The U.S. Financial Crimes Enforcement Network on March 7, 2022 instructed financial institutions—including cryptocurrency exchanges and administrators—to increase their vigilance for attempts to evade sanctions imposed after Russia’s February 24, 2022 invasion of Ukraine.
FinCEN’s alert, designated FIN-2022-Alert001, was not an enforcement action or a new prohibition. It was an operational warning under the Bank Secrecy Act, identifying behavior that could warrant closer examination and reminding covered institutions to report suspicious activity. Its importance for the digital-asset industry was unusually direct: businesses with visibility into convertible virtual currency flows were named alongside conventional financial institutions.
Crypto entered the sanctions-control perimeter
FinCEN said anti-money-laundering and sanctions-compliance obligations applied to convertible virtual currency transactions just as they applied to fiat transactions. Cryptocurrency exchangers and administrators generally treated as money services businesses were asked to identify and quickly report suspicious activity, conduct risk-based customer due diligence and consider information sharing under Section 314(b) of the USA PATRIOT Act.
The agency requested that related Suspicious Activity Reports carry the identifier `FIN-2022-RUSSIASANCTIONS`. That detail turned the alert from a general policy statement into an actionable reporting framework: filings from separate institutions could be grouped for analysis by investigators.
Crypto-specific warning signs included transactions connected to digital-asset addresses appearing on the Office of Foreign Assets Control’s sanctions list; activity initiated from suspicious or high-risk internet addresses; and use of foreign exchanges or money-services businesses in jurisdictions with deficient customer-identification controls. FinCEN separately highlighted rapid trading among multiple digital assets followed by withdrawal, transfers involving mixing services and blockchain-analysis exposure to ransomware.
The agency cautioned that none of its indicators, standing alone, established illicit conduct. Institutions were expected to assess the surrounding facts and circumstances rather than treating nationality, geography or one transaction pattern as proof of sanctions evasion.
A warning without a claim of mass evasion
FinCEN made an important distinction in the March 7 record. It said government-scale sanctions evasion through convertible virtual currency was “not necessarily practicable,” while warning that sanctioned people, illicit actors and their facilitators could still use digital assets or anonymizing tools to move or protect funds.
That distinction mattered because the debate surrounding cryptocurrency had begun to collapse two different questions into one: whether digital assets could help particular actors evade restrictions, and whether Russia could use them at sufficient scale to neutralize sanctions against its financial system. FinCEN treated the first as a concrete compliance risk without asserting that the second was occurring.
A contemporaneous industry disclosure illustrated how screening could work. In a March 6, 2022 statement, Coinbase chief legal officer Paul Grewal said the exchange blocked more than 25,000 addresses related to Russian individuals or entities that the company believed were engaged in illicit activity and shared the addresses with the U.S. government. Coinbase expressly said the total was not confined to the period after the invasion and that most addresses had been identified earlier.
The address count therefore should not be read as 25,000 customers, wallets, newly frozen accounts or confirmed sanctions violators. One person or service can control many blockchain addresses, and Coinbase did not disclose the assets, transaction values, chains, review period or number of affected users. The government’s receipt of the list also did not establish independent validation of every association.
Why the March 7 alert mattered
The alert placed regulated crypto intermediaries inside the same sanctions-surveillance system as banks while recognizing the distinctive evidence available from public blockchains. It also underscored a practical divide in the industry: decentralized networks could continue recording transactions, but regulated exchanges could screen customers, restrict account access, block assets under their control and report suspicious activity.
FinCEN supplied no cryptocurrency price or trading-volume dataset, so this reconstruction makes no causal market claim. The immediate significance was institutional rather than price-based: on March 7, 2022, crypto sanctions compliance became an explicit component of the U.S. financial response to the war, with concrete reporting instructions and carefully stated limits on what regulators believed digital assets could accomplish at national scale.
The complete source packet and revision history are retained with the newsroom record.
Automated systems may have assisted with source organization and drafting. Coinburn is accountable for the published text and maintains a revision record.
This article provides news and analysis, not investment, legal or tax advice. Digital assets are volatile and may result in total loss.

