A payments firm processes a digital-asset transfer routed through a non-custodial wallet. The compliance team flags the destination address. It matches a wallet associated with a designated person on the SDN List (OFAC's list of Specially Designated Nationals and blocked persons). The transaction settles before the alert clears the queue. What are the firm's obligations now? How does it report, and to whom?
Crypto and VASP sanctions compliance under OFAC rules is governed by the same statutory and regulatory authority that applies to conventional finance – principally IEEPA and TWEA. OFAC treats virtual currency as property. A VASP (virtual asset service provider, meaning any business that exchanges, transfers, or holds virtual assets on behalf of others) must screen transactions, block or reject dealings involving SDN-listed addresses, and report to OFAC. The ownership test – 50 percent or more – applies to virtual-asset addresses just as to conventional accounts.
As of mid-2026, OFAC has made clear that the nature of the underlying technology does not alter the substantive obligations. This briefing sets out who administers the regime, what the prohibitions are, how the ownership and control analysis works for digital assets, what the key risk flags look like in practice, and when cross-border complexity requires counsel.
Who administers OFAC crypto and VASP sanctions compliance – and what is the legal basis?
OFAC, a bureau of the US Treasury, administers the economic-sanctions programmes that catch virtual-asset activity. Its authority rests on IEEPA and TWEA, with programme-specific executive orders layered on top. Congress has not enacted a separate digital-assets sanctions statute; the existing authority extends to any property or property interest in which a designated person has an interest, and OFAC has confirmed that virtual currency constitutes property for this purpose.
The Bank Secrecy Act (BSA) adds a parallel layer. FinCEN classifies certain VASPs as money-services businesses, which carries its own recordkeeping and reporting obligations. OFAC and FinCEN are distinct authorities and distinct reporting channels. A VASP that conflates them – treating a FinCEN suspicious-activity report as a substitute for an OFAC blocked-property report – misunderstands its obligations. We regularly advise firms that have discovered this gap after an internal audit.
The legal environment extends further. The Financial Crimes Enforcement Network's travel rule requires certain originator and beneficiary information to accompany transfers above a threshold. OFAC obligations and travel-rule obligations interact: a VASP cannot pass accurate beneficiary data to a receiving institution if the beneficiary is an SDN and the transaction should have been blocked at source.
What does OFAC prohibit in relation to virtual assets and digital wallets?
OFAC's prohibitions in the virtual-asset context mirror its prohibitions for conventional finance: US persons and entities subject to US jurisdiction may not deal with SDN-listed persons, blocked property, or jurisdictions subject to comprehensive sanctions, regardless of the form that property takes. A blocked wallet address is blocked property. A transaction that moves value to or from a blocked address is a prohibited transaction.
Three specific prohibitions are worth unpacking for a VASP compliance team. First, the dealing prohibition: executing, facilitating, or approving a transfer to or from a blocked address. Second, the evasion prohibition: this is distinct from circumvention advice, which we do not provide – it is the legal standard that catches attempts to structure transactions so as to avoid the dealing prohibition. Third, the property-receipt prohibition: receiving blocked property, even if the recipient did not initiate the transaction.
Can a VASP rely on the argument that a blockchain transaction is irreversible and therefore beyond its control? OFAC's published guidance makes clear the answer is no. The obligation is to screen before the transaction executes, not after. Post-execution realisation that a counterparty is listed does not undo the violation. What it opens is a question about whether the VASP has a voluntary self-disclosure obligation – and on that question, timing matters acutely.
How does the 50 percent rule apply to digital-asset addresses and wallet structures?
The 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked, whether the ownership is direct or indirect) applies in the virtual-asset context with the same mechanical logic it applies to corporate counterparties. Where a blocked person owns or controls a wallet, that wallet is blocked property. The beneficial ownership of the wallet, not its technical architecture, determines the analysis.
This creates a practical problem that differs from corporate screening. In conventional finance, a compliance team runs a counterparty legal entity through an ownership database. In virtual-asset compliance, attribution of a wallet address to a natural person or entity requires different data sources: blockchain analytics, on-chain clustering, KYC information gathered at onboarding. OFAC has designated specific wallet addresses and has listed them on the SDN List alongside conventional entries. OFAC's Specially Designated Nationals and Blocked Persons List now carries digital-currency address identifiers as part of an SDN entry.
