Feature Regulatory Compliance
OFAC Targeted Iranian Crypto Exchanges and Shadow-Banking Networks. Your Controls Need More Than an SDN Name Match.
OFAC's August 7 Iran sanctions target crypto exchanges, exchange houses, wallets, and shell networks. Here is the control response for financial institutions.
Table of Contents
TL;DR
- OFAC issued two related Iran sanctions actions on August 7 covering digital asset exchanges, exchange houses, shell companies, facilitators, and international payment networks.
- The crypto action identified Shelbit Exchange and Aban Tether; OFAC said IRGC-linked addresses sent more than $1 million to Shelbit addresses and received more than $2 million from them.
- An exact SDN name screen is not enough. OFAC says Iranian digital asset exchanges are blocked even when not named, and its 50 Percent Rule reaches entities owned in aggregate by blocked persons.
- Sanctions, AML, crypto analytics, correspondent banking, and payments teams need one coordinated lookback—not five disconnected tickets.
OFAC’s August 7 Iran sanctions actions are a useful stress test for a control most financial institutions overestimate: the sanctions screen.
The first Treasury action targeted digital asset exchanges and a related network that OFAC says supported Iran’s Islamic Revolutionary Guard Corps and other illicit finance. The second action targeted exchange houses, companies, employees, and facilitators that moved money through Iran’s shadow-banking system.
If the response is “the vendor loaded the new SDN names overnight,” the institution has covered the easiest part. These actions require relationship analysis across aliases, ownership, wallets, nested exchange exposure, shell companies, invoices, correspondent accounts, and receiving institutions.
That is the practical takeaway: OFAC screening is no longer a list-matching problem once the network starts moving through digital assets and lightly regulated intermediaries.
What OFAC designated on August 7
The two releases describe related but distinct channels.
The digital asset exchange network
Treasury identified Siavash Kayvanpour as the operator of a multi-jurisdictional network tied to Shelbit Exchange. The release says:
- IRGC-linked digital currency addresses sent the equivalent of more than $1 million to Shelbit Exchange addresses;
- Shelbit addresses sent more than $2 million to IRGC digital currency addresses;
- addresses belonging to or controlled by Kayvanpour sent more than $2 million to previously designated Iranian exchange Nobitex; and
- tens of millions of dollars in digital assets connected to a Persian-language gambling network were laundered through Shelbit.
OFAC designated Kayvanpour under Executive Order 13224, as amended. The action also covered SHPS Shelbit, Shelbit General Trading LLC, Shelbit Technologies Ltd, Crypto Home DMCC, and NFT Home DMCC under the authorities described in the release.
Treasury separately identified Iran-based Aban Tether, saying it processed millions of dollars in transactions involving previously designated Iranian exchanges Nobitex, Wallex, Bitpin, and Ramzinex. OFAC designated Aban Tether under Executive Order 13902 for operating in Iran’s financial sector.
The release is careful about regulatory history. It says the UAE Virtual Assets Regulatory Authority took enforcement action against Shelbit General Trading in January 2025 and July 2026 and against Crypto Home in January 2025. The U.S. sanctions action therefore adds a direct U.S. blocking consequence to risks that had already surfaced in another regulator’s record.
The shadow-banking and exchange-house network
The second release focused on intermediaries serving Iran’s Shahr Bank and associated front-company structure. OFAC designated Titan Exchange and Alps International, plus employees, support personnel, and shell companies in several jurisdictions.
Treasury said Titan Exchange held tens of millions of dollars for Shahr Bank as of early 2026. It said Alps International and an operational team helped execute payments and produce invoices using selected shell-company letterhead, with Alps enabling hundreds of millions of dollars of transactions in multiple currencies during 2026.
The named companies span the UAE, Hong Kong, and Singapore. That matters for U.S. institutions because the control problem will not arrive labeled “Iran.” It can appear as a payment involving a trading company, exchange house, correspondent, or commercial invoice several relationships away from the sanctioned party.
| Exposure path | What a basic screen misses | Control that should catch it |
|---|---|---|
| Digital asset exchange | Exchange is Iranian but not separately named | Jurisdiction and business-model restrictions under OFAC FAQ 1250 |
| Wallet transfer | Address has no human-readable SDN name | Blockchain screening, address attribution, cluster analytics |
| Owned affiliate | Affiliate is not separately listed | OFAC 50 Percent Rule ownership aggregation |
| Nested exchange | Customer uses a foreign platform with downstream sanctioned exposure | Counterparty and nested-service due diligence |
| Shell-company payment | Neutral company name and plausible invoice | Network analytics, trade-document review, beneficial ownership |
| Foreign correspondent | Respondent facilitates a significant transaction for a designee | Correspondent monitoring and secondary-sanctions escalation |
| Alias or transliteration | Different spelling or commercial name | Alias, fuzzy, native-script, and identifier screening |
The rule many crypto controls still miss: an Iranian exchange need not be named
OFAC FAQ 1250, released May 1, says Iranian digital asset exchanges qualify as Iranian financial institutions under the Iranian Transactions and Sanctions Regulations. Their property and interests in property in the possession or control of U.S. persons—including U.S. financial institutions—or within U.S. jurisdiction are blocked under the cited authorities regardless of whether the exchange appears by name on the SDN List.
That changes the question an investigator asks.
The weak question is: “Did the counterparty match a named sanctioned exchange?”
The correct first question is: “Do the available facts indicate the counterparty is an Iranian digital asset exchange?” If yes, absence from the SDN List is not a clearance decision.
The same logic applies to indirect ownership. Treasury’s releases reiterate that entities owned directly or indirectly, individually or in the aggregate, 50 percent or more by one or more blocked persons are blocked. A screening vendor cannot apply that rule reliably if the institution has no current ownership information or cannot aggregate multiple blocked owners.
For crypto firms, the ownership record should connect legal name, commercial name, registration jurisdiction, operating jurisdiction, domains, apps, wallet addresses, key principals, and known service providers. For banks and payment companies, customer and counterparty due diligence should preserve enough of those identifiers to support a defensible escalation.
Secondary sanctions turn this into correspondent-banking work
OFAC FAQ 1257 says non-U.S. persons face sanctions risk for certain dealings with Iranian exchanges Nobitex, Wallex, Bitpin, and Ramzinex. OFAC can designate persons providing material support and can prohibit or impose strict conditions on a foreign financial institution’s U.S. correspondent or payable-through accounts where it knowingly conducts or facilitates a significant transaction for a covered person.
Treasury’s August 7 shadow-banking release repeats that correspondent-account consequence for certain significant transactions involving designated persons.
So the sanctions refresh cannot stop with direct customers. The Correspondent Banking team should identify:
- respondents operating in jurisdictions named in the actions;
- payment flows involving newly designated exchange houses and companies;
- respondents servicing digital asset exchanges or payment intermediaries without transparent downstream controls;
- repeated transfers involving common shell-company counterparties, invoices, domains, or contact details; and
- prior alerts closed because the direct party was not then listed.
This is where ownership gets messy. Sanctions Operations owns list screening. Correspondent Banking owns respondent due diligence. Financial Crime Analytics owns network patterns. Crypto Compliance owns wallet intelligence. Trade Finance owns invoice review. Without one accountable executive—usually the Chief Compliance Officer or BSA/AML and Sanctions Officer—the response fragments into separate tickets with no consolidated conclusion.
What to search in the lookback
A defensible lookback starts with the identifiers in the releases and current OFAC data, then expands by relationship. Do not invent a universal period or dollar cutoff. Calibrate the period to data retention, customer exposure, prior designation dates, and legal advice.
Layer 1: direct identifiers
Screen legal names, aliases, commercial names, persons, domains, registration details, and digital currency addresses published or linked by OFAC. Confirm the sanctions-data vendor has loaded the action and record the version and timestamp.
Layer 2: related ownership and control
Search customers and counterparties linked to designated owners or managers. Aggregate ownership interests for the 50 Percent Rule. Flag entities sharing addresses, directors, domains, phone numbers, registration agents, or wallet infrastructure with the designated network for review; shared data is an investigative lead, not automatic proof of blocking status.
Layer 3: transactional network
Trace one and two hops around identified wallets and counterparties using an approved blockchain analytics platform. Review exposure to deposits, withdrawals, swaps, bridges, payment processors, and nested exchange services. Document the vendor’s attribution confidence and supporting evidence rather than treating every cluster label as fact.
Layer 4: payment and trade artifacts
Search payment messages and trade records for the named companies, exchange houses, banks, locations, and invoice issuers. The shadow-banking release specifically describes shell-company invoices used to execute payments. An invoice that passes name screening can still be suspicious when its issuer, beneficiary, goods description, routing, and customer profile do not fit.
Layer 5: prior decisions
Re-open alerts where analysts noted Iranian exposure, Nobitex, Wallex, Bitpin, Ramzinex, Shelbit, Aban Tether, Shahr Bank, or related exchange-house activity but closed the case based solely on no exact SDN match. The purpose is not to reverse every disposition; it is to test whether the earlier rationale survives the new facts and applicable blocking rules.
Build the evidence package before closing the issue
For each business line, the sanctions-response package should show:
| Evidence | What it proves | Owner |
|---|---|---|
| Vendor update confirmation | New names, aliases, and identifiers entered production | Sanctions Operations |
| FAQ 1250 rule mapping | Unnamed Iranian exchanges are handled correctly | Sanctions Advisory |
| Ownership test results | The 50 Percent Rule is applied and aggregated | KYC / Sanctions |
| Wallet lookback memo | Digital-asset exposure was searched with documented attribution limits | Crypto Compliance |
| Payment and correspondent results | Direct and nested fiat exposure was reviewed | Payments / Correspondent Banking |
| Case dispositions | Matches and investigative leads received supported decisions | Financial Crime Investigations |
| Blocking/reporting records | Property was blocked and reported where legally required | Legal / Sanctions Operations |
| Independent sample | Included and excluded populations were tested | Compliance Testing |
The awkward but common failure is closing the regulatory-change ticket after the screening vendor sends “content loaded.” That proves the list changed. It does not prove the institution searched retained activity, assessed unnamed Iranian exchanges, applied ownership aggregation, reviewed nested exposure, or escalated blocked property correctly.
OFAC states that violations can carry civil or criminal consequences and that civil penalties may be imposed on a strict-liability basis. The Economic Sanctions Enforcement Guidelines explain the factors OFAC uses in enforcement. A documented, risk-based sanctions program does not erase a prohibited transaction, but it is materially different from an institution that cannot show what it screened, why it cleared an alert, or whether its controls addressed known exposure.
A 72-hour response sequence
First 8 hours — Sanctions Operations and Advisory
Confirm the action is loaded, collect OFAC identifiers, identify affected products and jurisdictions, issue an internal hold/escalation instruction, and preserve pre-update screening data for testing.
By 24 hours — Crypto, Payments, and Correspondent Banking
Run direct searches, identify customers and respondents with relevant exposure, and start wallet and transaction lookbacks. Escalate true matches and potential blocked property immediately under the institution’s legal procedure; the lookback project timeline does not delay blocking obligations.
By 48 hours — KYC and Investigations
Complete ownership aggregation, enrich related entities, review shared identifiers, and re-open prior cases where the absence of an exact list match drove closure.
By 72 hours — CCO or Sanctions Officer
Approve a consolidated exposure memo: populations searched, systems covered, limitations, potential matches, blocking/reporting decisions, SAR considerations, customer restrictions, correspondent actions, open issues, owners, and dates. Compliance Testing should then select a sample independently rather than accepting management’s summary as closure evidence.
For a broader operational framework, see the site’s FinCEN 314(b) fraud information-sharing guide and BSA/AML transaction-monitoring control metrics. The ransomware OFAC screening playbook covers the same strict-liability problem in an incident-response setting.
The August 7 actions are not a reason to indiscriminately block every crypto or Middle East-related transaction. They are a reason to stop using a negative exact-name match as the end of the analysis. The required judgment is narrower and harder: what is this entity, who owns it, what service does it provide, where does the transaction go, which wallets and intermediaries touch it, and does U.S. sanctions law block the property or expose a participant to additional sanctions risk?
If that review surfaces stale ownership data, missing wallet coverage, weak nested-service due diligence, or unsupported prior closures, track the remediation in the Issues Management Tracker & Template until independent validation—not a vendor email—supports closure.
Sources
- U.S. Treasury: Sanctions Crypto Exchanges Funding Iran’s IRGC and Enabling Illicit Finance, August 7, 2026
- U.S. Treasury: Dismantles Iranian Regime’s Global Clandestine Currency Networks, August 7, 2026
- OFAC FAQ 1250: Iranian digital asset exchanges
- OFAC FAQ 1257: Non-U.S. sanctions risk involving designated Iranian exchanges
- OFAC Economic Sanctions Enforcement Guidelines, 31 CFR Part 501 Appendix A
◆ Related template
Issues Management Tracker & Template
End-to-end issues tracking and remediation management for risk and compliance teams.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
Which crypto exchanges did OFAC target on August 7, 2026?
Are all Iranian digital asset exchanges blocked even if they are not named on the SDN List?
What does OFAC's 50 Percent Rule mean for the August 7 designations?
Can OFAC impose a civil penalty if an institution did not know a transaction was prohibited?
What should a financial institution do after OFAC adds a crypto exchange or wallet-linked network?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
Issues Management Tracker & Template
End-to-end issues tracking and remediation management for risk and compliance teams.
◆ Keep reading
Related posts.
Regulatory Compliance
FinCEN Renewed the Minnesota GTO. Banks Have Four Days to Restart $3,000 International Transfer Reporting.
The FinCEN Minnesota GTO starts August 11. Banks and money transmitters need complete data and monthly reporting for covered $3,000 transfers.
Aug 6, 2026
Regulatory Compliance
The OCC Called Them 'Available Funds.' Veterans Paid the Origination Fees. What the Federal Savings Bank Consent Order Teaches About Marketing Review.
The Federal Savings Bank of Chicago sent millions of mailers telling veterans they had 'available funds' — when accessing those funds required taking out a new VA cash-out refinance loan. Employees told consumers interest rates would decrease on what were actually permanent fixed-rate mortgages. The April 2026 OCC consent order requires restitution, a corrective action plan, and quarterly progress reports.
Aug 6, 2026
Regulatory Compliance
SEC’s New Financial Reporting and Accounting Unit: The ICFR Review to Start Now
The SEC Financial Reporting and Accounting Unit puts specialist scrutiny back on accounting fraud, ICFR, audit evidence, and auditor conduct.
Aug 5, 2026