CryptaCount
EN
EnglishENDeutschDEEspañolESFrançaisFRItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPT
Log in Start Free

OFAC Sanctions Hamas Financing Network: Crypto Compliance Alert for Accounting Firms and CFOs

CryptaCount Editorial · · 9 min read
AML / KYC / LICENSING OFAC Sanctions Hamas Financing Network:Crypto Compliance Alert for AccountingFirms and CFOs

On 23 July 2026, the US Treasury's Office of Foreign Assets Control designated three individuals and seven TRON cryptocurrency addresses linked to a Hamas financing network, adding the addresses to the Specially Designated Nationals (SDN) list. The seven wallets collectively received approximately $38.6 million in cryptocurrency. For any firm operating crypto accounting software, maintaining books for digital-asset businesses, or advising clients with exposure to TRON-based instruments, this action demands an immediate response.

OFAC Sanctions Hamas Financing Network: Crypto Compliance Alert for Accounting Firms and CFOs

What OFAC Actually Designated

The named individuals

OFAC designated Zaid Issam Ahmed al-Jebouri, an Iraqi national based in Istanbul, along with two associates: Abdulla Issam Ahmad al-Jebouri and Khaldun Khamis Zakaria Alden. All three were named as Specially Designated Global Terrorists (SDGTs). The designation centres on their operation of El-Kahira for General Trading, a Turkey-registered over-the-counter (OTC) exchange office that serves as the hub of the identified financing network.

The seven TRON addresses

OFAC added seven TRON-network cryptocurrency addresses as identifiers in the SDN entry. On-chain analysis cited in the underlying enforcement record shows that these wallets interacted significantly with addresses already listed in a January 2026 seizure order issued by Israel's National Bureau for Counter Terror Financing (NBCTF). Al-Jebouri's personal wallet received funds from several El-Kahira-related wallets that appeared in that earlier NBCTF order. Outflows from the same wallet reached a Gaza-based money service business (Buy Cash Money and Transfer Company, itself an OFAC SDN) and a UAE-based OTC desk. The wallet also sent funds to deposit addresses at mainstream exchanges, addresses that dually received transfers from a Palestine-based OTC and a separate Hamas-linked wallet.

The $38.6 million figure in context

The collective receipt figure of approximately $38.6 million across the seven wallets reflects cumulative inflows as identified by on-chain tracing. It does not necessarily represent funds that remain available today; some portion will have been moved, converted, or spent before the designation. The figure nonetheless signals the scale of the network and the sophistication of the layering: OTC desks, mainstream exchange deposit addresses, and cross-border MSBs all feature in the traced flows.

Why OTC Exchange Offices Are the Key Compliance Challenge

Small, informal, and often unlicensed

El-Kahira for General Trading is described in the OFAC action as a regional exchange office. These entities are frequently small businesses operating in jurisdictions where crypto-specific licensing requirements are limited, inconsistently enforced, or non-existent. They may process significant volumes while remaining below the thresholds that trigger formal AML obligations in their home country. That is precisely what makes them attractive to illicit finance networks: they offer a veneer of legitimacy without the compliance infrastructure that a regulated exchange would require.

The link to mainstream platforms

One of the more operationally significant details in this action is the path from a sanctioned OTC desk to deposit addresses at mainstream exchanges. When illicit funds reach a regulated exchange via an apparently clean intermediate address, they can pass initial screening if the exchange's transaction monitoring looks only one hop back. This is a known limitation of shallow-hop screening, and it is why FATF's Recommendation 16 travel rule and the associated on-chain tracing obligations exist. Compliance teams at regulated platforms cannot rely solely on direct counterparty checks.

TRON as a network of focus

All seven designated addresses sit on the TRON network. TRON-based stablecoins (primarily USDT-TRC20) have featured in multiple recent OFAC and NBCTF enforcement actions because they offer low transaction fees and high liquidity in informal OTC markets across the Middle East and Central Asia. Firms using crypto bookkeeping software to record client transactions should verify that their screening tools cover TRON addresses, not just Ethereum or Bitcoin wallets, against the OFAC SDN list.

Accounting and Bookkeeping Implications

Immediate wallet screening obligation

Under the US sanctions framework, any US person (including accounting firms advising US clients, and any foreign firm with US dollar clearing exposure) is prohibited from transacting with a designated address. The obligation applies to the exact addresses listed and, under OFAC's 50% rule, to any wallet more than 50% owned or controlled by a designated person. The seven TRON addresses must now be added to every active screening list used by compliance infrastructure connected to your practice.

Client portfolio review

If your practice provides digital asset accounting software support, bookkeeping services, or audit work for clients holding TRON-based assets, the following steps are necessary. First, pull a current ledger of all TRON addresses associated with client accounts. Second, run those addresses against the updated OFAC SDN list, which now includes the seven designated wallets. Third, check for indirect exposure: if a client's address has transacted with any of the newly listed addresses at any point, that interaction needs to be documented and assessed for materiality and reporting obligations.

Financial statement and balance sheet considerations

Under FASB ASC 350-60 (the crypto asset fair value standard that took effect for most calendar-year filers in 2025), digital assets held by a reporting entity must be measured at fair value each period. If an asset or address is subject to an OFAC freeze or connected to a sanctioned counterparty, questions arise about recoverability and whether an impairment or disclosure is required. Auditors reviewing crypto asset schedules should specifically query whether any holdings were sourced from or transacted through newly designated addresses. This is not a theoretical risk: the on-chain record is public and permanent, and a regulator or counterparty can trace it.

