76e4c5a1-5884-492d-9c49-d313e301954c

by Robin Dost


Anyone who has spent some time in the Russian cyberspace has surely heard of Cryptomus or Heleket.
When I look at cybercriminals and gray markets, I focus primarily on their infrastructure, which also includes the cryptocurrency exchanges that facilitate these transactions.


Cryptomus is the crypto payment processor that Canada’s financial intelligence unit FINTRAC fined a record CAD 176.96 million in October 2025.
In April 2026, TRM Labs assessed with high confidence that Cryptomus operators launched a parallel service, Heleket, to keep serving customers without strict identity checks.

My analysis goes beyond that.
It documents technical copy-paste artifacts that tie Heleket directly to Cryptomus, shows that Heleket undermines its own Russia ban in its Russian-language content and identifies a third stage in the chain “Mirocard“, operated by a company registered in Kyrgyzstan in August 2026.
The same Kyrgyz company is also named as owner of steam.ru and as payment agent for two further services selling to customers in Russia.

TL;DR

  • Cryptomus and Heleket share more than infrastructure.
    Identical API examples, the Cryptomus App Store ID in Helekets documentation, a shared mail setup and SDK traces add evidence of continuity between the brands.
  • Helekets card business continues as Mirocard.
    Existing accounts, cards and balances migrate automatically. The cards run on Visa and Mastercard BINs. Unremoved drafting notes in Mirocard’s terms identify Kyrgyz company Byte Commerce as its operator.
  • Byte Commerce connects several Russia-facing services.
    It is also named as operator of steam.ru and open-ps.ru and as payment agent for Wayment and KZ Gift Card. Kyrgyzstan’s central bank confirmed that the company holds no licence from it for payment activities.
  • Overcoming restrictions is part of the sales pitch.
    Despite its published Russia ban, Heleket promotes payments around sanctions-related banking barriers. Mirocard advertises no-KYC cards and recommends misleading billing details for payments from Russia.
  • European and US infrastructure supports these services.
    The findings give hosting providers and payment partners concrete reasons to examine the businesses they support.

Background: Cryptomus and Heleket

Cryptomus is operated by Xeltox Enterprises Ltd., registered at a Vancouver address.
FINTRAC found that the company had no employees in Canada.
According to FINTRAC, Cryptomus failed to report over 1,000 suspicious transactions in July 2024 alone, involving darknet markets, ransomware, sanctions evasion and CSAM, plus over 7,500 transfers from Iran.
Xeltox is appealing the fine and claims it had no knowledge or control over the transactions.

TRM Labs linked Cryptomus to Heleket through shared infrastructure, branding, unusual phrasing, a common privacy-focused registrar, personnel overlap and on-chain flows.
Heleket’s initial liquidity came from Garantex.
Cryptomus introduced mandatory KYC in February 2025 and illicit actors migrated to Heleket.
In May 2026, South Korean exchange Bithumb blocked all deposits and withdrawals involving Heleket.

What follows builds on that assessment with evidence that, to my knowledge, has not been published.


1. Heleket is built on Cryptomus

Cryptomus App Store ID in Helekets docs

Every page of doc.heleket.com carries the meta tag:

<meta name="apple-itunes-app" content="app-id=6464404665, app-argument=myAppArgument">

The exact same App ID appears on cryptomus.com and doc.cryptomus.com.
Helekets documentation advertises the Cryptomus iOS app.
The app-argument=myAppArgument part is an unfilled template placeholder.

Identical API, identical example values

Both “Request format” pages describe the same authentication scheme (merchant and sign headers, md5(base64_encode($data) . $API_KEY)) and use the same example merchant UUID 8b03432e-385b-4670-8d06-064591096795 and the same example signature f80fa426a89eb62bd53997326865d850.
The documentation meta description is word for word identical and the section structure (Static wallets, Block static wallet, Refund payments on blocked address, Transfer to personal/business wallet, Discount Payment) matches.

Helekets first PHP SDK, the Packagist package heleket/api-php-sdk released on 29 January 2025, was published from a fork of Cryptomus official SDK under a GitHub account named “cryptomus-plugin”, with the Cryptomus example values from 2022 still in place.
Who controls that account is not publicly documented.


Shared infrastructure

HostIPASN
mail.cryptomus.com109.206.164.168AS50245 Serverel Inc.
api.heleket.com31.133.222.28AS50245 Serverel Inc.
mirocard.com31.133.222.31AS50245 Serverel Inc.

api.heleket.com and mirocard.com sit three addresses apart in the same /24.
Cryptomus SPF record additionally authorises 109.206.164.171, next to mail.cryptomus.com in Serverels network.

