OFAC Sanctions List: Crypto Addresses and Sanctioned Entities Explained

OFAC Sanctions List: Crypto Addresses and Sanctioned Entities Explained

You send Bitcoin to a friend. It’s a simple transaction. But what if that wallet address is on the OFAC sanctions list? Suddenly, your bank freezes your account, or your exchange blocks the transfer. This isn’t hypothetical. As of 2025, the Office of Foreign Assets Control (OFAC) has designated over 1,200 cryptocurrency wallet addresses as prohibited for U.S. persons. These aren't just random strings of characters; they are digital fingerprints linked to money laundering, terrorism financing, and sanctions evasion.

If you’re in crypto, ignoring this list is like driving blindfolded. The rules have tightened significantly since 2024. We need to look at who is actually on these lists, how the technology tracks them, and why a single transaction can land you in regulatory hot water.

Who Is Actually On The List?

The core of OFAC’s enforcement power lies in the Specially Designated Nationals (SDN) list. Historically, this list targeted banks and corporations. Now, it targets code. When OFAC adds a crypto address, it effectively blacklists every dollar that touches that wallet. If you interact with it, you might be "tainted."

It’s not just about individuals anymore. In January 2025, OFAC expanded its criteria to include Decentralized Autonomous Organizations (DAOs). This was a massive shift. Previously, regulators struggled to sanction a protocol without a CEO. Now, if a DAO’s treasury holds assets from sanctioned entities, the entire organization faces restrictions. This move signals that decentralized doesn’t mean unregulated.

Consider the case of Garantex, a major Russian crypto exchange. After being sanctioned, it didn’t disappear. Instead, it tried to pivot through a successor platform called Grinex. OFAC caught this quickly. By March 2025, authorities seized over $26 million in assets controlled by Garantex. This shows that renaming a business or changing its frontend doesn’t hide the underlying blockchain activity.

The Tech Behind The Tracking

How does OFAC keep up? They don’t manually check every block. They rely on sophisticated software. The sanctions database is maintained in XML format, specifically through the `sdn_advanced.xml` file. Compliance tools parse this data to flag transactions in real-time.

In May 2025, OFAC launched Blacklist v2.0. This update wasn’t just cosmetic. It added support for Layer 2 networks like Arbitrum and Optimism. Before this, many sanctioned actors moved funds off-chain to avoid detection. Now, the monitoring extends to these scaling solutions. Platforms like Scorechain updated their systems within 15 minutes of the release. That speed is critical. A delay of even an hour could allow millions in illicit funds to slip through.

Three new wallet screening technologies were endorsed in March 2025, focusing specifically on DeFi platforms. These tools analyze smart contract interactions, not just simple transfers. They look for patterns that suggest mixing services or tumblers, which are often used to break the link between source and destination.

Coverage Across Blockchains

Many users assume sanctions only apply to Bitcoin. Wrong. The current framework covers 17 different cryptocurrencies. This includes the big names like Bitcoin (BTC) and Ethereum (ETH), but also privacy coins and stablecoins.

Key Cryptocurrencies Covered by OFAC Sanctions
Cryptocurrency Symbol Primary Use Case in Sanctions Context
Bitcoin BTC/XBT Store of value; primary target for large-scale laundering.
Ethereum ETH Smart contracts; used for complex DeFi laundering schemes.
Tether USDT Cross-border transfers; frozen $450M in Iranian-linked assets in 2025.
Monero XMR Privacy coin; harder to trace, but still subject to exchange bans.
Tron TRX High volume; heavily used in Asian markets and oil sales proceeds.

Stablecoins are particularly interesting here. In March 2025, Tether froze $450 million linked to sanctioned Iranian entities. Because stablecoins are centralized, issuers can freeze balances directly. This makes them less attractive for sanctioned entities compared to truly decentralized assets, but they remain popular for quick cross-border settlements due to their liquidity.

Retro futuristic AI tools scanning and locking down cryptocurrency flows.

New Frontiers: AI and Smart Contracts

The landscape changed again in February 2025. OFAC sanctioned the first AI-powered autonomous trading bot. This bot was used by a sanctioned entity to launder $60 million. It represents a new frontier: non-human agents executing financial moves. If an algorithm buys and sells tokens to obscure the origin of funds, who is liable? OFAC says the owner of the bot is responsible.

Proposed regulations from May 2025 take this further. They aim to hold smart contract developers liable for enabling sanctions evasion. If you write code that allows a sanctioned wallet to interact with your DeFi protocol, you could face penalties. This hasn’t been fully approved yet, but it’s casting a shadow over the development community. Developers are now auditing their contracts against the SDN list before deployment.

