AMLConsensus · course
Programme · Lesson 3.1
Section 3 · Lesson 3.1

Sanctions: OFAC, EU, UK and why this is the most dangerous risk

Sanctions risk stands apart from every other source of risk in an AML check. It is the only category where there is no such thing as "moderate" — here the rule is all or nothing. Let's look at who maintains sanctions lists, what an SDN is, why US sanctions reach you anywhere in the world, and why even 1% of sanctions exposure nullifies any transaction.

Who maintains sanctions lists, and why

Sanctions are a government tool that prohibits any economic relationship with specific individuals, organisations and — in our case — crypto addresses. Unlike "reputational" risk, which you assess yourself, sanctions have the force of law. A violation is not "bad practice" but a direct legal offence carrying criminal and financial liability.

What the SDN is, and the crypto addresses inside it

The SDN List is a register of parties with whom US citizens and companies are forbidden to do business. Historically it contained people's names, company names and passport numbers. Beginning in 2018, OFAC started adding a Digital Currency Address identifier — a specific public address on a blockchain. The first ones on the list were addresses linked to Iranian ransomware operators.

Technically an entry looks like this: the name of the subject, their country, and then lines of the form Digital Currency Address - ETH 0x8589427373D6D84E98730D7795D8f6f8731FDA16. From that moment, any transaction with this address is a breach of the sanctions regime. And the blockchain works against the violator here: the address is public, every transfer is visible forever, and nothing can be "rewound".

SDN address
on the OFAC list
1 transfer
Your wallet is "tainted"

Extraterritoriality: why this concerns everyone

The key feature of OFAC sanctions is their extraterritorial nature. Many people mistakenly think: "I'm not a US citizen, I'm not in the US — so this doesn't apply to me." That is a dangerous misconception.

Why this matters. The US dollar and dollar infrastructure permeate the entire world. The moment USDT/USDC appears in a chain (the issuers are the American companies Tether and Circle), or an American exchange, an American correspondent bank, or even a server in a US jurisdiction is involved — you fall under American law. Circle and Tether can technically freeze stablecoins at any address at OFAC's request, and they do so regularly. Your "frozen" USDT will simply stop moving.

This is precisely why sanctions compliance is not an "American whim" but essential hygiene for anyone who works with cryptocurrency professionally: exchanges, swap services, payment providers, custodians.

Three telling examples

  1. Tornado Cash (August 2022). OFAC added to the SDN not a person, but the mixer smart contract itself — a set of Ethereum addresses. This was a precedent: autonomous code fell under sanctions. Any transfer into or out of these contracts became a violation. Many ordinary users who were "cleaning" legitimate funds for the sake of privacy suddenly found themselves holding "dirty" money.In 2024–2025 there were legal disputes over whether sanctioning code is lawful, but for the practitioner the conclusion is the same: Tornado Cash addresses are toxic.
  2. Lazarus Group (DPRK). A state-run hacking outfit of North Korea. OFAC systematically adds their addresses after every major hack (Ronin Bridge — $625 million, Harmony Bridge and others). Lazarus funds go towards financing the DPRK's missile programme, which is why regulators react as harshly as possible.Exposure to Lazarus is not just an AML risk — it is the risk of being accused of financing weapons of mass destruction.
  3. Garantex. A Russian crypto exchange added to the OFAC SDN in April 2022 and finally destroyed at the infrastructure level in 2025 (USDT frozen, servers seized). A huge volume of funds that passed through Garantex now carries a sanctions mark. Wallets that received withdrawals from Garantex automatically acquire a high sanctions score.A classic example of "ordinary" exchange users picking up a problematic trail after the fact.

Why even 1% of sanctions exposure = stop

In ordinary AML logic, risk accumulates gradually: a bit of darknet, a bit of a high-risk exchange, and the overall score rises. Sanctions work differently — here there is no "a bit".

Caution. Sanctions law is built on the principle of strict liability. This means it does not matter whether you knew the funds were of sanctioned origin or not, whether you had intent or not. The mere fact of a transaction with a sanctioned address is already a violation. OFAC fines run into millions of dollars for individual episodes, and for legal entities it can also mean being cut off from the dollar system — corporate death.

That is why sanctions exposure is handled by a special rule in scoring. If even 1% of the funds on a wallet trace back to an SDN address, the final verdict is stop, regardless of how "clean" the remaining 99% look. Sanctions risk cannot be "averaged out" with something good. A single drop of sanctioned funds makes the entire wallet unfit for compliant work.

An analogy for intuition. Imagine a pool of clean water into which a drop of poison has fallen. Even if the poison is 1%, you would not drink that water or call it "99% clean". Sanctioned funds work the same way: they "poison" the entire pool they are mixed into.

How to check an address against sanctions lists

There are two levels of checking, and understanding the difference is critical.

  1. Direct match. The address being checked literally appears in the SDN/EU/UK list. This is the simplest case: take the address, search for it in the consolidated database. Here the verdict is unambiguous — a sanctioned subject.OFAC publishes the SDN list in machine-readable formats; there are regularly updated aggregators of crypto addresses drawn from sanctions lists.
  2. Indirect exposure (indirect / taint). The address itself is clean, but when you trace the chain of transactions, part of the funds comes from — or goes to — a sanctioned address. Here you need flow analysis: how many "hops" to the SDN, what share of the funds is tainted, whether it is a direct transfer or one through intermediate wallets.Indirect exposure is 95% of real cases. Direct SDN addresses on the input side are almost never seen; the danger is in the trail.
Why this matters. A good AML check is not limited to looking up an address in a list. It builds a transaction graph and calculates what share of the balance traces back to sanctioned sources. This is exactly what distinguishes a superficial "blacklist check" from genuine taint analysis, to which a separate lesson is devoted.

Practical takeaways

  • Sanctions are off the scaleDo not treat them as "just another risk". This is a binary flag: present — stop, absent — carry on.
  • OFAC is the core of the checkEven outside US jurisdiction you are tied to the dollar and stablecoins, so OFAC is relevant to everyone.
  • Lists are updated constantlyAn address that was clean yesterday can land on the SDN today. A check must use a fresh database, not a week-old cache.
  • Intent doesn't matterStrict liability means "I didn't know" is no excuse. Check before the deal, not after.

In the next lesson we will examine one of the most common sources of sanctions and high-risk exposure — crypto mixers and tumblers: how they work on the inside and how to recognise their trail on the blockchain.

This material is for educational purposes only and does not constitute legal advice.