
The Word “Potentially” on an FSB Slide: Russia Weighs Wiring Crypto Exchanges into SORM
By EIDEX Team
A presentation given in May by Alexander Samoylov, an official representative of Russia's Federal Security Service, at the Russian Telecom Operators Conference (KROS) contains a diagram that only drew attention now. In its upper right corner sits a separate box labelled “Potentially,” with two entries: crypto exchanges and gaming platforms.
At issue is extending SORM requirements to them — the System for Operative Investigative Activities, Russia's lawful-interception infrastructure. The outlet The Bell* flagged the presentation.
What the Slide Actually Shows
The slide is titled “Principles of Conducting Operative Investigative Activity,” and it maps an existing architecture rather than a hypothetical one. The top row lists categories already covered by regulation: telecom operators, information dissemination organisers, owners of autonomous systems, hosting providers and energy sector facilities. Arrows converge from all of them into the SORM block, while the bottom of the diagram lists the agencies entitled to conduct such activity — the Interior Ministry, the Federal Protective Service, the FSB itself, the Foreign Intelligence Service, Customs and the Federal Penitentiary Service.
Crypto exchanges appear in a separate box to the side. Formally, that means the agency treats them as the next category for inclusion rather than as one already regulated.
The company they keep is telling. Gaming platforms sit alongside them, and both categories share a property: they accumulate data about users' money and communications while remaining outside the perimeter built for telecom operators and hosting providers.
What SORM Provides
The system gives security services round-the-clock remote access to information about users. It allows internet traffic to be monitored and analysed in real time, metadata and user materials to be stored, and IP addresses, logins, social network pages and payment data to be linked together.
The fundamental difference from the current arrangement lies not in the volume of information but in the mode of access. Today, exchanges and conversion services hand over data on request, within financial monitoring procedures. SORM removes the request stage: access becomes direct and continuous.
For the crypto market this changes the underlying relationship with the state. A venue stops being a party that answers enquiries and becomes a node in the surveillance infrastructure itself.
Why Trading Venues Are Grouped With Social Networks
Judging by the presentation's logic, the agency considers crypto exchanges and gaming platforms functionally close to social networks. The rationale is legible enough: both have accounts, identity verification, internal messaging, transfers of value between users and outbound payments.
The analogy is imperfect. Social networks hold mostly content, whereas trading venues handle financial records — territory that belongs to banking supervision, with its own rules on retention and disclosure. In practice, two distinct regulatory regimes would be layered onto a single object.
Security officials want the new requirements met on the model of the largest banks, which are already obliged to install the equipment and provide access to client data. The template is borrowed from the banking sector rather than invented from scratch.
How This Differs From the 2022 Proposal
A similar idea surfaced four years ago: the FSB then wanted exchanges to hand over client data, but without mandatory equipment installation. That was an overlay on existing reporting.
The current version changes the nature of the obligation. Installing SORM is an infrastructure commitment with capital costs, technical specifications and a deployment plan that must be agreed with the agency. For mid-sized venues, those costs could rival a year's profit. Operators would also need to clear the technical plan with the service — not a quick procedure, and one that leaves the question of continued operation open while it runs.
The Enforcement Mechanism Is Already Proven
The levers exist and are in use. In June, the maximum fine for refusing to install the equipment was raised to 10 million rubles, roughly $125,000. Running in parallel is a more effective instrument: Roskomnadzor stopped issuing and renewing telecom licences for operators that had not agreed a deployment plan with the FSB.
That licensing mechanism is the one to watch. A fine is an expense that can be budgeted for. Losing a licence means ceasing to operate.
For the market this implies consolidation. Large exchanges can absorb the cost and spread it across turnover; smaller venues largely cannot. Something similar happened among telecom operators, where a share of regional companies exited or were absorbed after the requirements came in.
What Data Would Come Into View
If the requirement is extended, the visible surface expands considerably. Centralised exchanges would surrender the full picture:
- account linkage to passport details and phone number;
- login history, devices and IP addresses;
- the set of trading pairs a client uses, along with volumes and exact timestamps;
- account balances, plus staking as a separate income stream;
- withdrawals, including the external destination addresses.
The set of trading pairs is more revealing than it sounds. It reconstructs a client profile: appetite for speculation, interest in particular networks, the characteristic conversion into stablecoins ahead of a withdrawal. Exchanges have long run analytics on trading pair history for their own scoring and risk models.
