The U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) designated Iranian cryptocurrency exchange BitBank—also known as BitBank3—under Executive Order 13902 for its alleged role in financier Babak Zanjani’s digital-asset network. Treasury said the exchange transferred hundreds of millions of dollars’ worth of Bitcoin to Iran’s Islamic Revolutionary Guard Corps (IRGC) in June and July 2026, and that sanctioned maritime-services firm Hormuz Safe Marine Services Authority used BitBank to process cryptocurrency payments collected for services in the Strait of Hormuz.
OFAC also sanctioned BitBank developer Pishtaz Simorgh Electronic Trade Company and three executives tied to the Dot One Value Creation Group. The action extends prior measures against Zanjani-linked entities including Zedcex, Zedxion, ZedPay, ZEDX DMCC, BZ Diamond, and other Dot One operations, which include the MyDot platform, DOTO token, Dot One Smart Chain, and exchange services. Treasury’s public announcement did not provide wallet addresses, transaction hashes, counterparties, or other on-chain evidence supporting the stated transfer total.

See the reporting duties and controls this puts on the clock.
11 events from the most recent confirmed update back to the earliest known activity.
OFAC designated Iranian digital-asset exchange BitBank, also known as BitBank3, under Executive Order 13902 as part of Operation Economic Outcast. It also designated BitBank software developer Pishtaz Simorgh Electronic Trade Company and executives Mohammad Mahdi Zaker Hossein, Seyed Adel Heidari/Heydari, and Hossein Ali Zaker Hossein for their roles in Zanjani's network.
The United States sanctioned Hormuz Safe Marine Services Authority, which Treasury described as providing insurance, security, and other vessel services in the Strait of Hormuz and accepting Bitcoin and other cryptoassets as payment.
OFAC designated four additional individuals and nine entities in Zanjani's network, including Dot One Value Creation Group, ZEDX DMCC, ZedPay, BZ Diamond, transportation companies, and associated parties involved in digital-asset, gold-trading, transportation, and financial activities.
Treasury alleged that the Hormuz Safe Marine Services Authority began using BitBank to transfer cryptocurrency payments collected for its Strait of Hormuz maritime services to the Iranian regime.
OFAC designated Babak Zanjani, Zedcex Exchange, and Zedxion Exchange in what was described as the first U.S. sanctions action against digital-asset exchanges for supporting the IRGC.
A TRM Labs investigation identified approximately USD 1 billion in IRGC-linked activity through Zedcex and Zedxion during 2023–2025, with roughly 56% of observed transaction volume assessed as linked to the IRGC.
Treasury stated that Babak Zanjani had advertised BitBank on his social-media accounts since at least 2024.
TRM Labs assessed that IRGC-linked activity through Zedcex and Zedxion peaked at approximately USD 619 million, representing an estimated 87% of observed activity that year.
Zedcex Exchange Ltd was incorporated in the United Kingdom after Zanjani's formal departure from Zedxion. TRM Labs assessed that Zedcex and Zedxion operated as a single exchange operation through multiple legal entities.
Zedxion Exchange Ltd was incorporated in the United Kingdom. Later that year, UK records listed Babak Morteza, identified as a name used by Babak Zanjani in UK filings, as a director and person with significant control.
Treasury alleged that a network associated with Babak Zanjani used BitBank between June and July to transfer hundreds of millions of dollars in Bitcoin to the IRGC. The public Treasury release did not provide wallet addresses, transaction hashes, individual values, or other public on-chain evidence for the claimed total.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.