Skip to content
RiskTemplates · The Daily Brief Friday, July 31, 2026
Wire The Exodus OFAC Settlement: What a $3.1M Crypto Wallet Enforcement Action Teaches About Sanctions Compliance Programs JUL 30

Breaking Regulatory Compliance

The Exodus OFAC Settlement: What a $3.1M Crypto Wallet Enforcement Action Teaches About Sanctions Compliance Programs

OFAC's December 2025 settlement with Exodus Movement — $3.1 million for 254 apparent violations of the Iranian Transactions and Sanctions Regulations — is the clearest statement yet that non-custodial crypto wallets are in scope for sanctions obligations. The finding that staff advised Iranian users to use VPNs is the detail that turns a compliance failure into an egregious one.

By Rebecca Leung · July 30, 2026 ·
Table of Contents

TL;DR

  • OFAC’s December 2025 settlement with Exodus Movement — $3.1 million for 254 apparent violations of the Iranian Transactions and Sanctions Regulations — confirmed OFAC’s reach extends to US-based non-custodial crypto wallet providers
  • The egregious finding: Exodus staff advised Iranian users to use VPNs to circumvent geo-blocking of partner exchange integrations, treating the workaround as a customer service matter rather than a sanctions compliance failure
  • Terms of Service prohibiting Iranian users are not a compliance program — Exodus had ToS language and it didn’t help
  • The sanctions compliance infrastructure OFAC actually expects: IP screening, SDN list wallet screening, escalation procedures, staff training, and documented periodic testing

The VPN Advice Finding Is the One That Should Worry You

OFAC enforcement actions in crypto tend to produce a headline number and a one-line summary: “company violated Iranian sanctions, paid X million.” The important part of the Exodus settlement isn’t the $3.1 million — it’s the specific finding that made 12 of 254 violations egregious.

Exodus had implemented geo-blocking. The company had looked at its exchange partner integrations — the functionality that lets wallet users buy and sell crypto through third-party platforms directly within the Exodus interface — and identified that those transactions shouldn’t be available to Iranian users. So they blocked Iranian IP addresses from accessing those features.

That’s not nothing. Implementing geo-blocking demonstrates awareness that Iranian sanctions apply to the company’s services. It also demonstrates, according to OFAC’s analysis, that Exodus understood what the obligation was.

The problem is what happened next. Iranian users who encountered the geo-blocking contacted Exodus customer support. And customer support staff — apparently treating this as a technical issue to solve rather than a compliance matter — advised those users that they could use a VPN to work around the IP restriction.

OFAC’s designation of this conduct as egregious follows directly from that sequence. The company knew about the sanctions obligation (it implemented geo-blocking). When the sanctions control was triggered, staff actively helped users circumvent it. That’s not an inadvertent compliance failure. It’s the company’s own controls being used as a roadmap for evasion by the company’s own employees.

For every crypto company and fintech reading the Exodus enforcement action looking for the difference between “we had a screening gap” and “we have an egregious problem” — the VPN advice is exactly that difference.

What Exodus Did and What OFAC Found

Exodus Movement, Inc. is a US-based company that produces the Exodus wallet — a non-custodial, multi-asset software wallet that allows users to store, send, and receive cryptocurrency. “Non-custodial” means Exodus never holds user private keys or controls user funds. The user installs the software, controls their own wallet, and uses the Exodus interface.

The violations occurred between October 2017 and January 2019, when Exodus provided wallet software, customer support, and exchange integration services to users located in Iran, in apparent violation of the Iranian Transactions and Sanctions Regulations (ITSR), 31 CFR Part 560.

OFAC identified 254 apparent violations. Of those:

  • The majority involved the provision of wallet software downloads and updates to Iranian-located users
  • Exchange integration services provided through the Exodus interface to Iranian-located users
  • Customer support services provided to Iranian users, including the VPN advice that produced the egregious classification

The egregious designation applied to 12 violations — specifically the instances where customer support staff directly advised Iranian users on using VPNs to circumvent geographic access restrictions.

OFAC announced the settlement on December 16, 2025. The $3.1 million penalty reflects mitigation for cooperation with the investigation, the fact that Exodus did not appear to have profited significantly from the Iranian transactions, and remediation steps taken. It also reflects OFAC’s judgment about appropriate deterrence in a space where crypto companies have sometimes treated sanctions compliance as someone else’s problem.