The control question also arises. Where a designated person does not own a wallet outright but exercises control over it – for instance, through a smart contract or multi-signature arrangement – OFAC's authority to treat that wallet as blocked property is not extinguished. The analysis requires facts; a VASP cannot simply note that the nominal wallet holder is not itself listed and stop there. In our cross-border practice, we have seen this issue surface in DeFi contexts where the connection between a designated person and a protocol's administrative keys is indirect but documentable.
What are the key risk flags that a VASP compliance programme must catch?
Effective crypto and VASP sanctions compliance under OFAC rules requires a compliance programme that is calibrated to the transaction patterns that generate risk. The following are the categories we see most often when reviewing a firm's screening architecture.
- Address-only screening gaps. A firm that screens counterparty names but not wallet addresses misses the most direct form of OFAC designation for digital assets. OFAC's SDN List entries for virtual currency carry explicit address identifiers; a programme that ignores them is structurally incomplete.
- Aggregation failures under the 50 percent rule. Two listed persons, each holding below 50 percent of an entity or wallet structure, reach the threshold jointly. Screening tools that check each holder individually and independently will not surface this.
- Nested-exchange risk. A VASP that processes transfers originating from another exchange that itself has weak sanctions controls can receive transactions that were prohibited upstream. The downstream VASP may have received blocked property without initiating the prohibited dealing.
- Mixer and obfuscation detection. Transactions routed through mixing services or privacy protocols present elevated risk. OFAC has taken enforcement action in connection with mixing services. A VASP that accepts funds of unknown origin bears the risk that some of that value is blocked property.
- Inadequate IP and geolocation screening. A VASP operating online cannot rely solely on KYC documentation. IP-address screening, device-fingerprint analysis, and geolocation data are relevant controls where a customer may be accessing from a comprehensively sanctioned jurisdiction.
- Token-transfer contract interactions. Smart contract interactions are transactions in OFAC's view. A VASP that deploys or operates a smart contract that executes transfers on behalf of users is a party to those transfers for sanctions-compliance purposes.
The position above covers the standard screening architecture. Your specific facts – the asset class, the jurisdiction of the counterparties, the custody model, the on-chain architecture – change the analysis materially. Early-stage programme design with counsel prevents the more costly correction work that comes after a screening failure.
For a review of your VASP compliance architecture or an assessment of exposure under OFAC's crypto sanctions rules, contact Calder & Vance at info@caldervance.com.
How does OFAC enforce against VASPs, and what does a voluntary self-disclosure achieve?
OFAC enforces the same sanctions rules against VASPs that it applies to banks and conventional money-services businesses. The enforcement tools are civil monetary penalties – calculated by reference to the transaction value, with significant multipliers for egregious cases – and, where the matter involves wilful conduct, referral to the Department of Justice for criminal prosecution. OFAC may also issue a cautionary letter or a finding of violation without a penalty in cases where the violation is not egregious and cooperation was prompt.
A VSD (voluntary self-disclosure to OFAC) remains one of the most significant risk-management tools available. OFAC's enforcement guidelines describe a VSD as a factor that can reduce the base penalty amount by a substantial proportion. The reduction is not automatic and does not apply where the disclosure is made only after OFAC has already opened an investigation. Timing is everything. The moment a VASP identifies a probable violation, it faces a decision about whether to disclose – and that decision should be made with counsel, not deferred until the internal investigation is complete.
OFAC also has the ability to designate VASPs themselves as SDNs – and has done so. A VASP designated as an SDN is blocked property for US persons. Its counterparties, including other exchanges and payment processors, face immediate exposure. A VASP that operates without an adequate compliance programme faces not only penalty risk for individual violations but designation risk as an entity whose services are found to be used for prohibited purposes.
If a transaction has already been flagged, or if a filing has been refused or a notice received, an early review can preserve options that narrow materially with time. Contact Calder & Vance at info@caldervance.com for a confidential assessment of the position.
