Introduction

What a wallet designation actually means

A name appearing on a sanctions list is something most AML training covers reasonably well. A wallet address appearing on one is a different animal. The mechanics, the compliance obligations, and the practical traps are genuinely distinct from screening a person's name, and most training built for fiat AML doesn't translate cleanly.

⚠️
The OFSI Consolidated List closed on 28 January 2026
One structural fact worth knowing before anything else: if you're screening against UK sanctions data, the ground shifted recently. The OFSI Consolidated List, the list most UK compliance teams have built their screening processes around for years, closed on 28 January 2026. UK sanctions designations now live in a single UK Sanctions List, published by the Foreign, Commonwealth and Development Office. If your firm's screening tooling still references the old OFSI list as its primary source, that's now a live gap, not a future one.
Section 01

How a wallet address actually gets designated

OFAC has been adding cryptocurrency wallet addresses directly to the SDN List since 2018, starting with addresses tied to Iranian ransomware operators. The process is the same administrative mechanism used for any SDN designation: OFAC identifies a nexus between a wallet and a sanctioned party, typically through blockchain analytics, intelligence gathering, or coordination with law enforcement, then publishes the address alongside the underlying designation.

The scale has grown substantially

A single action in July 2026 added 134 wallet addresses tied to ISIS-K financing in one designation. A May 2026 action against Sinaloa Cartel-linked individuals added six Ethereum addresses, five of them attributed to a single individual, a pattern OFAC itself flagged as multi-wallet fragmentation used to layer funds. That detail matters operationally: a firm screening only the named addresses on the SDN list, without examining the wallet clusters and counterparty relationships around them, will miss exposure sitting one or two hops away from a listed address.

Blocked property doesn't require an individual listing

A wallet doesn't need to be individually listed to be blocked property. This is the detail that catches firms out.

πŸ’‘
OFAC FAQ 646
OFAC's own guidance is explicit: any wallet in which a sanctioned person has a property interest must be blocked, regardless of whether OFAC has published that specific address. The published list is there to help industry, it isn't the exhaustive boundary of what's actually prohibited.
Section 02

The UK picture: direct exposure versus indirect exposure

OFSI's own Cryptoassets Threat Assessment, published July 2025, sets out a framework worth internalising directly, since it's the regulator's own language, not a third party's interpretation of it. Click either card below for the detail behind each term.

On-chain, direct
Direct Exposure
+
  • Transacting with a wallet address known to belong to a designated person
  • Sending or receiving crypto-assets owned, held, or controlled by someone on the sanctions list
Source: OFSI Cryptoassets Threat Assessment, July 2025
Layered, obscured
Indirect Exposure
+
  • Crypto-assets pass through one or more intermediaries after originating from a designated person's wallet, layering
  • Assets arrive having been mixed or tumbled, making the original source harder to trace
Source: OFSI Cryptoassets Threat Assessment, July 2025

OFSI has flagged a specific, recurring failure pattern in how UK firms handle this: identifying a sanctioned transaction only retrospectively, once the firm gains access to better blockchain analytics, well after the transaction has already occurred. That delay creates a reporting problem on top of the underlying exposure, since UK firms classed as relevant firms are legally required to report to OFSI once they know or suspect a breach, and a late-discovered breach is still a breach that needed reporting when it was found, not when it happened.

A structural point worth understanding, not just memorising: unlike a bank, a crypto-asset firm generally can't simply reject an incoming transaction the way a bank can decline to open an account. Once value arrives on-chain, the firm has to deal with what's now sitting in a wallet it controls, freeze it, report it, and manage it under license conditions, rather than having declined it at the door. That changes the practical shape of sanctions compliance in this sector compared to traditional finance.

Section 03

OFSI's own red flags for crypto sanctions evasion

Straight from the regulator's July 2025 assessment, worth treating as a genuine working checklist rather than paraphrasing into something vaguer:

  • Counterparties with known associations to designated persons.
  • Unusual or sudden transaction activity, particularly dormant wallets suddenly becoming active.
  • Activity linked to sanctioned jurisdictions.
  • Proxy payment patterns, mixing, or layering designed to obscure a transaction's true origin or destination.

OFSI's assessment also names a concrete example worth knowing: the regulator found it likely that UK crypto-asset firms had facilitated transactions involving Nobitex, an Iranian exchange with suspected links to a designated entity, illustrating that exposure risk runs through counterparty exchanges, not just individually flagged wallets.

Exposure risk runs through counterparty exchanges, not just individually flagged wallets.
Put it into practice
Screen a counterparty or beneficial owner before onboarding
Free, no login. A clean wallet history doesn't rule out sanctions exposure sitting one hop away through a counterparty exchange.
Screen a name β†’
Section 04

What this actually means for screening design

The practical takeaway isn't "screen wallet addresses too", most teams already know that much. It's that wallet screening needs a fundamentally different design than name screening:

  1. Exact match isn't enough, but neither is fuzzy match. A wallet address is a cryptographic string, there's no "close enough" the way there is with name spelling variants. What's needed instead is cluster-level screening, checking whether an address has ever transacted with a known designated wallet, not just whether it matches one directly.
  2. Screening needs to be near-real-time, not point-in-time. OFSI's own assessment flags retrospective discovery as a recurring, reportable failure. A wallet clean at onboarding can become exposed the moment it receives funds from a newly designated source.
  3. The old OFSI Consolidated List is dead as a data source. If your tooling, or a vendor's, hasn't migrated to the UK Sanctions List as the primary source, that's a live gap worth checking today, not filed away as background reading.
πŸ“˜
This closes Part 4 of the series
Part 5 looks at the gap between how AML analysts are typically trained and what a real crypto-touching case actually demands of them. Part 6 goes deeper into where wallet screening logic itself tends to break down.
Quick Reference
How crypto wallets get sanctioned, cheat sheet summary Summary card covering wallet designation mechanics, direct versus indirect exposure, OFSI red flags, and a three-point screening design checklist, for the Crypto Guide Part 4 guide. How Wallets Get Sanctioned AT A GLANCE β€” CHEAT SHEET WALLET DESIGNATION OFAC adds addresses to the SDN List directly Blocked property doesn't require individual listing DIRECT VS INDIRECT Direct: wallet known to belong to designated person Indirect: layered through intermediaries or mixers OFSI RED FLAGS Dormant wallets suddenly active, sanctioned jurisdictions Proxy payments, mixing, counterparty exchange risk THE SCREENING DESIGN CHECKLIST 1 Cluster-level screening, not exact match alone 2 Near-real-time, not point-in-time 3 Migrate to the UK Sanctions List A summary aid, not a substitute for the full guide or professional advice. fincrimeradar.org