Why Non-Custodial Is Not a Defense

The Exodus settlement definitively answered a question that non-custodial wallet providers had been hoping to avoid: does OFAC’s jurisdiction extend to us?

The argument for “no” was this: OFAC prohibits transactions, and a non-custodial wallet doesn’t execute transactions — it just provides software that lets users control their own funds. The crypto moves from the user’s own wallet to wherever the user directs it. The wallet provider never has custody, never processes the transaction, never touches the funds.

OFAC rejected that framing. The basis for OFAC jurisdiction in the Exodus case wasn’t control over the funds — it was the provision of services by a US person to Iranian persons. Under the ITSR and OFAC’s sanctions authorities generally, US persons are prohibited from providing services to Iranian persons. Software as a service, customer support, technical assistance, exchange integration services — all of these are “services” within OFAC’s framework, regardless of whether the service provider controls any funds.

The practical implication: if you are a US company providing a product or service — any product or service — to users who may be located in sanctioned jurisdictions, OFAC’s sanctions authorities reach you. Non-custody is a fact about asset control, not a fact about sanctions jurisdiction.

This matters because a significant portion of crypto compliance programs at wallet providers and infrastructure companies were designed around the assumption that non-custodial products were outside the sanctions compliance perimeter. Exodus is the enforcement action that closes that assumption.

The Terms of Service Problem

Exodus’s compliance approach during the 2017-2019 period included Terms of Service language prohibiting use by Iranian users. This is standard for companies that understand they have OFAC exposure but haven’t implemented affirmative controls. It’s also, according to OFAC’s enforcement record, insufficient.

The ToS approach has a structural problem: it is self-certification by the user. The company publishes a prohibition. The user clicks “I agree.” If the user is actually in Iran, the Terms of Service prohibition has been violated — but the company has done nothing to detect or prevent the violation.

Compare that to the OFAC Framework for Compliance Commitments, published in 2019, which describes internal controls as including “real-time interdiction software” and systems for “screening transactions and parties.” The framework explicitly contemplates technical controls that do something, not contractual prohibitions that say something.

For sanctions screening approaches in fintech, the common techniques for managing sanctions screening — geolocation filtering, SDN list wallet address screening, fuzzy name matching — represent the kind of affirmative controls OFAC expects. ToS is not on that list.

What the Exodus case adds: even companies that do have geolocation controls need to think about what happens when those controls surface a potential violation. If the answer is “customer support solves it by explaining how to work around the control,” the control has no compliance value.

The Staff Training Failure

The VPN advice finding is ultimately a training failure. Exodus customer support staff knew about the geo-blocking — it was something they encountered when Iranian users reported access issues. They apparently did not know why the geo-blocking existed, what the regulatory basis for it was, or what the appropriate response was when a user encountered it.

An adequate sanctions compliance training program for a crypto wallet company would cover:

  • What OFAC sanctions are and which programs apply to the company’s user base
  • What to do when a user appears to be in a sanctioned jurisdiction (escalate to compliance, not advise a workaround)
  • What not to do (advise VPN use, help users bypass geographic restrictions, provide technical support that enables circumventing sanctions controls)
  • How to identify red flags for sanctions evasion (inconsistent geolocations, VPN use as stated in user messages, payment patterns inconsistent with stated location)

The AML/BSA risk assessment framework for fintech covers institutional risk exposure identification. Sanctions exposure belongs in that framework alongside AML risk — and the training gap that Exodus’s customer support team exhibited is exactly the kind of gap that shows up when compliance teams treat sanctions as an IT problem rather than a company-wide operational risk.

What the OFAC Enforcement Pattern Shows

The Exodus action doesn’t stand alone. OFAC has pursued a consistent series of crypto-related enforcement actions that progressively narrow the space for compliance program defenses:

  • ShapeShift AG (2020) — $975,000 settlement for violations of Cuban, Iranian, Sudanese, Syrian, and North Korean sanctions programs through its non-custodial crypto exchange
  • BitPay (2021) — $507,375 settlement for processing transactions for customers in Iran, Cuba, Sudan, North Korea, and the Crimea region
  • Bittrex (2022) — $29 million settlement, the largest crypto OFAC settlement at the time, for apparent violations involving users in Iran, Cuba, Sudan, Syria, and Crimea
  • Payoneer (2023) — $1.4 million for violations involving Iranian users, despite having sanctions screening in place, because the screening was applied inconsistently

The pattern: OFAC is not narrowing its view of sanctions jurisdiction in crypto. It is expanding its enforcement record to cover more company types, more product structures, and more geographic programs. The Exodus settlement extends this to software wallet providers specifically.