What matters most for investigations is not the trading activity itself but the link between an identity and an on-chain address. That link is what turns an anonymous address into a specific person — usually the whole point of requesting the data.
It is worth not overstating the novelty here. Much of the above is already available on formal request: exchanges operating within Russian law verify their clients and report to the financial intelligence unit. What changes is not the composition of the data but the speed and autonomy of access — investigative work stops depending on a venue's willingness to answer. For cases measured in hours, that difference is decisive.
Where the Requirement Hits Technical Limits
Here an asymmetry appears that the presentation does not resolve. Centralised exchanges have an operator, a legal entity and servers — there is someone to serve the requirement on and somewhere to install the hardware.
A decentralised exchange is built differently: settlement runs through smart contract execution, there is no operator in the conventional sense, and the front end may be nothing more than a static site. There is nowhere to install equipment and no one to compel.
The same problem arises with foreign venues. The largest exchanges are incorporated outside Russian jurisdiction, and an infrastructure requirement cannot be served on them directly — leaving only network-level blocking, with its limited effectiveness.
None of this makes such services a legal refuge. The law signed on 4 August obliges residents, from 1 July 2027, to transact only through authorised intermediaries. That duty sits with the user regardless of how a venue is architected.
How This Connects to the New Law
The timing is not coincidental. The digital currency law signed this week creates a register of licensed participants: exchanges, conversion services and depositories become identifiable legal entities with Russian registration.
Until now the main obstacle was the absence of anyone to address the requirement to — it was unclear whom to oblige when venues operate from abroad. The register solves that. The number of exchanges legally serving Russian clients will be limited, and every one of them will be on a list.
The sequence follows logically. First the market gets a legal framework and a roster of admitted participants; then disclosure requirements are applied to that roster. Organised crypto trading in Russia begins in September, and wiring new venues into a monitoring system at launch is technically simpler than retrofitting infrastructure already in operation.
Status of the Initiative
An important caveat tends to get lost in the retellings. This is an agency presentation, not a draft law. Nothing has been introduced in the State Duma; there are no deadlines and no drafted wording. The slide records the regulator's direction of thinking, but it creates no obligations.
For the market the practical takeaway is singular: plan on the assumption that disclosure will widen rather than narrow. Exchanges and conversion platforms expecting to operate inside the jurisdiction long-term are budgeting for these costs in advance, as banks and telecom operators did before them.
Earlier, members of Russia's Civic Chamber proposed tasking the FSB with investigating illegal crypto transactions in order to shut down underground conversion services, which officials say are used by fraudsters to launder criminal proceeds. The current presentation fits that same trajectory — and will most likely resurface as actual regulatory text.
* The Bell has been designated a “foreign agent” by Russia's Ministry of Justice. The designation is a Russian state classification and is noted here as such.
What is SORM?
SORM is Russia's System for Operative Investigative Activities — the country's lawful-interception infrastructure. It gives security services round-the-clock remote access to information about users, allows internet traffic to be monitored in real time, and links IP addresses, logins, social network pages and payment data together.
Are crypto exchanges already required to install SORM?
No. This is an agency presentation, not a draft law. Nothing has been introduced in the State Duma, there are no deadlines and no drafted wording. The slide records the regulator's direction of thinking, but it creates no obligations.
How would SORM differ from the data requests that exist today?
Not in the volume of information but in the mode of access. Today exchanges and conversion services hand over data on request, within financial monitoring procedures. SORM removes the request stage: access becomes direct and continuous.
What data would come into view?
Account linkage to passport details and phone number; login history, devices and IP addresses; the set of trading pairs with volumes and exact timestamps; account balances and staking; and withdrawals including the external destination addresses.
Would the requirement reach decentralised or foreign exchanges?
Technically it is hard to: a decentralised exchange has no operator to compel and nowhere to install equipment, and the largest venues are incorporated outside Russian jurisdiction. That does not make them a legal refuge — the law signed on 4 August obliges residents to transact only through authorised intermediaries from 1 July 2027.
Staking is locking cryptocurrency in a blockchain network to help validate transactions and earn passive rewards — similar to a bank deposit, but with crypto and typically higher yields.
A smart contract is a self-executing program stored on a blockchain that automatically enforces the terms of an agreement when predetermined conditions are met.
CTO of the EIDEX crypto exchange. Responsible for platform architecture, the trading engine and security; writes about the crypto market, regulation and blockchain technology.