What passive DNS and domain records add

Passive DNS data from CIRCL shows that Cryptomus once published exactly the mail setup Heleket uses today.
Between November 2024 and February 2025, cryptomus.coms SPF record read include:mailgun.org include:_spf.google.com include:mail.zendesk.com include:spf.smtp.bz -all.
Helekets current record contains the same four includes, including the Russian relay smtp.bz, in a different order.
Cryptomus has since replaced smtp.bz with its own IP address.
In 2023, Cryptomus SPF also included _spf.mail.ru, the mail service of Russias VK.

Between June and September 2025, the apex heleket.com resolved directly to 31.133.222.28, the Serverel address that serves api.heleket.com today, before moving behind Cloudflare.
Registry data (RDAP) shows that heleket.com was registered on 8 February 2024, almost a year before Heleket launched and a year before Cryptomus introduced mandatory KYC.
Both cryptomus.com and heleket.com are registered through Namecheap.
mirocard.com was registered on 13 April 2026 through Dynadot, one week before TRMs report.
Older DNS records for mirocard.com from 2024, pointing to Swiss hosting, belong to a previous registration of the name and are unrelated.

Passive DNS only shows what sensors observed.
“Last seen” is not the date a record was removed.


2. Russia: banned on paper, served in practice

Languages

PlatformLanguages
Cryptomus22, incl. ru, uk, uz, kk, fa
Heleketen, ru, uk, uz, kk
Mirocarden, ru, uk

The language menus show a progressively narrower selection. Cryptomus lists 22 languages.
Heleket offers English alongside Russian, Ukrainian, Uzbek and Kazakh.
Mirocard offers English, Russian and Ukrainian.
Heleket has no German, French, Spanish or other EU official language apart from English, despite describing its operations as primarily based in the EU.

Language support alone does not establish where customers live.
In this case, however, the Russian localisation comes with guides explicitly addressed to customers paying from Russia, a country Heleket lists as prohibited.
Those guides make the intended market considerably clearer than the language menu alone.

Cryptomus also lists Persian (Farsi). Archived page data from 1 February 2024 independently confirms Persian interface translations, including the heading and description of its AML page.
Separately, TRM Labs reported more than 75,000 transactions between Cryptomus and Iranian exchanges, including over 50,000 with Nobitex.


“How to pay from Russia”

Helekets Russian blog, now partly redirected to Mirocard, carries guides such as “How to pay for YouTube Premium from Russia” and “How to pay for a Skillshare subscription from Russia”.
The Mirocard version explains that Russian cards are cut off from international payments and instructs readers to register a YouTube account in another region and fill the address fields with “a random location in a US region” so that it matches the cards country.


Sanctions as a selling point

A Russian-language Heleket blog post from October 2025 on “avoiding banking restrictions” states that blockchain transactions go through without compliance checks, currency control or sanctions list screening and that sanctions do not affect them because they do not pass through US or European banks.
Target groups named are exporters and importers hit by sanctions and SWIFT restrictions.
The post uses Russian regulatory terms such as “валютный контроль” and the “экспериментальный правовой режим”, a construct from Russian law.

Built for the Russian hosting market

Heleket offers a payment module for BILLmanager, the hosting billing software from ISPsystem, obtained via isplicense.com.
It also runs dedicated landing pages for VPN, proxy, eSIM and VoIP providers, the same segment where this research started.

Russian infrastructure

  • smtp.bz in Helekets SPF record, a Russian transactional email service.
  • Unisender in Mirocards SPF record. Unisender is operated by ООО «Юнисендер СМАРТ» in Moscow (founded April 2022) and states that its servers are in Russia.

Helekets Privacy Policy also uses Russian-style guillemets (“Heleket”, “Company”, “we”), unusual in English legal text.


3. Mirocard: stage three

Heleket used to issue virtual Visa and Mastercard cards funded with crypto.
That business now runs as Mirocard (mirocard.com).
Mirocards own guide tells users: “If you already have a Heleket account, it is better to log in through it, all your funds and cards will transfer automatically.” heleket.com/card now serves Mirocard content.
Users on Trustpilot describe the switch as a rename with customer migration by email.
Mirocard replied there that the card service “is now being developed separately”.




Timing (blog and PDF dates are self-reported and can be edited. They are indicators for us and not proof of when a change happened):

  • 8 February 2024: heleket.com is registered (RDAP).
  • 13 April 2026: mirocard.com is registered (RDAP).
  • 20/21 April 2026: TRM publishes its Cryptomus/Heleket report.
  • 21 May 2026: Bithumb blocks Heleket.
  • 23 June 2026: Helekets new AML policy, ToS and Privacy Policy are dated this day.
    Mirocards “from Russia” YouTube guide carries the same date.
  • 9 August 2026: Byte Commerce LLC is registered in Bishkek (official register).
  • 13 August 2026: creation date in the metadata of Mirocards current AML and Privacy PDFs.
  • 17 September 2026: creation date in the metadata of the Terms of Use PDF containing the drafting notes.