For fintech companies that have convinced themselves they’re outside the OFAC perimeter because they don’t process transactions directly, the enforcement record is the answer. OFAC will assess jurisdiction based on the services you provide, the users you serve, and the assistance your company extends to those users — not on the custody question.

The ransomware OFAC enforcement guidance covers a parallel enforcement environment where companies discovered OFAC reach extended to their facilitation role even without custody. The mechanism is the same.

Building the Program OFAC Is Actually Looking For

The Exodus settlement points to four specific deficiencies that an adequate sanctions compliance program must address:

1. Affirmative technical screening. Geo-blocking of partner integrations, while present at Exodus, wasn’t extended to the wallet software downloads and updates themselves. A complete technical control would cover all vectors through which the company provides services to users: software distribution, in-app services, customer support channels, and partner integrations. Each service vector needs its own screening mechanism.

2. Escalation procedures for flagged events. When geo-blocking fires, what happens? If the answer is “customer support handles it,” the escalation procedure has failed. Geo-blocking and other screening controls need a defined escalation path to a compliance function — not a customer service function — with documented resolution requirements.

3. Staff training on sanctions compliance specific to the company’s exposure. General sanctions awareness training isn’t sufficient. Staff who interact with users — customer support, account management, technical support — need training that specifically covers: what the company’s sanctions controls are, why they exist, and what to do (and not do) when those controls surface a potential issue.

4. Periodic compliance program testing. OFAC’s Framework for Compliance Commitments calls for testing and audit of the compliance program at regular intervals. For crypto companies, this means periodically testing whether geographic controls are working as expected, whether escalation procedures function correctly, and whether training is producing the right behavior from staff. An untested compliance program is not a compliance program — it’s an aspiration.

So What?

The Exodus settlement is the closest thing OFAC has produced to a direct manual for what non-custodial crypto wallet compliance looks like. Not because the settlement tells you what to do — it’s an enforcement action, not guidance — but because the specific findings tell you exactly where an otherwise moderately functional compliance effort broke down.

Geo-blocking existed. Terms of Service existed. And staff were advising Iranian users to use VPNs, converting a screening program into a roadmap for evasion.

The lesson isn’t complicated: sanctions compliance requires affirmative controls across all service delivery vectors, escalation procedures that route potential violations to compliance rather than customer service, training that gives staff the information they need to respond correctly when those controls fire, and documented testing that confirms all of this works.

If your crypto or fintech company’s sanctions compliance program relies primarily on Terms of Service prohibitions and user self-certification, the Exodus settlement is the enforcement precedent for why that isn’t enough. The question to answer now, before an OFAC review, is whether your technical controls, escalation procedures, and staff training would survive the same scrutiny that Exodus’s did.


The AML/BSA Risk Assessment Template covers sanctions risk alongside AML exposure, with the institutional risk factor inventory and control framework that examiners expect to see documented before an exam.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

