What a wallet designation actually means
A name appearing on a sanctions list is something most AML training covers reasonably well. A wallet address appearing on one is a different animal. The mechanics, the compliance obligations, and the practical traps are genuinely distinct from screening a person's name, and most training built for fiat AML doesn't translate cleanly.
How a wallet address actually gets designated
OFAC has been adding cryptocurrency wallet addresses directly to the SDN List since 2018, starting with addresses tied to Iranian ransomware operators. The process is the same administrative mechanism used for any SDN designation: OFAC identifies a nexus between a wallet and a sanctioned party, typically through blockchain analytics, intelligence gathering, or coordination with law enforcement, then publishes the address alongside the underlying designation.
The scale has grown substantially
A single action in July 2026 added 134 wallet addresses tied to ISIS-K financing in one designation. A May 2026 action against Sinaloa Cartel-linked individuals added six Ethereum addresses, five of them attributed to a single individual, a pattern OFAC itself flagged as multi-wallet fragmentation used to layer funds. That detail matters operationally: a firm screening only the named addresses on the SDN list, without examining the wallet clusters and counterparty relationships around them, will miss exposure sitting one or two hops away from a listed address.
Blocked property doesn't require an individual listing
A wallet doesn't need to be individually listed to be blocked property. This is the detail that catches firms out.
The UK picture: direct exposure versus indirect exposure
OFSI's own Cryptoassets Threat Assessment, published July 2025, sets out a framework worth internalising directly, since it's the regulator's own language, not a third party's interpretation of it. Click either card below for the detail behind each term.
- Transacting with a wallet address known to belong to a designated person
- Sending or receiving crypto-assets owned, held, or controlled by someone on the sanctions list
- Crypto-assets pass through one or more intermediaries after originating from a designated person's wallet, layering
- Assets arrive having been mixed or tumbled, making the original source harder to trace
OFSI has flagged a specific, recurring failure pattern in how UK firms handle this: identifying a sanctioned transaction only retrospectively, once the firm gains access to better blockchain analytics, well after the transaction has already occurred. That delay creates a reporting problem on top of the underlying exposure, since UK firms classed as relevant firms are legally required to report to OFSI once they know or suspect a breach, and a late-discovered breach is still a breach that needed reporting when it was found, not when it happened.
A structural point worth understanding, not just memorising: unlike a bank, a crypto-asset firm generally can't simply reject an incoming transaction the way a bank can decline to open an account. Once value arrives on-chain, the firm has to deal with what's now sitting in a wallet it controls, freeze it, report it, and manage it under license conditions, rather than having declined it at the door. That changes the practical shape of sanctions compliance in this sector compared to traditional finance.
OFSI's own red flags for crypto sanctions evasion
Straight from the regulator's July 2025 assessment, worth treating as a genuine working checklist rather than paraphrasing into something vaguer:
- Counterparties with known associations to designated persons.
- Unusual or sudden transaction activity, particularly dormant wallets suddenly becoming active.
- Activity linked to sanctioned jurisdictions.
- Proxy payment patterns, mixing, or layering designed to obscure a transaction's true origin or destination.
OFSI's assessment also names a concrete example worth knowing: the regulator found it likely that UK crypto-asset firms had facilitated transactions involving Nobitex, an Iranian exchange with suspected links to a designated entity, illustrating that exposure risk runs through counterparty exchanges, not just individually flagged wallets.
What this actually means for screening design
The practical takeaway isn't "screen wallet addresses too", most teams already know that much. It's that wallet screening needs a fundamentally different design than name screening:
- Exact match isn't enough, but neither is fuzzy match. A wallet address is a cryptographic string, there's no "close enough" the way there is with name spelling variants. What's needed instead is cluster-level screening, checking whether an address has ever transacted with a known designated wallet, not just whether it matches one directly.
- Screening needs to be near-real-time, not point-in-time. OFSI's own assessment flags retrospective discovery as a recurring, reportable failure. A wallet clean at onboarding can become exposed the moment it receives funds from a newly designated source.
- The old OFSI Consolidated List is dead as a data source. If your tooling, or a vendor's, hasn't migrated to the UK Sanctions List as the primary source, that's a live gap worth checking today, not filed away as background reading.