Binance provided Russian authorities with client transaction data that was used to bring criminal charges against a Russian IT specialist over donations he made to Ukraine, according to a Reuters report surfaced by Cointelegraph on August 17, 2026. The detail that gives the story its edge: Binance publicly exited the Russian market in 2023, yet the data it held was still reachable by Moscow.
The report describes a data-sharing request that Binance answered, and the records then formed part of the evidence used to prosecute the individual. For anyone who assumed that an exchange leaving a country severs its data ties to that country's law enforcement, this is a direct counterexample.
Compliance obligations meeting a geopolitical fault line
Every regulated exchange sits on a stack of legal duties: know-your-customer checks, transaction monitoring, and cooperation with lawful requests from authorities. Those duties are usually framed as protection, aimed at money laundering, sanctions evasion, and fraud. This case shows the same machinery pointed at a person for sending money across a border that Moscow treats as hostile.
That is the uncomfortable part. A compliance system built to satisfy regulators does not distinguish between a request it finds morally sound and one it does not. If the request arrives through a channel the exchange recognizes as lawful in the relevant jurisdiction, the data can move. The donor's intent, humanitarian or otherwise, is not a field the compliance workflow weighs.
Binance's 2023 withdrawal from Russia was presented as a clean break. The company sold its Russian business and said it would stop serving the market. A withdrawal from active operations, though, is not the same as the deletion of historical records or the end of any legal reachability. Account data created while a user was onboarded can persist long after the storefront closes.
Custodial data outlives the account
The practical lesson runs deeper than one prosecution. When you use a custodial exchange, you hand over two things: your funds and your identity graph. The funds you can withdraw. The identity graph, the linkage between your verified name, your addresses, and every transaction that touched the account, stays with the provider on its own retention schedule.
This is the same counterparty exposure that shows up when a custodial provider faces insolvency and balances get frozen, except here the asset at risk is information rather than money. A user cannot un-KYC themselves. Once the record exists, its future depends entirely on the provider's policies, the jurisdictions it answers to, and the requests it receives.
Self-custody changes the funds side of that equation. Spending directly from your own wallet through a non-custodial card means the provider is not holding your balance and cannot freeze it. It does not, on its own, erase the identity data an exchange already collected during past onboarding, and any card that touches a regulated payment rail still involves KYC somewhere. The point is narrower: fewer custodians holding your records means fewer parties that can be compelled to produce them.
The read for crypto users
For most people moving money legally, an exchange answering a lawful data request is routine and unremarkable. The friction appears at the edges, where a lawful request in one jurisdiction targets conduct that is legal, or even celebrated, in another. Cross-border donations, activism, and payments to sanctioned or contested regions are exactly the edges where the interests of the state and the interests of the individual diverge.
Users who care about that exposure have a few concrete levers. Read the data-retention and law-enforcement-request policies of any exchange before onboarding, not after. Assume that anything submitted during KYC is permanent and potentially discoverable by the authorities of any country the exchange operates in or once operated in. And separate the accounts you use for routine spending from the accounts you use for anything you would not want cross-referenced, since a single verified identity linking them removes the separation.
None of this argues against compliance. Exchanges that ignore lawful requests do not survive as regulated businesses, and the alternative, unregulated venues with no KYC at all, carries its own well-documented risks around fraud and asset loss. The takeaway is more grounded: custodial convenience comes with a data footprint you do not control, and that footprint can be read by parties whose interests are not aligned with yours.
Overview
Reuters reports that Binance supplied client transaction data to Russian authorities, and that data was used to charge a Russian IT specialist over donations to Ukraine, despite Binance exiting Russia in 2023. The case highlights a durable tension between exchange compliance duties and customer privacy, sharpened when a lawful request in one country targets conduct that is legal in another. The concrete lesson for users is that custodial data, unlike custodial funds, cannot be withdrawn once it exists.



