CryptaCount
EN
EnglishENDeutschDEEspañolESFrançaisFRItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPT
Log in Start Free

US Treasury Sanctions Iranian Firms Taking Bitcoin for Hormuz Passage: What Accounting Firms and CFOs Must Act On Now

CryptaCount Editorial · · 9 min read
AML / KYC / LICENSING US Treasury Sanctions Iranian Firms TakingBitcoin for Hormuz Passage: What AccountingFirms and CFOs Must Act On Now

The US Treasury's Office of Foreign Assets Control (OFAC) has sanctioned a group of Iranian entities that were allegedly collecting Bitcoin payments in exchange for granting safe passage through the Strait of Hormuz, one of the world's most strategically critical maritime chokepoints. The designations, published on 31 July 2026, represent a direct signal from regulators that state-linked actors are actively exploiting crypto rails to circumvent conventional financial controls — and that any accounting firm, CFO, or compliance officer whose clients touch digital assets needs to respond with concrete screening and recordkeeping action right now.

US Treasury Sanctions Iranian Firms Taking Bitcoin for Hormuz Passage: What Accounting Firms and CFOs Must Act On Now

What OFAC Has Actually Designated

OFAC's action targets Iranian companies and associated individuals accused of operating what amounts to a crypto-denominated toll scheme on Hormuz traffic. Ships transiting the strait were allegedly required to pay in Bitcoin, with the proceeds flowing to entities that US authorities say are linked to Iran's broader sanctions evasion infrastructure.

The Core Mechanics of the Scheme

The scheme is notable for several reasons beyond the headline. First, it used Bitcoin — a transparent, pseudonymous ledger — rather than privacy coins or mixers, suggesting the operators either underestimated blockchain analytics capabilities or relied on layering techniques to obscure the trail. Second, the payments were structured as operational charges for maritime services, which is precisely the kind of commercial-sounding transaction that can slip past generic transaction monitoring rules if a compliance team is not screening counterparties against OFAC's Specially Designated Nationals (SDN) list in real time. Third, the geographic chokepoint — Hormuz handles roughly 20 percent of global oil trade — means the transaction flows would have touched shipping companies, insurers, commodities traders, and potentially their financial intermediaries across multiple continents.

Who Is Named and What It Means Legally

Once an entity appears on the SDN list, US persons and entities — and in many cases non-US firms subject to secondary sanctions exposure — are prohibited from transacting with them. Any crypto wallet addresses published alongside the designations become blocked addresses. Receiving funds from, or sending funds to, those addresses after the designation date constitutes a sanctions violation regardless of whether the transacting party knew about the underlying scheme. Ignorance is not a complete defence under OFAC's strict liability framework.

Why This Enforcement Action Stands Out

OFAC has sanctioned crypto-adjacent actors before, but this action has a distinct character. It targets what looks like a quasi-governmental revenue mechanism: a state-linked entity using decentralised payment infrastructure to monetise control over a physical chokepoint. That blurs the line between traditional sanctions evasion and the use of crypto as sovereign financial infrastructure — a pattern regulators in Washington have been watching with growing concern.

The Blockchain Analytics Dimension

Because the payments were made in Bitcoin, every transaction is, in principle, traceable on-chain. OFAC and its law enforcement partners will have used blockchain analytics to map the wallet clusters, identify counterparties, and build the evidentiary record that underpins the designations. For compliance teams, this cuts both ways. On one hand, the on-chain record means investigators can reach back in time and identify firms that unwittingly processed related transactions. On the other hand, firms that have already embedded blockchain analytics into their own AML workflows have a defensible audit trail demonstrating proactive due diligence — precisely the kind of evidence that matters when OFAC weighs whether to bring an enforcement action or issue a no-action finding.

Secondary Sanctions Risk for Non-US Firms

Non-US accounting firms advising clients in the shipping, commodities, or energy sectors face a particular exposure. US secondary sanctions can reach foreign financial institutions that knowingly facilitate significant transactions with SDN-listed parties. If a foreign firm's client paid a Hormuz Bitcoin toll and that payment is now traceable to a newly designated entity, the firm may need to assess whether it has a disclosure obligation, a suspicious activity reporting obligation under its local AML regime, or a duty to advise the client to self-report to OFAC's licence application process.

Accounting and Recordkeeping Implications

From a pure accounting standpoint, any Bitcoin transaction linked to a newly sanctioned entity must be treated carefully in the books. If a client received Bitcoin as payment for services and that Bitcoin originated from a wallet now associated with a designated party, the receivable may need to be written off or held in suspense pending legal advice. If the client paid Bitcoin as a fee and the recipient is now sanctioned, the payment may need to be disclosed as a potential sanctions exposure in the financial statements' contingent liabilities note.

Digital Asset Accounting Software and SDN Screening

Firms using crypto accounting software need to verify that their chosen platform ingests OFAC SDN wallet address updates and flags affected transactions automatically. This is no longer a nice-to-have feature. OFAC publishes updated SDN lists — including crypto wallet addresses — continuously, and a firm's ledger system should be capable of matching on-chain transaction history against those lists on a rolling basis. Digital asset accounting software that cannot do this forces manual screening, which introduces lag and human error at precisely the moment regulators expect automated controls.

Firms should also confirm that their crypto bookkeeping software generates an immutable audit log of every wallet address involved in a transaction, the timestamp, the USD equivalent at the time of the transaction, and the SDN screening result. That log is the first document OFAC will request if it opens a voluntary self-disclosure or enforcement investigation.

