Sanctions on the financial system work because payments pass through institutions that can be compelled to stop them. A dollar payment touches a correspondent bank; a correspondent bank screens it; a match blocks it. Every layer of that architecture depends on an intermediary existing.
A transfer on a public blockchain has no such intermediary. It is validated by a network, it settles in minutes, and no participant can reverse it. That is what makes virtual assets relevant here — and the same properties are what make them traceable in ways bank payments are not.
How it works
There are two distinct uses, and they have very different profiles.
Settlement. Value owed between counterparties is transferred on-chain rather than through banks. Because volatility makes ordinary cryptocurrencies impractical for commercial settlement, this use is dominated by fiat-referenced stablecoins, which is why stablecoin settlement is treated separately on this site.
Realisation. Value acquired on-chain is converted into usable currency. This is the harder half, because conversion requires a service that touches the banking system, and that is where identification obligations apply. This is the harder half, because conversion requires a service that touches the banking system, and that is where identification obligations apply.
What is actually screened
OFAC’s 2021 guidance for the virtual currency industry sets the expectation: a sanctions compliance programme, geolocation tools and IP address blocking controls to prevent access from sanctioned jurisdictions1 , and know-your-customer procedures whose output is actually used to conduct due diligence sufficient to mitigate sanctions risk2 .
The SDN List has carried digital currency addresses as a structured identifier field since 2018. That is what makes address screening possible at all, and it means a designated address is checkable by anyone, instantly, without a subpoena.
The guidance recommends specific controls: geolocation tools and IP address blocking to prevent access from sanctioned jurisdictions1 , and know-your-customer procedures whose output is actually used for sanctions screening2 . It defines red flags as indications that illicit activity or compliance breakdowns may be occurring3 . It does not mention mixers — an earlier version of this page said it named mixer exposure as an indicator, which was wrong. The document that names mixers and tumblers4 is FATF’s virtual assets guidance.
The visibility trade-off
This is the point most often got backwards. A public blockchain is a permanent, complete, universally readable record of every transaction ever made on it. There is no bank secrecy, no jurisdiction to petition and no records retention period.
The difficulty is not seeing the transactions; it is attributing addresses to real parties. That is what blockchain analytics does, by clustering addresses likely under common control and labelling clusters with known services. Attribution is an inference and its confidence varies, and treating a cluster label as established fact is the commonest analytical error in this area.
How it is caught
Address screening. Direct, immediate and available to everyone, because the identifiers are published on the list itself.
Cluster analysis. Addresses under common control are grouped by on-chain behaviour, and exposure to labelled services — exchanges, mixers, designated addresses — is measured across the cluster rather than the single address.
The off-ramp. Value on-chain is of limited use until it becomes currency, and conversion requires a service subject to identification obligations. That chokepoint is where most enforcement occurs, and it is why over-the-counter brokers who convert for a fee appear so consistently in Panel of Experts reporting.
Off-chain correlation. On-chain timing and amounts are matched against off-chain events — an invoice, a shipment, a designation — to attribute a flow to a transaction in the physical world.
The three problems virtual assets do and do not solve
Setting these out separately is the fastest way past the noise in this subject.
Transfer. Solved, completely. A transfer on a public blockchain needs no correspondent bank, settles in minutes, cannot be reversed, and cannot be blocked in transit by any intermediary, because there is no intermediary. For moving value between two parties who both already hold the asset, this works.
Denomination. Solved, but only by stablecoins. A commercial obligation is denominated in a national currency, and settling it in a volatile asset means one party takes a price position they did not contract for. This is why fiat-referenced tokens, not bitcoin, dominate the commercial settlement material, and why [stablecoin settlement](/techniques/stablecoin- settlement/) is treated separately here.
Realisation. Not solved, and this is the binding constraint. Value on-chain buys very little in the physical economy. Turning it into currency, or into goods, requires a counterparty willing to accept it, and at some point that counterparty faces the identification obligations the chain avoided.
