Note: This article is an educational overview of financial-sanctions risk, not legal advice. Firms should obtain jurisdiction-specific counsel before making a reporting, blocking, or customer-offboarding decision.
Crypto moves value at internet speed. Compliance moves at the speed of a sensible question: who is involved, where is the money going, and should this transaction be stopped before it becomes tomorrow’s regulator meeting? In its July 2025 Cryptoassets Threat Assessment, the United Kingdom’s Office of Financial Sanctions Implementation (OFSI) made the gap between those two speeds impossible to ignore.
The report is not a declaration that every wallet is a crime scene. It is a warning that sanctions exposure can enter through an exchange, a wallet provider, a payment flow, a developer hire, or a customer whose address looked ordinary yesterday and acquired a very different reputation today. For crypto businesses, banks, fintech platforms, and companies touching virtual assets, sanctions compliance cannot be a dusty policy PDF that wakes up only when someone asks for it.
Published on July 21, 2025, the assessment reviewed risks relevant to UK cryptoasset-related service firms from January 2022 through May 2025. It addresses suspected breaches rather than final findings of wrongdoing. In other words, it is a risk map, not a courtroom verdictbut it is drawn with a very bright highlighter.
What OFSI’s July 2025 Crypto Report Says
OFSI is the UK Treasury office responsible for helping ensure financial sanctions are understood, implemented, and enforced. In the crypto context, it treats digital assets as assets, not as magical coupons that slipped through a regulatory trapdoor. Asset-freeze obligations, prohibitions on making funds or economic resources available to designated persons, reporting duties, and due-diligence expectations still apply.
Its most striking conclusion was that it is almost certain UK cryptoasset firms have under-reported suspected financial-sanctions breaches since August 2022. OFSI did not say every missed report involved intentional misconduct. It found that problems often arise when firms link a wallet to a designated person too late, recognize an indirect connection after a transaction is complete, or fail to freeze assets promptly once attribution changes.
The reporting figures matter
Since January 2022, just over 7% of all suspected breaches reported to OFSI involved cryptoasset firms in some capacity, and more than 90% of those crypto-related reports were made after April 2024. Russia accounted for more than 90% of reports in the relevant crypto dataset, while Iran represented the remaining 10%. The report cautions that inconsistent reporting and delayed attribution mean the visible number may be smaller than the actual risk.
A rising report count can reflect more misconduct, better detection, stronger reporting culture, or all three wearing the same trench coat. The better test is whether a firm can explain what it detected, when it detected it, what it did next, and why.
The Five Risks OFSI Put in Bold Print
1. Under-reporting is more than paperwork
UK cryptoasset firms have reporting obligations when they know or have reasonable cause to suspect that they have encountered a designated person or a sanctions breach. OFSI wants timely, useful reports: transaction hashes, wallet and intermediary addresses, values, customer details, the rationale for the suspected exposure, and the action taken. “We found something weird” is not a report. It is merely the opening line of one.
2. Indirect exposure can be as serious as direct exposure
OFSI found it likely that most non-compliance by UK crypto firms has been inadvertent. Direct transfers to a designated wallet are easy to understand; indirect exposure is harder. Value may pass through several wallets, exchanges, swaps, bridges, or over-the-counter channels before it reaches a sanctioned actor. That is why firms need more than a static list of known addresses. They need customer and counterparty screening, ownership-and-control analysis, wallet monitoring, geographic controls, and reviews when new intelligence appears.
3. Garantex illustrates evolving infrastructure risk
OFSI concluded it is highly likely UK cryptoasset firms have had direct or indirect exposure to the designated Russian exchange Garantex. It observed that direct flows decreased as the exchange changed its infrastructure, while indirect flows increased. When a sanctioned service becomes easier to identify at the front door, risk may try the side entrance.
The report also discussed OFSI’s assessment that liquidity and customer activity associated with Garantex had shifted into a related ecosystem involving Grinex and the ruble-backed A7A5 stablecoin. The compliance lesson is straightforward: investigate more than a brand name. Shared infrastructure, recurring counterparties, linked wallet clusters, common administrators, and sudden migration patterns can matter just as much as the logo on a website.
