A compliance officer at a bank, custodian or exchange does not meet a sanctions designation as an abstract policy question. It arrives as a string of characters, a wallet address, and a decision has to be made quickly about what to do with anything touching it. The rules behind that decision sit across several legal regimes and at least three technical layers, and the vendor scoring that supports it is proprietary. This is what has to happen, what it rests on, and where the obligation runs out before the technology does. None of it is legal or compliance advice.
What a designation reaches
When the US Office of Foreign Assets Control (OFAC) adds a person or entity to the Specially Designated Nationals and Blocked Persons (SDN) List, US persons must block property in which that person has an interest, not merely decline to deal. OFAC has applied that to wallet addresses since 2018. It may add digital currency addresses to the SDN List to alert the public to identifiers associated with a blocked person, and it says those listings "are not likely to be exhaustive": anyone who identifies an unlisted address they believe is associated with an SDN, and holds that property, is told to block it and file a report (OFAC FAQ 562, 19 March 2018). The published string is the floor of the obligation, not its limit.
FAQ 560, released the same day, answers the prior question. Obligations "are the same" whether a transaction is denominated in digital currency or traditional fiat currency, and the blocking duty extends to entities owned 50 per cent or more, directly or indirectly, by one or more blocked persons (OFAC FAQ 560, 19 March 2018). There is no carve-out for crypto in the statute. There is only a harder identification problem.
OFAC's October 2021 guidance for the virtual currency industry sets out what that problem asks of a programme: screening against the SDN List, using a listed address to identify other addresses that may belong to the same blocked person, and geolocation controls, including screening for known VPN addresses, against the comprehensively sanctioned jurisdictions, Cuba, Iran, North Korea, Syria and the Crimea region of Ukraine (summary of OFAC's guidance, Cooley, 29 October 2021). How far the second of those has to reach is where scoring comes in.
How screening and scoring actually work
Wallet and transaction screening is not a lookup against a static list. Vendor material describes it as checking an address against blockchain risk data to assess exposure to illicit activity, measuring both direct exposure, funds sent to or received from a risky entity, and indirect exposure, funds connected through intermediary hops; compliance teams then configure the rules and thresholds to their own risk appetite (vendor material, Chainalysis, "What Is Wallet Screening?", accessed September 2026). That last part carries more weight than it sounds. The weighting is not published and is set institution by institution, so two firms working from the same underlying data can reach different pass or hold decisions on an identical address.
Timing is the second complication. An address can be unremarkable today and designated tomorrow, and funds that moved through it last month were not sanctioned property when they moved. Vendors now split exposure into pre-designation and post-designation windows, treating the first as a matter for enhanced due diligence or a suspicious activity report and the second as requiring blocking or immediate escalation (vendor material, Chainalysis, 17 June 2026). The tooling draws that line cleanly. The law behind it does not: how much liability attaches to funds that were clean when they moved is not resolved by regulatory text, and is a matter of enforcement discretion. For the separate and harder problem of establishing who actually controls an address behind an alert, see our account of what blockchain analytics can and cannot establish: a risk score is a lead, not an attribution.
Three chokepoints, three different obligations
"Blocking a sanctioned address" describes at least three distinct actions, at three layers of the stack, and a programme has to know which one it is actually capable of.
Freezing at the issuer
A stablecoin issuer can freeze its own token at the contract level. After OFAC designated Tornado Cash on 8 August 2022, Circle blacklisted 81 of the named addresses and froze more than 75,000 USDC held across them, using a function built into the USDC contract (Cointelegraph, 9 August 2022). This is decisive but narrow. It stops that issuer's token moving out of those addresses and nothing else: not the underlying chain, not other assets at the same address, not another issuer's token.
Blocking at a service
An exchange, custodian or payment processor blocks at the account and transaction level, screening counterparties and refusing to process once its own screening flags something. This is where enforcement has mostly landed. OFAC's settlement with Bittrex, announced 11 October 2022, resolved 116,421 apparent violations involving more than $263 million in transactions with apparent users in Cuba, Iran, Sudan, Syria and the Crimea region of Ukraine, for $24,280,829.20 (OFAC recent action, 11 October 2022). FinCEN settled in parallel on the same day over Bank Secrecy Act failures stemming from some of the same conduct, assessing $29,280,829.20 and crediting the OFAC payment against it, so total payments to Treasury came to the larger figure (Steptoe, October 2022). OFAC's finding was not that there was no sanctions programme. It was that the screening failed to use customer information, including IP addresses and physical addresses, that the firm already held.
Filtering at the protocol layer
Some validators, builders and relays filter transactions before inclusion in a block, most visibly around Ethereum block building after the Tornado Cash designation. This layer sits on the weakest legal footing of the three, because it asks infrastructure with no counterparty relationship to anyone to make a sanctions determination, and because the litigation that followed put the premise itself in doubt.
Mixers and the Tornado Cash reversal
Tornado Cash is the case every compliance team now has to be able to explain, because it changed direction twice. OFAC designated the mixer in August 2022 on the stated basis that it had laundered more than $7 billion in virtual currency since its creation in 2019, including funds attributed to North Korea's Lazarus Group. Users challenged the designation, and on 26 November 2024 a unanimous Fifth Circuit panel held in Van Loon v. Department of the Treasury that OFAC had exceeded its statutory authority: immutable smart contracts are not "property" under the International Emergency Economic Powers Act, because once deployed they lack the hallmarks of ownership, control and exclusivity (Fifth Circuit opinion, No. 23-50669, 26 November 2024; see also Jones Day, December 2024). The court also declined to give OFAC heightened deference, citing Loper Bright.
