TL;DR - Aeza Group, a Russian bulletproof-hosting firm OFAC sanctioned in July 2025, moved criminal crypto through exchanges, so screen your address against the sanctions list and a multi-chain exposure tool before a deposit gets frozen.
Most people have never heard of a bulletproof host, yet the crypto that pays for one can travel a long way. When the US sanctioned Aeza Group in mid 2025, it named a single payment wallet that had already cashed out through mainstream exchanges. Funds that pass through those same exchanges can carry a faint link back to the sanctioned address, which is how a wallet that never dealt with Aeza can still show exposure. This guide explains what Aeza was, how its money spreads, and how to check your own address.
What is Aeza Group and why was it sanctioned?
Aeza Group LLC is a hosting company based in St. Petersburg, Russia. It sold what the security industry calls bulletproof hosting: servers and infrastructure rented to criminals with a promise to ignore abuse reports and resist law enforcement takedown requests. That service let ransomware crews and data thieves run their operations without the usual risk of being shut off.
On July 1, 2025, the US Treasury's Office of Foreign Assets Control, or OFAC, added Aeza Group to the sanctions list along with its leadership and several affiliated entities. The US led the action, and the United Kingdom and Australia took coordinated steps against the same Russian cybercrime infrastructure. According to the Treasury, Aeza hosted the Meduza and Lumma infostealer operations that targeted the US defense industrial base and technology firms, the BianLian ransomware group, panels for the RedLine infostealer, and BlackSprut, a Russian darknet marketplace for illegal drugs.
How much crypto did the Aeza Group wallet move?
The designation named one cryptocurrency address tied to Aeza's payment system, a TRON wallet. Investigators reported that this single address received more than $350,000 in crypto and then cashed out at a range of deposit addresses across several exchanges. That figure is small next to a billion-dollar laundering network, but it matters for a different reason: the money did not stay put. It flowed into the same exchanges ordinary traders use, so its trail runs straight into normal circulation.
OFAC named a single TRON payment wallet, but its funds cashed out through exchanges that everyday users share.
How does Aeza-linked crypto reach an ordinary wallet?
You never have to touch a criminal service to end up holding a link to one. Exposure spreads because cash-out funds look ordinary by the time they reach a normal user.
The path usually runs like this: infostealer and ransomware crews pay Aeza for hosting, that payment wallet cashes out at exchange deposit addresses, and the value re-enters the market as clean-looking crypto. From there a peer-to-peer trade, an over-the-counter deal, or a withdrawal from a careless service can pass that history on. Because the link can be indirect and several hops removed, you can carry exposure without any direct transfer from the sanctioned address.
Cash-out funds are layered through exchanges and brokers, then re-enter the market as clean-looking crypto you can receive.
How do you check your wallet for Aeza Group exposure?
Start with the free, manual checks, then widen the net:
Search your address on the OFAC Sanctions Search portal to confirm it is not directly listed.
Open the address on a block explorer such as Etherscan for EVM chains, or Tronscan for the TRON network, and review recent counterparties for any sanctioned-entity or known-laundering label.
Trace large or unexpected deposits by hand to see whether they arrived from a flagged service or a high-risk broker.
Manual tracing runs out of road fast. A block explorer shows only direct, single-chain labels, so it misses multi-hop links and exposure on other networks, and the Aeza cash-out addresses at exchanges were never individually sanctioned. Rather than checking one list at a time, screen the address with Plastron to see sanctions, mixer, and stolen-funds exposure across Ethereum and six other EVM chains in one pass. One honest limit: the Aeza payment wallet itself sat on TRON, which is outside EVM screening, so pair an EVM screen with a Tron explorer if your funds moved there.
What should you do if your wallet is exposed?
Finding exposure is not an accusation, and it does not mean you broke the law. It means you should act before an exchange or an issuer does.
Stop moving the funds and screen the address to confirm how close the link is and how much value it touches.
Keep separate wallets so one risky deposit cannot reach your main balance.
Save screening records and a clear timeline so you can answer a source-of-funds request quickly.
Screen any counterparty address before a large peer-to-peer or OTC trade, and avoid services that skip compliance checks.
Sanctions exposure is a practical risk, not a rare one. An exchange that spots a link to a listed address can freeze a deposit while it reviews the source, and that review can take days. A quick check before each deal turns a surprise freeze into a risk you can see coming.
FAQ
Does receiving Aeza-linked crypto make me a criminal?
No. Receiving tainted funds without knowledge is not a crime, but it can still trigger a frozen deposit or an account review. The risk is practical, not automatic guilt, which is why a record of how the funds arrived matters.
Is Aeza Group exposure the same as being on the OFAC list?
No. Being directly listed by OFAC is the most severe outcome and is rare for individuals. Aeza exposure usually means an indirect link to the sanctioned payment wallet several hops away, which a multi-chain screener can measure even when your own address is not listed.
Which network carries the most Aeza risk?
The address named in the sanctions sat on TRON, so start there with a Tron explorer. The cash-out then spread through exchanges that also serve Ethereum and other EVM chains, so screen your EVM addresses as well.
Can an exchange still flag Aeza funds after the sanctions?
Yes. Tainted funds keep their history after a designation, and sanctioned links do not expire on their own. Exchanges and issuers still flag addresses with exposure to the listed wallet, so the passage of time does not clear the risk.
Disclaimer: This article is for educational and informational purposes only and is not legal, financial, tax, or compliance advice. Crypto carries risk; you act on this information at your own risk. Always do your own research and consult a qualified professional before making decisions. Views are the author's own and do not constitute financial, legal, or investment advice.
About Plastron
Plastron is a free, non-custodial wallet screening tool. It checks Ethereum and six EVM chains for AML and KYT risk — sanctions exposure, mixer contact, and stolen-funds proximity — and returns a risk report in seconds. It reads public on-chain data only: it never takes custody of funds and never asks for private keys.