The Shadow States: How Iran, Russia, and North Korea Turned Cryptocurrency Into the Infrastructure of Sanctions Evasion

The Shadow States: How Iran, Russia, and North Korea Turned Cryptocurrency Into the Infrastructure of Sanctions Evasion

2026-08-18

Iran charges tankers a bitcoin toll for passing the Strait of Hormuz, and gives their captains a few seconds to pay. North Korea robs an exchange of a billion and a half dollars in a single operation. Russia designs a stablecoin of its own, deliberately built without a freeze function. Evading sanctions with cryptocurrency has stopped being money laundering; it has become the construction of a parallel financial system. This piece picks up where our analysis of a Warsaw company inside the Shelbit network left off, this time on a global scale.

Robert Nogacki, attorney (radca prawny) · Warsaw, August 18, 2026

 

A Few Seconds to Pay: The Scale of Crypto Sanctions Evasion

In the spring of 2026, in the brittle ceasefire that followed February’s strikes on Iran, the captains of tankers approaching the Strait of Hormuz began receiving unusual instructions. A ship was to declare its cargo to the Iranian authorities by e-mail, wait for an assessment, and then, as the Financial Times reported, quoting a spokesman for Iran’s oil exporters’ union, it received “a few seconds to pay in bitcoin, so that the fee could not be traced or confiscated because of sanctions.” The rate: about a dollar a barrel, or nearly two million dollars for a loaded supertanker; empty vessels passed free. According to an analysis by Chainalysis, an informal toll had been collected since March by a middleman tied to the Islamic Revolutionary Guard Corps, accepting yuan and stablecoins, and enforcement remained irregular. The design itself, though, is the message: a state made cryptocurrency an official instrument of customs policy, chosen precisely because it eludes seizure.

That scene compresses the subject of this piece. For sanctioned states, cryptocurrencies have stopped being a tool of improvised money laundering and have become the infrastructure through which they trade, arm themselves, and finance their allies. The scale can be counted. Chainalysis, in its report on 2025, calculated that the value received by sanctioned entities rose 694 per cent in a single year, to a hundred and four billion dollars, and that this surge drove total illicit crypto flows to a record hundred and fifty-four billion. Two-thirds of the world’s cryptocurrency crime is now, to put it plainly, the business of states and their clients.

The diagnosis deserves a frame before the case studies. Regimes do not reach for cryptocurrency because it is anonymous; for the most part it is not, and a public blockchain is the most durably documented ledger ever devised. They reach for it because it is stateless. A dollar wire sooner or later passes through a correspondent bank in New York, where it can be stopped; a transaction in bitcoin, or in a stablecoin on the Tron network, has no such choke point. Three states drew three different conclusions from that difference, and the three answers map the problem.

 

North Korea: Theft as a Line Item

Begin with the purest case. For Pyongyang, cryptocurrency is not a way around trade sanctions; it is direct revenue, acquired by theft. On February 21, 2025, hackers drained about $1.46 billion in Ether from the exchange Bybit, the largest single cryptocurrency theft on record. Five days later, the F.B.I. attributed the operation to a group it tracks as TraderTraitor, better known as Lazarus and answerable to North Korean intelligence. The anatomy of the breach is instructive: the attackers did not crack the exchange. They compromised a developer’s machine at Safe, the supplier of Bybit’s multi-signature wallet, and injected a malicious script into its cloud infrastructure. The executives who believed they were approving a routine transfer from cold storage to a hot wallet were in fact signing funds over to Lazarus addresses. It was an attack on the software supply chain, not on cryptography.

What happened next is more interesting still. Between February 24 and March 2, the stolen Ether poured through THORChain, a decentralized swap protocol, and came out the other side as bitcoin; the volume exceeded a billion dollars in two days, and analysts at Elliptic counted more than eleven thousand intermediary addresses. Investigators call the technique flooding the zone: thousands of near-simultaneous transactions overwhelm the compliance systems trying to keep pace. When a proposal to block the North Korean funds failed, over the objections of THORChain’s node operators, one of the protocol’s lead developers quit. An architecture conceived as a guarantee of transactional freedom turned out to be a guarantee of impunity; according to TRM Labs, the same protocol laundered proceeds from this year’s raids on Drift and KelpDAO, from which North Korea took $577 million, and by April the country accounted for 76 per cent of the value of all cryptocurrency thefts worldwide. The share has climbed without interruption: 22 per cent in 2022, then 37, then 39, then 64. The final stage of the laundering, meanwhile, is handled mostly by Chinese brokers, evidence that a specialized supply chain has grown up around the stealing.

