Blockchain Analytics and Sanctions Compliance: What Crypto Firms Must Do Now
Economic sanctions are reshaping the compliance obligations of every business that touches cryptocurrency. Whether you run a crypto exchange, manage a digital asset treasury, or advise clients on crypto compliance reporting, the question is no longer whether sanctions rules apply to you — it is whether your monitoring infrastructure can actually detect the exposures that regulators expect you to catch. A new guide published by Elliptic sets out precisely why indirect exposure is the compliance blind spot that enforcement actions are most likely to exploit, and what blockchain analytics must do to close that gap.
Why Sanctions Risk in Crypto Is Wider Than Most Firms Assume
The conventional model of sanctions screening asks a simple question: did we transact with a listed entity? In traditional finance, that question is manageable. Counterparties are identified at onboarding, transactions flow through known correspondent banks, and screening databases can be matched against named individuals and institutions.
Crypto changes the geometry of that problem entirely.
The Indirect Exposure Problem
Indirect exposure arises when funds passing through your platform are connected to a sanctioned entity not through a direct transaction but through one or more intermediate steps. A wallet that received funds two or three hops ago from a sanctioned address can still carry compliance risk, even if none of your immediate counterparties appear on any watchlist.
Elliptic's guidance makes clear that indirect exposure can persist across multiple hops and even across chains. A firm can therefore become exposed without ever transacting knowingly with a sanctioned party. The practical implication is significant: screening only immediate counterparties leaves a firm with a compliance programme that regulators in the US, UK, and EU are likely to view as inadequate.
Stablecoins as a Sanctions Vector
Stablecoins add a specific layer of risk that compliance teams must not underestimate. Because they track the value of fiat currencies, particularly the US dollar, they give sanctioned actors a way to hold and move dollar-equivalent value without going through the correspondent banking system. Elliptic's research indicates that Iran-linked actors have acquired US dollar stablecoins worth at least half a billion dollars. That figure should reset any assumption that stablecoins are a lower-risk asset class from a sanctions perspective.
For context on how stablecoin accounting intersects with sanctions enforcement, the OFAC action against Xinbi Guarantee offers a direct parallel — see our earlier coverage of OFAC sanctions Xinbi Guarantee and what it means for crypto accounting.
What Blockchain Analytics Must Actually Do
The Elliptic framework is built around the principle that effective sanctions compliance in crypto requires attribution and tracing across both multiple transaction hops and multiple chains. Neither capability alone is sufficient.
Multi-Hop Tracing
A blockchain analytics solution needs to assess how closely a given wallet or transaction is connected to sanctioned entities, not just at one remove but across a configurable number of hops. The ability to set different risk thresholds at different hop distances is important. A direct link to an OFAC-listed wallet will demand an immediate alert and transaction block. An indirect link several hops away may warrant enhanced due diligence or a suspicious activity report rather than an outright block, but it still demands a response.
Compliance rules should be configurable to reflect this graduated risk. Treating all indirect exposure identically, whether one hop or five hops away, produces either too many false positives or too many missed risks.
Cross-Chain Attribution
Illicit actors routinely move value across blockchains using bridges and cross-chain protocols, precisely because many compliance tools monitor only a single chain. Effective sanctions screening must follow funds as they move from one network to another, attributing activity to sanctioned-linked actors regardless of which chain the relevant transaction settles on. A tool that monitors Bitcoin but not the chain to which funds have been bridged provides only partial coverage.
Configurable Rule Sets
Elliptic's framework emphasises that compliance teams need the ability to configure the rules that govern when an alert is generated. Different businesses carry different risk appetites. A payment processor settling high volumes of low-value retail transactions will calibrate thresholds differently from a custodian holding institutional client assets. The analytics layer should support that configurability rather than imposing a one-size-fits-all alert logic.
The Regulatory Backdrop Across Key Jurisdictions
The pressure to adopt blockchain analytics for sanctions compliance is not theoretical. Regulators across the principal crypto markets have made clear that AML and sanctions programmes must be commensurate with the actual risk profile of the business.
United States
OFAC operates a strict liability standard for sanctions violations. The fact that a firm did not know it was transacting with a sanctioned party is a mitigating factor in penalty calculations, not a defence. That standard creates a strong incentive to invest in technology that detects indirect exposure before a transaction settles rather than after enforcement has begun. The Bank Secrecy Act requirements administered by FinCEN similarly oblige covered businesses to maintain AML programmes that are reasonably designed to detect and report suspicious activity, and regulators have consistently signalled that technology investments are part of what "reasonably designed" means in a digital asset context.
European Union
The EU's Markets in Crypto-Assets Regulation (MiCA) and the forthcoming Anti-Money Laundering Authority (AMLA) framework place heightened compliance obligations on crypto asset service providers. Travel Rule requirements, which mandate that originator and beneficiary information travels with a transfer, increase the importance of accurate counterparty attribution. Indirect exposure risks are directly relevant to Travel Rule compliance: if you cannot attribute the origin of funds accurately, you cannot fulfil the Travel Rule accurately.
United Kingdom
The Financial Conduct Authority's registration regime for cryptoasset businesses requires firms to demonstrate robust AML controls. The UK's Office of Financial Sanctions Implementation (OFSI) has powers to impose civil penalties for sanctions breaches, and the threshold for a breach does not require intent. UK-registered crypto businesses therefore face the same structural incentive as their US counterparts: detect and prevent indirect exposure before it becomes an enforcement matter.