4. DPRK activity combines cyber risk with sanctions risk
OFSI called DPRK-linked actors the most significant and persistent threat currently facing the cryptoasset sector. It assessed that UK-based crypto firms are highly likely to be targeted by DPRK-linked hackers and IT workers seeking illicit funds. The February 2025 theft of roughly $1.5 billion in virtual assets from Bybit, attributed publicly by the FBI to North Korean actors, gives that warning uncomfortable real-world weight.
The lesson is not simply “buy more cybersecurity software.” A compromised private key, fraudulent contractor identity, suspicious salary wallet, or engineer with privileged access can turn an IT incident into a sanctions, AML, legal, and reputational emergency in a hurry.
5. Iranian exposure requires more than country-name screening
OFSI also found it likely that UK crypto firms were facilitating transfers to Iranian cryptoasset firms with suspected links to designated persons. It highlighted activity involving Nobitex, which OFSI described as an Iranian exchange with suspected links to the Islamic Revolutionary Guard Corps. Enhanced due diligence should examine the customer, beneficial ownership, wallet exposure, transaction purpose, source of funds, geography, counterparties, and route of value. A sanctions program that only checks a country field can be defeated by a VPN, a third-country bank account, and a convincing shrug.
Crypto Sanctions Red Flags That Need a Closer Look
OFSI is clear that one red flag is not proof of wrongdoing. But several indicators together can justify enhanced due diligence and faster escalation. Think of them as dashboard lights: one may be low tire pressure; five may be the car politely asking you to stop driving it.
- Large or unusual transfers immediately after sanctions announcements.
- Exposure to counterparties associated with designated persons.
- Rapid movement through multiple wallets, chains, swaps, bridges, or new addresses.
- Wallet clustering, sudden dormant-wallet activity, or large transfers into brand-new wallets.
- Repeated micro-transfers, frequent address changes, and unexplained pattern shifts.
- Use of no-KYC services, weak-AML services, mixers, privacy tools, or high-risk DEX activity.
- VPN use that masks location, evasive responses to due diligence, or inconsistent source-of-funds explanations.
The answer is not to turn every odd transaction into a five-alarm fire. It is to pair automated alerts with trained human review. Blunt systems create false positives that exhaust analysts and frustrate legitimate customers; relaxed systems create gaps that bad actors adore. The goal is disciplined, documented judgment.
How to Build a Crypto Sanctions Compliance Program That Works
Give compliance real authority
Senior leadership should approve the framework, provide enough staff and technology, and empower the compliance team to pause risky activity. The sanctions lead needs a direct path to decision-makers, not a treasure-map route through six committees and a quarterly meeting.
Know the customer, wallet, and route
Screen customers, beneficial owners, counterparties, wallets, and relevant transaction paths. Use lawful geolocation and device signals, confirm source-of-funds explanations, and reassess risk when behavior changes. Screen at onboarding, at transaction time, and continuously as designations and attribution data evolve.
Use analytics without worshipping the dashboard
Blockchain analytics can identify direct and indirect exposure, wallet clusters, mixer activity, high-risk services, and cross-chain movement. They are powerful but not oracles. A tool’s attribution can change, and vendors may disagree. Validate critical alerts, understand methodology, document decisions, and never treat a risk score as a substitute for judgment.
Practice the investigation and reporting workflow
When a potential hit appears, the firm should already know who decides, what can be paused, how assets are safeguarded, how the case is investigated, and when reporting duties may be triggered. OFSI encourages detailed and timely reporting and expects firms to describe transaction routes, addresses, values, KYC information, screening processes, and remedial actions. Relevant cases may also require suspicious activity reports or notification to other authorities.
Test, train, and perform targeted lookbacks
Train operations, engineering, fraud, customer-support, and compliance teamsnot only the person with “sanctions” in a job title. Test controls after a major designation, product launch, vendor change, or new-chain integration. Perform targeted lookbacks when intelligence changes. It is not glamorous, but neither is explaining why a three-month-old alert spent summer vacation in an unattended queue.
