CryptaCount
EN
EnglishENDeutschDEEspañolESFrançaisFRItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPT
Log in Start Free

Treasury Sanctions Crypto Exchange Behind Iran's Bitcoin Ship Tolls

CryptaCount Editorial · · 7 min read
ENFORCEMENT Treasury Sanctions Crypto ExchangeBehind Iran's Bitcoin Ship Tolls

The US Department of the Treasury's Office of Foreign Assets Control (OFAC) has sanctioned a cryptocurrency exchange it says was the financial backbone of a scheme in which Iran collected Bitcoin as forced transit fees from commercial vessels navigating the Strait of Hormuz. The action, dated 18 September 2026, adds the exchange and associated wallet addresses to the Specially Designated Nationals (SDN) list, making any US person's dealings with them a federal violation. For accounting firms, CFOs, and compliance officers who manage digital asset exposures, the designation carries immediate practical consequences.

Treasury Sanctions Crypto Exchange Behind Iran's Bitcoin Ship Tolls

What OFAC Actually Alleged

According to Treasury's designation, Iranian authorities demanded Bitcoin payments from ship operators as a condition of safe passage through the Strait of Hormuz, one of the world's most critical maritime chokepoints. The sanctioned exchange allegedly provided the conversion and settlement infrastructure that turned those Bitcoin receipts into spendable value for the Iranian parties involved, effectively functioning as the off-ramp for a state-directed crypto revenue stream.

The Exchange's Role in the Payment Chain

OFAC's framing is significant: the exchange is not accused simply of failing to screen customers. It is described as an active participant in routing proceeds tied to coercive state conduct. That distinction matters legally. Designations that allege operational involvement, rather than passive negligence, tend to accompany broader secondary-risk warnings to the financial sector, signalling that Treasury views the surrounding ecosystem as potentially tainted.

Wallet Addresses and the SDN List

As is now standard practice, Treasury published specific cryptocurrency wallet addresses alongside the entity designation. Those addresses become immediately blocked property under US sanctions law. Any US person who transacts with, processes, or facilitates a transfer involving those addresses, even inadvertently, faces strict-liability exposure. There is no "good faith" carve-out in OFAC's strict-liability framework for crypto.

Why the Hormuz Angle Changes the Risk Calculus

Most crypto sanctions cases to date have involved exchanges accused of serving darknet markets, ransomware groups, or terrorist financiers. A case centred on state-directed maritime toll collection is materially different in its industry reach.

Shipping Finance and Trade Clients

Accounting firms serving shipping companies, commodity traders, or freight forwarders should note that this action bridges two previously separate compliance domains: maritime trade sanctions and digital asset controls. A client that operates or charters vessels in or near the Strait of Hormuz now has a crypto-adjacent sanctions exposure, even if that client has never held a digital asset in its own name. If a counterparty somewhere in the payment chain used a sanctioned exchange to settle a shipping-related obligation, the exposure can travel upstream.

State-Actor Crypto Use as a Systemic Signal

This case fits a pattern that regulators and intelligence agencies have highlighted with increasing frequency: sovereign or quasi-sovereign actors are experimenting with crypto not just to evade dollar-denominated banking but to monetise coercive power in new ways. The Hormuz scheme, if the allegations are accurate, represents a novel application: using Bitcoin as a toll booth currency backed by the implicit threat of force. Compliance frameworks designed around retail or commercial crypto flows were not built with this threat model in mind. Firms need to widen their scenario analysis accordingly.

Accounting and Bookkeeping Implications

The designation creates several discrete accounting challenges that practitioners using any crypto accounting software or digital asset accounting software stack must address without delay.

Blocking and Freezing Obligations

US persons who discover they hold, or have recently processed, assets traceable to the newly listed wallet addresses must block those assets and report the blocking to OFAC within ten business days. From an accounting standpoint, blocked assets cannot be recognised as freely available cash or cash equivalents. They must be reclassified, typically as restricted assets, and disclosed in the notes to financial statements. The blocking obligation applies regardless of how the asset arrived on the books: a client that received crypto from a counterparty who in turn sourced funds from the exchange could find itself holding tainted value.

Transaction Lookback and Ledger Review

When a new SDN designation drops, the practical first step for any firm running a crypto bookkeeping software workflow is to run the published wallet addresses against historical transaction records. Most enterprise-grade blockchain analytics integrations can do this automatically, but the results require human review and legal sign-off before any remediation steps are taken. Document every step of that review; OFAC gives significant weight to a demonstrated, contemporaneous compliance process when assessing penalties.