KYC in practice:

Mirocards AML policy describes a risk-based KYC programme.
Its own Russian landing page for advertising cards, titled “Virtual card for paying for ads from Russia”, answers the question “Do I need to pass verification (KYC) to issue a card?” with “No”.
Cards are issued “without providing passport data and video identification”.
If an ad account is blocked, users can simply issue a new card.
The shopping card page likewise states that no passport verification is needed and recommends parcel forwarding services.
On Trustpilot, Mirocard states that KYC is currently not required to issue a card.
ForkLog reported in December 2025 that Helekets cards were issued without KYC.

Mirocard lists card programs from Singapore, Estonia and Hong Kong, including a card “for arbitrage and advertising” aimed at Facebook, TikTok and Google Ads.

The card issuance screen in a Mirocard account shows which networks are behind these programs.
The advertising card is offered with Mastercard BINs for Singapore and Hong Kong, including 559268.
The travel card is offered with the Visa BIN 493724 (Singapore), the subscriptions card with the Visa BIN 474362 (Estonia). We did not issue a card or make a deposit.

Asked about these findings, Mastercard said in a statement: “We want to be clear that so-called reloadable ‘no-KYC’ cards are not allowed on our network.” The company added that when it sees or is made aware of such allegations or activity, it investigates “in order to take action and ensure compliance with both local laws and our rules and standards”.
The statement does not address Mirocard or the BINs specifically.


4. Two companies: Handy Elect in Georgia, Байт Коммерц in Kyrgyzstan

Heleket names no legal entity anywhere on its website.
Its terms of service, AML policy and privacy policy (all dated 23 June 2026) refer only to “HELEKET” or the “Heleket platform”, with no company name, registration number or jurisdiction.
The governing-law clause points to “the applicable rules of private international law”.
TRM Labs identified the operator as Handy Elect LLC in Georgia without publishing a source.
The Georgian public registry confirms it.

Helekets Georgian company

The National Agency of Public Registry (NAPR) lists შპს ჰენდი ელექთ, Handy Elect LLC.
Its founding file, which the registry publishes as a scan, contains the application, the charter, a notarised power of attorney and a copy of the founders passport.
The charter gives lawyer@heleket.com as the contact address of the person in charge of management and representation.

FieldValue
Nameშპს ჰენდი ელექთ (Handy Elect LLC)
Identification code400429906
Application / registration23 April 2025 / 24 April 2025
Registered address (until August 2026)Tbilisi, Omar Khizanishvili St. 264, Tbilisi Technology Park Free Industrial Zone
Contact e-mail in the charterlawyer@heleket.com
Sole partner (100%) and directorRadik Akhmetov, a citizen of Kazakhstan, resident in Petropavlovsk
Declared activity“Any activity allowed by Georgian legislation”
VAT registration / Georgian bank accountBoth declined in the application
Status since 12 August 2026“Deficient company” (Art. 80, Law on Entrepreneurs)

Several details in the file are unusual:

  • The company came after the product.
    heleket.com was registered in February 2024 and, according to TRM, Heleket went live between January and March 2025. Handy Elect was founded in April 2025, after Heleket was already processing payments.
  • The founder never appeared in Georgia.
    He signed a power of attorney before a notary in Petropavlovsk on 2 April 2025. It authorises two Tbilisi registration agents to found a company “under any name”, choose its address, e-mail and phone number and appoint any person as director. His passport was issued on 28 February 2025, five weeks earlier.
  • A company without a bank account.
    The application declines both VAT registration and a Georgian bank account. The registered address is a free-industrial-zone address provided by the Tbilisi technology park, arranged by the same agent who filed the founding application.
  • The address was withdrawn in August 2026.
    On 11 August 2026 the technology park, as property owner, had the company’s registered address cancelled. On 12 August the registry classified Handy Elect as a “deficient company”.
    Under that status its registered data are suspended and the registry issues no extracts.
    Byte Commerce had been registered in Bishkek two days before the cancellation.

The documents show who is registered as owner and director.
They do not necessarily show who controls Heleket.
A founder from a provincial city, a freshly issued passport, a remote power of attorney and a company with no bank account fit the pattern of a nominee structure, but they do not prove it.
The timing in August may also be coincidental, for example an unpaid address service.
The founders personal data (passport and identification numbers, date of birth, home address) are part of the public file and are deliberately not reproduced here.



