UK targets Xeltox Enterprises Ltd for operating Cryptomus and Heleket as linked sanctions evasion vehicles
The UK designated Cryptomus and Heleket as a single entity under parent company Xeltox Enterprises Ltd, blocking a proven sanctions evasion playbook in which Russian operators launch parallel services after regulatory pressure. For institutional crypto compliance teams, the move signals that rebranding or spinning off services no longer provides cover once regulators identify operational linkage.
- UK designated Xeltox Enterprises Ltd on October 8, 2026 for owning Cryptomus and operating Heleket as continuation vehicles for Russian financial services evasion.
- Heleket launched January 2025 after Cryptomus implemented mandatory KYC in February 2025, causing Cryptomus on-chain volume to drop from USD 153 million to USD 86 million by March.
- TRM Labs identified shared infrastructure, personnel, liquidity sourcing, and illicit actor migration patterns proving both brands operated as a single sanctions evasion apparatus.
- 38 Russia-related designations issued by UK on October 8, 2026, spanning oil companies, shadow fleet tankers, military suppliers, and financial channels
- USD 950 million transferred by TokenSpot to Grinex, Garantex, and A7 network, showing scale of parallel-service sanctions evasion networks
- CAD 177 million fine issued by Canadian FINTRAC to Xeltox in October 2025 for money laundering and terrorist financing violations
The UK Foreign, Commonwealth and Development Office designated Xeltox Enterprises Ltd on Thursday, October 8, 2026, consolidating Cryptomus, Heleket, and Certa Payments Ltd as a single sanctioned entity. The move closes a loophole that Russian operators have repeatedly exploited: launching nominally separate services to retain users who flee tightened compliance at the original platform. TRM Labs assessed with high confidence that Cryptomus and Heleket ran on shared infrastructure and served the same illicit user base, with on-chain and off-chain evidence showing the timing, personnel overlap, and transaction patterns of a coordinated sanctions evasion strategy.
Heleket launched to absorb users fleeing Cryptomus KYC controls
Cryptomus began mandatory Know Your Customer checks in February 2025, prompting an immediate user exodus and a sharp drop in on-chain transaction volume. TRM Labs reported that Cryptomus processed USD 153 million in on-chain volume during January 2025, but this fell to USD 86 million by March after KYC implementation. Heleket, which had launched in January 2025, saw its volume rise during the same window. TRM identified numerous cybercrime service vendors and sanctions-linked actors switching wallets from Cryptomus to Heleket.
TokenSpot designated as Grinex front, repeating Garantex-to-Grinex pattern
The UK also designated TokenSpot, a Kyrgyzstan-based exchange, after TRM Labs determined on October 6 that TokenSpot operated on shared wallet infrastructure with Grinex and functioned as a front company for the sanctioned exchange.
TokenSpot transferred over USD 950 million to Grinex, Garantex, and the A7 network, a Kremlin-backed sanctions evasion apparatus. Of that total, A7 received USD 679.5 million. The pattern echoes the Garantex-to-Grinex succession: Garantex was designated by the UK on May 4, 2022, went dormant, and Grinex emerged afterward as its operational successor.
The US Treasury sanctioned Grinex in August 2025, and the UK followed suit barely a week later.
A7 itself was recently sanctioned by the US government for assisting Iran evade financial restrictions.
Broader October 8 package targets Russian oil revenue and military supply chains
The 38 designations announced Thursday also targeted two Russian oil companies, 12 shadow fleet tankers, 17 entities and individuals supplying military goods to Russia, and additional payment processors and a Moscow bank with Russia linkage.
Tsunami Payments LLC and Processing KG, both registered in Kyrgyzstan, were designated alongside Processing KG’s director Ulan Bukabaev. Russian oil companies Zarubezhneft and INK-Capital, along with Moscow lender Stolichny Kredit, also faced designation under the Russia (Sanctions) (EU Exit) Regulations 2019.
A material question remains open: whether Xeltox Enterprises or its controllers have already prepared successor platforms for launch, and whether other payment processors or exchanges currently operating may share infrastructure patterns with Cryptomus or Heleket without yet being detected.
TRM advised compliance teams to screen both brand names, monitor for new services with similar operational signatures, and cross-reference TokenSpot exposure against Grinex exposure in their customer risk portfolios.
The CCS read. We see a regulatory enforcement playbook that has worked for two years but is now breaking: parallel-service succession worked for Garantex-to-Grinex and Cryptomus-to-Heleket, but the moment regulators can prove operational linkage, on-chain, infrastructure, and personnel, both entities face designation together. Crypto compliance teams must treat brand names as ephemeral and build controls around detected on-chain patterns and counterparty networks instead.
Institutional crypto service providers and derivatives exchanges should prepare now to screen updated designations: the FCDO updates the Russia sanctions list regularly, and new successor entities are expected. Compliance officers should also monitor whether Processing KG, Tsunami Payments, or other newly designated Kyrgyzstan-registered entities spawn parallel services in the coming months, repeating the pattern TRM has now documented twice in a single designation cycle.
Original reporting: cryptopolitan.com