Why the OFSI Warning Matters Beyond the United Kingdom
The report targets UK firms, but its implications are international. A single transaction can involve a U.S.-dollar stablecoin, a UK customer, a developer in a third country, an exchange elsewhere, and a wallet connected to a designated actor. U.S. firms must consider OFAC rules; UK-connected firms must consider OFSI duties; multinational businesses can face EU, UN, and local obligations as well. U.S. guidance and FinCEN materials make the same central point: virtual-currency transactions do not receive a sanctions exemption because the technology is new.
Practical Experiences and Lessons from the Crypto Sanctions Front Line
This section distills recurring lessons from public threat assessments, enforcement actions, and compliance operations. It does not claim personal legal, investigative, or regulatory experience.
The first practical lesson is that sanctions incidents rarely arrive wearing a label that says “Hello, I am a sanctions incident.” They usually show up as an ordinary customer-support ticket, an analytics alert with an uncertain confidence score, a request to unlock an account, or a business team asking why a perfectly good transaction has been delayed. The initial facts are incomplete. The pressure to resolve the case quickly is real. And somewhere in the background, a sales team is asking whether the customer can be released before lunch.
Teams that handle these moments well have already agreed on the basics. They know which alerts can be cleared by an analyst, which require escalation, who can impose a temporary restriction, and who calls legal counsel. They do not wait until a suspicious wallet is moving funds across three chains to decide whether the firm even has an incident-response playbook. That is like trying to write a parachute manual after jumping from the plane.
A second lesson is that data quality can make or break a program. Firms often discover that customer information is fragmented across onboarding systems, transaction-monitoring tools, customer-service platforms, and third-party analytics vendors. When an alert arrives, analysts may have to reconcile inconsistent names, dates of birth, IP records, device fingerprints, wallet labels, and transaction histories. The longer this takes, the greater the chance that a report, asset freeze, or customer restriction will be delayed. Good programs invest in clean case-management records and clear evidence trails because a compliance decision should be reproducible, not dependent on who remembers the incident.
Third, vendor management is not a procurement formality. Blockchain analytics vendors can provide valuable attribution, but they do not eliminate responsibility. A mature firm asks what a tool detects, how quickly it updates labels, where its blind spots are, how alerts are prioritized, and what happens when two data providers disagree. It also tests integrations after technical changes. A rule that worked on one blockchain may not behave the same way after a bridge, token migration, or new custody architecture enters the picture.
Fourth, human behavior still matters as much as clever technology. Phishing, social engineering, fake contractor identities, rushed approvals, and incomplete due diligence remain recurring weaknesses. Security teams should watch for credential compromise and privileged-access anomalies. HR and engineering teams should verify remote workers carefully. Compliance teams should train staff to recognize when a “small exception” is actually the beginning of a large problem. The scariest spreadsheet in sanctions compliance is the one full of exceptions that were supposed to be temporary.
Finally, firms learn that respectful friction is healthy. A customer may be annoyed by enhanced due diligence. A product manager may dislike a paused launch. An executive may ask why compliance needs another analyst. Yet the cost of thoughtful friction is generally far lower than the cost of freezing assets late, reporting late, or discovering that the business enabled a prohibited transaction. The organizations that build trust do not promise zero delays; they promise fair, consistent, well-explained decisions. In a sector famous for moving fast, that may be the most durable competitive advantage of all.
Conclusion: “On-Chain” Does Not Mean “Out of Scope”
OFSI’s July 2025 report is a practical compliance wake-up call. Its warnings about under-reporting, delayed attribution, Garantex exposure, DPRK-linked cyber threats, and Iranian crypto risks all point to the same conclusion: sanctions risk in crypto is dynamic, cross-border, and operational. Firms do not need a crystal ball. They need governance, reliable data, intelligent screening, human investigation, fast escalation, and the discipline to document and report suspected breaches appropriately. The strongest businesses will treat sanctions compliance as a product and security responsibilitynot a ceremonial checkbox in a folder labeled “Important Stuff.”