Why Heleket hides its company and Mirocard does not

Heleket has a company and does not mention it.
Mirocard and the Russian shops around it, name theirs.
The documents suggest why the two behave differently:

  • Nobody forces Heleket to name one.
    A crypto processor that settles in stablecoins needs no bank and no card network and its merchants do not ask. Handy Elect had no Georgian bank account.
  • A named company is a target.
    Cryptomus named Xeltox Enterprises in Canada and got a FINTRAC penalty. A company on the website gives regulators, courts and journalists a jurisdiction and a register to look in. The Georgian file above shows how much a register reveals.
  • Georgia regulates crypto services. Virtual asset service providers in Georgia must register with the National Bank of Georgia and since January 2026 registered providers must display that registration on their websites. Handy Elect appears neither among registered nor among cancelled providers in the NBGs register (version of 16 September 2026).
    Presenting it as Helekets operator would raise the question of why a Georgian company runs a crypto payment service without that registration.
  • Cards and Russian offers require a counterparty.
    Card issuers and program managers onboard a legal entity, not a brand. Russian consumer offers and payment aggregators expect a named seller or payment agent.
    That is where Byte Commerce appears. In Mirocards terms and in the offers of steam.ru, KZ Gift Card, Wayment and open-ps.ru.
    Even at Mirocard the name surfaced only by accident, through drafting notes left in the terms.
    The entity was prepared for partners, customers were never meant to see it.

In short, the company is named where a counterparty demands it and omitted everywhere else.


Mirocards Kyrgyz company

Mirocards AML policy names no company either.
The Terms of Use PDF does, by accident.

It opens with drafting instructions that were never removed:

1. In the definitions section, replace the generic definition of “Company” with: “Company” means ОсОО “Байт Коммерц”, a company incorporated and existing under the laws of the Kyrgyz Republic […]
6. Before publication, add the company’s registered address, registration number and other mandatory corporate details […]

The document was published with the notes and without the details.

The Kyrgyz Ministry of Justice register confirms the company:

FieldValue
NameОбщество с ограниченной ответственностью “Байт Коммерц”
Registration no.332531-3301-ООО
OKPO35162242
INN00908202610033
AddressBishkek, Leninsky district, ul. Turusbekova 109/3, non-residential premises 208
First registration09.08.2026
Participants1
Form (per osoo.kg)LLC with foreign participation
Activity (per osoo.kg)62.01.0 Software development
Budget payments 2026 (per osoo.kg)none

A few observations:

  • The company was registered after Mirocard had been operating for months. The legal entity was added retroactively, as with Handy Elect and Heleket.
  • Registration as a software developer matches the ToS construction: Mirocard claims to be a pure technology provider that does not provide financial services, holds no funds and issues no cards.
  • The company has a single participant with foreign participation per osoo.kg, no budget payments recorded in 2026 and a director listed without a patronymic.
    None of this establishes who controls the company.
    Handy Elect’s sole partner is a Kazakh national, whether Byte Commerce’s foreign participant is also from Kazakhstan is not known.
  • For context only: Kyrgyzstan is also where Grinex, the Garantex successor and Old Vector, the A7A5 issuer, are registered; both were sanctioned by OFAC and OFSI in August 2025. No connection between those entities and Byte Commerce has been established.

Byte Commerce is behind more than Mirocard

The Mirocard Terms name the company but no registration number.
Three other services name the company with the identical registration number 332531-3301-ООО and the same Bishkek address:

ServiceRole of Byte Commerce (self-declared)What the service does
steam.ru“Owner and operator” (about page, public offer)Steam wallet top-ups, games, subscriptions and “300+ services” for users whose “usual payment does not go through”. Payment via SBP, Russian/MIR cards, USDT, TRX.
KZ Gift Card (kzgiftcard.com)“The sellers payment agent” (offer, section 11)Kazakh Apple gift codes, paid by card or SBP, settled in Russian rubles.
Wayment (wayment.net)“Payment agent” (offer, preamble)Foreign virtual cards for customers in Russia, topped up via SBP or crypto, managed in Telegram. Operated by LVLUP LIMITED, Hong Kong, reg. no. 77106962, incorporated 25 September 2024 (Hong Kong Companies Registry weekly list).
open-ps.ruListed legal entity; payment-agent role stated belowopen-ps.ru sells PlayStation, Xbox, Steam and Nintendo games and subscriptions to customers in Russia, sourced from Turkish, Ukrainian and Indian store regions and paid via SBP and MIR cards.

Wayment is a second foreign-card product aimed at Russia, next to Mirocard, with the same Kyrgyz payment agent.
Its offer is marked “updated 3 February 2026”, six months before Byte Commerce was registered, so the company reference was added later without changing the date.

An agent relationship is not ownership and using Russian payment rails is not in itself a sanctions breach.
What the documents do show is that one newly registered Kyrgyz company sits at the payment layer of several services whose business is getting money out of Russia to foreign merchants.

