HTX Rotating Wallets Under UK Sanctions: What Accounting Firms and CFOs Must Act On Now
Blockchain analytics firm TRM Labs has identified a pattern of systematic wallet rotation at HTX, the crypto exchange associated with Justin Sun, carried out in the period following UK sanctions designations. The finding puts accounting firms, auditors, and CFOs on notice: any client or counterparty with HTX exposure now carries a materially elevated sanctions and AML risk profile, and existing due-diligence frameworks may not be sufficient to catch it.
What TRM Labs Found
According to reporting by Decrypt, TRM Labs tracked on-chain activity at HTX and observed the exchange cycling through new wallet addresses at an accelerated rate after the UK's Office of Financial Sanctions Implementation (OFSI) moved to designate related entities. The technique, commonly described as wallet rotation or address hopping, is a well-documented obfuscation method. By regularly generating fresh deposit and withdrawal addresses, an exchange can make it significantly harder for compliance teams, counterparties, and analytics providers to maintain a continuous view of fund flows.
Why Wallet Rotation Matters for Sanctions Screening
Sanctions screening in traditional finance relies on name matching against designated-person lists. In crypto, the equivalent is wallet-address screening: you check whether an address appears on a published list of designated wallets. Wallet rotation directly undermines that model. A sanctioned entity can render a screened address obsolete within hours simply by moving activity to a new one. Unless a firm's screening infrastructure ingests real-time blockchain data and applies cluster analysis to link new addresses back to known entities, the screen will return a false negative.
TRM Labs is a blockchain intelligence company whose findings are used by regulators and financial institutions. Their identification of this pattern is not a casual observation: it reflects forensic on-chain analysis correlating address creation timing, fund flows, and entity attribution. Accounting firms and CFOs should treat it as a credible red flag, not a working hypothesis.
The UK Sanctions Context
The UK has maintained its own autonomous sanctions regime since departing from EU frameworks. OFSI, sitting within HM Treasury, administers financial sanctions and has the authority to impose civil penalties of up to the greater of one million pounds or fifty percent of the breach value, without requiring a criminal conviction. The UK's approach to crypto sanctions has become progressively more assertive, with OFSI updating its guidance to make clear that the obligation to screen extends to crypto-asset addresses and that ignorance of a counterparty's sanctions status is not an automatic defence.
HTX and the Justin Sun Connection
HTX, formerly known as Huobi, operates under the umbrella of entities connected to Justin Sun, who himself has faced regulatory scrutiny in multiple jurisdictions. UK sanctions designations in this context form part of a broader international enforcement picture. Accounting firms advising clients who trade on HTX, hold HTX-issued tokens, or maintain any commercial relationship with HTX-connected entities must reassess whether that relationship triggers a sanctions exposure under the UK regime.
AML Obligations That Are Triggered Now
For UK-regulated firms, the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017, as amended, require enhanced due diligence where there is a higher risk of money laundering or sanctions breach. A credible public report of systematic wallet rotation by a sanctions-adjacent exchange almost certainly meets that threshold. That means the following obligations are live.
Enhanced Due Diligence and Ongoing Monitoring
Firms must apply enhanced due diligence to any client whose assets, counterparties, or transaction history connects to HTX. This is not a one-time exercise. The MLR 2017 require ongoing monitoring, meaning you need a process for detecting new flows to HTX-linked addresses as they emerge, not just checking a static list at onboarding.
Standard periodic review cycles, whether quarterly or annual, are inadequate here. The wallet rotation behaviour TRM Labs identified means the risk profile of a client can shift between review dates. Firms that rely solely on crypto accounting software without a live blockchain analytics feed will have a structural gap in their monitoring capability.
Suspicious Activity Reporting
Where a firm identifies a transaction that involves, or may involve, proceeds of crime or a sanctions breach, a Suspicious Activity Report must be filed with the UK's National Crime Agency. The obligation arises on reasonable suspicion, a lower bar than proof. Given TRM Labs' published findings, any professional who identifies a client transaction touching HTX-linked addresses and does not at minimum document their consideration of an SAR filing is exposed to regulatory criticism.
Record-Keeping and Audit Trail
MLR 2017 require firms to keep records of due diligence, risk assessments, and transaction monitoring decisions for at least five years. In a sanctions context, the Financial Conduct Authority and OFSI will want to see a documented audit trail showing what checks were run, when, and what was concluded. This is precisely the kind of structured record that digital asset accounting software should be generating automatically, but many implementations are not configured to do so for AML purposes.
Accounting Implications for Firms and CFOs
Beyond the regulatory filing obligations, there are direct accounting consequences that CFOs and auditors need to assess.
Asset Recoverability and Impairment
Any crypto assets held on HTX, or in wallets associated with HTX, may be subject to freezing orders or restrictions as sanctions enforcement develops. Under IFRS, that raises a recoverability question. If access to an asset is legally restricted or practically impaired, management must consider whether the carrying value is supportable. Auditors should be asking management for written confirmation of the platforms and custodians holding client crypto assets, and assessing whether any of those relationships are now sanctions-proximate.
