What exactly happened?
Russian investigators detained IT specialist Yuri Belenky in September 2025. According to reporting by CryptoSlate, which draws on materials reviewed by Reuters, the Binance exchange provided Russian authorities with personal and transaction data that was subsequently folded into a criminal file on terrorism financing.
A key detail: Binance was no longer formally present in Russia at that time. It had pulled out of the Russian market nearly two years earlier. Even so, customer records remained accessible and ultimately served as evidence.
Who is the accused and what is he charged with?
According to CryptoSlate, this involves a 49 year old holder of a Russian passport who also has a Bulgarian residence permit. Russian authorities claim that between January 2023 and March 2024 he sent crypto worth more than 700 dollars to Ukrainian recipients, and they classify this activity as terrorism financing.
In terms of volume, the amount is tiny. That is part of the story: this is not about large sums, but about how an exchange's archived data can be used retroactively in criminal proceedings in a jurisdiction the company has officially left.
Why did Binance still have the data after leaving Russia?
This is the point where caution is warranted. The disclosed sources confirm that the data was available and was handed over, but they do not explain in detail the legal or technical mechanism by which the transfer occurred, nor the specific request it was based on.
As a general rule, centralized exchanges (that is, platforms where a client entrusts funds to an operator, such as Binance) retain KYC data (Know Your Customer, meaning identity verification) and the complete transaction history of their users. These records do not disappear simply because the firm stops operating in a given country. The specific reason why and how the data was made available to the Russian side in this case does not clearly follow from the published sources.
How is the detention of employees in the UAE related?
In a separate but thematically related event, authorities in the United Arab Emirates detained two Binance employees at airports and questioned a third. This was reported by The New York Times citing four sources, as noted by the Polish outlet Incrypted and others.
According to the outlets CrypS.pl and Incrypted, and per a statement from the exchange's spokesperson to Cointelegraph, all the employees were subsequently released. Binance emphasizes that none of them was a target of the investigation and that they appeared in the role of witnesses. A spokesperson for the exchange told Cointelegraph that the employees provided statements regarding third party fund flows through the company's client account.
According to the Polish sources, the UAE investigation concerns fund flows through the exchange and is meant to focus primarily on the platform's clients, not on its employees.
What do the two events have in common?
The common thread is not that this is a single case. These are two different situations in two different jurisdictions. What connects them is one theme: how the data and records of a centralized exchange enter into law enforcement investigations, even when the firm itself claims it is merely an information provider or that it no longer operates in the country in question.
| Element | Russian case | UAE case |
|---|---|---|
| Who is at the center | Former user (Belenky) | Exchange employees and clients |
| Binance's role per sources | Provided data to authorities | Employees as witnesses, released |
| Source of information | Reuters (via CryptoSlate) | NYT (via Cointelegraph, CrypS.pl, Incrypted) |
| Status | Criminal prosecution underway | Employees released, investigation continues |
What we still do not know
It is not publicly documented on the basis of what precise legal request Binance provided the Russian data, nor what the outcome of the proceedings against Belenky was. It is also not clear from available sources what specific offenses the UAE authorities are investigating and whether the two events are formally connected in any way. These points remain open.
What to watch out for with this type of news
With cases where exchange data features in criminal proceedings, it pays to track three things: who exactly provided the data and on what basis, whether these are officially confirmed documents or unconfirmed sources, and how the exchange itself comments on the matter. The difference between "the firm was a target" and "the firm provided information as a third party" is fundamental and is often blurred in the first reports.