Does OFAC apply to non-custodial crypto wallets like Exodus?
Yes. The Exodus settlement confirmed that OFAC's sanctions jurisdiction extends to US-based companies that provide software wallet products, even non-custodial ones where the user controls their own private keys. OFAC's jurisdiction reaches US persons and US-origin software. The theory: Exodus, as a US company, provided services (software downloads, customer support, technical assistance) to users who were located in Iran or subject to the Iranian Transactions and Sanctions Regulations, regardless of whether Exodus directly held or transferred the digital assets in question. The settlement established that non-custodial wallet providers cannot claim they are merely software publishers outside OFAC's reach — the provision of ongoing services, support, and related exchange integrations connects them to the prohibited dealings.
What made the Exodus violations 'egregious' under OFAC's framework?
OFAC classified 12 of the 254 apparent violations as egregious based on several factors: (1) Exodus had actual knowledge that it was providing services to users in Iran — the company had implemented geo-blocking of its exchange integrations for Iranian IP addresses, demonstrating awareness of the sanctions obligation; (2) staff members affirmatively advised Iranian users to use VPNs to circumvent the geo-blocking, which OFAC treated as active facilitation of sanctions evasion rather than inadvertent non-compliance; (3) the violations were not isolated incidents but part of a pattern extending from October 2017 to January 2019; and (4) Exodus lacked a compliance program adequate to prevent or detect the violations. The VPN advice was particularly damaging — it converted what might have been a screening failure into evidence that the company was aware of the sanctions issue and took steps to work around it rather than comply.
What is the Iranian Transactions and Sanctions Regulations (ITSR) and what does it prohibit?
The Iranian Transactions and Sanctions Regulations (ITSR), 31 CFR Part 560, implement the U.S. economic embargo against Iran. The ITSR broadly prohibits US persons from engaging in transactions or dealings with Iran, Iranian nationals, or the Government of Iran, unless authorized by OFAC. For financial services and crypto companies, the practical prohibitions include: providing financial services, software, or technology to Iranian users; processing transactions that involve Iran as a counterparty; exporting or re-exporting US-origin goods, technology, or services to Iran; and facilitating any transaction by a non-US person that would be prohibited if done directly by a US person. The ITSR applies to US persons anywhere in the world and to anyone acting within the United States.
Why was Exodus's Terms of Service prohibition against Iranian users insufficient as a sanctions compliance measure?
OFAC's settlement made clear that a contractual prohibition in Terms of Service does not constitute an adequate sanctions compliance program. Terms of Service are self-certification by the user — they don't screen for whether the user is actually located in a sanctioned jurisdiction, they don't detect violations in real time, and they have no enforcement mechanism other than account termination (which itself requires detection of the violation). OFAC expects companies with OFAC exposure to implement active controls: IP-based geolocation screening, real-time transaction monitoring for indicators of sanctions evasion, escalation procedures for anomalies, and documented compliance training for staff. The fact that Exodus staff were advising users to work around the company's own geo-blocking while relying on ToS to maintain formal compliance is precisely the kind of gap that OFAC's enforcement program targets.
What does an adequate sanctions compliance program look like for a crypto company or fintech?
OFAC's 2019 Framework for OFAC Compliance Commitments identifies five components: management commitment, risk assessment, internal controls, testing and auditing, and training. For a crypto wallet provider or fintech, these translate to: (1) a sanctions risk assessment that identifies the company's specific exposure pathways (user locations, transaction types, exchange integrations, third-party partners); (2) technical controls such as IP geolocation screening, wallet address screening against OFAC's SDN list, and automated alerts for anomalous geographic patterns; (3) a clear escalation process when a potential sanctions issue is identified, with documented resolution; (4) sanctions-specific training for customer support, compliance, and product teams that covers what to do (and not do) when a user appears to be in a sanctioned jurisdiction; and (5) periodic testing and audit of the controls, documented with evidence. The VPN advice finding in the Exodus case points specifically to the training failure — customer support staff who knew about geo-blocking but not about why it existed, and who were willing to advise users on workarounds.
What is the voluntary self-disclosure credit for OFAC violations and did Exodus receive it?
OFAC's civil penalty framework provides significant mitigation for voluntary self-disclosure — up to 50% reduction in the base penalty calculation. Exodus received a reduced penalty in part because of mitigating factors including cooperation with OFAC's investigation and, importantly, that Exodus did not appear to have received significant financial benefit from the violations. The $3.1 million settlement reflects these mitigation factors. The base penalty calculation under OFAC's statutory authority would have been significantly higher — each violation carries a statutory maximum of the greater of $356,579 (adjusted annually) or twice the amount of the underlying transaction. For 254 violations, the theoretical statutory maximum would be in the hundreds of millions. The $3.1 million settlement shows the impact of cooperation and mitigating factors — but it also shows that OFAC pursued a meaningful penalty despite those mitigations, precisely because the egregious findings (VPN advice) offset the cooperation credit.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

● Don't wait for your own enforcement action

Every case like this started with a gap someone knew about but hadn't documented. The template below gives you the framework to get ahead of it.

AML/BSA Risk Assessment Template (Fintech Edition)

32 pre-populated fintech risk factors in the FFIEC exam manual structure, with customer risk rating methodology, five-pillar control inventory, and board dashboard.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.