What Dubai published on 24 July

VARA's notice names the entity, the trading names it used and three breaches, and it publishes no figure for the penalty. The Virtual Assets Regulatory Authority issued a notice of fines on 24 July 2026 against Shelbit General Trading L.L.C, which operated commercially as Shelbit and Shelbit Exchange. The regulator set out that the entity was identified as continuing to provide virtual asset services to customers in and from Dubai without holding a valid regulatory licence, to onboard users without the Know-Your-Customer checks UAE law requires, and to market its services in Dubai without authorisation. In consequence, VARA said it had exercised enforcement measures, imposed financial penalties on the entity, and directed it to cease and desist immediately from all unlicensed virtual asset activity in or from Dubai.

The word carrying the weight in that notice is "continuing." That is not how a regulator writes about something it has just found. It is how a regulator writes about something it has already ordered stopped, and then watched not stop. The notice says so directly in its own opening: the action follows the cease-and-desist notice of 2 January 2025. Everything useful in this story sits in the distance between those two dates.

The first order was public eighteen months earlier

The gap between the order to stop and the published fine is 568 days. A cease-and-desist notice went out on 2 January 2025. The notice of fines followed on 24 July 2026. In between sits a year and a half in which the entity was, on the regulator's own account, still onboarding users and still marketing in Dubai. Reuters reported that hundreds of millions of dollars in additional funds were processed in the months after that first order.

It is worth being precise about what the first notice was and was not. It was a public statement, at a public address, naming a specific legal entity and its trading names. Anyone running a check on the name Shelbit on 3 January 2025 would have found it. It was not, on the evidence of what followed, a mechanism that removed the entity from the payments landscape. A regulator can publish; it cannot unplug.

That distinction is unglamorous and it is the whole practical lesson. The register is a record of what the regulator has said. It is never a record of what the counterparty has done since. Firms routinely treat the two as the same thing because a name either appears on a list or does not, and that binary is easy to automate. The binary is real. What it means is not what most onboarding flows assume it means.

The register dates its own lag

VARA's public notices page carries the timestamps that prove the pattern, and they are not hard to read off. On 5 March 2026 the authority published warnings naming MEXC Estonia OU and MEXC Global LTD in one notice, and Phoenixfin Pte Ltd, MEK Global Limited, Peken Global Limited and KuCoin Exchange EU GmbH in another. Fines followed against MX Global LTD, trading as MEXC, on 22 June 2026, and against Peken Global Limited, trading as KuCoin, on 24 June 2026. That is 109 and 111 days from the warning to the penalty. CoinMENA FZE was fined on the same June date as MEXC.

Three months is a fast turn by the standards of financial enforcement, and none of this suggests the authority is idle. The point is narrower and it survives the compliment: even when a regulator moves briskly, there is a measurable window in which a named entity is named and nothing else has happened to it. For Shelbit that window ran to eighteen months. For the June cases it ran to roughly a quarter.

So the question a European operator should ask of its own process is not whether it screens against enforcement registers. Almost everyone does. It is how often, and against what. A quarterly re-screen and a 109-day enforcement cycle are the same interval, which means a quarterly cycle can miss a full escalation between two passes.

What Reuters traced through it

The investigation published on 31 July 2026 describes an exchange functioning as a junction rather than a destination. Reuters reported that Shelbit, run by an Iranian expatriate named Siavash Kayvanpour, sat at the centre of flows of at least USD 4 billion moved since May 2024, connecting an illegal gambling network of more than two thousand platforms, the Central Bank of Iran, and other sanctioned Iranian entities to global crypto markets. The Central Bank of Iran has been under US sanctions since 2019. An earlier Reuters investigation preceded US sanctions on the Iranian exchange Nobitex.

Attribution matters here and the reporting is careful about it. Investigators quoted in the piece assess the operation as run by the Islamic Revolutionary Guard Corps, but Reuters stated plainly that it could not determine whether the Guard Corps directly controlled either Shelbit or the gambling network. That is an unresolved question, not a finding, and anyone summarising this internally should carry the hedge across rather than round it up.

The most instructive detail for an operator is Binance's response. The platform said Shelbit had never held an account with it and that the associated transactions were not flagged as high risk, while stating that it had investigated users, frozen accounts and reported findings to law enforcement. Read that carefully. Exposure arrived through users, not through a named commercial relationship. A check that asks only whether you have a contract with a listed entity would have returned a clean answer at every step.

A name on a list is not a state of the world

The practical instruction is to date your checks and repeat them, because the register you are checking is itself a lagging record. Note the date you screened a counterparty and the date of the most recent notice you saw. If those two dates are months apart, you have not verified a counterparty; you have verified what a regulator had published by the time you last looked. For European firms the same discipline applies on the home side, where authorisation under the Markets in Crypto-Assets Regulation is recorded by national competent authorities and collated at EU level, and where the register answers the same narrow question: what has been decided, not what is happening now.

The second instruction follows from the Binance answer. Ask who your counterparty's counterparties are, because that is where this particular exposure travelled. A firm can hold no relationship at all with a named entity and still process its flows through customer accounts. Screening the name on the contract is the shallowest check available, and in this case it was the one that returned nothing.

None of this requires new tooling or a larger compliance budget. It requires treating a register entry as evidence with a timestamp on it, which is what it has always been. The January 2025 order sat in public for 568 days doing exactly the job it was built to do, which was to inform anyone who looked. What it never did, and was never able to do, was stop the money.