OFAC Sanctions BitBank: Iran's Hormuz Toll Settled in Bitcoin
The U.S. Treasury's Office of Foreign Assets Control has designated BitBank, a Tehran-based cryptocurrency exchange, along with its software developer, Pishtaz Simorgh Electronic Trade Company. The allegation: BitBank moved hundreds of millions of dollars in bitcoin to Iran's Islamic Revolutionary Guard Corps and processed fees collected from tankers paying for passage through the Strait of Hormuz. For compliance teams, accounting firms, and any institution with exposure to global crypto flows, the designation carries consequences that extend well beyond Iran's borders. Robust crypto accounting software and sanctions screening protocols are now, more than ever, a frontline compliance requirement.
What OFAC Actually Alleged
BitBank was incorporated in 2024. Within roughly two years of its founding, Treasury says it had become a conduit for significant bitcoin transfers to the IRGC, which the U.S. designates as a foreign terrorist organisation. The exchange is accused of processing flows on behalf of Hormuz Safe Marine Services Authority, an entity that was itself sanctioned on 29 July and that sells "safe passage" insurance to vessels transiting the Strait of Hormuz.
The Hormuz toll arrangement
Iran's economy ministry created Hormuz Safe, which markets insurance, traffic control, and emergency response to ships willing to pay. Rates have ranged from $1 million to $2 million per vessel. Shipping lawyers consulted by OFAC characterised the scheme as a breach of transit rights under the Law of the Sea. Since at least June, Treasury says, a portion of those fees has been funnelled through BitBank to Iranian regime entities.
Secondary sanctions: the wider blast radius
A primary designation freezes BitBank's U.S.-jurisdiction property and bars Americans from transacting with it. The sharper edge is secondary sanctions. Any foreign institution, whether an exchange in Dubai, a custodian in Singapore, or a correspondent bank in Istanbul, that processes BitBank-linked flows risks being cut off from the U.S. financial system. No American nexus is required for that exposure to attach. For offshore venues serving Iranian counterparties, the practical threat is losing dollar access entirely.
The Missing Wallet Addresses
One notable gap in Wednesday's action: OFAC published no cryptocurrency wallet addresses. In previous crypto designations, wallet strings have been the operationally critical output. When OFAC sanctioned Zedcex in January, for instance, it included seven TRON wallet addresses that compliance teams could load directly into screening tools.
Why the omission matters for screening workflows
Without published addresses, sanctions screening teams cannot conduct on-chain lookups against the designation in the standard way. Firms must instead rely on entity-name screening and enhanced due diligence on any counterparty with Iranian exposure. That is a materially heavier lift. Compliance officers should not treat the absence of wallet data as a reduced-risk signal. OFAC can and does publish supplementary wallet information after initial designations, and the obligation to avoid facilitating sanctioned-party transactions is immediate.
The omission also underscores a structural point about how crypto sanctions are evolving: entity designations without on-chain identifiers shift more of the screening burden onto virtual asset service providers and their compliance infrastructure rather than onto automated address matching alone.
Accounting and Regulatory Implications for Firms
Immediate counterparty screening obligations
Any institution that holds, settles, or custodies digital assets must treat this designation as a trigger for a fresh review of Iranian counterparty exposure. That covers exchanges, prime brokers, OTC desks, and any treasury function running a bitcoin position through a third-party venue. The secondary sanctions clause means geographic proximity to Iran, or simply routing through a jurisdiction with Iranian user bases, creates risk even without a direct relationship with BitBank.
What crypto accounting software must capture
This case illustrates why digital asset accounting software cannot be treated as a back-office reconciliation tool alone. When OFAC designates an exchange, any historical transactions that passed through that exchange's wallets, even unknowingly, may require retrospective review. Firms need audit trails that can isolate transaction flows by counterparty, jurisdiction, and date range. Crypto bookkeeping software that cannot produce that kind of granular ledger on demand is a liability in an enforcement environment where secondary sanctions reach globally.
The designation also raises questions about asset recognition. If a firm has digital assets held at a venue that is subsequently found to have BitBank exposure, those assets may be frozen or inaccessible. Under IFRS and US GAAP, an asset that cannot be recovered or transferred presents an impairment question. Controllers and CFOs should map their custodial relationships now, before an OFAC update forces the issue.