Almost every enforcement outcome in this area occurs at the third step.
The visibility trade-off, stated correctly
The persistent misconception is that blockchains are anonymous. The accurate statement is that they are pseudonymous and permanently public, which is a very different property and in several respects a worse one for the user.
A public ledger is a complete, permanent, universally readable record of every transaction ever made on it. There is no bank secrecy to pierce, no jurisdiction to petition, no retention period after which records are destroyed, and no need for legal process to read it. An investigator who identifies one address can trace its entire history immediately, including transactions that occurred years before anyone was looking.
Bank records have none of those properties. They are private, they are held in a jurisdiction, they require legal process, and they are eventually destroyed.
The difficulty on-chain is attribution, not visibility: connecting an address to a person. That is what blockchain analytics does, by clustering addresses that behave as though under common control and labelling clusters with known services. It is an inference with a confidence level, and treating a cluster label as an established fact is the commonest analytical error in this field.
What OFAC’s guidance actually asks for
The 2021 guidance for the virtual currency industry is worth reading directly because it is more prosaic than its reputation.
It states that firms providing virtual currency services are financial institutions for these purposes, and expects a sanctions compliance programme with the same components as any other: management commitment, risk assessment, internal controls, testing and training. It expects screening of names and of digital currency addresses against the lists. And it expects firms to use the tools they already have, naming geolocation and internet protocol data specifically.
That last point is the one the smaller enforcement actions turn on, and OFAC’s own guidance anticipates it: it describes a company that tracked users’ IP addresses for security purposes but did not use that information to screen for and prevent potential sanctions violations5 . The Bittrex settlement is that finding in an enforcement record. The data was already there.
The largest action in this sector is not a control gap at all, and the distinction matters. In the Binance settlement OFAC found that the exchange’s trade-matching engine paired users in sanctioned jurisdictions with US users solely by price and time, that senior management knew, and that the compliance programme was deliberately kept a paper one. Bittrex’s conduct was found non-egregious; Binance’s was found egregious, and that single determination accounts for most of the difference between a $24 million settlement and a $969 million one.
The state-actor case is a different problem
A distinct strand involves proceeds of intrusion attributed to state-sponsored actors, which is revenue generation rather than settlement of a trade obligation. The scale is documented: the Panel of Experts’ final report records that it was investigating 58 suspected cyberattacks on cryptocurrency-related companies between 2017 and 2023, valued at approximately $3 billion5 .
The profile is different in ways that matter. The value starts on-chain rather than arriving there. The holder has no need to make anything look like commerce. And the entire operation is a realisation problem: converting a large on-chain balance with a documented criminal history into usable currency.
The Panel’s account of the cash-out stage names the mechanism directly: heavy reliance on third-party launderers and over-the-counter brokers6 . Its successor is more specific still. The Multilateral Sanctions Monitoring Team records that actors are highly reliant on Chinese underground banking and China-based facilitators7 , that the DPRK heavily relies on Chinese banks to access the formal financial system to cash out stolen cryptocurrency8 , and that brokers have used front companies to enable actors to bypass financial institutions’ anti-money laundering requirements and reach the US financial system9 .
Those are individuals and small firms with banking relationships and physical locations, which is why they, rather than the chain analysis, are where enforcement concentrates. Those brokers are individuals and small firms with banking relationships and physical locations, which is why they, rather than the chain analysis, are where enforcement in this strand concentrates.
Why designation of addresses changed the analysis
Carrying digital currency addresses on the SDN List as a structured identifier field, which OFAC began doing in 2018, did something no other sanctions instrument does.
It made a designation checkable by anyone, instantly, at zero cost, without any request to any authority. A bank cannot tell whether a name in a payment message is the designated person of that name. An address either is or is not on the list, and the answer is arithmetic.
That is a genuinely unusual property in this field, and it is why address screening is the one control here that works better than its banking equivalent rather than worse.