The U.S. Treasury sanctioned crypto settlement provider Shelbit, founder Siavash Kayvanpour, affiliated entities in the UAE, Poland, and Georgia, and Iran-based exchange Aban Tether for allegedly facilitating Iran-linked illicit finance tied to IRGC-controlled wallets, sanctioned Iranian platforms, and laundering connected to a Persian-language gambling network. TRM Labs said Shelbit processed more than $6.3 billion in blockchain flows between May 2024 and March 2026, operating primarily on TRON using USDT-TRC20 and behaving less like a conventional exchange than a rapid settlement conduit, with near-zero retained balances and tightly matched inflows and outflows.
The sanctions action aligns with broader reporting that Iran has built a large crypto-enabled sanctions-evasion and threat-finance system that relies heavily on Tether on TRON when traditional banking channels are blocked. Separate analysis alleged that more than $3 billion flowed into IRGC-associated addresses in 2025 and mapped links from Iranian leadership and front companies to verified wallet addresses, Dubai exchange houses, shadow-fleet tankers, ransom payments, sanctioned oil sales, and drone-component procurement. Investigators also reported Shelbit’s direct exposure to the IRGC, a wallet later designated by Israel as Hamas infrastructure, and Russian sanctions-evasion services including A7, while warning that the underlying illicit finance network may continue despite the platform’s shutdown.

See the reporting duties and controls this puts on the clock.
9 events from the most recent confirmed update back to the earliest known activity.
On August 7, 2026, OFAC sanctioned Shelbit under Executive Order 13224, along with founder Siavash Kayvanpour and affiliated entities in the UAE, Poland, and Georgia. OFAC also separately designated Iran-based exchange Aban Tether under Executive Order 13902 for operating in Iran's financial sector.
TRM Labs' traced observation period for more than USD 6.3 billion in Shelbit-related blockchain flows ran through March 2026. The study found the infrastructure rotated wallets every one to four months and kept virtually no residual balances.
TRM Labs notes that OFAC designated Zedcex in January 2026 as an IRGC front company. TRM traced about USD 2.2 million in exposure between Shelbit and Zedcex.
TRM Labs reported that Shelbit's monthly traced volume peaked at about USD 735 million in November 2025. The activity was concentrated on TRON and heavily used USDT-TRC20.
On September 17, 2025, Shelbit sent about USD 2 million across four transfers to a wallet that Israel's National Bureau for Counter Terror Financing later designated as Hamas infrastructure. TRM Labs highlighted this transfer as part of Shelbit's direct exposure to sanctioned actors.
According to TRM Labs, Shelbit's monthly traced volume more than doubled in July 2025. It then remained above roughly USD 600 million for six consecutive months.
The Cyber Shafarat-cited report says Chainalysis traced more than USD 3 billion in inflows to IRGC-associated addresses in 2025. It describes that figure as a lower bound and says it represented roughly half of the Iranian ecosystem in the fourth quarter.
TRM Labs identified about USD 5.6 million across 36 transfers between Shelbit and wallets associated with the Islamic Revolutionary Guard Corps over a period spanning July 2024 to July 2025. Treasury later cited digital currency transfers between Shelbit and IRGC-controlled addresses in its sanctions action.
TRM Labs traced more than USD 6.3 billion in blockchain flows through Shelbit infrastructure over a period running from May 2024 to March 2026. The analysis later characterized Shelbit as a high-throughput settlement conduit rather than a conventional exchange.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See what this changes for your reporting obligations and which controls it puts on the clock.
3 references tracked. Mallory keeps watching after this page renders.
infosecurity-magazine.com
Open sourcetrmlabs.com
Open sourcecybershafarat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.