The U.S. Treasury has designated the A7 Network as a significant transnational criminal organization while exposing a sprawling payments network connecting Russian sanctions evasion, Iranian financial activity, the Nobitex crypto exchange, the ruble-backed A7A5 token and transactions related to North Korean cryptocurrency-exchange hacks.
The Oct. 1 action combines sanctions from the Office of Foreign Assets Control with a separate Financial Crimes Enforcement Network effort aimed at restricting A7’s access to the wider financial system.
According to the U.S. Treasury’s Operation Economic Outcast action, FinCEN identified more than $17 billion in transactions processed globally by A7 Network sub-agents between January 2025 and June 2026.
Those sub-agents are companies positioned in third-country jurisdictions that Treasury says were built to receive and transmit payments on behalf of the network while making sanctioned or illicit transactions appear to be ordinary commercial activity.
A7 allegedly used falsified trade documentation, misleading descriptions of goods and networks of intermediary companies to disguise the real parties behind payments. Treasury says the infrastructure has been used by Russian interests, Iran’s Central Bank and Islamic Revolutionary Guard Corps, Iranian sanctions-evasion networks, ransomware actors and other illicit-finance participants.
A7’s Own Claims Point to a Much Larger Payment Network
The $17 billion identified by FinCEN is not an estimate of A7’s entire transaction volume.
Treasury says A7 itself claimed that by January 2026 it was processing more than 2,000 transactions per day with total transaction volume exceeding 7.5 trillion rubles, equivalent to approximately $91.5 billion. Treasury said that amount was equal to roughly 13% of Russia’s 2025 foreign trade transactions.
The difference matters. FinCEN’s $17 billion number represents transactions its investigation identified through A7 sub-agents over a defined period. The $91.5 billion figure is A7’s own claim about the broader network and should therefore not be treated as an independently verified Treasury estimate.
The structure resembles a parallel payments network more than a conventional crypto operation. Companies, bank accounts, trade documents and digital assets all appear to serve the same purpose: getting value between parties that may struggle to use ordinary international financial channels.
Treasury Connects A7 to Iran’s Nobitex Exchange
The cryptocurrency component becomes more significant through Nobitex.
Treasury explicitly says the A7 Network has been linked to Nobitex, which the agency describes as Iran’s largest digital-asset exchange. OFAC separately designated Nobitex on June 2.
At the time of that earlier action, Treasury said Nobitex processed more than half of all Iranian digital-asset inflows during 2025 and had facilitated transactions connected with the IRGC, including wallets associated with IRGC-affiliated ransomware actors. Treasury also accused the exchange of enabling Iranian regime insiders to reach international digital-asset markets and move value across jurisdictions.
The Oct. 1 action expands the picture beyond the exchange itself. Rather than viewing Nobitex as an isolated venue, Treasury is placing it within a wider financial ecosystem where crypto platforms, trading companies, payment intermediaries and sanctioned entities can potentially connect with one another.
A7 Also Handled Transactions Related to North Korean Exchange Hacks
Treasury added another important crypto connection: the A7 Network facilitated transactions related to North Korean hacks of cryptocurrency exchanges.
The agency did not identify which exchange hacks were involved in the Oct. 1 announcement, nor did it say Nobitex itself processed the North Korean hack proceeds. The claims are separate: Treasury says A7 is linked to Nobitex and that A7 also facilitated transactions related to North Korean crypto-exchange hacks.
That distinction is important because North Korean laundering networks have become increasingly sophisticated at moving stolen assets between blockchains, exchanges, cross-chain protocols and other financial infrastructure.
The issue has become particularly visible following recent exchange breaches. Dave Finances examined how the Bitget hack forced THORChain and NEAR Intents into very different approaches to handling stolen funds, illustrating how compliance controls can vary dramatically depending on who actually controls the infrastructure.
A7A5 Turns a Ruble-Backed Token Into Sanctions Infrastructure
A7A5 creates another bridge between traditional sanctions evasion and blockchain settlement.
The ruble-backed token is issued by Old Vector LLC, which OFAC sanctioned in August 2025 over its involvement with A7 and the sanctioned crypto-exchange ecosystem surrounding Garantex.
Treasury now explicitly describes A7A5 as blocked property. It says the token was created so A7 members could transact internationally and evade sanctions while also generating revenue for sanctioned infrastructure providers benefiting from its circulation.
That makes A7A5 fundamentally different from much of the regulated stablecoin infrastructure being built around payments and banking. The technology can look superficially similar—digitized value designed for blockchain settlement—but the regulatory and institutional structure behind the asset determines whether it becomes compliant financial infrastructure or a sanctions risk.
OFAC Sanctions and FinCEN’s Proposed Rule Work in Different Ways
The Oct. 1 action contains two regulatory mechanisms that should not be confused.