Disclosure Obligations
IAS 37 requires disclosure of contingent liabilities where an outflow of resources is possible but not probable. A firm that has transacted with HTX and faces potential OFSI scrutiny may need to assess whether a contingent liability disclosure is warranted. Legal counsel should be involved, but the accounting team needs to identify the exposure first.
Transaction Classification and Crypto Bookkeeping
Crypto bookkeeping software used by firms with HTX-linked transactions must be reviewed to ensure those flows are correctly classified. If assets were received from, or sent to, an address that is subsequently identified as sanctions-linked, that reclassification needs to flow through to the ledger with appropriate documentation. This is not a theoretical risk: OFSI has previously required firms to unwind transactions and provide detailed transaction histories as part of enforcement investigations.
Global Dimension: Not Just a UK Problem
While the sanctions in question sit within the UK regime, the implications cross borders. Global accounting networks and multinational CFOs need to consider whether their non-UK entities are also exposed. The EU, US, and other jurisdictions may act on the same underlying intelligence. A group treasury function that clears HTX transactions through a UK subsidiary while booking them in a lower-oversight jurisdiction is creating a consolidation-level risk that group auditors must address.
The FATF framework, which underpins AML rules in most major jurisdictions, already identifies high-risk exchanges as a typology concern. TRM Labs' findings reinforce that classification for HTX. Firms operating across borders should check whether their crypto accounting software and digital asset accounting software infrastructure supports multi-jurisdiction sanctions screening, or whether each local entity is running a siloed check that misses the consolidated picture.
For further context on how regulators are moving toward real-time on-chain surveillance, see our coverage of how VARA, FCA and HKMA signal a new era of real-time AML supervision. The HTX situation illustrates precisely the gap between static list-screening and the dynamic monitoring those regulators are now expecting. Separately, the ongoing UK lawmakers' inquiry into crypto banking access is relevant context: HTX-linked de-risking decisions by UK banks will have downstream effects on which platforms remain viable for UK-connected clients.
Practical Steps for Accounting Firms Right Now
The following is a structured checklist for compliance and accounting teams responding to this development.
| Action | Responsible Party | Urgency |
|---|---|---|
| Screen all client portfolios for HTX-linked addresses using a blockchain analytics tool with cluster analysis | Compliance / MLRO | Immediate |
| Review onboarding files for clients with known HTX accounts or HTX token holdings | Client-facing team | Within 48 hours |
| Assess whether any open transactions require SAR consideration | MLRO | Within 48 hours |
| Document risk-assessment decisions and monitoring rationale in the client file | Compliance / Audit | Ongoing |
| Notify group compliance (if applicable) of any consolidated HTX exposure | CFO / Group Finance | Within 72 hours |
| Review crypto bookkeeping software configuration to ensure HTX transactions are flagged for manual review | Finance / Technology | Within one week |
Frequently Asked Questions
Does a UK accounting firm have a sanctions obligation if a client merely holds an account on HTX, without transacting recently?
Yes. Holding assets on a platform that is subject to, or closely associated with, sanctions designations can itself constitute a prohibited dealing under UK financial sanctions law if the underlying entity is designated. The firm's obligation is to identify whether any client assets are, directly or indirectly, caught by a designation and to seek legal advice if there is any ambiguity. Static account holdings are not exempt simply because no recent transaction occurred.
What is wallet rotation and why does it complicate compliance?
Wallet rotation is the practice of regularly generating new blockchain addresses to receive or send funds, rather than using a fixed address. From a compliance perspective, it means that a list of sanctioned addresses becomes stale almost immediately after publication. Effective screening requires analytics that can attribute new addresses to known entities through on-chain behavioural patterns, not just a name-to-address lookup.
Is TRM Labs' report sufficient grounds to trigger enhanced due diligence, or do we need a formal regulatory notice?
UK AML regulations require firms to apply enhanced due diligence where there is a higher risk of money laundering or sanctions breach. The test is risk-based, not notice-based. A credible public report by a recognised blockchain analytics firm identifying wallet-rotation behaviour at a sanctions-proximate exchange is exactly the kind of information that a competent MLRO is expected to assess and act on. Waiting for a formal regulatory notice before escalating would be a defensibility problem in any subsequent OFSI or FCA review.
How should crypto assets held on HTX be treated in financial statements?
The carrying value of any crypto asset held on HTX should be reviewed for recoverability given the sanctions context. If there is a genuine risk that the firm cannot access or withdraw those assets due to regulatory action, an impairment assessment is required. Auditors should request management representations covering platform counterparty risk, and consider whether a contingent liability disclosure under IAS 37 is appropriate where the sanctions exposure is possible but the outcome remains uncertain.
Do these obligations apply to non-UK subsidiaries of a UK-headquartered group?
UK financial sanctions apply to UK persons and UK-incorporated entities wherever they are located, and to activity taking place in the UK. For non-UK subsidiaries, the local jurisdiction's sanctions regime applies. However, group auditors and CFOs should assess the consolidated position: a group-level sanctions exposure arising from a subsidiary's HTX dealings may require disclosure at the parent level, and group-wide AML policy should set a minimum standard that covers all entities regardless of local law.
Source: Decrypt
