Breaking Regulatory Compliance
The Exodus OFAC Settlement: What a $3.1M Crypto Wallet Enforcement Action Teaches About Sanctions Compliance Programs
OFAC's December 2025 settlement with Exodus Movement — $3.1 million for 254 apparent violations of the Iranian Transactions and Sanctions Regulations — is the clearest statement yet that non-custodial crypto wallets are in scope for sanctions obligations. The finding that staff advised Iranian users to use VPNs is the detail that turns a compliance failure into an egregious one.
Table of Contents
TL;DR
- OFAC’s December 2025 settlement with Exodus Movement — $3.1 million for 254 apparent violations of the Iranian Transactions and Sanctions Regulations — confirmed OFAC’s reach extends to US-based non-custodial crypto wallet providers
- The egregious finding: Exodus staff advised Iranian users to use VPNs to circumvent geo-blocking of partner exchange integrations, treating the workaround as a customer service matter rather than a sanctions compliance failure
- Terms of Service prohibiting Iranian users are not a compliance program — Exodus had ToS language and it didn’t help
- The sanctions compliance infrastructure OFAC actually expects: IP screening, SDN list wallet screening, escalation procedures, staff training, and documented periodic testing
The VPN Advice Finding Is the One That Should Worry You
OFAC enforcement actions in crypto tend to produce a headline number and a one-line summary: “company violated Iranian sanctions, paid X million.” The important part of the Exodus settlement isn’t the $3.1 million — it’s the specific finding that made 12 of 254 violations egregious.
Exodus had implemented geo-blocking. The company had looked at its exchange partner integrations — the functionality that lets wallet users buy and sell crypto through third-party platforms directly within the Exodus interface — and identified that those transactions shouldn’t be available to Iranian users. So they blocked Iranian IP addresses from accessing those features.
That’s not nothing. Implementing geo-blocking demonstrates awareness that Iranian sanctions apply to the company’s services. It also demonstrates, according to OFAC’s analysis, that Exodus understood what the obligation was.
The problem is what happened next. Iranian users who encountered the geo-blocking contacted Exodus customer support. And customer support staff — apparently treating this as a technical issue to solve rather than a compliance matter — advised those users that they could use a VPN to work around the IP restriction.
OFAC’s designation of this conduct as egregious follows directly from that sequence. The company knew about the sanctions obligation (it implemented geo-blocking). When the sanctions control was triggered, staff actively helped users circumvent it. That’s not an inadvertent compliance failure. It’s the company’s own controls being used as a roadmap for evasion by the company’s own employees.
For every crypto company and fintech reading the Exodus enforcement action looking for the difference between “we had a screening gap” and “we have an egregious problem” — the VPN advice is exactly that difference.
What Exodus Did and What OFAC Found
Exodus Movement, Inc. is a US-based company that produces the Exodus wallet — a non-custodial, multi-asset software wallet that allows users to store, send, and receive cryptocurrency. “Non-custodial” means Exodus never holds user private keys or controls user funds. The user installs the software, controls their own wallet, and uses the Exodus interface.
The violations occurred between October 2017 and January 2019, when Exodus provided wallet software, customer support, and exchange integration services to users located in Iran, in apparent violation of the Iranian Transactions and Sanctions Regulations (ITSR), 31 CFR Part 560.
OFAC identified 254 apparent violations. Of those:
- The majority involved the provision of wallet software downloads and updates to Iranian-located users
- Exchange integration services provided through the Exodus interface to Iranian-located users
- Customer support services provided to Iranian users, including the VPN advice that produced the egregious classification
The egregious designation applied to 12 violations — specifically the instances where customer support staff directly advised Iranian users on using VPNs to circumvent geographic access restrictions.
OFAC announced the settlement on December 16, 2025. The $3.1 million penalty reflects mitigation for cooperation with the investigation, the fact that Exodus did not appear to have profited significantly from the Iranian transactions, and remediation steps taken. It also reflects OFAC’s judgment about appropriate deterrence in a space where crypto companies have sometimes treated sanctions compliance as someone else’s problem.
Why Non-Custodial Is Not a Defense
The Exodus settlement definitively answered a question that non-custodial wallet providers had been hoping to avoid: does OFAC’s jurisdiction extend to us?
The argument for “no” was this: OFAC prohibits transactions, and a non-custodial wallet doesn’t execute transactions — it just provides software that lets users control their own funds. The crypto moves from the user’s own wallet to wherever the user directs it. The wallet provider never has custody, never processes the transaction, never touches the funds.
