General
How compliance teams screen stablecoin payments: lessons from A7A5
A sanctions designation sets the rule. The control is the screen that catches the exposure when a stablecoin payment arrives.

When a jurisdiction loses access to correspondent banking, new payment networks emerge to move money outside those channels. Since 2025, some of those networks have gone a step further by issuing their own stablecoins, giving them control over both the payment rail and the asset moving through it.
That creates a different screening problem. A company name can be checked against a sanctions list. A token cannot. It can reach you inside a transaction, several hops away from a sanctioned entity or address.
That is why bank partners and auditors increasingly ask how stablecoin payments are screened. A sanctions check performed only when a counterparty is onboarded cannot detect the exposure that appears later in a transaction.
The EU prohibited the token itself
In October 2025, the EU prohibited any direct or indirect transaction involving A7A5, effective 25 November 2025. The restriction applied to the token itself, as well as to entities connected to it.
That distinction matters. If the prohibited asset is A7A5, screening only the sender is not enough. You also need to identify what asset is moving through the transaction.
The EU extended the same approach in its 20th sanctions package, adopted on 23 April 2026, prohibiting transactions involving RUBx and the digital ruble from 24 May 2026.
Range helps regulated companies apply these requirements to transactions across stablecoins, digital assets and fiat. A company can turn its policies and regulatory obligations into controls that run against each transaction, while continuing to use the risk and compliance providers it already has.
Existing screening vendors connect to Range using the company's own API keys, so teams do not need to replace their current providers or workflows. Range brings their signals into the same counterparty and transaction record used for monitoring, reconciliation and reporting.
Screening and counterparty risk sit in Protect. The unified ledger they run against sits in Unify.
Who issued A7A5, and what it was built from
A7A5 launched in January 2025, issued by Old Vector LLC in Kyrgyzstan and operating on Ethereum and Tron.
The EU describes the token as backed by ruble deposits at Promsvyazbank, a sanctioned Russian state-owned bank that helped create A7, the payment network A7A5 was built to serve. A7 was established by Ilan Shor, who was convicted of fraud and money laundering in connection with the theft of roughly $1 billion from three Moldovan banks in 2014.
Range's data shows 12 addresses at the core of A7A5. They include contracts across two chains: a wrapped version and the contract it replaced; a reserve, treasury, execution manager, deployer; three individually labeled large holders; and Old Vector LLC.
The important part is the structure around the token. A7A5 expanded across chains, changed its token infrastructure and concentrated significant holdings across a small number of identifiable addresses.
For a compliance team, that means the risk cannot be reduced to a single issuer name or contract address. The asset sits within a broader network of contracts, holders and counterparties that must be traced at the transaction level.
The designations arrived after the flows
A7 LLC was designated by the UK in May 2025, the EU in July and OFAC in August, alongside entities including Old Vector and Grinex.
By then, the infrastructure around A7A5 was already changing. Garantex's domain had been seized in March 2025, and former users were credited with A7A5 through Grinex. Kyrgyz government records show Grinex had been incorporated in December 2024, months before the seizure.
The pattern repeated elsewhere. Several Russia-linked exchange services that absorbed similar flows were later added to sanctions lists.
That lag matters. A designation tells a company what is prohibited once the rule exists. It does not tell you what exposure entered your accounts before the designation arrived.
How sanctions reached the asset
In November 2025, Uniswap added A7A5 to its list of unsupported tokens and removed it from its interface.
That is an asset-level restriction: A7A5 itself became unsupported, regardless of the identity of a specific sender.
A7A5 also depended on its ability to move into dollar-backed stablecoins. The Wall Street Journal reported that the token was exchanged into assets such as USDT to pay for sanctioned goods. Users later reported that funds received after A7A5 swaps were being flagged or frozen by exchanges.
At the same time, other pressures were reducing activity. Russian authorities tightened access to bank-card purchases, no new A7A5 had been issued since July 2025 and major exchange access became more difficult.
For a compliance team, the relevant part is the sanctions exposure. That is the part a company can control by screening the transaction when it arrives.
What Range's data shows
Range's A7A5 label set shows why a sanctions list alone cannot provide complete visibility.
58 addresses now included in Range's A7A5 label set were already in our graph in October 2024, before any Western regulator had designated A7 or A7A5. Those addresses were part of 126 records created that month. By 17 August 2026, the label set had grown to 15,565 addresses. Of those, 229 were analyst-verified and 15,336 were derived from relationships in the transaction graph. Only 1,782 addresses carried a direct designation link. The remaining 13,783 did not.
That does not mean all 13,783 addresses are sanctioned or illicit. Most are graph-derived. What it shows is the visibility gap: a control based only on matching names or directly designated addresses cannot see the full network around an asset.
The same data shows value connected to the network moving through 28 third-party services, including 12 centralized exchanges and brokers and 16 DEX aggregators, routers, bridges and wallet infrastructure protocols.
Their presence does not make those services sanctioned or non-compliant. Public blockchain infrastructure is shared.
For the receiving company, the implication is different: judging only the address that sent the payment is not enough. You need to understand where the value came from across previous hops.
The activity moved beyond the blockchain
A7A5 activity fell sharply, but the wider A7 network continued to expand.
The Wall Street Journal reported that A7 opened offices in Nigeria and Zimbabwe. In July 2026, the EU designated A7 Nigeria, A7 Africa and PilotFinance Ltd.
Part of the network also operated outside blockchain rails.
The Open Source Centre identified entities across Kyrgyzstan, the UAE, Hong Kong, Hungary and Mongolia acting as payment vehicles and external treasuries for Russian customers.
It also identified software called Invoicer that altered supplier invoices by replacing the description of the underlying goods with ordinary items such as LED lights, shelving units and garbage bins.
One example involved Rustakt, a supplier of FPV drones to Russian military units that the EU designated in December 2024. The Open Source Centre found that an A7-linked Kyrgyz entity subsequently processed 21 bills of exchange worth RUB 1.3 billion, approximately $13.1 million.
The important point is not the individual payment method. It is that value can move between rails.
If a control covers only blockchain transactions, activity can move into fiat. If it covers only named bank counterparties, exposure can arrive through stablecoins.
What to check in your current stack
None of this requires Range. The A7A5 case gives finance, compliance and risk teams a practical set of controls to check against the systems they already use:
- Screen transactions on receipt as well as on send. An onboarding check cannot detect exposure introduced by a later payment.
- Trace provenance across hops. A payment can carry exposure even when the sending address itself is not designated.
- Screen the asset as well as the counterparty. A prohibited token has no company name to match against a list.
- Continuously re-screen existing counterparties. Sanctions can change months after a relationship begins.
- Keep stablecoin and fiat activity in one record. Exposure can move between rails.
Each control also needs an audit trail. An examiner will want to know how the exposure was identified, what rule triggered and what happened next.
Range's Protect modules apply transaction screening and counterparty risk controls against the same ledger Unify uses for reconciliation. Compliance and finance therefore work from the same underlying transaction record.
Visibility is not the control
The next sanctions-evasion instrument will be designed around what made the previous one difficult to use.
But the operational problem for a receiving company remains the same: eventually, the value arrives as a transaction into an account you control.
Range had 58 analyst-verified addresses connected to A7A5 in its graph in October 2024, before Western sanctions named A7 or A7A5.
That visibility matters, but visibility alone is not a control. The control is what happens when the transaction reaches you.
If a bank partner asks how you screen for a prohibited token and your process still relies on an onboarding sanctions check, get in touch. We can show you how an exposure like A7A5 surfaces in Range.
Protect your time and money
Get your unified treasury dashboard in 30 minutes.