Asked about the company, the National Bank of the Kyrgyz Republic stated that Byte Commerce “does not hold a license issued by the NBKR to carry out payment activities” and that payment services subject to licensing “may be carried out only upon obtaining the respective license from the competent authority”. For crypto-funded cards and virtual assets, the NBKR referred to the National Agency for Virtual Assets and Blockchain Technologies (NAVA).


5. Who pays through Cryptomus and Heleket

Merchants own payment pages, FAQs and privacy policies show what the processors are used for.
The pattern is consistent:
Services that supply account fraud and platform abuse, plus Russia-facing hosting.
The table counts only services that name the processor in their own material, technology-detection lists were excluded.

CategoryExamples (processor, own statement)
SMS activation / virtual numbersTIGER SMS (Cryptomus, next to Russian bank cards and SBP), Eveses, SMSCode, SMS Orange (Heleket), SMSPool (Cryptomus)
ProxiesOneDash Proxy (Heleket, RUB pricing, T-Bank), ProxyWing, Proxyma (Cryptomus)
HostingMgnHost (Heleket next to MIR and SberPay), DHosting (Heleket next to SBP/MIR), UFO Hosting (Heleket)
CAPTCHA solving, antidetectDeathByCaptcha (Heleket), GoLogin (Cryptomus)
Account shopsdark.shopping (Heleket, plus Russian card/SBP processors)
SMM panelsSMM Africa, SMMResellersHub (both processors)

Two cases stand out.
DeathByCaptcha announced Heleket support on 19 May 2026, a month after TRMs report and two days before Bithumbs block. Public reporting did not deter merchants from onboarding.
And DDoS-Guard, the Rostov-on-Don-based DDoS protection provider that KrebsOnSecurity has repeatedly linked to cybercrime and phishing sites, might have verified its main domain as a Cryptomus merchant project.
ddos-guard.net publishes the TXT record cryptomus=1a6d928a (checked via Google Public DNS on 22 September 2026; historical DNS data shows the record set since March 2024).
Only the owner of the DNS zone can set such a record.
It shows a merchant registration, not the volume or current use of payments.

Heleket uses the same verification format, a third-party DNS listing shows heleket=<8 hex characters> on a merchant domain.
Identical verification schemes are another sign of a shared codebase and a far better way to find merchants than technology-detection lists.

Accepting a processor does not make a merchant complicit.
Several services seen on detection lists, including VPNs used in Russia to bypass censorship, are legitimate and are deliberately not named here.
KrebsOnSecurity described Cryptomus merchant ecosystem in December 2024, the new element is Heleket taking over the same clientele.


Merchants that do not advertise it

The merchants above name Cryptomus or Heleket themselves.
Most merchants do not.
They can still be found, because both processors make every merchant prove ownership of its website before it can accept payments.
Helekets documentation lists four ways to do this:

  • A DNS TXT record,
  • a meta tag in the homepages HTML,
  • a file in the web root,
  • or, for Telegram bots, a code in the bots description.


The meta tag is the easiest to search for, because internet scanners index homepages.

<meta name="cryptomus" content="<8 hex characters>">
<meta name="heleket" content="<8 hex characters>">

By the way, a meta tag or DNS entry does not mean that verification has taken place, it simply means that the integration was planned.


A Censys search on 23 September 2026 returned 3.430 web properties carrying the Cryptomus tag and 1.569 carrying the Heleket tag.
The numbers count scan results and one site can appear several times under its domain, its IP address and different ports.
They still give a sense of scale and clientele.

We sorted the first 100 results of each search by what the site sells.
The two samples look alike:

CategoryWhat we found
Social media manipulationThe largest group by far: “SMM panels” selling followers, likes and views for Instagram, TikTok, Telegram and VK, many of them Russian-language (накрутка), many aimed at India
Phone numbers and verificationVirtual numbers for receiving SMS codes, eSIM shops, temporary email addresses sold explicitly “for OTP & verification codes”
Fake engagement and spamPurchased Google reviews, bought email lists, SMTP access, website traffic, tools that scrape and mass-add Telegram group members
Game cheatsAimbots and “anti-cheat bypass” tools, including hardware cheats for Counter-Strike 2
Gaming and digital goodsIn-game currency shops, game-server hosting, marketplaces for mods and accounts
Gambling and tradingCrypto casinos, betting sites, crypto arbitrage scanners
Hosting and proxiesVPS rental, including in Kyrgyzstan, proxy services, Telegram bot hosting
Russia-specificA service shipping parcels from the United States to Russia, paid via Cryptomus

Nine sites appear in both samples, meaning they have verified with Cryptomus and Heleket.
That does not show a common operator, since a merchant can use two processors.
But it does show that Heleket serves the same customer base as Cryptomus and that some merchants simply added the second brand.