How does the OFAC regime for crypto compare with OFSI and EU requirements?
The cross-border dimension of VASP sanctions compliance is where exposure multiplies fastest. A VASP that operates in the United Kingdom and the United States faces two sets of obligations that overlap on substance but diverge on mechanics and enforcement posture.
Under OFSI (the UK Office of Financial Sanctions Implementation), the financial-sanctions regime applies to virtual assets. OFSI administers the UK's autonomous sanctions programmes under SAMLA and the relevant thematic regulations. The ownership and control test under the UK regime differs from OFAC's mechanical 50 percent rule: OFSI applies an ownership and control test (the UK and EU test for whether a non-listed entity is caught through a listed person) that can capture a non-listed entity even below the ownership threshold where a listed person exercises effective control. For a VASP with a governance structure that gives a designated person significant influence over operations, the UK test may produce a different result from the OFAC analysis.
The EU regime mirrors the UK's control-based analysis in this respect. Under the relevant Council Regulation, an entity owned or controlled by a listed person is subject to the asset-freeze. Control is assessed by reference to the ability to direct decisions. Both the EU and the UK approaches require a qualitative judgment that OFAC's quantitative rule does not.
What does this mean for a VASP? A counterparty analysis that clears under OFAC because the listed person's stake is below 50 percent may not clear under OFSI or the EU test. And where a VASP operates in multiple jurisdictions, the stricter prohibition governs for the transactions within that jurisdiction's reach. Convergence between the major regimes on the substantive outcome – blocking the same designated entity – can disguise divergence on the analysis required to reach that outcome.
For regimes outside the US, UK, and EU, the analysis shifts again. Singapore's MAS, Japan's METI, and the UAE's Executive Office of AML/CFT have each addressed virtual-asset sanctions obligations through their domestic regulatory channels. The obligation to check the relevant domestic list alongside the UN Consolidated List is a minimum; it is not always sufficient where extraterritorial reach of the US or EU programmes is in play.
Our practice regularly acts for VASPs that need a cross-regime compliance architecture – one that satisfies OFAC, OFSI, and EU requirements simultaneously rather than treating each as a separate check-the-box exercise.
What should a VASP compliance programme contain to satisfy OFAC's expectations?
OFAC has published guidance on what it regards as a well-designed compliance programme. The guidance describes five essential components: management commitment, risk assessment, internal controls, testing and auditing, and training. VASPs are explicitly within the scope of this guidance. OFAC's expectation is that each of the five components is calibrated to the specific risk profile of the business – its transaction volumes, counterparty types, geographies, and asset classes.
For a VASP, the risk-assessment component is where many programmes fall short. A generic financial-institution risk assessment does not address blockchain-specific risk factors: the pseudonymous nature of on-chain transactions, the use of privacy tools, the cross-border flow of value without correspondent-banking controls, and the speed at which value can move before a screening alert resolves. OFAC expects the risk assessment to be specific enough to drive the design of the internal controls.
Internal controls for a VASP need to address at minimum: wallet-address screening against OFAC's SDN List (with a refresh cadence that accounts for the frequency of OFAC's list updates); IP and geolocation screening; transaction-monitoring rules calibrated to mixing-service and obfuscation indicators; and a clear escalation and blocking procedure with a short response time. The escalation path matters. An alert that sits in a queue for hours before a compliance officer reviews it in a fast-moving blockchain environment is a structural gap.
Testing and auditing is the component most often under-resourced. OFAC's guidance treats periodic testing as evidence of good faith in an enforcement context. A VASP that has never stress-tested its wallet-address screening against a live SDN address, or that has not reviewed its risk assessment since its last product launch, is building compliance fragility. The audit record also has evidentiary value if an enforcement matter arises: it demonstrates that the firm understood its obligations and invested in meeting them.
In a recent matter, a financial-technology business processing peer-to-peer transfers identified through an internal audit that its address-screening tool was not receiving OFAC list updates at the published refresh interval. The gap had persisted across a number of transactions. We assessed the scope of the apparent violations, advised on VSD timing and preparation, and assisted with the design of a remediation programme. The matter was resolved with a finding that did not proceed to a civil monetary penalty, in part because of the prompt and well-documented disclosure.
