CryptaCount
EN
EnglishENDeutschDEEspañolESFrançaisFRItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPT
Log in Start Free

OFAC Sanctions Eight Houthi Crypto Wallets: Compliance and Accounting Obligations for Firms and CFOs

CryptaCount Editorial · · 10 min read
AML / KYC / LICENSING OFAC Sanctions Eight Houthi Crypto Wallets:Compliance and Accounting Obligations for Firmsand CFOs

The US Treasury's Office of Foreign Assets Control (OFAC) has designated eight cryptocurrency wallet addresses linked to Ansarullah, commonly known as the Houthis, as part of a broader sanctions action targeting the group's financial infrastructure. On-chain analysis of those addresses shows millions of dollars flowing to other sanctioned entities, including the Russia-based exchange Garantex and networks connected to unmanned aerial vehicle (UAV) suppliers in China and Russia. For accounting firms, auditors, and CFOs managing digital asset portfolios or client crypto exposure, the action is not background geopolitical news: it creates live compliance obligations right now.

OFAC Sanctions Eight Houthi Crypto Wallets: Compliance and Accounting Obligations for Firms and CFOs

What OFAC Designated and Why

The eight cryptocurrency addresses

OFAC's action targets the financial network of Ansarullah, a Yemen-based group carrying the Specially Designated Global Terrorist (SDGT) label. The Houthis were first designated on 10 January 2021, removed in February 2021, and re-designated on 16 February 2024. The current action expands the designation list to include eight specific cryptocurrency wallet addresses controlled by the group and associated actors.

Two of the eight addresses were previously linked to Sa'id al-Jamal, an Iran-based financial facilitator with ties to both the Houthis and the Islamic Revolutionary Guard Corps Qods Force (IRGC-QF). Other addresses in the batch are connected to entities that Israel's National Bureau for Counter Terror Financing (NBCTF) had separately flagged for involvement in terrorist financing. This cross-jurisdictional overlap is notable: it signals coordinated intelligence-sharing between US and Israeli authorities, and it reinforces that the underlying networks are already known to multiple regulators.

On-chain flows to other sanctioned actors

Blockchain intelligence analysis of the eight addresses reveals transaction flows running to several categories of high-risk counterparties: other OFAC-designated individuals and entities within the al-Jamal network, the sanctioned Garantex exchange, and addresses associated with manufacturers and sellers of both UAVs and anti-UAV equipment with links to China and Russia. The volume involved runs into the millions of dollars. This is not a case of isolated wallets with thin transaction histories; these addresses sit within a live, cross-border financing web.

The al-Jamal network has historically used money service businesses, including Mohammed Ali Al Thawr Exchange, Al Hazmi Exchange, and the Davos Exchange and Remittances Company, to move funds into Yemen. Cryptocurrency addresses are layered on top of that structure to add pseudonymity and to route value across jurisdictions where correspondent banking access is limited or monitored.

Why This Matters Beyond the Houthi Context

The Garantex connection

Garantex was sanctioned by OFAC in April 2022. Its reappearance in transaction flows connected to these eight addresses is a significant compliance signal. Any virtual asset service provider (VASP), exchange, or institutional wallet that processed transactions touching Garantex after the date of that designation is already in potential OFAC exposure territory. The Houthi-linked addresses compound that risk by adding an SDGT nexus. For firms reviewing historic crypto ledgers, any transaction path that passes through Garantex addresses and then continues to addresses now appearing on the OFAC SDN list warrants immediate escalation.

The UAV supply-chain angle

On-chain flows connecting these wallets to entities involved in UAV and anti-UAV equipment supply represent a category of risk that goes beyond standard terrorist financing screening. Dual-use goods and military equipment have their own export-control frameworks, and involvement in financing their procurement can trigger obligations under the Export Administration Regulations (EAR) and the Arms Export Control Act, not just OFAC's sanctions programs. CFOs at firms with any crypto treasury activity, and auditors reviewing clients in the digital asset space, need to assess whether transaction-monitoring configurations are calibrated to catch this type of indirect supply-chain exposure.