OFAC rejected that framing. The basis for OFAC jurisdiction in the Exodus case wasn’t control over the funds — it was the provision of services by a US person to Iranian persons. Under the ITSR and OFAC’s sanctions authorities generally, US persons are prohibited from providing services to Iranian persons. Software as a service, customer support, technical assistance, exchange integration services — all of these are “services” within OFAC’s framework, regardless of whether the service provider controls any funds.
The practical implication: if you are a US company providing a product or service — any product or service — to users who may be located in sanctioned jurisdictions, OFAC’s sanctions authorities reach you. Non-custody is a fact about asset control, not a fact about sanctions jurisdiction.
This matters because a significant portion of crypto compliance programs at wallet providers and infrastructure companies were designed around the assumption that non-custodial products were outside the sanctions compliance perimeter. Exodus is the enforcement action that closes that assumption.
The Terms of Service Problem
Exodus’s compliance approach during the 2017-2019 period included Terms of Service language prohibiting use by Iranian users. This is standard for companies that understand they have OFAC exposure but haven’t implemented affirmative controls. It’s also, according to OFAC’s enforcement record, insufficient.
The ToS approach has a structural problem: it is self-certification by the user. The company publishes a prohibition. The user clicks “I agree.” If the user is actually in Iran, the Terms of Service prohibition has been violated — but the company has done nothing to detect or prevent the violation.
Compare that to the OFAC Framework for Compliance Commitments, published in 2019, which describes internal controls as including “real-time interdiction software” and systems for “screening transactions and parties.” The framework explicitly contemplates technical controls that do something, not contractual prohibitions that say something.
For sanctions screening approaches in fintech, the common techniques for managing sanctions screening — geolocation filtering, SDN list wallet address screening, fuzzy name matching — represent the kind of affirmative controls OFAC expects. ToS is not on that list.
What the Exodus case adds: even companies that do have geolocation controls need to think about what happens when those controls surface a potential violation. If the answer is “customer support solves it by explaining how to work around the control,” the control has no compliance value.
The Staff Training Failure
The VPN advice finding is ultimately a training failure. Exodus customer support staff knew about the geo-blocking — it was something they encountered when Iranian users reported access issues. They apparently did not know why the geo-blocking existed, what the regulatory basis for it was, or what the appropriate response was when a user encountered it.
An adequate sanctions compliance training program for a crypto wallet company would cover:
- What OFAC sanctions are and which programs apply to the company’s user base
- What to do when a user appears to be in a sanctioned jurisdiction (escalate to compliance, not advise a workaround)
- What not to do (advise VPN use, help users bypass geographic restrictions, provide technical support that enables circumventing sanctions controls)
- How to identify red flags for sanctions evasion (inconsistent geolocations, VPN use as stated in user messages, payment patterns inconsistent with stated location)
The AML/BSA risk assessment framework for fintech covers institutional risk exposure identification. Sanctions exposure belongs in that framework alongside AML risk — and the training gap that Exodus’s customer support team exhibited is exactly the kind of gap that shows up when compliance teams treat sanctions as an IT problem rather than a company-wide operational risk.
What the OFAC Enforcement Pattern Shows
The Exodus action doesn’t stand alone. OFAC has pursued a consistent series of crypto-related enforcement actions that progressively narrow the space for compliance program defenses:
- ShapeShift AG (2020) — $975,000 settlement for violations of Cuban, Iranian, Sudanese, Syrian, and North Korean sanctions programs through its non-custodial crypto exchange
- BitPay (2021) — $507,375 settlement for processing transactions for customers in Iran, Cuba, Sudan, North Korea, and the Crimea region
- Bittrex (2022) — $29 million settlement, the largest crypto OFAC settlement at the time, for apparent violations involving users in Iran, Cuba, Sudan, Syria, and Crimea
- Payoneer (2023) — $1.4 million for violations involving Iranian users, despite having sanctions screening in place, because the screening was applied inconsistently
The pattern: OFAC is not narrowing its view of sanctions jurisdiction in crypto. It is expanding its enforcement record to cover more company types, more product structures, and more geographic programs. The Exodus settlement extends this to software wallet providers specifically.
For fintech companies that have convinced themselves they’re outside the OFAC perimeter because they don’t process transactions directly, the enforcement record is the answer. OFAC will assess jurisdiction based on the services you provide, the users you serve, and the assistance your company extends to those users — not on the custody question.