Hacks are only one of two streams. The second is quieter: an army of North Korean I.T. workers who, under stolen identities, take remote jobs at Western companies. In June, 2025, the Justice Department described raids on twenty-nine so-called laptop farms in sixteen states; facilitators took delivery of the company laptops of fictitious employees and kept the machines running, so that someone logging in from Asia appeared to be working from Phoenix. The salary itself is the loot: by figures cited in American filings, close to $800 million flowed to Pyongyang this way in 2024, paid out mostly in stablecoins. On July 31, 2026, eleven countries issued a joint alert, the first with France, Germany, Italy, and the Netherlands among the signatories, warning, among other things, of real-time deepfakes deployed in job interviews. Since 2017, North Korea has stolen more than six billion dollars in cryptocurrency, over two billion of it in 2025 alone. This is not the margin of cybercrime. It is a line item in a national budget.

 

Iran: Energy Into Bits, an Exchange Into an Organ of the State

Iran chose the opposite road: it does not steal what belongs to others; it processes what it owns. If sanctions block the export of oil and gas, the energy can be burned at home for electricity, the electricity can feed Bitcoin mines, and the mined coins can be sold on a global market that does not show their provenance. Tehran legalized mining in 2019 and required licensed operators to sell their output to the central bank; Elliptic estimated as early as 2021 that the power consumed by Iranian mines was equivalent to about ten million barrels of oil a year, and in various years the country’s share of the Bitcoin network’s computing power was put at between two and five per cent.

An ecosystem grew around the mechanism, one that Chainalysis valued at $7.78 billion for 2025; addresses linked to the Revolutionary Guard and its networks accounted for more than half of the incoming value in the fourth quarter, and more than three billion dollars moved through them across the year. The heart of the system was an exchange called Nobitex: more than half of all Iranian crypto inflows in 2025, some eleven million users, at its peak nearly 70 per cent of the country’s activity in digital assets. Elliptic tied its infrastructure to Guard-linked operators, to wallets attributed to Hamas, Palestinian Islamic Jihad, and the Houthis, and to Russia’s Garantex and to North Korean groups. The most telling finding arrived in January of this year: an Elliptic analysis showed that Iran’s own central bank had accumulated at least $507 million in the stablecoin USDT during 2025, bought for dirhams through intermediaries and routed mainly onto Nobitex, most likely to buy rials in support of the currency and to settle imports. Elliptic called it the construction of “off-book eurodollar accounts” beyond the reach of American authorities. As a defense it had its limits (after United Nations sanctions snapped back in the fall of 2025, the rial touched 1.4 million to the dollar), but the direction of travel says everything: a central bank conducting open-market operations in someone else’s privately issued token is a picture the history of finance had not previously supplied.

War and law struck this architecture in turn. On June 18, 2025, in the middle of the twelve-day war between Israel and Iran, a pro-Israel group called Predatory Sparrow pulled more than ninety million dollars out of Nobitex and, as Elliptic established, burned it on purpose, sending the funds to vanity addresses spelling out obscenities aimed at the Guard (on the Tron network, one began TKFuckiRGCTerrorists). No private keys exist for such addresses, so the money became irretrievable: not robbery but a public execution of an enemy’s assets, recorded forever in a ledger no one can amend. The day before, the same group had paralyzed the state-owned Bank Sepah; the day after, it published the exchange’s source code. A year later, the regulatory front closed in: on June 2, 2026, OFAC sanctioned Nobitex along with the exchanges Wallex, Bitpin, and Ramzinex, and four of their managers, under Executive Orders 13224 and 13902, warning outright, in an accompanying interpretation, FAQ 1257, that foreign financial institutions servicing these platforms face secondary sanctions. Nor did the Treasury hide the connection to the Strait of Hormuz: the designations were meant, among other things, to complicate the collection of tolls from shipowners. The Polish thread of the same wave, a Warsaw company on the register of virtual-asset service providers, designated on August 7 as part of the Shelbit network laundering for the Guard, has an analysis of its own, and there is no need to retell it here. Its moral, though, belongs to this puzzle: Iran’s shadow economy shops for credibility wherever credibility is cheap.

