This website uses cookies
We use cookies to personalise content and ads, to provide social media features and to analyse our traffic. We also share information about your use of our site with our social media, advertising and analytics partners who may combine it with other information that you’ve provided to them or that they’ve collected from your use of their services.
Consent Selection
Details
  • Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
  • Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
    • We do not use cookies of this type.

  • Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
    • We do not use cookies of this type.

  • Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.
    • We do not use cookies of this type.

  • Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    • __emg_sidPending
      Maximum Storage Duration: 1 dayType: HTTP Cookie
      __emg_vidPending
      Maximum Storage Duration: 1 yearType: HTTP Cookie
      nl-read-countPending
      Maximum Storage Duration: PersistentType: HTML Local Storage
Cookie declaration last updated on 8/12/26 by Cookiebot
[#IABV2_TITLE#]
[#IABV2_BODY_INTRO#]
[#IABV2_BODY_LEGITIMATE_INTEREST_INTRO#]
[#IABV2_BODY_PREFERENCE_INTRO#]
[#IABV2_BODY_PURPOSES_INTRO#]
[#IABV2_BODY_PURPOSES#]
[#IABV2_BODY_FEATURES_INTRO#]
[#IABV2_BODY_FEATURES#]
[#IABV2_BODY_PARTNERS_INTRO#]
[#IABV2_BODY_PARTNERS#]
About
Cookies are small text files that can be used by websites to make a user's experience more efficient.

The law states that we can store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies we need your permission.

This site uses different types of cookies. Some cookies are placed by third party services that appear on our pages.

You can at any time change or withdraw your consent from the Cookie Declaration on our website.

Learn more about who we are, how you can contact us and how we process personal data in our Privacy Policy.

Please state your consent ID and date when you contact us regarding your consent.
NewsLayer.com
NewsLayer PulseLIVEBTC$63,838+1.21%ETH$1,904+1.13%SOL$75.83+0.45%XRP$1+0.09%DOGE$0.0703+0.44%ADA$0.1742-1.40%Total Cap$2.29T+0.84%Layer Index44 Neutral
External Reporting发布于 13 小时前

How Sanctions and Risk Scoring Can Turn Clean Crypto “Dirty”

Imagine this: it's 2024 and you move some USDT onto HTX, buy ETH, and a month later withdraw everything back to your own wallet. Sounds Clean, you passed KYC, compliance silent and you forget the whole thing ever happened.

How Sanctions and Risk Scoring Can Turn Clean Crypto “Dirty”
Publisher HackerNoon 7 分钟阅读
Image via HackerNoon

Regulation Context

Track live crypto policy developments across jurisdictions.

Market Context

Ethereum

ETH

$1,904

+1.13% 24h

Layer Index

44

↑ 2 pts in 24h

Imagine this: it's 2024 and you move some USDT onto HTX, buy ETH, and a month later withdraw everything back to your own wallet. Sounds Clean, you passed KYC, compliance silent and you forget the whole thing ever happened.

Fast-forward eighteen months to the summer of 2026. You try to deposit those very same coins onto a European exchange and get rejected. Deposit frozen, account under manual review, support asking you to "explain the source of funds". You did nothing wrong and you'd honestly forgotten that transaction existed.

Welcome to the world of retroactive toxicity, arguably the most underrated risk in crypto. Sanctions move forward in time; blockchain analytics moves backward. When those two vectors collide, it isn't only the sanctioned platform that bleeds. It's the perfectly ordinary users who once simply passed through.

What actually happened to HTX

On May 26, 2026, United Kingdom published an updated sanctions list under its Russia-related package (18 new entries in one shot: EXMO, Bitpapa, ABCEX, Aifory, Rapira, and a string of affiliated entities). But the headline name was Huobi Global S.A., the Panama-based company behind the HTX exchange.

For the first time, direct UK restrictions landed on one of the largest exchanges on earth. For scale: in its own 2025 recap report, HTX claimed ~$3.3 trillion in annual trading volume (up ~39% year over year) and more than 55 million registered users by year-end.