The ransomware OFAC enforcement guidance covers a parallel enforcement environment where companies discovered OFAC reach extended to their facilitation role even without custody. The mechanism is the same.
Building the Program OFAC Is Actually Looking For
The Exodus settlement points to four specific deficiencies that an adequate sanctions compliance program must address:
1. Affirmative technical screening. Geo-blocking of partner integrations, while present at Exodus, wasn’t extended to the wallet software downloads and updates themselves. A complete technical control would cover all vectors through which the company provides services to users: software distribution, in-app services, customer support channels, and partner integrations. Each service vector needs its own screening mechanism.
2. Escalation procedures for flagged events. When geo-blocking fires, what happens? If the answer is “customer support handles it,” the escalation procedure has failed. Geo-blocking and other screening controls need a defined escalation path to a compliance function — not a customer service function — with documented resolution requirements.
3. Staff training on sanctions compliance specific to the company’s exposure. General sanctions awareness training isn’t sufficient. Staff who interact with users — customer support, account management, technical support — need training that specifically covers: what the company’s sanctions controls are, why they exist, and what to do (and not do) when those controls surface a potential issue.
4. Periodic compliance program testing. OFAC’s Framework for Compliance Commitments calls for testing and audit of the compliance program at regular intervals. For crypto companies, this means periodically testing whether geographic controls are working as expected, whether escalation procedures function correctly, and whether training is producing the right behavior from staff. An untested compliance program is not a compliance program — it’s an aspiration.
So What?
The Exodus settlement is the closest thing OFAC has produced to a direct manual for what non-custodial crypto wallet compliance looks like. Not because the settlement tells you what to do — it’s an enforcement action, not guidance — but because the specific findings tell you exactly where an otherwise moderately functional compliance effort broke down.
Geo-blocking existed. Terms of Service existed. And staff were advising Iranian users to use VPNs, converting a screening program into a roadmap for evasion.
The lesson isn’t complicated: sanctions compliance requires affirmative controls across all service delivery vectors, escalation procedures that route potential violations to compliance rather than customer service, training that gives staff the information they need to respond correctly when those controls fire, and documented testing that confirms all of this works.
If your crypto or fintech company’s sanctions compliance program relies primarily on Terms of Service prohibitions and user self-certification, the Exodus settlement is the enforcement precedent for why that isn’t enough. The question to answer now, before an OFAC review, is whether your technical controls, escalation procedures, and staff training would survive the same scrutiny that Exodus’s did.
The AML/BSA Risk Assessment Template covers sanctions risk alongside AML exposure, with the institutional risk factor inventory and control framework that examiners expect to see documented before an exam.
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
Does OFAC apply to non-custodial crypto wallets like Exodus?
What made the Exodus violations 'egregious' under OFAC's framework?
What is the Iranian Transactions and Sanctions Regulations (ITSR) and what does it prohibit?
Why was Exodus's Terms of Service prohibition against Iranian users insufficient as a sanctions compliance measure?
What does an adequate sanctions compliance program look like for a crypto company or fintech?
What is the voluntary self-disclosure credit for OFAC violations and did Exodus receive it?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
● Don't wait for your own enforcement action
Every case like this started with a gap someone knew about but hadn't documented. The template below gives you the framework to get ahead of it.
AML/BSA Risk Assessment Template (Fintech Edition)
32 pre-populated fintech risk factors in the FFIEC exam manual structure, with customer risk rating methodology, five-pillar control inventory, and board dashboard.
◆ Keep reading
Related posts.
Regulatory Compliance
Iuka State Bank Written Agreement: The Fed's 30-Day Credit Risk and BSA/AML Remediation List
The Iuka State Bank written agreement maps Fed findings to 30- and 60-day fixes across credit, capital, liquidity, and BSA/AML.
Jul 30, 2026
Regulatory Compliance
OCC-FDIC CRA Proposal: The 2026 Changes Banks Need to Map Now
The OCC-FDIC CRA proposal changes bank thresholds, lending tests, grant eligibility, and reporting. Here is the control impact.
Jul 30, 2026
Regulatory Compliance
NYDFS Part 500 Class A Requirements: What the 2023 Amendments Added and Where 2026 Exams Are Finding Gaps
NYDFS's Second Amendment to Part 500 created a new Class A tier for larger covered entities. The final compliance deadline passed November 1, 2024 — and 2026 is the first full examination cycle with all amended requirements in scope. Here's what examiners are finding and what covered entities are still getting wrong.
Jul 28, 2026