 

Russia: From Garantex to the Ruble Stablecoin A7A5, and Then a Statute

If North Korea steals and Iran processes, Russia institutionalizes. The starting point was the fall of Garantex, an exchange that, by the State Department’s count, processed about $96 billion between April, 2019, and March, 2025; TRM Labs linked 82 per cent of that volume to sanctioned entities, ransomware, and darknet markets. On March 6, 2025, a coördinated operation by the U.S. Secret Service and German and Finnish authorities seized the exchange’s domains; more than $26 million was frozen, and one of the administrators was arrested in India. Set against the volume, the frozen sum was a rounding error, and the sequel became a lesson in the resilience of such structures: within days, Telegram channels were advertising a twin exchange, Grinex, which, as TRM Labs established, had been registered in Kyrgyzstan back in December, 2024, months before the takedown. The contingency plan was waiting before the first blow landed.

Russian infrastructure drew a technical lesson from the Garantex story as well: if the issuer of a centralized stablecoin can freeze funds with a single command in a smart contract, one needs a token that has no such function. That is A7A5, a ruble-pegged stablecoin issued out of Kyrgyzstan by a company called Old Vector and backed, analysts have found, by deposits at Promsvyazbank, the sanctioned bank of the Russian defense sector. A7A5 was designed without a freeze mechanism, and the result exceeded expectations: according to Chainalysis, the token settled $93.3 billion in under a year, with flows concentrated on weekdays, the signature of business-to-business settlement rather than retail speculation. A purpose-built system for clearing trade had come into being, out of reach of Western blocks. The sequel has the flavor of a spy novel: in April of this year, Grinex was itself attacked, lost the equivalent of about $13.7 million, and suspended operations, blaming “the special services of unfriendly states”; on-chain analysis by Chainalysis undercuts that version, because the perpetrator swapped the stablecoins into TRX at speed through a decentralized exchange that Garantex itself had once used, whereas Western authorities freeze funds rather than liquidate them.

The crowning stage of the evolution is a statute. In early August, Vladimir Putin signed Russia’s first comprehensive federal law on digital currencies, No. 282-FZ, effective September 1. Its construction is pragmatism set into paragraphs: inside the country, cryptocurrencies still may not be used for payment, but Russian firms engaged in foreign trade may lawfully settle their contracts in digital assets. The wall for the citizen stands (an annual limit of three hundred thousand rubles for the retail investor, a knowledge test, a ban on privacy coins); the window for the exporter is open wide; and the whole apparatus of central-bank licensing serves to legalize a channel around the dollar system. A draft directive of the central bank, dated August 11, completes the paradox: it would admit Tether to trading on licensed exchanges alongside Bitcoin and Ether, even as Russian officials themselves conceded that USDT’s issuer can freeze the wallet of any licensed Russian exchange within seconds, with no Russian court order required. Russia has thus built a two-track system: A7A5 as the freeze-proof channel for the most sensitive settlements, and a legal market for everything else, the risk accepted with eyes open.

 

Stablecoins: The Common Denominator, and the Only Pressure Point

Three states, three strategies, one shared piece of engineering. By Chainalysis’s count, stablecoins now account for 84 per cent of all illicit crypto volume, because they combine the statelessness and speed of cryptocurrency with a stability of value that Bitcoin does not offer; nobody wants to settle an oil contract in an asset that can shed ten per cent in a day. And precisely here lies the only real pressure point: the most popular stablecoins are centrally issued, and the issuer can freeze any address. Hence the regimes either build tokens of their own stripped of that function, as with A7A5, or play cat and mouse, in which the authority freezes and the funds scatter to fresh addresses.

The game unfolds amid a legal uncertainty best illustrated by the American saga of Tornado Cash, a mixer that Lazarus, among others, made use of. In August, 2022, OFAC put the protocol itself on the sanctions list; in November, 2024, the Fifth Circuit held, in Van Loon v. Department of the Treasury, that immutable smart contracts are not “property” within the meaning of the International Emergency Economic Powers Act, since after deployment no one controls them, and that OFAC had exceeded its authority; in March, 2025, the protocol came off the list. A criminal branch runs in parallel: on August 6, 2025, a jury found Roman Storm, one of the protocol’s creators, guilty of conspiring to run an unlicensed money-transmitting business while hanging on the counts of money laundering and sanctions violations, and in March of this year prosecutors moved for a retrial on those two counts, proposing October, 2026, and keeping Storm exposed to an additional forty years. The savor of the case lies in the timing: that same March, the Treasury conceded, in a report to Congress, that mixers can serve the lawful protection of financial privacy. The boundary, for now, runs like this: people and entities may be sanctioned; autonomous code requires an explicit statutory footing; and a person’s liability for code he no longer controls remains an open question. For anyone who writes financial software, that is a live boundary of professional risk.

