In October 2025, Unchained reported that Binance handed over detailed KYC data of a Ukrainian donor to Russian investigators. The data included passport scans, transaction history, and IP logs. This is not a hack. It is a feature.
Context
In 2023, Binance declared it had “completely exited Russia.” The narrative was clear: no operations, no employees, no local entity. Yet, the official Binance website still maintains a dedicated page for Russian and Belarusian law enforcement agencies, complete with a direct email address for data requests. The contradiction is not a bug in the code—it is a feature of the global compliance architecture.
The event centers on a Ukrainian expatriate, a Russian-born individual with a Bulgarian residence permit, who used Binance to donate to Ukrainian volunteer groups. Russian investigators charged him with terrorism financing, citing the Azov Regiment as a terrorist organization. Binance responded to the Russian request, providing a complete dossier: full name, address, passport scans, transaction history, and device information.
Core: Technical Systematic Teardown
Let’s dissect the technical infrastructure. Binance’s KYC system stores user identity documents and transaction records. The law enforcement response system (LERS) is a structured process: request submission via official channels, identity verification, data extraction, and cross-border transmission. The presence of a dedicated Russian/Belarusian channel indicates that the system is not a generic “global” endpoint but a jurisdictionally routed pipeline.
From a forensic audit perspective, this is a classic case of misaligned trust assumptions. The user believed their data was protected by Binance’s “exit Russia” narrative. But the chain of custody reveals that the KYC data remained accessible to a Russian-facing compliance team. The technical term for this is a “jurisdictional routing table” that maps legal requests to specific processing pipelines. The system does not self-censor based on geopolitical sensitivity—it is designed to be neutral, responding to any “legitimate” request.
Based on my audit experience of CEX compliance systems, I have seen how these routing tables are built. In 2022, I audited a mid-tier exchange’s reserve proofs and found a similar structure: a SQL database query that grouped users by country code, then applied different data retention policies. The problem is that the “legitimate” flag is a legal determination, not a technical one. The system cannot distinguish between a request from the U.S. Department of Justice and one from the Russian Investigative Committee. It only sees the digital signature of the requesting authority.
This is where the algorithm determinism breaks down. The code does not lie, but it does hide. The hidden assumption is that all jurisdictions are equal. But they are not. The Russian request targets a donor to a group that the U.S. considers a partner in the war effort. The same technical pipeline that satisfies Russian law enforcement simultaneously violates EU GDPR if the user is a Bulgarian resident. The system is designed for efficiency, not for geopolitical nuance.
Contrarian: What the Bulls Got Right
Some argue that Binance is simply following the law. Every regulated financial institution has an obligation to respond to lawful requests. The CEO, Richard Teng, stated that operating globally means engaging with all jurisdictions. Bulls point out that Binance is not unique—Coinbase also responds to U.S. requests, and Kraken does the same. The framework is consistent.
They are right on the legal form. But the execution reveals a fatal flaw: the “exit Russia” narrative was a public relations construct, not a technical reality. The infrastructure was never dismantled. The compliance team responsible for Russian requests was never disbanded. The system was left in place, waiting for a request. This is not a failure of compliance—it is a failure of governance. The decision to maintain the Russian channel was made at a level that did not account for the downstream political consequences.
Moreover, the bulls miss the core issue: the data handover was not an isolated incident. It is a precedent. The same pipeline can be used for requests from China, Iran, or Venezuela. The “jurisdictional routing” creates a slippery slope where each new request becomes a test of the system’s neutrality. The system will comply, because it cannot do otherwise. The code is deterministic.
Takeaway: The Pre-Mortem for All CEXs
This event is a pre-mortem for every centralized exchange. The chain remembers what the ledger forgets. The ledger of KYC data is a liability that cannot be erased. The moment a user uploads a passport, they surrender control to a system that will respond to the most powerful legal request. The geopolitical paradox is that no CEX can serve all jurisdictions without eventually betraying some of them.
The audience should ask: what happens when the next request comes from a country under U.S. sanctions? The system will comply, because that is what it was built to do. The only solution is to redesign the system with jurisdictional asymmetry—treating requests from different regions with different thresholds. But that would violate the principle of equal treatment that forms the basis of global compliance. The trade-off is stark: either you treat all requests equally and risk geopolitical fallout, or you prioritize certain jurisdictions and risk accusations of bias.
Binance chose the first path. The result is a case study in how technical neutrality is impossible in a politically charged world. The code does not lie, but it also does not protect. The ultimate takeaway is that trust is a variable, not a constant. And in the current market, survival matters more than gains. The data shows that the real risk is not the smart contract bug—it is the geopolitical bug that no audit can find.