OFAC’s designation immediately blocks property and interests in property belonging to the A7 Network that are in the United States or under the possession or control of U.S. persons. Entities owned 50% or more by blocked persons can also become blocked under OFAC rules.
Unless an exemption or authorization applies, U.S. persons are generally prohibited from conducting transactions involving blocked property.
FinCEN, meanwhile, proposed a separate rule that would prohibit covered financial institutions from transmitting funds involving A7 Network sub-agents. The proposal remains subject to the regulatory process and a public-comment period rather than operating as a final rule immediately.
FinCEN also issued an alert containing indicators designed to help financial institutions identify A7-related activity and file suspicious activity reports.
The Real Story Is the Convergence of Crypto and Shadow Banking
The most important part of Treasury’s action is not that cryptocurrency appeared in another sanctions case.
It is how little separation now exists between digital-asset laundering and traditional shadow banking.
A7’s infrastructure allegedly uses shell companies, bank accounts, fabricated trade documents and disguised commercial payments. At the same time, the same broader network touches a crypto exchange, a ruble-backed blockchain token and transactions linked to stolen cryptocurrency.
That combination makes the old distinction between “crypto crime” and conventional financial crime increasingly artificial.
A sanctioned actor no longer has to choose between a bank transfer and a blockchain transaction. It can move between them. A company can receive conventional currency, disguise the commercial purpose, route value through another jurisdiction and potentially settle part of the transaction through digital assets.
For compliance departments, that means screening wallet addresses alone is not enough. Banks, exchanges and payment companies increasingly need to understand corporate ownership, trading counterparties, intermediary companies and blockchain activity as parts of the same transaction network.
Crypto’s Transparency Helps—but Only at Certain Points
Digital assets create an unusual enforcement trade-off.
Public blockchains can give investigators visibility that would be impossible with cash or opaque offshore accounts. Once an address is identified, historical transfers can often be reconstructed and counterparties mapped.
That capability has already enabled private-sector intervention at significant scale. Tether, TRON and TRM Labs have reported freezing more than $450 million in crypto connected to illicit activity, including funds associated with exchange breaches and North Korea-linked laundering operations.
But transparency does not mean every transaction can be stopped.
Attackers and sanctions-evasion networks can move between chains, use intermediaries, transact through less regulated venues or convert assets into forms where no centralized issuer has the ability to freeze a balance.
A7 appears important precisely because it allegedly provided those connective layers rather than relying on one payment method.
A7A5 Shows Why Token Issuers Are Becoming Compliance Gatekeepers
The A7A5 designation may have implications beyond this specific sanctions action.
Tokens used for payments are increasingly becoming part of real financial infrastructure. Once they reach meaningful scale, regulators care not only about the underlying blockchain but also about who issues the asset, what backs it, who controls redemption and which entities profit from its circulation.
That means the issuer can become as important as the token contract.
In the case of A7A5, Treasury’s position is straightforward: because the token is issued by sanctioned Old Vector and is part of A7’s infrastructure, the token itself represents blocked property.
That creates a compliance problem for any service that encounters it. A crypto exchange or payment provider cannot safely treat every ruble-backed token simply as another digital asset with a market price. The identity and sanctions status of the issuer can determine whether touching the token creates legal exposure.
The $17 Billion Figure Shows the Scale of the Compliance Challenge
The broader lesson from the A7 action is scale.
FinCEN did not uncover a handful of suspicious wallet transfers. It says A7 sub-agents processed more than $17 billion during an 18-month period, while A7 itself claimed activity many times larger.
Networks operating at that level can blend into legitimate trade because they have enough corporate entities, accounts, counterparties and transaction volume to create convincing commercial cover.
That makes enforcement increasingly dependent on connecting information that traditionally lived in separate departments: trade finance records, corporate registries, bank wires, exchange accounts and blockchain analytics.
Treasury’s Oct. 1 action effectively treats those layers as one financial network.
For crypto exchanges, stablecoin issuers and payment firms, that is probably the most important takeaway. Sanctions exposure is no longer limited to checking whether a customer’s name appears on a blacklist or whether a wallet is directly associated with a sanctioned entity.
The harder problem is identifying when apparently ordinary transactions are passing through infrastructure built specifically to make sanctioned money look ordinary.
Johan Shamshad is a financial markets writer at Dave Finances covering cryptocurrencies, trading platforms, brokers, fintech, financial regulation, and developments across global markets. He previously worked at Gulf News, adding newsroom experience to his coverage of fast-moving financial and digital-asset markets.
His work focuses on identifying market-moving events, company developments, regulatory changes, product launches, and shifts in trading and financial infrastructure.
Johan contributes news and analysis designed to help readers understand not only what happened, but why a development matters and how it may affect the wider financial landscape.