 

Europe Responds: From Naming Names to Banning Categories

The European Union drew a systemic conclusion from Garantex and Grinex, and it bears noting, because it ties the global picture directly to the obligations of companies in Poland. The nineteenth sanctions package, of October 23, 2025, was the first in history to ban transactions in a specific crypto-asset: A7A5 entered Annex LIII of Regulation 833/2014, with all transactions prohibited from November 25, 2025, alongside a ban on providing crypto-asset services, within the meaning of MiCA, the E.U.’s Markets in Crypto-Assets Regulation, to Russian persons. The twentieth package, adopted on April 23, 2026, and effective May 24, went a step further: rather than name the next platforms, it prohibited all transactions with any crypto-asset service provider established in Russia or Belarus, decentralized platforms included, and added the stablecoin RUBx and the digital ruble to the list of banned assets. The Council’s reasoning was plain: point designations breed successors, so ban the category. It is exactly the lesson Grinex taught the world in four days.

For a business in Poland, the frame is therefore three layers deep. The E.U. regulations (269/2014 and 833/2014) apply directly, and crypto-assets fall within the funds and economic resources that must not be made available to listed parties. The domestic layer is the Polish act of April 13, 2022, on special measures counteracting support for the aggression against Ukraine (ustawa o szczególnych rozwiązaniach w zakresie przeciwdziałania wspieraniu agresji na Ukrainę), which provides administrative fines of up to twenty million złotys, roughly five million dollars, and criminal liability starting at three years’ imprisonment; the deadline for transposing Directive 2024/1226, which harmonizes the criminalization of sanctions violations across the Union, passed on May 20, 2025. The third layer is American extraterritoriality, with its fifty-per-cent rule and its secondary sanctions, whose mechanics we described in the Shelbit case. The Polish peculiarity is that, under so dense a mesh of prohibitions, the crypto-asset market still has no domestic steward: after a third presidential veto of the crypto-assets act and the expiry, on July 1, 2026, of the transition period under Article 143(3) of MiCA, the only ticket into the market is a CASP license that, in Poland, no one is currently in a position to issue. The prohibitions run; the supervision does not. It is the configuration in which mistakes come easiest.

 

What Follows for Companies

Three conclusions emerge from this panorama. First: sanctioning a single entity is necessary and structurally late, because a well-designed evasion infrastructure has its successor ready before the predecessor falls; the E.U. has admitted as much by moving to sectoral bans, and the real choke points lie where relocation is impossible, with the stablecoin issuers capable of freezing, on the bridges between chains, and at the ramps where cryptocurrency meets traditional money.

Second: the technology is ambivalent toward sanctions, and that is its most interesting property. The same blockchain that gives regimes statelessness gives investigators a permanent, undeniable record. Half a billion dollars of Iran’s central bank traced across public addresses; eleven thousand wallets mapped after the Bybit heist; the weekday rhythm that betrayed A7A5’s commercial character: these are exhibits that traditional laundering through shell companies never left behind. The blockchain is at once the best tool for evading sanctions and the best tool for enforcing them; the question is which side reads the same ledger faster.

Third, practically: neutrality does not exist. The Shelbit case showed that a Polish registry entry can end up inside a network financing the Revolutionary Guard, and that the same Warsaw address had earlier served a Cambodian laundry with North Korean clients. For compliance teams, this means at least four things: verifying counterparties by their registry identifiers, not by trade names alone; analyzing the on-chain origin of funds before accepting payment in crypto-assets, because the taint of a transaction chain runs backward; applying, rigorously, the travel rule of Regulation 2023/1113; and preparing for the banks, which terminate crypto accounts faster than legislatures write rules. In the age of stateless money, the choice is not between oversight and its absence but between oversight of one’s own choosing and someone else’s.

Kancelaria Prawna Skarbiec advises crypto-asset businesses on CASP licensing and MiCA implementation, conducts sanctions screening of counterparties and of on-chain exposure, and represents victims in cryptocurrency fraud cases. If your company accepts payment in crypto-assets or works with counterparties from high-risk jurisdictions, that exposure is worth examining before a bank, or a foreign regulator, examines it for you.

The law and the facts are stated as of August 18, 2026.

 

Further Reading (in Polish)

Blockchain remembers everything

Regulation Without Recourse: Poland’s Third Crypto-Assets Veto and the Anatomy of a Self-Inflicted Regulatory Vacuum

The Second Laundromat on Bartycka Street. How a Shell Company With $1,400 in Capital Landed on America’s Terrorism Sanctions List