The tag also works as an identifier.
The token in the content field belongs to one merchant account.
When the same token appears on several unrelated-looking domains, they were registered by the same account.
In our sample, one news site used a single Heleket token across more than a dozen language subdomains.
Applied to the full result set, this can group sites by operator.

Honest limits of my method:
The scan only finds merchants that chose the meta tag, so the real number of merchants is higher.
A tag shows that someone registered the site with the processor.
It doesn’t give us the information how much money flows through it or whether the account is still in use.
Our categories are based on page titles and a manual review of 200 results out of roughly 5,000.

Most of these businesses sit in a grey zone and many are legal where they operate.
What matters is the shape of the customer base.
It matches what KrebsOnSecurity described for Cryptomus in 2024 and it carries over to Heleket unchanged.


The phone numbers Heleket removed

Helekets contact page lists eleven business development and key account managers, each with an email address and a Telegram handle.
It lists no phone numbers (checked on 23 September 2026).
Googles search index still holds an older version of the same page.
In the snippets Google shows for the Russian, Uzbek and Kazakh language versions of heleket.com/contacts, most managers also have a WhatsApp number.

We recovered eight numbers this way. We mask the last digits here because the numbers may belong to individuals. The full values are in our evidence set.

Role on the old pageWhatsApp numberCountry / area
Head of Business Development+43 678 443xxxxxAustria, mobile
Key Account Manager+43 678 443xxxxxAustria, mobile
Business Development Manager+372 592xxxxxEstonia, mobile
Business Development Manager (no longer listed)+372 592xxxxxEstonia, mobile
Business Development Manager+1 213 xxx xxxxUSA, Los Angeles
Key Account Manager+1 713 xxx xxxxUSA, Houston
Key Account Manager+1 253 xxx xxxxUSA, Tacoma
Key Account Manager+1 647 xxx xxxxCanada, Toronto

Three details stand out.

  • Numbers come in pairs
    The two Austrian numbers share the prefix +43 678 443, the two Estonian numbers share +372 592.
    Consecutive or near-consecutive numbers usually come from the same provider and the same order.
    Two “managers” with numbers from one batch fits the picture of personas run by a small team.
  • The page changed
    In the old version, the Head of Business Development was followed by a manager who no longer appears.
    That slot now belongs to a manager who never had a number in any snippet we found.
    The numbers were removed at some point before 23 September 2026.
    We have not been able to date the change precisely.
  • One number is Canadian
    A Toronto number on the contact page of the service TRM Labs links to Cryptomus sits oddly with the fact that Canadas regulator fined Cryptomus in 2025.

What we have not done:
We did not call or message any of these numbers and we have not checked whether they are mobile SIMs or virtual numbers.
Search engine snippets are also weaker evidence than an archived copy of the page, because Google does not show when it captured the text.
We therefore treat the numbers as a lead.
If the Austrian numbers are regular SIM cards, whoever holds them had to identify themselves to the carrier, since Austria requires registration of all SIM cards.
That makes them useful to authorities in a way they are not to us.

open-ps.ru: two companies on the same page

open-ps.ru sells games and subscriptions to customers in Russia.
Its contact page now lists Byte Commerce under “Юридическое лицо” – “Legal entity”, alongside registration number 332531-3301-ООО and the same Bishkek address used by the other services in this investigation.
Presented as the shops business details, this gives the impression that Byte Commerce is the company behind the service.

The paragraph immediately below describes a narrower role.
A payment agent collecting and processing customer payments under an agreement with the seller.
The page therefore places Byte Commerce in its company-details block while describing an agency relationship with a separately referenced seller.
It establishes a declared business connection, but does not clearly identify Byte Commerce as the shops owner or operator.

The earlier contact page, captured by the Wayback Machine on 9 May 2026, named a Russian sole proprietor registered in Saint Petersburg in February 2022, with a Russian tax number (INN) and registration number (OGRNIP).
The current footer still names that proprietor and carries the same identifiers, while the contact section above presents Byte Commerce.

This leaves two entities on the same page.
A Russian sole proprietor in the footer and the Kyrgyz company connected to Mirocard in the business-details block.
The payment-agent wording could explain their coexistence, but the page does not clearly assign responsibility for operating the shop.
We found no evidence connecting the sole proprietor to Cryptomus, Heleket or Mirocard beyond this documented relationship with Byte Commerce.

[open-ps.ru/contacts, Wayback Machine snapshot of 9 May 2026]

Today, the contact section names ОсОО «Байт Коммерц», registration number 332531-3301-ООО, with an address in Bishkek. It lists the company under “Legal entity”, while the paragraph below describes its role as a payment agent acting for the seller.

The footer still names the Russian sole proprietor and carries the proprietors twelve-digit Russian tax number, which belongs to the previously listed operator; Byte Commerces own Kyrgyz INN is 00908202610033.
The page now presents Byte Commerce in its business details while retaining the Russian proprietors details below.
The agency wording could explain why both appear, but the page does not clearly distinguish who operates the shop from who processes its payments.