Real-World Impact: Lazarus Group and Iran

Let’s look at specific examples. The Lazarus Group, a North Korean hacking collective, stole $200 million in Q1 2025 via sanctioned DeFi protocols. They exploited vulnerabilities in decentralized exchanges to siphon funds. Because these protocols were already flagged or closely monitored, tracing the stolen assets became a priority for global law enforcement.

Another case involves Iranian nationals Alireza Derakhshan and Arash Estaki Alivand. Designated in September 2025, they processed over $100 million in Iranian oil proceeds using Ethereum and TRON wallets. Their total inflows exceeded $600 million. This highlights how state-level actors use multiple chains to diversify risk. If one chain is blocked, they move to another. OFAC’s multi-chain coverage aims to close these gaps.

Even election interference operations have gone crypto. SECONDEYE SOLUTION, linked to the Internet Research Agency, used specific Bitcoin addresses like `1NE2NiGhhbkFPSEyNWwj7hKGhGDedBtSrQ`. These weren’t just for buying ads; they were part of a broader funding network. Monitoring these addresses helps analysts track influence campaigns funded by digital assets.

Anthropomorphic crypto coins on trial with hackers and global maps in background.

Compliance: What You Need To Do

If you run an exchange or a service provider, compliance is no longer optional. You must implement real-time screening. The industry standard is updating your watchlist within 15 minutes of an OFAC release. Missing this window means you might process a prohibited transaction.

Here is a checklist for staying compliant:

  • Integrate XML Feeds: Connect your system to OFAC’s `sdn_advanced.xml` feed automatically.
  • Screen All Chains: Don’t just check BTC and ETH. Include USDT, TRX, and other covered assets.
  • Monitor DeFi Interactions: Track calls to smart contracts, not just token transfers.
  • Assess Risk Scores: Use tools that assign risk scores to addresses. High-risk addresses require manual review.
  • Train Your Team: Staff should understand why a transaction was flagged. False positives happen, but ignoring true positives is costly.

The learning curve for implementing these systems is typically 3-6 months. It requires both technical infrastructure and specialized personnel. Smaller projects often outsource this to providers like Chainalysis or Elliptic, who maintain the databases and provide API access.

International Coordination

OFAC doesn’t work alone. In 2024, joint raids with Interpol and Europol hit six international crypto hubs. This coordination is increasing. A joint directive with the Financial Action Task Force (FATF) in April 2025 standardized enforcement approaches globally. This means a sanctioned address in the U.S. is likely to be blocked in Europe and Asia too.

This multilateral approach reduces the chance of arbitrage. Sanctioned entities can’t simply move their operations to a jurisdiction with laxer rules. The net is tightening worldwide.

Future Outlook

Expect more expansion. Privacy coins like Monero are under scrutiny because they resist tracking. However, exchanges are delisting them rather than banning the coin itself. This creates a two-tier market: regulated exchanges ban privacy coins, while peer-to-peer markets continue to trade them, albeit with higher risk premiums.

Layer 2 networks will see increased surveillance. As users migrate to cheaper chains, OFAC’s Blacklist v2.0 ensures they aren’t left behind. The goal is seamless coverage across all layers of the stack.

What happens if I accidentally send crypto to a sanctioned address?

If you send funds to a sanctioned address, the recipient may not be able to cash out. For you, the risk is that your wallet becomes "tainted." Exchanges may freeze your account until you prove the transaction was unintentional. Using a reputable compliance tool beforehand can prevent this.

Are all stablecoins covered by OFAC sanctions?

Major stablecoins like USDT and USDC are covered. Because they are centralized, issuers can freeze funds directly upon request from OFAC. Decentralized stablecoins are harder to control but are increasingly subject to indirect pressure through exchange listings.

Can I use a mixer to evade sanctions checks?

Mixers obscure the trail, but advanced analytics can still detect patterns. Many exchanges refuse deposits from known mixers. Relying solely on a mixer is risky; compliance algorithms often flag post-mixer addresses as high-risk.

Does OFAC sanction individual miners?

Generally, no. OFAC targets entities and addresses involved in illicit finance. Miners receive rewards from the network protocol. Unless a miner’s payout address is explicitly linked to a sanctioned entity, they are usually unaffected. However, exchanges selling mined coins must screen the seller.

How often is the OFAC crypto list updated?

The list is dynamic. New designations can occur daily. Automated systems pull updates every 15 minutes. Manual checks are insufficient for businesses; real-time API integration is necessary for compliance.