Reuters reports that Binance shared user data with Russian investigators in a terrorism-financing case against a Russian IT specialist, and the legal question hanging over it is whether EU privacy rules should have limited that disclosure.
- Reuters says Binance provided identity and transaction records in 2025
- The case centers on Yuri Belenkiy and more than $700 in alleged crypto transfers
- The unresolved issue is whether GDPR or other EU rules should have blocked the handover
- The case shows how centralized exchanges can become surveillance chokepoints
According to Reuters, Binance gave Moscow client details used to charge Russian authorities identity documents and transaction records that were later used in a terrorism-financing case against Yuri Belenkiy, a 49-year-old Russian IT specialist. The alleged transfers totaled more than $700 in cryptocurrency and were said to have taken place between January 2023 and March 2024.
That amount is tiny. The consequences are not.
Reuters reported that the funds were tied to a wallet promoted by exiled Kremlin critic Arkady Babchenko and to a group associated with the Azov Brigade. Russia designates Azov as a terrorist organization, which is the legal trigger that turns a small crypto transfer into a serious criminal matter inside Russia.
Belenkiy was detained in Russia and is awaiting trial, according to the reporting. The case is being handled by Russia’s Investigative Committee, which reportedly obtained records including an address, telephone number, date of birth, passport details, and a Bulgarian residency permit.
The whole thing is messy because the money trail is only part of the story. The bigger issue is what Binance knew, what it was allowed to share, and under which legal framework it did so.
Binance announced in September 2023 that it would fully exit Russia and sell its Russian business to CommEX. That exit matters, but not in the simplistic “left the country, therefore no records remain” way some people like to pretend. Exiting a market does not erase historical KYC data, account records, or law-enforcement obligations tied to earlier activity.
For readers unfamiliar with the term, KYC means Know Your Customer, the identity checks exchanges use to verify users. Once a platform has collected that information, it can become a liability, a compliance obligation, or evidence, depending on who comes asking.
Binance told Reuters:
“Like other global financial institutions, we cooperate with lawful information requests from law enforcement globally, subject to applicable legal, privacy and regulatory requirements.”
The company also said it does not create national laws, determine criminal charges, or control how governments use information in court proceedings. That is standard compliance-speak. Translation: “We answered a legal request, don’t pin the state’s use of the data on us.”
Fair enough, but that still leaves the central question unanswered: was the disclosure lawful in the first place?
That is where the GDPR angle enters the picture.
GDPR, the EU’s General Data Protection Regulation, sets strict rules around how personal data is collected, stored, and transferred. If a person is considered an EU resident, a company may face tighter limits on handing that data to foreign authorities, especially in jurisdictions that do not offer comparable privacy protections.
Reuters could not establish whether Belenkiy registered with Binance as a Bulgarian or European resident. That missing fact is not a footnote; it is the hinge on which the privacy question turns.
Lawyer Mike Bystrov, quoted in the reporting, said Binance had no obligation to provide the records because it had already left Russia. He also said Binance may have had an obligation not to disclose the information under EU law if Belenkiy was registered as an EU resident.
That is an argument, not a ruling. No regulator or court in the reporting has concluded that Binance violated GDPR. So the honest position is simple: the legal risk is real, but the alleged violation is not proven.
And that distinction matters.
Crypto users often talk about Bitcoin and blockchain as if they automatically deliver privacy. They do not. Bitcoin is censorship-resistant at the protocol level, meaning the network itself is hard to shut down or rewrite. But the minute you use a centralized exchange, you step into a world of passports, phone numbers, residency documents, and compliance departments that can be compelled to hand over records.
That is the weak point. Not the chain. The gatekeepers around it.
The alleged transfers also show how politically charged crypto fundraising can become when legal definitions diverge across borders. A wallet promoted by Arkady Babchenko, an exiled Kremlin critic, may be seen by some as support for Ukraine’s defense effort. Inside Russia, the same funding stream can be framed as terrorism financing if it touches an organization the state has blacklisted.
Same transaction. Different state. Very different prison cell.
That mismatch is one reason crypto cases like this can be so toxic. Code may be neutral, but governments are not. A wallet address does not know whether it is being used for aid, protest, resistance, or a criminal allegation. Prosecutors, of course, will happily decide for it.
Reuters said it could not determine whether other donors were identified through the same wallets, whether additional cases were opened, or which Binance entity handled the request. The European Data Protection Board declined to comment on the individual case, and Bulgaria’s Commission for Personal Data Protection did not respond to Reuters’ questions.
So what do we actually know? Binance reportedly provided records. Russian investigators reportedly used them. Belenkiy is facing a terrorism-financing case. And the key legal question, whether Binance should have disclosed the data under EU privacy rules, remains unresolved.
What this means for crypto users
This case is another reminder that centralized exchanges are not privacy tools. They are data collection machines with trading features attached. If you use them, assume the exchange knows who you are, where you live, and how to reach your funds.
Self-custody changes that risk profile. It does not make you invisible, but it does reduce the number of intermediaries who can be leaned on by prosecutors, regulators, or foreign governments. That is one reason Bitcoin matters so much: not because it makes users untouchable, but because it gives them an escape hatch from the surveillance-heavy machinery of legacy finance.
There is also a darker lesson here. Compliance can protect markets, but it can also become the plumbing that turns financial infrastructure into an evidence machine. Sometimes that is legitimate law enforcement. Sometimes it is state power with a fancy dashboard.
Key questions and takeaways
-
Did Binance reportedly hand over user data to Russian investigators?
According to Reuters, yes. The exchange allegedly provided identity documents and transaction records that were used in a Russian terrorism-financing case. -
Who is Yuri Belenkiy?
Reuters identified him as a 49-year-old Russian IT specialist who is detained in Russia and awaiting trial. -
Why does the Bulgarian residency permit matter?
If Belenkiy was registered as an EU resident, GDPR or other EU privacy rules may have limited how Binance could share his data with Russian authorities. -
Does this prove Binance broke the law?
No. Reuters reported the data transfer, but no regulator or court in the reporting has ruled that Binance violated GDPR or EU privacy law. -
Why does the small dollar amount matter so little here?
In Russia, the charge is about terrorism financing and the destination of the funds, not just the size of the transfer. More than $700 can still trigger a serious case. -
What does this say about exchange privacy?
Centralized exchanges are major surveillance chokepoints. Once KYC data exists, it can be shared with authorities when legal or quasi-legal requests come in.
The broader lesson is blunt: crypto gives users more freedom than legacy finance, but not immunity from it. If funds touch a centralized platform, the old system can still reach in and pull out the records.
Binance says it cooperates with lawful requests. Russia says it has a terrorism case. The unresolved issue is whether the data shared in between belonged to someone protected by EU privacy law, and whether that protection was ignored.
Further reading
A few related reports and background pieces that help put the privacy and compliance angle in context:
- Binance gave Russia data used in Ukraine donation case
- Binance Reportedly Gave Client Data to Russian Authorities
- Binance gave Russian authorities client data used in terrorism-financing case
- Binance Shared Client Data with Russia Leading to Charges
- EU data protection rules and GDPR overview
- Binance Shared Russian KYC Data Used in $700 Terror Case
- Blum Co-Founder Arrested in Russia on $15M Fraud Charges
- Bitcoin Tests $62K Support as Miner Deposits to Binance Spike to Four-Month High