Treasury removed the Tornado Cash listings on 21 March 2025, saying the action followed "the Administration's review of the novel legal and policy issues raised by use of financial sanctions against financial and commercial activity occurring within evolving technology and legal environments", and restating its concern about North Korean state-sponsored hacking (US Department of the Treasury, 21 March 2025). The release does not concede the court's reasoning, and does not say the underlying policy has changed.
What that leaves is genuinely unsettled: a live appellate holding that an immutable protocol may not be a valid sanctions target, alongside continued official appetite to reach mixing activity by some other route. FinCEN's proposal to designate international convertible virtual currency mixing as a class of transactions of primary money laundering concern, under section 311 of the USA PATRIOT Act and the first use of that authority against a transaction type rather than a named institution or jurisdiction, was released on 19 October 2023 and published in the Federal Register on 23 October 2023, with comments due by 22 January 2024 (Federal Register, 23 October 2023). It remains a proposed rule; no final rule could be located as of September 2026. A designated mixer and an undesignated one performing the same function are not the same compliance problem, and at present the line between them is drawn as much by litigation as by rulemaking.
Self-hosted wallets and secondary exposure
A self-hosted wallet has no institution to send a blocking instruction to. The obligation does not disappear, it moves to whoever is regulated at the edge of the transaction: a regulated firm sending to or receiving from a self-hosted address still has to screen it, and an unscreenable counterparty is itself a risk signal rather than a neutral one. Our comparison of Travel Rule regimes sets out how sharply jurisdictions differ on what a self-hosted counterparty requires. Sanctions screening rests on a separate legal basis from the Travel Rule and is triggered differently, but the two run on the same address-level plumbing, so a gap in one tends to surface as a gap in the other.
Secondary exposure, indirect contact through an intermediary, is where scoring judgement matters most and regulatory text says least. FATF's sixth targeted update on implementation of its standards for virtual assets, published 26 June 2025, found that 99 jurisdictions are now adopting Travel Rule legislation while supervision, enforcement and compliance lag behind, and that the share of assessed jurisdictions not compliant with Recommendation 15 fell from 25 per cent, 25 of 130 in 2024, to 21 per cent, 29 of 138 in 2025. It also flagged rising illicit use of stablecoins, including by actors affiliated with North Korea (FATF targeted update on virtual assets and VASPs, 26 June 2025). None of it tells an institution how many hops of separation from a designated address is acceptable. That judgement is made programme by programme.
Where the EU and UK diverge from the US
The EU works through its general Russia sanctions regulation rather than a crypto-specific statute. Council Regulation (EU) No 833/2014 already reached crypto-assets, and the eighth package, Council Regulation (EU) 2022/1904 of 6 October 2022, hardened Article 5b by removing the earlier value threshold: EU providers are banned from supplying crypto-asset wallet, account or custody services to Russian nationals and residents regardless of the amount held (Regulation (EU) 2022/1904; Morgan Lewis, October 2022). The nineteenth package, adopted 23 October 2025, went further, adding a transaction ban covering listed Russian crypto-asset service providers and a full prohibition on dealing in the Russian-backed A7A5 stablecoin, applying from 25 November 2025 (Council of the EU, 23 October 2025).
The UK's stated position is that cryptoasset sanctions evasion is treated no differently from the exploitation of traditional currencies, and 2026 brought a more visibly resourced enforcement posture: the Office of Financial Sanctions Implementation (OFSI) announced on 28 January 2026 that it had joined the Crypto Cash Fusion Cell alongside the National Crime Agency, the Metropolitan Police Service, HM Revenue and Customs, the Financial Conduct Authority and City of London Police (OFSI, 28 January 2026). For a firm with both US and EU exposure, the practical consequence is that one screening stack has to carry three lists whose scope, thresholds and effective dates do not line up.
What regulators require against what vendors deliver
The regulatory text is comparatively simple: screen, block, report, keep records, and treat certain jurisdictions and addresses as off-limits. What a screening vendor delivers is a probabilistic score built on clustering heuristics, which is a very different object (see our piece on the limits of that evidence). The gap between the two is where most institutional risk sits. Treat a vendor's high-risk score as equivalent to an OFAC determination and you are over-relying on a tool never built to make one; ignore it and you have discarded the only instrument that works at the scale public ledgers operate at. Neither position survives examination, which is why OFAC's guidance frames screening as one input to a risk-based programme rather than a substitute for one.
The same gap runs through privacy-preserving infrastructure. Confidentiality and screenability are not opposites in principle, since an institution can in theory prove compliance to a regulator without exposing counterparty data to everyone, but selective disclosure of that kind is an architecture decision taken long before a designation appears, not a response to one; see our breakdown of what institutional privacy requires. Custody complicates it further, because where a custodian's duties come from shapes what it can do when an instruction to freeze arrives, and the answer starts with who actually holds the asset, which our custody piece works through.
Proof of Talk's Paris 2026 programme put that tension on one stage. "Privacy and Compliance: Two Sides of the Same Coin" ran on the Taostats Stage on 2 June 2026, from 12:30 to 13:05, moderated by Nicola Massella of Storm, with panellists including James Smith, co-founder of Elliptic. The session is worth noting here because provable compliance and confidentiality are pursued by the same institutions at the same time, which is the tension this piece has been describing one layer down.
Sanctions exposure is fact-specific and the US regime imposes strict liability, so the points left open here, how much liability attaches to pre-designation funds, whether protocol-level filtering rests on anything durable, and whether the FinCEN mixer proposal is ever finalised, are exactly the ones a programme cannot settle by buying a tool. What is settled is narrower than the marketing around screening suggests, and what is unsettled is larger than most compliance memos admit.