Cryptocurrency mining by a designated group

Evidence cited in the underlying analysis indicates the Houthis have been involved in mining decentralised cryptocurrencies since at least 2017. While the direct revenue impact of that mining activity is described as limited, the existence of a mining operation run by an SDGT entity matters to compliance programs. Mining rewards deposited into addresses that later touch institutional wallets or exchange order books create a contamination risk that standard transaction-screening tools miss unless they are running full graph-traversal analysis rather than simple address matching.

Accounting and Ledger Implications for Firms and CFOs

Immediate SDN list screening

The first practical step is straightforward: the eight newly designated addresses must be loaded into every active screening tool and reconciled against historic transaction data across all client portfolios and internal treasury positions. Any direct or indirect exposure requires a Suspicious Activity Report (SAR) filing under the Bank Secrecy Act for covered financial institutions, and a voluntary disclosure assessment for other entities. The window for proactive disclosure matters: OFAC's enforcement guidelines treat self-reporting as a significant mitigating factor.

For firms relying on crypto bookkeeping software or digital asset accounting software to manage client ledgers, now is the time to verify that the sanctions-list update cycle for those tools is current and that the eight addresses appear in screening outputs. An address that appears on the SDN list but is not yet loaded into your compliance stack is a gap that OFAC will not treat sympathetically if a transaction is processed in the interim.

Ledger review and impairment considerations

If any tokens held in a client or firm portfolio can be traced, even indirectly, to these addresses, the accounting treatment becomes complicated. Under US GAAP, ASC 820 fair-value measurement principles apply to crypto assets, but the existence of a sanctions taint can affect both the marketability of the asset and management's ability to legally dispose of it. OFAC's rules prohibit transactions with SDN-listed parties without a specific licence, which means a tainted asset may need to be segregated, disclosed in footnotes, and potentially written down to zero if no licence pathway exists.

Auditors conducting risk assessments for clients with digital asset holdings should add a specific inquiry about exposure to the Houthi network and the al-Jamal facilitator chain to their standard AML and sanctions questionnaire. This is particularly relevant for clients operating in or transacting with jurisdictions where the Houthis have governance presence, including ports and checkpoints in northwest Yemen.

Client onboarding and ongoing due diligence

For accounting firms advising VASPs, crypto exchanges, or any business that accepts digital assets as payment, this action reinforces the importance of robust know-your-transaction (KYT) procedures alongside standard know-your-customer (KYC) checks. Wallet address screening at onboarding is necessary but not sufficient: the Garantex flows and UAV supply-chain links in this case were identified through graph-traversal analysis, which traces value through multiple hops rather than checking only the immediate counterparty address. Client engagement letters and AML policies should be reviewed to confirm that KYT scope extends to indirect transaction exposure.

Broader Enforcement Context

An accelerating pattern

This action does not stand alone. In December 2024, OFAC sanctioned cryptocurrency wallets connected to the al-Jamal network in a separate action. The US also launched military strikes against Houthi targets in Yemen in March 2025 in response to attacks on Red Sea merchant shipping. Treasury's sanctions program has run in parallel with those kinetic measures, and the trajectory is clearly toward more designations, not fewer. Accounting firms and CFOs should treat the current eight-address list as a floor, not a ceiling, and build compliance processes that can absorb additional designations rapidly.

The broader Iran-linked sanctions context is also expanding. A separate OFAC action targeted Iranian entities accepting Bitcoin in connection with Strait of Hormuz activities, and the US Treasury sanctions on Iranian firms accepting Bitcoin for Hormuz passage share the same IRGC-QF thread that runs through the Houthi designations. These are not isolated enforcement events; they reflect a coordinated strategy to close cryptocurrency off-ramps for sanctioned Iranian-linked actors.

The pattern also aligns with the broader financial crime escalation documented in the BDO Worldwatch 2026 white-collar crime trends for accounting firms, which flags the growing intersection of geopolitical sanctions enforcement and digital asset flows as a top compliance priority for the profession.

Cross-border coordination signals higher future risk

The involvement of Israel's NBCTF in flagging some of the designated addresses is a concrete example of the multilateral intelligence-sharing that now underpins crypto sanctions enforcement. Firms that operate or advise clients across multiple jurisdictions need to ensure their compliance frameworks are calibrated to designations issued by non-US authorities, not just the OFAC SDN list. An address flagged by the NBCTF but not yet on the OFAC list can still create reputational and regulatory exposure, and in some jurisdictions it creates direct legal obligation.