Revenue recognition for service providers

Accounting firms and fintech service providers that bill fees in TRON-based stablecoins, or whose clients do, need to check whether any fee receipts trace back to the El-Kahira network. Revenue recognised from a transaction that is later found to involve a sanctioned counterparty creates both a legal exposure (unlicensed dealing) and a financial reporting issue (whether that revenue is truly earned and whether it must be disgorged). Robust crypto accounting software with on-chain tracing integration is the practical defence here.

AML and KYC Obligations for Regulated Firms

Travel rule and transaction monitoring updates

Regulated virtual asset service providers (VASPs) and any accounting firm acting as a VASP or providing VASP-adjacent services must update their transaction monitoring rules to flag TRON addresses transacting with the SDN-listed wallets. The FATF travel rule, now implemented in the US under FinCEN rules and in many other jurisdictions, requires the collection and transmission of originator and beneficiary information for transfers above threshold. An OTC desk operating outside formal licensing, as El-Kahira appears to have done, will typically not have supplied accurate travel rule data, making the on-chain tracing of counterparty addresses the primary detection mechanism.

Suspicious Activity Report considerations

If a US financial institution or money services business identifies a past transaction with one of the seven newly designated TRON addresses, the standard SAR filing analysis applies: is the transaction structurally suspicious, does it involve a now-designated party, and does it meet the dollar threshold for mandatory filing? The designation date of 23 July 2026 is the operative date from which US persons are prohibited from transacting. Past transactions that occurred before designation are not automatically violations, but they should be reviewed and documented, and a SAR may still be warranted if the pattern of activity meets the suspicious-activity test.

Cross-border exposure and non-US firms

Non-US firms are not directly bound by OFAC, but secondary sanctions risk is real. Any transaction that clears in US dollars, involves a US correspondent bank, or touches a US-person counterparty brings the OFAC framework into play. Firms in the EU, UK, and Gulf region that provide crypto accounting or bookkeeping software services to clients with TRON exposure should treat this designation as a signal to review their own screening coverage, even absent a direct US nexus. The NBCTF January 2026 seizure order that preceded this action already placed the El-Kahira addresses in the Israeli sanctions framework; the OFAC action now adds a US-law dimension.

What Compliance Teams Should Do Now

Immediate actions

Update SDN screening lists to include all seven TRON addresses designated on 23 July 2026. Run retrospective checks against client transaction histories on TRON, covering at minimum the twelve months prior to designation. Document the results and retain records in accordance with your firm's AML record-keeping policy, typically five years under FinCEN rules. If any match is found, escalate to your Money Laundering Reporting Officer and seek legal advice before any further action.

Longer-term programme enhancements

This action reinforces a pattern visible across recent OFAC and NBCTF enforcement: small regional OTC desks are a key node in terror and sanctions evasion networks, and mainstream platforms are reached through multi-hop routing. Compliance programmes that rely only on direct counterparty screening will miss this exposure. Firms should invest in crypto accounting software that integrates blockchain analytics at the address level, not just at the exchange or entity level, and that covers TRON alongside Bitcoin and Ethereum. Partnership with specialist blockchain analytics providers, as explicitly noted in the OFAC enforcement record, is increasingly an expected component of a robust AML framework, not an optional enhancement.

OFAC Sanctions Hamas Financing Network: Crypto Compliance Alert for Accounting Firms and CFOs

Frequently Asked Questions

Does this designation affect firms outside the United States?

Directly, OFAC sanctions bind US persons and entities. Indirectly, any firm clearing transactions in US dollars, using US correspondent banking, or dealing with US-person clients acquires a secondary sanctions exposure. Non-US firms in the EU, UK, and elsewhere should treat this designation as a prompt to review their own screening coverage, particularly for TRON-network addresses.

What does the OFAC 50% rule mean for these wallets?

Under OFAC's 50% rule, any entity or wallet that is 50% or more owned or controlled by a designated person is itself treated as a sanctioned entity, even if it is not explicitly named in the SDN list. This means that wallets controlled by al-Jebouri, Abdulla Issam Ahmad al-Jebouri, or Khaldun Khamis Zakaria Alden that were not individually listed may still be off-limits to US persons if ownership or control can be established.

How should past TRON transactions be treated under FASB ASC 350-60?

FASB ASC 350-60 requires crypto assets to be carried at fair value. If a historical transaction involved a now-sanctioned address, the accounting question shifts to whether the associated asset is recoverable and whether there is a disclosure or impairment obligation. Auditors should request that management identify any on-chain interactions with the seven designated addresses and assess the impact on asset recoverability and financial statement disclosure.

Is TRON-based USDT specifically at higher risk?

The OFAC action designated TRON-network addresses specifically. USDT on TRON (TRC-20) is frequently used in informal OTC markets in the Middle East and Central Asia because of its low fees and high liquidity. Firms processing or recording TRC-20 transactions should ensure their screening tools flag TRON addresses against the SDN list, which many basic screening solutions handle less thoroughly than Bitcoin or Ethereum addresses.

What records should a compliance team retain after running a retrospective screen?

Under FinCEN rules, records related to suspicious activity reports and the underlying transaction data must be retained for five years. Even where no SAR is filed, firms should document the screening methodology, the date the screen was run, the result, and any escalation decision. This documentation is your defence in a subsequent regulatory examination.

Source: Chainalysis

USGLOBALGeneralEnforcementAML/KYC & Licensing

Related articles

AML/KYC & Licensing
Bitcoin ATM Scams: What Banks and Accounting Firms Must Do Now
AML/KYC & Licensing
MetaMask hired suspected North Korean dev flagged months earlier
AML/KYC & Licensing
EU Sanctions 'Stern': Trickbot Boss and the $300M Ransom Trail
AML/KYC & Licensing
OFAC Adds 134 ISIS-K and PCC-Linked Crypto Wallets: What Firms Must Do Now