The largest virtual-currency-related sanctions settlement on Treasury’s published list, and — read against the notice rather than the coverage — not a screening-failure case at all.
What the notice actually finds
Binance Holdings, Ltd., a Cayman Islands exchange, settled potential civil liability for 1,667,153 apparent violations. Between August 2017 and October 2022 it matched and executed virtual currency trades on its platform between US-person users and users in sanctioned jurisdictions or blocked persons.
OFAC’s characterisation is unusually direct. Binance “took steps to project an image of compliance, including by misleading third parties about its controls”; senior management “knew of and permitted the presence of both U.S. and sanctioned jurisdiction users on its platform”; and it did so “despite understanding that Binance’s trade matching algorithm could cause violations.” Management additionally “took steps to undermine its own compliance function, encouraging users to circumvent the company’s own ostensible controls.”
Internal communications, OFAC says, show the failure to implement effective controls “was the product of deliberate choices by senior management” that ensured the compliance programme “would primarily remain only a ‘paper program.’”
The mechanism is worth understanding precisely
Trades between Binance users did not occur on a blockchain and were not recorded on one. Users deposited funds into omnibus wallets Binance controlled; the exchange kept an internal ledger; matching engines paired incoming orders against the orderbook solely according to price and time.
That last clause is the whole case. The engine had no jurisdictional input. It was not defeated, circumvented or deceived — it was doing what it was built to do, and what it was built to do was match any user with any other user. With sanctioned-jurisdiction users retained on the platform, the algorithm generated violations continuously and automatically, which is how a single business produces one and a half million of them.
What did and did not fail
Binance had written policies. It hired a chief compliance officer in April 2018, issued a Global Compliance Policy stating it adhered to the OFAC list, and updated its terms in October 2018 to prohibit new users from sanctioned jurisdictions. It then began identifying such users for offboarding.
Those efforts were, in OFAC’s words, “implemented inadequately.” The notice records that IP address screening could be defeated by a user switching to a VPN, and that a user could reach trading services after failing Binance’s own know-your-customer screening. Separately, the then chief compliance officer misled a financial institution in an anti-money-laundering due diligence questionnaire about the controls in place.
The contrast with Bittrex
Placing these two side by side is the most useful thing to do with them, because they look similar and are not.
Bittrex collected internet protocol and physical address data at onboarding and was not screening it — a control that was absent. OFAC found that conduct non-egregious.
Binance had the controls on paper and, per OFAC, deliberately did not operate them. That conduct was found egregious, and the difference in that single determination is most of the difference between a $24 million settlement and a $969 million one.
The arithmetic
The statutory maximum in this case was $592,133,829,398 — the per-violation maximum multiplied by 1.67 million violations. Because the conduct was egregious and not self- disclosed, the base penalty equalled that maximum.
The settlement was $968,618,825, of which $898,618,825 was deemed satisfied by payment to the Department of Justice for violations arising from the same conduct. Mitigating factors included no prior OFAC penalty in the preceding five years and substantial cooperation, including an extensive independent internal investigation. Binance also agreed to retain an independent compliance monitor for five years.
What this case is not evidence of
It says nothing about whether blockchains are traceable, and nothing about cryptographic obfuscation. Nobody in this case used a mixer, hopped chains or hid anything on-chain — most of the transactions were never on a chain at all. It is a case about an exchange that knew who its users were and matched them anyway.