AML programme review
For accounting firms advising clients in the digital asset space, the Hormuz case is a concrete example of how sanctions evasion through crypto works in practice: a jurisdiction-restricted entity, a compliant-looking exchange wrapper, and bitcoin as the settlement layer. AML programmes that do not model this threat pattern, state-sponsored actors using newly incorporated exchanges to move value at scale, are under-calibrated for the current environment. Travel Rule compliance, beneficial ownership verification, and transaction monitoring thresholds all warrant revisiting in light of this action.
Geopolitical Context and What Comes Next
The Strait of Hormuz is the transit point for a significant share of global seaborne oil. Iran's decision to monetise safe passage in bitcoin, rather than through conventional banking channels, reflects the degree to which dollar-based sanctions have pushed regime-linked entities toward crypto rails. Treasury Secretary Scott Bessent stated directly that designating Iranian digital asset infrastructure is intended to signal that cryptocurrency is not a sanctions-proof settlement layer.
Precedent for future designations
This action follows a pattern visible in recent OFAC crypto enforcement: entities are designated quickly, wallet addresses may follow later, and secondary sanctions are used to create maximum deterrence for foreign intermediaries. Firms should build their compliance architecture around that pattern rather than waiting for a single comprehensive enforcement package. The gap between entity designation and on-chain identifier publication is a compliance window that needs to be managed actively.
The designation of Pishtaz Simorgh, the software developer behind BitBank, is also worth noting. OFAC reached the technology layer, not just the exchange itself. That is consistent with a broader enforcement posture in which infrastructure providers, not only the exchanges that use their products, are treated as designated entities when they knowingly support sanctioned activity.
Practical Steps for Compliance and Finance Teams
The following actions are warranted immediately following this designation.
For accounting firms and auditors
Re-run counterparty screening for any client with digital asset holdings custodied at venues with documented Iranian user bases. Document that review and its methodology. Where historical transactions involved BitBank or Hormuz Safe-linked flows, flag for legal review before the next audit cycle. Assess whether any client's digital asset holdings require an impairment disclosure if custodial access is compromised by downstream sanctions exposure.
For CFOs and treasury functions
Map all third-party venues and custodians against current OFAC SDN and non-SDN lists, including today's additions. Confirm that your crypto accounting software vendor can produce a time-stamped audit trail isolating transactions by counterparty exchange. If your firm holds bitcoin at any venue with known MENA-region exposure, escalate to legal and compliance for a secondary-sanctions risk assessment. Ensure your AML policy explicitly addresses state-sponsored actors using newly formed crypto exchanges as settlement infrastructure.
For firms already following the OFAC-sanctioned Iranian exchange BitBank story from our earlier coverage, today's action represents an escalation: the Hormuz toll-booth angle adds a geopolitical dimension that expands the pool of potentially exposed institutions well beyond those with any direct Iran connection, to include any global shipping financier or commodity trader that interacts with Hormuz transit logistics.
Source: CoinDesk Policy
Frequently Asked Questions
What does the BitBank OFAC designation mean for firms that have never dealt with Iran?
Secondary sanctions mean that any foreign institution processing transactions connected to BitBank risks losing access to the U.S. financial system, regardless of whether it has any direct Iranian relationship. Compliance teams at global exchanges, custodians, and banks should screen for BitBank exposure even if they believe their Iranian exposure is zero.
Why did OFAC not publish wallet addresses, and does that change my obligations?
OFAC sometimes publishes wallet addresses separately from or after an initial designation. The absence of wallet strings does not reduce the legal obligation to avoid facilitating transactions involving designated entities. It does, however, shift screening reliance from automated address matching to entity-name and jurisdiction-based due diligence.
What accounting treatment applies if assets are held at a venue with BitBank exposure?
If digital assets are held at a custodian that is subsequently found to have material BitBank-linked flows, those assets may be at risk of freezing or inaccessibility. Under both IFRS and US GAAP, assets that cannot be reliably recovered warrant impairment assessment. Controllers should document custodial relationships and their sanctions-screening status as part of period-end close procedures.
Does designating the software developer, Pishtaz Simorgh, set a precedent?
It is consistent with OFAC's broader enforcement trend of reaching technology infrastructure providers that knowingly support sanctioned activity, not just the end-user exchange. Firms building or licensing software to exchanges with sanctioned-country users should treat this as a material compliance signal.
How should AML programmes be updated in response to this case?
AML frameworks should explicitly model the pattern of newly incorporated exchanges, incorporated in non-sanctioned jurisdictions but controlled by or serving sanctioned entities, being used as settlement infrastructure by state actors. Beneficial ownership verification, transaction monitoring thresholds, and Travel Rule compliance should all be reviewed against this threat pattern.