OFAC Sanctions Eight Houthi Crypto Wallets: Compliance and Accounting Obligations for Firms and CFOs

Practical Next Steps for Accounting Firms and CFOs

A prioritised action checklist

The following steps address the most time-sensitive obligations created by this designation:

  • Load all eight designated addresses into active screening systems and verify that any crypto accounting software or digital asset accounting software used by the firm or its clients is updated with the current SDN list.
  • Run retroactive transaction screening against the designated addresses and the known al-Jamal network, including Mohammed Ali Al Thawr Exchange, Al Hazmi Exchange, and the Davos Exchange and Remittances Company.
  • Assess any historic exposure to Garantex transaction flows for potential OFAC disclosure requirements.
  • Review client digital asset holding disclosures and audit files for any indirect exposure to SDGT-linked addresses.
  • Update client onboarding and AML policies to require graph-traversal KYT analysis, not just point-in-time address screening.
  • Brief senior leadership and audit committees on the dual sanctions risk: OFAC liability and the separate export-control exposure created by the UAV supply-chain flows.
  • Consult OFAC-specialist counsel if any historic exposure is identified, to assess whether voluntary self-disclosure is appropriate before any regulatory inquiry.

Source: TRM Labs

Frequently Asked Questions

What does it mean for a crypto address to be on the OFAC SDN list?

Once an address is designated, US persons and entities are prohibited from transacting with it. Any funds or assets connected to a designated address are considered blocked, and processing a transaction involving a blocked address, even inadvertently, can result in civil or criminal penalties. The prohibition applies to direct transactions and, in many enforcement cases, to transactions where the SDN-listed address appears within a short number of hops in the transaction graph.

Does our firm have an obligation if a client's wallet indirectly touched one of these addresses?

Indirect exposure does not automatically trigger the same hard prohibition as direct transactions, but it does create a risk that OFAC and bank regulators will scrutinise. Covered financial institutions have SAR filing obligations where there is reason to suspect a transaction involves funds derived from illegal activity, including sanctions evasion. Non-bank accounting and advisory firms should document their analysis of any indirect exposure and take legal advice on whether voluntary disclosure is warranted.

Are the Houthi designations relevant to firms with no Middle East exposure?

Yes. The on-chain flows identified in this action pass through Garantex, which operated out of Russia, and through addresses linked to suppliers in China. A firm does not need any direct connection to Yemen to encounter this risk. Any client or counterparty that transacted with Garantex after April 2022 or that has on-chain links to the UAV-connected addresses could create indirect exposure for firms involved in their accounting or audit.

How quickly does the OFAC SDN list update in practice, and what should firms do in the interim?

OFAC publishes SDN list updates on its website, and the list can change on any business day. Firms should subscribe to OFAC's free email alert service for SDN updates and ensure that any third-party screening tool used in their crypto accounting software stack has a documented update SLA. In the period immediately after a new designation, manual cross-referencing against OFAC's published list is advisable until automated tools confirm the update is live.

What accounting standard governs the treatment of a crypto asset that may be tainted by sanctions?

Under US GAAP, ASC 820 governs fair-value measurement of crypto assets. If sanctions taint restricts the firm's or client's ability to sell or transfer an asset, that restriction is a Level 3 input that affects the fair-value calculation. In practice, an asset with a direct SDN taint and no available OFAC licence may need to be disclosed in financial statement footnotes and written down to reflect the legal constraint on disposal. Auditors should raise this as a going-concern or material-misstatement risk where the exposure is material to the balance sheet.

USGLOBALGeneralEnforcementAML/KYC & Licensing

Related articles

AML/KYC & Licensing
OFAC Sanctions Hamas Crypto Facilitators and Seven TRON Addresses: What Accounting Firms and CFOs Must Act On Now
AML/KYC & Licensing
US Treasury Sanctions Nemesis Darknet Admin: AML Alert for Accounting Firms and CFOs
AML/KYC & Licensing
OFAC Sanctions Sinbad: What Accounting Firms and CFOs Must Act On Now
AML/KYC & Licensing
OFAC Sanctions Nearly 400 Russia-Linked Targets: Crypto Screening Duties for Accounting Firms and CFOs