[open-ps.ru/contacts today, captured 23 September 2026]

At the time of writing, the footer on the sites homepage still names the sole proprietor.

Byte Commerce was registered on 9 August 2026, so the switch happened between May and September 2026.
The same pattern of an old entity in one place and Byte Commerce in another appears on Wayment, whose offer page names Byte Commerce under a date six months before the company existed.

What this shows is limited.
The shop may have been sold.
Its operator may now use Byte Commerce as a legal and payment front, which is a common arrangement for Russian sellers since 2022.
Or the people behind Byte Commerce may have run the shop all along.
We found no evidence linking the former operator to Heleket, Mirocard or Cryptomus.
What open-ps.ru does show is how Byte Commerce appears on Russian shops: as a name swapped into an existing page, without the rest of the page being changed.

A special rate for Russian exchange offices

Russia has a large market of online exchange offices, known as obmenniki, that swap rubles from Russian bank cards or SBP transfers for crypto and back.
Aggregators such as BestChange list hundreds of them.
Most do not build their own software, they run on ready-made exchange scripts and Premium Exchanger is one of the most widely used.

Premium Exchanger’s documentation includes a ready-made Heleket module.
It opens with an invitation:

«Для подключения к сервису и получения специального тарифа для обменника, свяжитесь с представителем сервиса Heleket в Телеграм.»

“To connect to the service and get a special rate for your exchange office, contact a Heleket representative on Telegram.”

The guide walks an exchange operator through creating a Heleket merchant, verifying the domain and entering the API keys.
The module can issue a temporary address for each order or a permanent address per customer and can convert incoming coins to USDT automatically.
A note dated 23 June 2025 about a new USDT TRC20 fee shows the module was in use within six months of Helekets launch.
Premium Exchanger also sells a merchant and auto-payout module for Cryptomus.

This matters because exchange offices are where money from Russian bank accounts enters crypto.
A payment processor that offers them a dedicated rate and a plug-in module is building that bridge on purpose.
It is also the point where Helekets own AML policy, which lists Russia as a prohibited jurisdiction and its business practice are furthest apart.

For Cryptomus, the link is documented.
In December 2024, KrebsOnSecurity named several Russian exchange offices that used Cryptomus to turn crypto into rubles, among them Casher, Grumbot, Flymoney, Obama and Swop.

For Heleket, the traces so far come from customer reviews on BestChange.

In January 2026, a customer of the exchange office ObmenGuru named Heleket as the intermediary in a payment and an account marked as the operator confirmed on BestChange that it was in contact with Heleket about the case.
ObmenGuru lists Ukraine as its location.
Complaints about at least three other exchange offices name Heleket as the processor or counterparty, but without a visible confirmation from the operator.

In that case, Heleket froze the customers funds for about a week for an AML review, so the processor does run checks.

What we have not established:
How many exchange offices use Heleket and how much money passes through them.
A module in the documentation and a handful of customer reports show that Heleket targets this market, but they do not show volume.
A payout from a Heleket wallet to an exchange office also does not prove the office is a Heleket merchant.
Exchange offices have to verify their domains like any other merchant, so the method described above can identify them.


Iranian shops carrying the tags

FINTRAC found more than 7,500 transactions originating from Iran that Cryptomus failed to report and TRM Labs counted over 75,000 transactions between Cryptomus and Iranian exchanges.
Both Cryptomus and Heleket list Iran as a prohibited jurisdiction.

The tag search also returned shops that identify themselves as Iranian businesses through Iranian government trust seals (Enamad, Samandehi) and Iranian payment gateways.
Two examples: Shiznumber, a virtual-number shop that lists “bypassing sanctions” as the first use case on its homepage, carries a Heleket tag.
FastKeys (fastkeys.ir), a shop for Steam keys priced in toman, carries a Cryptomus tag.

As noted above, a tag shows that a site was set up for the processor, but we do not know if the verification was completed, that the account is active or that any payment went through and we made no purchases.
We asked both processors how their onboarding treats these shops, neither had responded by the time of publication.

6. The pattern

StageBrandLegal entityPossible Trigger
1CryptomusXeltox Enterprises Ltd., Canada (mailbox address)Sanctions & Money
2Heleketnone named, identified as Handy Elect LLCKYC pressure (Feb 2025), later FINTRAC fine
3Mirocard (plus steam.ru, KZ Gift Card, Wayment as agent, open-ps.ru)ОсОО “Байт Коммерц”, KyrgyzstanTRM report (Apr 2026), Bithumb block (May 2026)

Each step reduces regulatory exposure.
Canada brought an MSB registration and, with it, a supervisor that eventually issued a fine.
Heleket answered by naming no entity at all.