Revenue Recognition and Realisation Risk

For any firm that recognised revenue from a crypto payment that is later found to be SDN-linked, there is a potential restatement question. Revenue from a transaction that violates US sanctions law is not legally recognisable under US GAAP or IFRS as earned income in the ordinary course of business. Depending on materiality, this could require a prior-period adjustment. Auditors reviewing crypto revenue streams should add SDN wallet screening to their substantive testing procedures, not treat it as a purely legal matter sitting outside the audit scope.

Compliance Steps for Accounting Firms and CFOs

The actionable list below is drawn from OFAC's published compliance frameworks and standard AML practice, not from any proprietary methodology.

Immediate Actions

First, extract the newly published wallet addresses from OFAC's SDN list and push them into every screening system your firm or your clients' firms use, whether that is a dedicated blockchain analytics platform, a crypto accounting software integration, or a manual watchlist. Do this before the next transaction cycle runs.

Second, notify relevant client-facing staff, particularly those working on shipping, commodity trading, or cross-border payment mandates, that this designation exists and that they should escalate any transaction query involving those sectors before proceeding.

Third, if you have clients who operate vessels or own cargo in Hormuz-adjacent routes, initiate a targeted AML review of their crypto-adjacent counterparties. The nexus between maritime operations and digital asset payments is no longer theoretical.

Medium-Term Procedure Updates

Update your client onboarding questionnaires to capture whether a client has received crypto payments in connection with any shipping, port, or transit-fee arrangement. This sounds niche, but the Hormuz case shows that state actors can insert crypto into supply chains in ways that do not announce themselves as sanctions-adjacent.

Review the sanctions screening cadence for crypto wallets held by clients. Screening at onboarding only is no longer sufficient when OFAC is adding wallet addresses in real time to the SDN list. A wallet that was clean last quarter may carry risk today. Firms relying on crypto bookkeeping software should verify that their provider pushes SDN wallet updates automatically and that the update frequency matches or exceeds OFAC's publication cadence.

For firms with clients in the digital asset accounting software space, consider whether your engagement letters and representation letters adequately capture the client's obligation to maintain current SDN screening. If they do not, this is a good moment to refresh those documents.

Treasury Sanctions Crypto Exchange Behind Iran's Bitcoin Ship Tolls

Frequently Asked Questions

Does this OFAC action affect non-US firms?

Directly, it applies to US persons and US-nexus transactions. However, non-US firms that maintain dollar-denominated accounts, have US counterparties, or process transactions through US correspondent banks are exposed to secondary sanctions risk. Treasury has broad authority to designate non-US financial institutions that knowingly facilitate transactions for SDN-listed parties.

What should an auditor do if a client's crypto ledger shows transactions with the listed wallet addresses?

Escalate immediately to the engagement partner and, where applicable, the client's legal counsel. Do not sign off on any financial statements that include unresolved SDN-linked balances. The auditor's responsibility is to obtain sufficient appropriate evidence that material amounts are free from sanctions taint; an unresolved SDN hit is a scope limitation until it is cleared or appropriately disclosed.

Can a firm transact with the listed exchange if it obtains an OFAC licence?

Specific licences are available from OFAC for certain categories of otherwise prohibited transactions, but they are not routinely granted for dealings with exchanges designated on national security grounds. Any firm considering a licence application should seek specialised sanctions counsel; the process is fact-specific and can be lengthy.

How does this affect crypto accounting software workflows specifically?

Any digital asset accounting software that ingests wallet-level transaction data should be configured to flag SDN-listed addresses as they appear in imported records. Firms should test this functionality actively rather than assume it works. If the software does not support automated SDN screening, a manual reconciliation against the OFAC SDN list must be built into the month-end close process.

Is there a lookback obligation for historical transactions with the listed exchange?

OFAC's guidance on voluntary self-disclosure encourages firms to review historical transactions when a new designation is published and to report any apparent violations. The look-back period is not formally capped, but regulators typically focus on transactions within the preceding five years. A structured, documented lookback combined with prompt voluntary disclosure is the most effective mitigation strategy if historic exposure is found.

Source: Decrypt

USGeneralEnforcementEnforcement

Related articles

Enforcement
DOJ Seizes $2.3M in Bitcoin from Colonial Pipeline Ransomware Attack
Enforcement
Robinhood Engineers Charged Over Hyperliquid Insider Trades
Enforcement
US Seeks $61M Crypto Forfeiture in Iranian Oil Sanctions Case
Enforcement
Retirees Sue Broad Street Fund Over Z Squared Dogecoin Miner Deal