The regulator's allegation: HTX allegedly served as a conduit for funds tied to Russian networks (specifically the A7 network and the exchange Garantex) sending over $1.5 billion into Russia. Swiss analytics firm Global Ledger estimated that ~$21 billion in high-risk flows passed through HTX between 2021 and May 2026, which is around $7.6 billion of it linked to Russian high-risk entities and darknet markets.

HTX denies all of it and its position is simple: the sanctioned legal shell, Huobi Global S.A., is not the HTX platform its customers use, so the designation shouldn't touch day-to-day operations.

Bybit almost immediately warned customers that any HTX-linked deposits or withdrawals could trigger additional AML and compliance checks, and advised users to avoid HTX-associated wallets. More than $100 million in HTX-controlled USDT came under scrutiny and Tether has frozen stablecoins on flagged addresses before.

The mechanics: why "clean then" ≠ "clean now"

To understand the danger, you have to understand how modern crypto compliance actually works.

Blockchain analytics firms (Chainalysis, Elliptic, TRM Labs, Global Ledger, Scorechain, and dozens more) turn the public but pseudonymous ledger into a map of real-world entities. It works in layers:

  • Clustering: Heuristic methods combine thousands of addresses into a single "cluster" belonging to a single object. Could be an exchange, a mixer, a darknet market.
  • Attribution: Each cluster gets a label: "HTX", "Garantex", "ransomware", "sanctioned address". Databases now hold over a billion labeled entities.
  • Taint/risk scoring: Every coin gets a "taint", like the percentage of funds traceable to a known illicit source. The most common approach is the haircut method: if a transaction's input has between 1 "dirty" BTC and 9 "clean" BTC, then all outputs inherit 10% pollution. Each hop dilutes the taint but never eliminates it.
  • Direct vs. indirect exposure: Direct exposure (funds received one hop from a flagged address) usually triggers immediate action. Indirect exposure (funds that passed through intermediaries) is weighed by number of hops, velocity, and other signals.
How an Ordinary User Goes Toxic

When a platform is added to a sanctions list, analytics providers update the cluster's label and some systems retroactively re-label historical data. A transaction that was spotless at the moment it executed gets reclassified, after the fact, as linked to a sanctioned entity. Your dormant address suddenly turns "red" with zero action on your part.

The blockchain never forgets and that was always its beauty and the trap at the same time. The ledger is immutable, but the labels layered on top of it are not.

Precedent #1: Tornado Cash — toxicity that outlived the sanctions themselves

On August 8, 2022, OFAC added Tornado Cash to the SDN list, the first time sanctions targeted not a person or company but a decentralized on-chain protocol, a set of smart contracts. The mixer was allegedly used by North Korea's Lazarus Group.

People who had interacted with Tornado Cash months or years before the sanctions (for privacy, which is legal in itself) found their addresses flagged. Some received unsolicited "dusting" from the sanctioned contract and were made toxic entirely against their will.

On November 26, 2024, the U.S. Court of Appeals for the Fifth Circuit ruled in Van Loon v. Treasury that immutable smart contracts are not "property" under IEEPA (meaning OFAC had overstepped its statutory authority). On March 21, 2025, the U.S. Treasury formally removed Tornado Cash from the SDN list, though it framed the move as its own discretionary choice rather than compliance with the court.

You'd think: rehabilitation. But here's the main point as delisting removes the legal prohibition, but it does not erase the taint. Labels, once they've spread through compliance pipelines, take on a life of their own. Many platforms keep flagging addresses with a mixer-interaction history anyway.

Formally the protocol is clean. Practically, the residue lingers in the databases. (Note that criminal cases around the founders continued regardless, Roman Storm's trial proceeded, and co-founder Roman Semenov remains designated).

Even reversing sanctions doesn't guarantee your history gets cleaned.

Precedent #2: Garantex — the platform vanishes, the trail stays

Garantex was a Russian exchange favored, according to analysts, by ransomware crews and sanctions evaders. The U.S. designated it back in April 2022; the EU followed in February 2025.

