Skip to main content
Sanctions Lists Won't Stop Digital Asset EvasionIncident Response and Skimming
4 min readFor Fintech Risk and Compliance Teams

Sanctions Lists Won't Stop Digital Asset Evasion

The conventional wisdom: Add sanctioned entities to your watchlist screening tool, run transactions against it, and you've met your sanctions compliance obligation.

Every compliance team knows the drill. Treasury's Office of Foreign Assets Control (OFAC) publishes a sanctions list. You import it into your screening platform. Transactions get flagged if they match. Case closed.

Except it isn't. The U.S. Department of the Treasury recently sanctioned nearly 60 Iran-linked entities and individuals, including five members of the Mabna Institute connected to breaches of U.S. critical infrastructure. TRM Labs analyzed 30 wallet addresses tied to these actors and found $16.8 million in total funds received. One individual, Keyvan Fayyaz Ghareh Blagh, controlled 10 addresses that received $15.5 million between January 2018 and August 2026.

Here's what matters: those wallets were active for years before the sanctions designation. Your screening tool didn't flag them because they weren't on the list yet.

Why Watchlist Screening Alone Fails

Sanctions lists are reactive. They formalize what intelligence agencies already know. By the time Treasury designates an address, the damage is done and the actors have moved on.

Digital assets make this worse. Creating a new wallet costs nothing and takes seconds. The Mabna Institute members operated 30 known addresses. How many unknown addresses did they control? Your screening tool can only catch what's been publicly designated.

The gap widens with mixing services, decentralized exchanges, and privacy coins. Sanctioned actors don't send funds directly from a designated address to your platform. They route through intermediaries, swap chains, and fragment transactions. A wallet that received $1.2 million, like the 15 addresses linked to Behzad Mesri, can distribute that across hundreds of smaller wallets before any of it touches your system.

This isn't theoretical. Iran-linked entities used two U.K.-based front companies, Zedcex and Zedxion, to process approximately $1 billion in funds connected to the Islamic Revolutionary Guard Corps. These weren't obscure operations. They were functioning exchanges with customer bases. Watchlist screening didn't stop them because the beneficial ownership was hidden behind corporate structures.

What the Evidence Shows

Look at the timeline. The Mabna Institute actors breached U.S. critical infrastructure entities since at least late 2023. They targeted energy companies, defense contractors, healthcare institutions, and financial institutions. In summer 2024, they compromised local, state, and federal government offices.

Treasury sanctioned them in 2026. That's a multi-year window where traditional watchlist screening provided zero protection.

The blockchain analytics firm that identified the $16.8 million in wallet activity didn't rely on OFAC's list. They used transaction pattern analysis, clustering algorithms, and attribution techniques that connect on-chain behavior to known threat actors. The residual balance across all 30 addresses was $202,662 at the time of analysis, meaning the bulk of funds had already moved.

Your screening tool can't do this. It checks names and addresses against a static list. It doesn't analyze transaction velocity, counterparty risk, or behavioral anomalies that indicate evasion.

Build a Behavioral Screening Layer

Start with transaction pattern monitoring. Flag wallet addresses that exhibit structuring behavior: multiple small deposits that sum to significant amounts, rapid movement of funds immediately after receipt, or frequent interactions with mixing services. These patterns appear before an address gets sanctioned.

Implement counterparty risk scoring. If a wallet interacts heavily with addresses later designated by OFAC, that wallet carries elevated risk even if it's not sanctioned itself. The Mabna Institute network didn't operate in isolation. They had funding sources, cash-out points, and service providers. Map those relationships.

Use blockchain analytics platforms that provide risk scores based on exposure to sanctioned entities, darknet markets, ransomware groups, and theft. These tools assign probability ratings, not binary yes/no matches. A wallet with 40% exposure to high-risk counterparties deserves scrutiny even if it's not on OFAC's list.

Deploy geolocation heuristics. Certain IP addresses, exchange patterns, and on-ramp/off-ramp behaviors correlate with sanctioned jurisdictions. Iran-linked actors don't advertise their location, but their transaction patterns reveal it. If you're seeing repeated interactions with exchanges that don't enforce Know Your Customer requirements and have high volumes from sanctioned regions, that's a signal.

Document your methodology. Bank Secrecy Act compliance doesn't require perfect detection. It requires reasonable controls and evidence that you're adapting to emerging risks. When examiners ask how you're managing sanctions evasion in digital assets, "we screen against OFAC's list" won't satisfy them. Show them your behavioral monitoring rules, your risk scoring model, and your process for investigating elevated-risk transactions.

When Watchlist Screening Is Sufficient

If you don't handle digital assets, traditional watchlist screening still works. Wire transfers, ACH payments, and correspondent banking relationships operate through regulated intermediaries with verified identities. The sanctions list remains effective for fiat currency transactions because the financial system enforces identity verification at every hop.

Watchlist screening also catches unsophisticated actors who reuse sanctioned addresses. Not every threat actor has the Mabna Institute's resources. Some designated entities continue using the same wallets after sanctions, either through negligence or because they assume you're not monitoring blockchain activity. Your screening tool will catch those.

For low-volume digital asset operations where you can manually review every transaction, watchlist screening plus human judgment may be adequate. If you're processing 50 crypto transactions per month and each one gets reviewed by a trained analyst who checks blockchain explorers and transaction history, you're not relying solely on automated screening.

But if you're operating at scale, handling significant digital asset volume, or serving customers in high-risk sectors, watchlist screening alone is compliance theater. You're checking a box while the actual risk walks past you. The Mabna Institute moved $16.8 million through 30 wallets before anyone sanctioned them. Your screening tool wouldn't have flagged a single transaction.

You Might Also Like