Fair Value and Impairment Considerations

Under the FASB's ASC 350-60 fair value model for crypto assets, a firm holding Bitcoin that is subsequently identified as having passed through a sanctioned wallet cluster faces a nuanced accounting question. The Bitcoin itself is not impaired in the traditional sense — its market price is unchanged — but the firm's ability to sell or transfer it may be restricted pending legal review. Depending on the facts, that restriction could trigger a disclosure or, in extreme cases, an impairment assessment if the asset cannot be liquidated without regulatory risk. Auditors should discuss this scenario with engagement teams before it becomes a last-minute year-end surprise.

Practical Steps for Accounting Firms and CFOs

The designation creates a short, urgent checklist. Acting on it promptly is both a regulatory requirement and a demonstration of the kind of proactive compliance culture that OFAC treats as a mitigating factor in enforcement decisions.

Immediate Actions in the First 48 to 72 Hours

First, pull the full SDN list update and extract any Bitcoin wallet addresses published alongside the Iranian designations. Cross-reference those addresses against all client transaction histories held in your digital asset accounting system. Document the screening date, the methodology, and the result.

Second, contact any client with known exposure to Hormuz-transit shipping, commodities, or energy trading and ask directly whether they have made or received Bitcoin payments to or from parties involved in maritime transit fees in the Gulf region. The question may feel unusual, but the conversation is far less costly than a sanctions violation discovered during an OFAC investigation.

Third, review your own firm's trust accounts, crypto custody arrangements, or any digital asset holdings for indirect exposure. A fund-of-funds or multi-asset portfolio can carry indirect exposure through a sub-fund that had no idea it was touching a sanctioned counterparty.

Longer-Term Compliance Infrastructure

This action reinforces a point that has appeared repeatedly in OFAC guidance: firms operating in or advising clients in the digital asset space need a written, risk-based sanctions compliance programme that specifically addresses crypto. That programme should cover real-time wallet screening, escalation procedures when a match is found, and a documented training schedule for staff who handle crypto transactions. For detailed frameworks on structuring these controls, see our analysis of AML and sanctions best practices for digital asset firms and our earlier breakdown of OFAC sanctions involving crypto compliance obligations for firms and CFOs.

The Broader Enforcement Signal

Taken together with a series of OFAC crypto-related designations over the past 18 months, this action confirms a clear trajectory: US authorities are using blockchain analytics to proactively identify crypto-denominated sanctions evasion, and they are willing to designate state-linked actors even when the schemes involve physical infrastructure rather than purely financial flows. The Hormuz case is unusual in its geopolitical texture, but the underlying compliance failure it exploits — inadequate wallet screening by parties in the transaction chain — is entirely routine.

For accounting firms, the enforcement signal is unambiguous. Clients in shipping, energy, commodities, and any sector with Gulf region exposure need a documented crypto sanctions screening programme, and those clients' auditors need to be asking about it. For CFOs, the lesson is that Bitcoin's on-chain transparency cuts both ways: it is the same feature that lets investigators trace every hop in the payment chain back to your firm's treasury if controls were not in place.

Regulators are not slowing down. The pace of OFAC crypto designations has accelerated, the analytical tools available to investigators have improved significantly, and the expectation of proactive compliance from the private sector has never been higher. Firms that treat crypto sanctions screening as an afterthought are not just taking a regulatory risk — they are taking a reputational and financial one.

US Treasury Sanctions Iranian Firms Taking Bitcoin for Hormuz Passage: What Accounting Firms and CFOs Must Act On Now

Frequently Asked Questions

Does OFAC publish wallet addresses when it sanctions crypto-linked entities?

Yes. OFAC now routinely includes specific cryptocurrency wallet addresses in SDN designations involving digital asset activity. Those addresses are published in the SDN list update and must be screened against by any US person or entity — and by non-US firms subject to secondary sanctions exposure — from the designation date forward.

What is the legal standard for a sanctions violation involving crypto?

OFAC operates under a strict liability framework for most sanctions violations. That means a firm can be held liable even if it did not know it was transacting with a sanctioned party. The presence or absence of a reasonable compliance programme, and whether the firm self-disclosed, are factors OFAC weighs when determining the severity of the penalty — but they do not eliminate liability.

How should an accounting firm handle a client transaction that may have touched a newly designated wallet?

The first step is to preserve all records related to the transaction and avoid further dealings with the relevant wallet. The firm should then seek legal counsel with OFAC experience to assess whether a voluntary self-disclosure is warranted. OFAC's enforcement guidelines treat proactive self-disclosure as a significant mitigating factor that can substantially reduce penalties.

Do non-US accounting firms need to worry about US sanctions on Iranian crypto entities?

Yes, in certain circumstances. US secondary sanctions can reach non-US financial institutions and professional service firms that knowingly facilitate significant transactions with SDN-listed parties. Non-US firms advising clients in affected sectors should assess their exposure and, where relevant, consult with US sanctions counsel.

What should CFOs look for when evaluating crypto accounting software for sanctions compliance?

Key capabilities include automated ingestion of OFAC SDN wallet address updates, real-time or near-real-time transaction screening against those lists, an immutable audit log of screening results, and escalation workflows when a potential match is identified. Systems that require manual SDN list updates introduce lag that regulators do not accept as a mitigating factor.

Source: Decrypt

USGLOBALGeneralEnforcementAML/KYC & Licensing

Related articles

AML/KYC & Licensing
New York Sues Kalshi: Licensing and Compliance Implications for Accounting Firms and CFOs
AML/KYC & Licensing
US Sanctions Iran's Strait of Hormuz Bitcoin Insurance Scheme: What Accounting Firms and CFOs Must Act On Now
AML/KYC & Licensing
Digital Asset AML and Sanctions: BDO's Best Practices for Firms
AML/KYC & Licensing
OFAC Sanctions Hamas Financing Network: Crypto Compliance Alert for Accounting Firms and CFOs