Governments are increasing pressure on the cryptocurrency ecosystem through sanctions enforcement and stricter compliance obligations aimed at disrupting money laundering, ransomware payments, and terrorism financing. OFAC has progressively expanded sanctions designations to include cryptocurrency addresses and, in some cases, entire crypto services, reflecting the view that virtual assets are being used to evade traditional financial controls; this approach has been supported by published guidance for the virtual currency industry on how to mitigate sanctions risk and avoid facilitating crypto-enabled crime.
India has similarly tightened its anti–financial crime posture by updating rules for cryptocurrency service providers via FIU-IND guidelines that require registration for any crypto entity serving Indian residents, including offshore operators. The new requirements mandate enhanced KYC and ongoing monitoring—collecting identity documents and financial details, plus technical and geolocation data (e.g., IP addresses and latitude/longitude with timestamps) and selfie-based verification—along with continuous transaction monitoring and suspicious activity reporting for both fiat and virtual currency flows, aligning crypto compliance expectations more closely with those applied to traditional financial institutions.

See the reporting duties and controls this puts on the clock.
8 events from the most recent confirmed update back to the earliest known activity.
On 2026-07-01, OFAC updated its Specially Designated Nationals list to add 134 cryptocurrency addresses linked to Islamic State Khorasan Province (ISKP). Treasury said the addresses had moved more than $2 million in terrorist financing.
On 2026-04-24, OFAC updated the SDN entry for the Central Bank of Iran by adding two cryptocurrency addresses tied to the bank. The bank had originally been sanctioned in 2019, and the update followed U.S.-linked enforcement activity targeting Iranian sanctions-evasion flows involving USDT.
India's Financial Intelligence Unit issued updated rules requiring cryptocurrency entities serving Indian residents, including offshore operators, to register and disclose officer, location, and ownership details. The framework also mandates enhanced customer due diligence, transaction monitoring, and suspicious activity reporting to address fraud, money laundering, and terrorism financing risks.
The European Union announced its 19th package of sanctions against Russia on 2025-10-23, including measures targeting crypto providers alongside Russian energy interests and third-country banks. The action marked a new sanctions development by the EU expanding pressure on financial and crypto-related channels linked to Russia.
On 2025-08-14, OFAC re-designated Garantex under cyber-related authorities and designated successor exchange Grinex, three Garantex executives, and six associated companies in Russia and the Kyrgyz Republic. Treasury said the network enabled sanctions evasion and processed over $100 million in illicit transactions tied to ransomware actors, darknet markets, and other cybercriminal activity since 2019.
OFAC published formal compliance guidance for the virtual currency industry in October 2021, expanding its sanctions expectations for crypto businesses and related compliance programs.
The U.S. Treasury's Office of Foreign Assets Control first included cryptocurrency addresses in a sanctions designation on 2018-11-28, when it sanctioned two Iran-based individuals linked to the SamSam ransomware scheme and listed two Bitcoin addresses.
In 2018, OFAC began issuing frequently asked questions for the virtual currency industry to clarify how U.S. sanctions rules apply to cryptocurrency activity and compliance obligations.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See what this changes for your reporting obligations and which controls it puts on the clock.
6 references tracked. Mallory keeps watching after this page renders.
trmlabs.com
Open sourcechainalysis.com
Open sourcechainalysis.com
Open sourcescworld.com
Open sourceconsilium.europa.eu
Open sourcehome.treasury.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.