For a related look at how DeFi operator classification affects AML obligations at the legislative level, see our breakdown of how the revised CLARITY Act targets non-decentralised DeFi operators.
Accounting and Operational Implications for Compliance Teams
Sanctions compliance is not only a legal obligation. It has direct consequences for financial reporting, operational controls, and the integrity of the data that flows into any crypto accounting software or digital asset accounting software your firm relies on.
Transaction-Level Data Quality
When blockchain analytics flags a transaction as having indirect exposure to a sanctioned entity, the downstream accounting treatment depends on what happens next. If the transaction is blocked before settlement, the accounting entry is straightforward: the transaction never completed. If the transaction has already settled before the flag is raised, the firm faces a more complex position, potentially requiring the funds to be frozen, a SAR to be filed, and the amount held in a separate suspense account pending regulatory guidance. Each of those outcomes has a different accounting treatment, and the crypto bookkeeping software used by the firm must be capable of recording and distinguishing them.
Audit Trail Requirements
Regulators and auditors expect to see a documented audit trail showing that sanctions screening occurred, what the result was, and what action was taken. For indirect exposure findings, that trail needs to show the hop-by-hop analysis, the risk score assigned, and the compliance decision made. Firms that cannot produce that documentation on demand face both regulatory risk and audit qualification risk. Building that trail into the workflow from the outset is far less costly than reconstructing it after the fact.
On-Boarding and Ongoing Monitoring
The Elliptic framework applies to both the on-boarding stage and ongoing transaction monitoring. A wallet that passes screening at on-boarding can subsequently receive funds from a newly sanctioned entity. Ongoing monitoring is therefore not optional: it is the mechanism by which indirect exposure that develops after the initial relationship is established gets detected. Compliance programmes that treat on-boarding screening as a one-time event are structurally incomplete.
Practical Steps for Compliance Officers and CFOs
Immediate Actions
Compliance officers and CFOs should take stock of whether their current analytics tools assess indirect as well as direct exposure. If the answer is that only direct counterparties are screened, the coverage gap is material. The next step is to audit which chains the business transacts on and whether the analytics layer covers all of them. Cross-chain gaps are a common and exploitable weakness.
Rule configuration should be reviewed to confirm that alert thresholds reflect the firm's actual risk profile, and that different thresholds apply at different hop distances. A flat rule that treats all indirect exposure identically is unlikely to satisfy a regulator who asks to see the methodology behind the compliance programme.
Documentation and Governance
Every compliance decision generated by the analytics tool should be logged with enough detail to reconstruct the reasoning: the wallet or transaction assessed, the risk score produced, the hop distance of any flagged connection, the chain or chains involved, and the action taken. That log should be accessible to auditors and, if requested, to regulators. Governance documentation should specify who has authority to override an alert and what approval process applies.
Staying Ahead of Designation Lists
Sanctions lists change frequently. OFAC, the EU, and OFSI all add and remove entries, sometimes with immediate effect. Compliance programmes need to be configured to pull updated designation data in near real time, and to re-screen existing customer wallets against new designations as they are published. A firm whose screening database is even a few days out of date carries risk it may not have priced.
Frequently Asked Questions
What is indirect sanctions exposure in a crypto context?
Indirect exposure arises when a wallet or transaction is connected to a sanctioned entity through one or more intermediate transactions rather than through a direct transfer. Compliance risk can still exist several hops away from the original sanctioned address, which is why multi-hop tracing is a core requirement for any adequate sanctions screening programme.
Are stablecoins subject to the same sanctions rules as other crypto assets?
Yes. Stablecoins are crypto assets and are subject to the same sanctions obligations as any other digital asset. The fact that they track fiat currency values makes them an attractive vehicle for sanctioned actors seeking dollar-equivalent value without using the traditional banking system, which is precisely why stablecoin transactions require the same level of screening rigour as Bitcoin or Ether transactions.
Does OFAC's strict liability standard apply to indirect exposure?
OFAC's strict liability standard means that a sanctions violation can occur even without actual knowledge that a counterparty is sanctioned. While the degree of indirect exposure and the adequacy of the compliance programme are relevant to penalty mitigation, they are not a complete defence. Firms are expected to have controls proportionate to the risks they face, and indirect exposure is an identified and documented risk in the digital asset sector.
How does cross-chain activity create compliance gaps?
Illicit actors use cross-chain bridges and swap protocols to move value from one blockchain to another, exploiting tools that monitor only a single chain. If an analytics tool tracks Bitcoin transactions but not the Ethereum or other chain addresses to which bridged funds are sent, the indirect link to a sanctioned entity can disappear from the compliance view mid-chain. Cross-chain attribution is therefore an essential capability, not an optional enhancement.
What accounting records should a firm keep when an alert is generated?
At minimum, a firm should retain the wallet or transaction identifier, the timestamp of the screening check, the risk score and hop distance of any flagged connection, the chain or chains involved, the compliance decision taken, the name of the person who took that decision, and the date. If a transaction is blocked, that fact and the basis for the block should be recorded. If funds are frozen pending regulatory guidance, they should be held in a separately designated suspense account with clear ledger coding. These records form the audit trail that both external auditors and regulators may request.
Source: Elliptic
