ransomware groups. In late 2025, the number of illicit counterparties using these services surged to over 900 in a single month. The services exceeded all tracked mixing services in terms of illicit funds received across categories such as scams and sanctioned jurisdictions. Additionally, Canada’s FINTRAC imposed a CAD 177 million penalty on Cryptomus in October 2025 for anti-money laundering violations.
TokenSpot is linked to the A7A5 sanctions-evasion network, sharing infrastructure characteristics with previously sanctioned exchanges Grinex and Meer. Analysis shows funds from these three Kyrgyzstani exchanges converging on a single HTX deposit address that received more than $308 million. The broader sanctions package also targets Russian oil companies Zarubezhneft and INK Capital, bringing coverage to over 90% of Russia’s total oil production capacity, alongside twelve shadow fleet tankers and entities involved in missile and drone supply chains.
The designation of Cryptomus and Heleket underscores a critical shift in how regulators view ostensibly legitimate payment processors. By demonstrating that these services facilitated more illicit volume than dedicated mixers, authorities highlight the operational risk posed by platforms with minimal identity verification. This challenges the assumption that only purpose-built obfuscation tools pose significant threats, suggesting instead that lax compliance standards in mainstream crypto infrastructure can rival or exceed the concealment capabilities of specialized illicit services.
The connection between TokenSpot and the A7A5 network reveals the persistent adaptability of sanctions-evasion mechanisms within specific jurisdictions. As established channels like Garantex face disruption, actors migrate to alternative providers, creating a whack-a-mole dynamic for enforcement agencies. The convergence of funds from multiple Kyrgyzstani exchanges into a single destination monitored by Chainalysis illustrates the need for cross-border intelligence sharing. Future regulatory efforts will likely focus on dismantling these interconnected networks rather than targeting isolated entities, emphasizing the importance of tracking fund flows through intermediary wallets and shared infrastructure.