A common misconception about OFAC and decentralised protocols
A persistent myth in the VASP compliance space is that decentralised or non-custodial protocols sit outside OFAC's reach because there is no intermediary to whom OFAC can direct an obligation. The position is more nuanced. OFAC's jurisdiction turns on whether a US person or a person subject to US jurisdiction is involved in the transaction – as a counterparty, as a facilitator, or as a recipient. A US-resident user of a non-custodial protocol who interacts with a blocked address is in violation. A developer who is a US person and who deploys or maintains a protocol used for prohibited transactions faces its own exposure analysis.
The technology does not insulate the persons behind it. OFAC has designated smart-contract addresses. The designation of a protocol's contract address as blocked property has the effect that US persons may not interact with it. The question is not whether a human intermediary sits in the transaction path. The question is whether a US person has an interest in, or is a party to, a transaction involving blocked property.
Related practices
- Sanctions compliance audit and testing – independent programme review to surface gaps before an enforcement action does.
- Crypto and VASP sanctions compliance under OFSI – the UK regime's ownership and control test and reporting obligations for virtual-asset businesses.
- Escalation and reporting obligations in Australia – how the Australian autonomous-sanctions regime applies reporting requirements to financial institutions and VASPs.
Frequently asked questions: crypto and VASP sanctions compliance under OFAC
Who administers crypto and VASP sanctions compliance under OFAC?
OFAC, a bureau of the US Treasury, administers all US economic-sanctions programmes, including those that apply to virtual assets and VASPs. OFAC derives its authority primarily from IEEPA and TWEA, supplemented by programme-specific executive orders. FinCEN administers the parallel BSA obligations that apply to VASPs classified as money-services businesses. The two authorities are distinct and require separate compliance responses; a VASP must understand both but must not conflate them.
What does OFAC prohibit in relation to crypto and VASP sanctions compliance?
OFAC prohibits US persons and persons subject to US jurisdiction from dealing in virtual currency that constitutes blocked property, transacting with SDN-listed wallet addresses, or facilitating transactions that would be prohibited if conducted directly. The dealing prohibition, the receipt prohibition, and the facilitation prohibition all apply. OFAC has added wallet-address identifiers directly to SDN List entries, making address-level screening an express regulatory expectation rather than a best-practice option.
How is crypto and VASP sanctions compliance enforced under OFAC?
OFAC enforces through civil monetary penalties, cautionary letters, and, for wilful violations, criminal referrals to the Department of Justice. Penalties are assessed by reference to transaction value, the degree of wilfulness, and the sophistication of the firm. A timely voluntary self-disclosure is a significant mitigating factor under OFAC's enforcement guidelines and can reduce the penalty substantially. OFAC has also designated VASPs as SDNs, which blocks them as entities and exposes their counterparties to secondary dealing risk.
About the author
Renata Costa advises banks, payment firms, and virtual-asset businesses on sanctions screening, compliance-programme design, and financial-crime controls. She regularly advises VASPs on OFAC, OFSI, and EU sanctions obligations across multi-regime compliance architectures. Calder & Vance – International Sanctions & Export Control Counsel.
About Calder & Vance
Calder & Vance is an independent international sanctions and export-control boutique. We advise multinationals, financial institutions, exporters, and individuals on the major regimes – OFAC and BIS in the United States, OFSI and ECJU in the United Kingdom, the EU Council regulations and the EU General Court, the United Nations Consolidated List, and the regimes of Switzerland, Canada, Australia, the UAE, Singapore, and Japan. Our work is limited to lawful compliance, licensing, delisting, enforcement defence, and due diligence. To discuss a matter, contact info@caldervance.com.
Disclaimer: This material is general information, not legal advice, and is not a substitute for advice on your specific facts. Sanctions and export-control rules change frequently and differ by regime; verify the current position before relying on anything stated here. Calder & Vance does not advise on circumventing or evading sanctions. For advice on your situation, contact info@caldervance.com.