On March 6, 2025, the reckoning arrived: a coordinated international operation (the U.S. Secret Service plus German and Finnish authorities) seized domains and servers, and Tether froze ~$28 million in USDT. By some estimates Garantex processed around $96 billion since 2019, and TRM Labs attributed to it up to 82% of all crypto volume tied to sanctioned entities worldwide.

The moment the platform was shut down, its addresses became radioactive retroactively. Anyone who had ever withdrawn through Garantex, or received coins that had passed through its cluster, inherited the taint.

The Pattern of Retroactive Toxicity

Garantex's operators, meanwhile, knew exactly how analytics works: they constantly rotated hot wallets (first quarterly, then weekly, eventually daily) and routed flows through Asian exchanges like HTX and OKX to sever the link. Less than two weeks later, the platform resurfaced as Grinex (registered in Kyrgyzstan back in December 2024), meaning the contingency plan for a seizure had been prepped in advance, dragging along customer balances and a new ruble stablecoin, A7A5. In August 2025, the U.S. slapped sanctions on Grinex too.

Why this hits ordinary people hardest

Connect three facts and you'll see why the HTX story is more dangerous than it looks.

  1. Indirect exposure: You never needed an HTX account. It's enough that the coins you received (for freelance work, a sold NFT, a transfer from a friend) passed through the HTX cluster somewhere a couple of hops back in their history. At $3.3 trillion in volume and 55 million users, the odds of such a "touch" for any active crypto user are far from zero.
  2. There is no single standard: No industry consensus exists on how many hops to trace, what taint threshold is disqualifying, or which tainting method to use. One exchange will accept a deposit another rejects. Your "cleanliness" is a function of whose software, with which settings, is screening you.
  3. Labeling is fast and sticky: The UK's HTX designation propagated through compliance pipelines within hours. Flagging an address as risky is one automatic operation. Proving otherwise is weeks of correspondence, statements, and source-of-funds paperwork.
How “Haircut” Taint Works

You can become "toxic" retroactively, through no fault of your own, without warning and discover it only at the moment of rejection.

What to do about it (no panic, no financial advice)

I'm not a lawyer or a financial advisor, so what follows isn't advice, it's hygiene worth thinking through for yourself.

  • Check your addresses before, not after. Public and semi-public risk screeners (from Chainalysis, Elliptic, TRM, plus more accessible consumer tools) let you see your own exposure.
  • Keep your source-of-funds history: Screenshots, statements, contracts, TXIDs. Source-of-funds requests are getting more common, and the person with paperwork clears review while the person without it stalls.
  • Separate your flows: Don't mix funds with different histories in one wallet. A single hop to a toxic cluster can color your whole balance because of the haircut logic.
  • Be wary of "grey-zone" platforms: A live exchange today can be a sanctioned name tomorrow and your year-old transactions through it retroactively re-labeled the day after.
  • **Delisting ≠ cleaning:**The Tornado Cash case shows that even an official reversal doesn't guarantee your labels get lifted in private databases.

Conclusion

Crypto was sold to us as a system without retroactivity: what's written into a block is written forever, and no one rewrites the past. That's true about the transactions themselves but it is not true about their interpretation.

The real threat of 2026 is that someone will alter the label on top of it, after the fact, by their own formula, without your involvement and with no right of appeal. Tornado Cash and Garantex were the dress rehearsal on niche platforms. HTX, with its 55 million users, is a whole different order of magnitude.

Your old transactions didn't get dirtier but the world that reads them just changed its glasses.


突发新闻

Never miss a breaking story

Advertisement

House — Advertise on NewsLayer
NewsLayerAd

Protocols in this story · Live TVL · DeFiLlama

Sourced by

Originally reported by HackerNoon

NewsLayer coverage based on externally reported material.

The Daily Brief

The onchain economy, before your day starts.

Curated markets, onchain insights, and key headlines — delivered every weekday morning.

Weekdays · Free · ~5 minute read

相关报道