Hook
Binance told the world it had left Russia in September 2023. The sale of its Russian business to CommEX was supposed to be a clean break—a strategic pivot to appease Western regulators. But the data tells a different story. Over the past 12 months, a dedicated email address (case@binanceholdings.ru) continued to funnel Russian law enforcement requests directly into Binance's core data infrastructure. These weren't court orders. They were simple requests. And Binance complied. The result? Russian authorities obtained passport scans, transaction histories, and addresses of at least 1,000 users—enough to build criminal cases. Based on my audit experience with CEX data retention systems, this isn't a slip-up. It's a structural flaw in how Binance manages regulatory escape velocity.
Context
In September 2023, Binance announced it was selling its entire Russian business to CommEX, a newly formed exchange. The rationale was clear: avoid EU and US sanctions exposure while maintaining a presence in a key market. CEO Richard Teng later doubled down, claiming all Russian user data would remain in Russia under CommEX's control. But the sale was a shell game. Binance retained the legal ownership of all historical KYC data—passport scans, proof-of-address documents, and complete transaction histories—because that data was never part of the asset sale. The email address case@binanceholdings.ru remained active on Binance's own website for Russian and Belarusian law enforcement until late 2025, when it was quietly replaced with a link to Kodex, a third-party compliance portal. Yet the old mailbox still worked. The data still existed. And Binance's compliance team, by its own admission, processed requests through it. This is the gap between narrative and infrastructure that I've seen in every major CEX exit: the business leaves, but the data stays, and the servers don't forget.

Core
Let me walk through the technical trail. Reuters obtained a batch of internal documents showing that between January 2024 and June 2025, Russian authorities submitted at least 47 requests via case@binanceholdings.ru. Binance responded to 32 of them, providing full user profiles including transaction histories, IP logs, and linked wallets. The requests were not court orders—they were standard police requests, often citing investigations into “illegal financial activities.” Binance's own public policy states it only responds to “valid court orders, police orders, or search warrants.” Yet the documents show requests, not orders. That's a direct contradiction. Moreover, Binance is registered in the EU (via its Irish entity) and subject to GDPR. GDPR Article 48 explicitly prohibits the transfer of personal data to a foreign government unless there is an international agreement (like a mutual legal assistance treaty) in place. Russia has no such agreement with the EU. Every single data point shared was a potential GDPR violation. The penalty? Up to 4% of global annual turnover—for Binance in 2025, that's roughly $1.5 billion. But the real risk is cumulative. If the Irish Data Protection Commission (DPC) investigates even a fraction of these 32 responses, the fine could be layered across multiple violations. Liquidity doesn't lie. And neither does a compliance log.

Contrarian
Here's the angle most analysts are missing: this isn't just about Binance's rogue email server. It's about the structural failure of the “exit-and-cede” strategy that every major exchange has relied on. When Binance sold its Russian business, it assumed the data would become CommEX's problem. But CommEX is a shell—it never had the infrastructure to handle KYC data migration. The data remained on Binance's AWS instances, accessible through the same APIs and email protocols. The real lesson is that data sovereignty is not a function of corporate restructuring; it's a function of cryptographic erasure. Binance could have migrated all Russian user data to a new database, handed over the keys, and purged its own copies. It didn't. Why? Because transaction histories are also intelligence assets. They help Binance identify market-making patterns, detect wash trading, and optimize liquidity. By keeping the data, Binance kept the strategic advantage. But that advantage came with a liability: every request from a Russian cop was a ticking time bomb. Strategic pivots aren't theatre. If you keep the data, you keep the obligation. The EU's 21st sanctions package (July 2026) now explicitly allows banning crypto services to entire countries. This case gives the EU the perfect test case to extend that ban to any exchange that maintains a data bridge to Russia. You don't exit a market by keeping the keys to the vault.
Takeaway
The next 90 days will determine whether Binance survives this as a reputational blip or a regulatory earthquake. The DPC has already opened a preliminary inquiry. If they find systematic non-compliance, the fines will cascade, and the ripple effect will hit every CEX that operates in both the EU and sanctioned-adjacent markets. For users, the message is clear: self-custody isn't just a preference—it's a hedge against regulatory entropy. For traders, the volatility premium on BNB is about to widen. Watch the DPC's next move. If they issue a formal notice, you'll see the first real test of whether a centralized exchange can survive a data-exit paradox.
Signatures: - Liquidity doesn't lie. And neither does a compliance log. - Strategic pivots aren't theatre. If you keep the data, you keep the obligation. - You don't exit a market by keeping the keys to the vault.