For card programs, issuers need a contracting party, so a company had to reappear, this time in a jurisdiction with a permissive crypto framework, registered as a software developer.

The camouflage is built to pass formal onboarding checks.
An AML policy, a country list, a legal entity.
It is not built to withstand anyone comparing documentation, page source, DNS and sitemaps side by side.
The operators appear to be optimizing for speed and customer continuity.

A comparable relaunch pattern played out with Garantex and Grinex, where OFAC eventually designated the successor for acting on behalf of the sanctioned predecessor.


Why This Is Important

Part of this business runs on European and US infrastructure.
The hosting addresses identified in this research are listed in the Netherlands, under Serverels US-operated network.
All three brands use Cloudflare nameservers and Google mail infrastructure and all three authorise Mailgun in their SPF records.
Western providers are supplying ordinary commercial services to businesses whose Russian-language pages explain how to get around restrictions on international payments.

Heleket publishes a Russia ban alongside instructions for paying from Russia.
Mirocard describes a KYC programme in its policies while advertising cards without passport verification.
Its guides also recommend using a random US billing address.
A partner reviewing the English compliance documents would get a considerably different impression from a customer reading the Russian sales pages.

Overcoming payment restrictions is an advertised feature of these services.
Heleket explicitly promotes payments without sanctions-list screening and addresses exporters and importers affected by sanctions and SWIFT restrictions.
Mirocard complements that pitch with crypto-funded cards advertised without identity verification and guides recommending misleading billing details to access foreign services from Russia.
Taken together, the marketing, product features and instructions support a clear conclusion:
A substantial part of this offering is deliberately aimed at making financial and platform restrictions easier to circumvent, including obstacles arising from sanctions.

The published AML policies need to be assessed against that sales pitch.
Card issuers and payment partners should establish how customers are identified, how the stated country restrictions are enforced and how sanctions screening works when the absence of checks is itself used to attract business.
A specific sanctions violation still requires evidence of a prohibited transaction under the applicable rules.
What is already documented is the commercial proposition.
Helping customers regain access where ordinary payment channels refuse them.
European and US providers supporting these services have concrete grounds to examine what their infrastructure and financial products are enabling.



Requests for comment

Before publication, the companies, card networks and supervisors below were sent the findings concerning them in late September 2026, with specific questions and a deadline of 5 October 2026.

RecipientAsked aboutResponse
HeleketHandy Elect LLC, ownership, licensing, Russia and Iran exclusions, MirocardNo response
MirocardByte Commerce, card issuers, no-KYC advertising, US billing-address guidanceNo response
CryptomusRelationship to Heleket and Mirocard, shared documentation and infrastructureNo response
MastercardMastercard BINs offered by Mirocard, no-KYC advertisingStatement, see below
VisaVisa BINs offered by Mirocard, no-KYC advertisingNo response
National Bank of the Kyrgyz RepublicLicensing of Byte CommerceStatement, see below
Financial Market Supervision Service, KyrgyzstanVirtual asset licensing of Byte CommerceRegistered on 2 October 2026 (incoming no. 14188), no response
National Bank of GeorgiaVASP registration of Handy Elect LLCNo response

“No response” means no reply had been received by the time of publication. Responses received later will be added to this article.

Mastercard

“We take seriously our responsibility to maintain strong governance standards through a comprehensive compliance program and strong internal controls. Mastercard’s franchise standards require that customers must not engage in illegal activity. We use a combination of the latest technologies and best practices to monitor, analyze and understand the activity on our network and take action as necessary.

We want to be clear that so-called reloadable “no-KYC” cards are not allowed on our network. We have zero tolerance for unlawful activity on our network. When we see or are made aware of such allegations or activity, we investigate in order to take action and ensure compliance with both local laws and our rules and standards.”

National Bank of the Kyrgyz Republic

“ОсОО «Байт Коммерц» (Byte Commerce LLC) does not hold a license issued by the NBKR to carry out payment activities. […] In accordance with the legislation of the Kyrgyz Republic, activities in the field of payment services that are subject to licensing may be carried out only upon obtaining the respective license from the competent authority.”

For crypto-funded cards and virtual assets, the NBKR referred to NAVA, the National Agency for Virtual Assets and Blockchain Technologies under the President of the Kyrgyz Republic.

FINTRAC

The findings were submitted to FINTRAC, Canadas financial intelligence unit, on 25 September 2026.


Methodology

All findings are based on publicly accessible websites, documentation, DNS records, public registers and published reports, retrieved between 22 and 30 September 2026.
Individuals are named only where they are public office holders of the operating companies in official registers or cited in published reporting.
Private individuals who appear in the material without being part of the operating structure are not named.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *