Skip to content
RiskTemplates · The Daily Brief Friday, August 7, 2026
Wire SEC’s New Financial Reporting and Accounting Unit: The ICFR Review to Start Now AUG 5

Feature Regulatory Compliance

OFAC Targeted Iranian Crypto Exchanges and Shadow-Banking Networks. Your Controls Need More Than an SDN Name Match.

OFAC's August 7 Iran sanctions target crypto exchanges, exchange houses, wallets, and shell networks. Here is the control response for financial institutions.

By Rebecca Leung · August 6, 2026 ·
Table of Contents

TL;DR

  • OFAC issued two related Iran sanctions actions on August 7 covering digital asset exchanges, exchange houses, shell companies, facilitators, and international payment networks.
  • The crypto action identified Shelbit Exchange and Aban Tether; OFAC said IRGC-linked addresses sent more than $1 million to Shelbit addresses and received more than $2 million from them.
  • An exact SDN name screen is not enough. OFAC says Iranian digital asset exchanges are blocked even when not named, and its 50 Percent Rule reaches entities owned in aggregate by blocked persons.
  • Sanctions, AML, crypto analytics, correspondent banking, and payments teams need one coordinated lookback—not five disconnected tickets.

OFAC’s August 7 Iran sanctions actions are a useful stress test for a control most financial institutions overestimate: the sanctions screen.

The first Treasury action targeted digital asset exchanges and a related network that OFAC says supported Iran’s Islamic Revolutionary Guard Corps and other illicit finance. The second action targeted exchange houses, companies, employees, and facilitators that moved money through Iran’s shadow-banking system.

If the response is “the vendor loaded the new SDN names overnight,” the institution has covered the easiest part. These actions require relationship analysis across aliases, ownership, wallets, nested exchange exposure, shell companies, invoices, correspondent accounts, and receiving institutions.

That is the practical takeaway: OFAC screening is no longer a list-matching problem once the network starts moving through digital assets and lightly regulated intermediaries.

What OFAC designated on August 7

The two releases describe related but distinct channels.

The digital asset exchange network

Treasury identified Siavash Kayvanpour as the operator of a multi-jurisdictional network tied to Shelbit Exchange. The release says:

  • IRGC-linked digital currency addresses sent the equivalent of more than $1 million to Shelbit Exchange addresses;
  • Shelbit addresses sent more than $2 million to IRGC digital currency addresses;
  • addresses belonging to or controlled by Kayvanpour sent more than $2 million to previously designated Iranian exchange Nobitex; and
  • tens of millions of dollars in digital assets connected to a Persian-language gambling network were laundered through Shelbit.

OFAC designated Kayvanpour under Executive Order 13224, as amended. The action also covered SHPS Shelbit, Shelbit General Trading LLC, Shelbit Technologies Ltd, Crypto Home DMCC, and NFT Home DMCC under the authorities described in the release.

Treasury separately identified Iran-based Aban Tether, saying it processed millions of dollars in transactions involving previously designated Iranian exchanges Nobitex, Wallex, Bitpin, and Ramzinex. OFAC designated Aban Tether under Executive Order 13902 for operating in Iran’s financial sector.

The release is careful about regulatory history. It says the UAE Virtual Assets Regulatory Authority took enforcement action against Shelbit General Trading in January 2025 and July 2026 and against Crypto Home in January 2025. The U.S. sanctions action therefore adds a direct U.S. blocking consequence to risks that had already surfaced in another regulator’s record.

The shadow-banking and exchange-house network

The second release focused on intermediaries serving Iran’s Shahr Bank and associated front-company structure. OFAC designated Titan Exchange and Alps International, plus employees, support personnel, and shell companies in several jurisdictions.

Treasury said Titan Exchange held tens of millions of dollars for Shahr Bank as of early 2026. It said Alps International and an operational team helped execute payments and produce invoices using selected shell-company letterhead, with Alps enabling hundreds of millions of dollars of transactions in multiple currencies during 2026.

The named companies span the UAE, Hong Kong, and Singapore. That matters for U.S. institutions because the control problem will not arrive labeled “Iran.” It can appear as a payment involving a trading company, exchange house, correspondent, or commercial invoice several relationships away from the sanctioned party.

Exposure pathWhat a basic screen missesControl that should catch it
Digital asset exchangeExchange is Iranian but not separately namedJurisdiction and business-model restrictions under OFAC FAQ 1250
Wallet transferAddress has no human-readable SDN nameBlockchain screening, address attribution, cluster analytics
Owned affiliateAffiliate is not separately listedOFAC 50 Percent Rule ownership aggregation
Nested exchangeCustomer uses a foreign platform with downstream sanctioned exposureCounterparty and nested-service due diligence
Shell-company paymentNeutral company name and plausible invoiceNetwork analytics, trade-document review, beneficial ownership
Foreign correspondentRespondent facilitates a significant transaction for a designeeCorrespondent monitoring and secondary-sanctions escalation
Alias or transliterationDifferent spelling or commercial nameAlias, fuzzy, native-script, and identifier screening

The rule many crypto controls still miss: an Iranian exchange need not be named

OFAC FAQ 1250, released May 1, says Iranian digital asset exchanges qualify as Iranian financial institutions under the Iranian Transactions and Sanctions Regulations. Their property and interests in property in the possession or control of U.S. persons—including U.S. financial institutions—or within U.S. jurisdiction are blocked under the cited authorities regardless of whether the exchange appears by name on the SDN List.

That changes the question an investigator asks.

The weak question is: “Did the counterparty match a named sanctioned exchange?”

The correct first question is: “Do the available facts indicate the counterparty is an Iranian digital asset exchange?” If yes, absence from the SDN List is not a clearance decision.

The same logic applies to indirect ownership. Treasury’s releases reiterate that entities owned directly or indirectly, individually or in the aggregate, 50 percent or more by one or more blocked persons are blocked. A screening vendor cannot apply that rule reliably if the institution has no current ownership information or cannot aggregate multiple blocked owners.

For crypto firms, the ownership record should connect legal name, commercial name, registration jurisdiction, operating jurisdiction, domains, apps, wallet addresses, key principals, and known service providers. For banks and payment companies, customer and counterparty due diligence should preserve enough of those identifiers to support a defensible escalation.

Secondary sanctions turn this into correspondent-banking work

OFAC FAQ 1257 says non-U.S. persons face sanctions risk for certain dealings with Iranian exchanges Nobitex, Wallex, Bitpin, and Ramzinex. OFAC can designate persons providing material support and can prohibit or impose strict conditions on a foreign financial institution’s U.S. correspondent or payable-through accounts where it knowingly conducts or facilitates a significant transaction for a covered person.

Treasury’s August 7 shadow-banking release repeats that correspondent-account consequence for certain significant transactions involving designated persons.

So the sanctions refresh cannot stop with direct customers. The Correspondent Banking team should identify:

  • respondents operating in jurisdictions named in the actions;
  • payment flows involving newly designated exchange houses and companies;
  • respondents servicing digital asset exchanges or payment intermediaries without transparent downstream controls;
  • repeated transfers involving common shell-company counterparties, invoices, domains, or contact details; and
  • prior alerts closed because the direct party was not then listed.

This is where ownership gets messy. Sanctions Operations owns list screening. Correspondent Banking owns respondent due diligence. Financial Crime Analytics owns network patterns. Crypto Compliance owns wallet intelligence. Trade Finance owns invoice review. Without one accountable executive—usually the Chief Compliance Officer or BSA/AML and Sanctions Officer—the response fragments into separate tickets with no consolidated conclusion.

What to search in the lookback

A defensible lookback starts with the identifiers in the releases and current OFAC data, then expands by relationship. Do not invent a universal period or dollar cutoff. Calibrate the period to data retention, customer exposure, prior designation dates, and legal advice.

Layer 1: direct identifiers

Screen legal names, aliases, commercial names, persons, domains, registration details, and digital currency addresses published or linked by OFAC. Confirm the sanctions-data vendor has loaded the action and record the version and timestamp.

Search customers and counterparties linked to designated owners or managers. Aggregate ownership interests for the 50 Percent Rule. Flag entities sharing addresses, directors, domains, phone numbers, registration agents, or wallet infrastructure with the designated network for review; shared data is an investigative lead, not automatic proof of blocking status.

Layer 3: transactional network

Trace one and two hops around identified wallets and counterparties using an approved blockchain analytics platform. Review exposure to deposits, withdrawals, swaps, bridges, payment processors, and nested exchange services. Document the vendor’s attribution confidence and supporting evidence rather than treating every cluster label as fact.

Layer 4: payment and trade artifacts

Search payment messages and trade records for the named companies, exchange houses, banks, locations, and invoice issuers. The shadow-banking release specifically describes shell-company invoices used to execute payments. An invoice that passes name screening can still be suspicious when its issuer, beneficiary, goods description, routing, and customer profile do not fit.

Layer 5: prior decisions

Re-open alerts where analysts noted Iranian exposure, Nobitex, Wallex, Bitpin, Ramzinex, Shelbit, Aban Tether, Shahr Bank, or related exchange-house activity but closed the case based solely on no exact SDN match. The purpose is not to reverse every disposition; it is to test whether the earlier rationale survives the new facts and applicable blocking rules.

Build the evidence package before closing the issue

For each business line, the sanctions-response package should show:

EvidenceWhat it provesOwner
Vendor update confirmationNew names, aliases, and identifiers entered productionSanctions Operations
FAQ 1250 rule mappingUnnamed Iranian exchanges are handled correctlySanctions Advisory
Ownership test resultsThe 50 Percent Rule is applied and aggregatedKYC / Sanctions
Wallet lookback memoDigital-asset exposure was searched with documented attribution limitsCrypto Compliance
Payment and correspondent resultsDirect and nested fiat exposure was reviewedPayments / Correspondent Banking
Case dispositionsMatches and investigative leads received supported decisionsFinancial Crime Investigations
Blocking/reporting recordsProperty was blocked and reported where legally requiredLegal / Sanctions Operations
Independent sampleIncluded and excluded populations were testedCompliance Testing

The awkward but common failure is closing the regulatory-change ticket after the screening vendor sends “content loaded.” That proves the list changed. It does not prove the institution searched retained activity, assessed unnamed Iranian exchanges, applied ownership aggregation, reviewed nested exposure, or escalated blocked property correctly.

OFAC states that violations can carry civil or criminal consequences and that civil penalties may be imposed on a strict-liability basis. The Economic Sanctions Enforcement Guidelines explain the factors OFAC uses in enforcement. A documented, risk-based sanctions program does not erase a prohibited transaction, but it is materially different from an institution that cannot show what it screened, why it cleared an alert, or whether its controls addressed known exposure.

A 72-hour response sequence

First 8 hours — Sanctions Operations and Advisory

Confirm the action is loaded, collect OFAC identifiers, identify affected products and jurisdictions, issue an internal hold/escalation instruction, and preserve pre-update screening data for testing.

By 24 hours — Crypto, Payments, and Correspondent Banking

Run direct searches, identify customers and respondents with relevant exposure, and start wallet and transaction lookbacks. Escalate true matches and potential blocked property immediately under the institution’s legal procedure; the lookback project timeline does not delay blocking obligations.

By 48 hours — KYC and Investigations

Complete ownership aggregation, enrich related entities, review shared identifiers, and re-open prior cases where the absence of an exact list match drove closure.

By 72 hours — CCO or Sanctions Officer

Approve a consolidated exposure memo: populations searched, systems covered, limitations, potential matches, blocking/reporting decisions, SAR considerations, customer restrictions, correspondent actions, open issues, owners, and dates. Compliance Testing should then select a sample independently rather than accepting management’s summary as closure evidence.

For a broader operational framework, see the site’s FinCEN 314(b) fraud information-sharing guide and BSA/AML transaction-monitoring control metrics. The ransomware OFAC screening playbook covers the same strict-liability problem in an incident-response setting.

The August 7 actions are not a reason to indiscriminately block every crypto or Middle East-related transaction. They are a reason to stop using a negative exact-name match as the end of the analysis. The required judgment is narrower and harder: what is this entity, who owns it, what service does it provide, where does the transaction go, which wallets and intermediaries touch it, and does U.S. sanctions law block the property or expose a participant to additional sanctions risk?

If that review surfaces stale ownership data, missing wallet coverage, weak nested-service due diligence, or unsupported prior closures, track the remediation in the Issues Management Tracker & Template until independent validation—not a vendor email—supports closure.

Sources

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

Which crypto exchanges did OFAC target on August 7, 2026?
Treasury's August 7 action identified Shelbit Exchange and Aban Tether. It also designated Siavash Kayvanpour and related entities including SHPS Shelbit, Shelbit General Trading, Shelbit Technologies Ltd, Crypto Home DMCC, and NFT Home DMCC under applicable Iran and counterterrorism authorities.
Are all Iranian digital asset exchanges blocked even if they are not named on the SDN List?
Yes. OFAC FAQ 1250 states that Iranian digital asset exchanges meet the definition of an Iranian financial institution and are blocked under Executive Order 13599 and the Iranian Transactions and Sanctions Regulations regardless of whether they appear by name on the SDN List.
What does OFAC's 50 Percent Rule mean for the August 7 designations?
Entities owned directly or indirectly, individually or in the aggregate, 50 percent or more by one or more blocked persons are also blocked even if the entity is not separately named. Institutions therefore need ownership aggregation and related-party review, not only exact-name screening.
Can OFAC impose a civil penalty if an institution did not know a transaction was prohibited?
Yes. Treasury's August 7 releases reiterate that OFAC may impose civil penalties on a strict-liability basis. Knowledge and the quality of a compliance program can affect enforcement analysis, but lack of knowledge does not automatically eliminate civil exposure.
What should a financial institution do after OFAC adds a crypto exchange or wallet-linked network?
Refresh sanctions data, ingest available digital-currency addresses and aliases, search recent activity, block property in U.S. possession or control, report blocked property as required, investigate indirect exposure through counterparties and nested services, and document the disposition and any escalation.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

Issues Management Tracker & Template

End-to-end issues tracking and remediation management for risk and compliance teams.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.