Tether said it helped US authorities freeze nearly $550 million in USDT during 2026 from wallets authorities linked to the Central Bank of Iran and sanctions-evasion networks. The disclosure coincided with Treasury’s April Iran-related designations and was supported by on-chain Tron records showing two wallet blacklists in April and four in July tied to the Central Bank of Iran sanctions entry. Tether said it has assisted in freezing more than $4.9 billion in assets globally.
A Senate Permanent Subcommittee on Investigations minority-staff report questioned the adequacy and timeliness of Tether’s sanctions controls, alleging that some illicit wallets were blacklisted late or not at all. The report found that 84% of 846 wallets sanctioned or targeted for seizure over alleged Iran and regional-proxy links used USDT exclusively or almost exclusively, while cautioning that this statistic does not represent USDT’s share of all Iranian payment activity. Tether did not reconcile its $550 million figure with Chainalysis’s earlier estimate of nearly $475 million in Central Bank of Iran-related wallet freezes.

Track how attackers are adapting to this technology.
5 events from the most recent confirmed update back to the earliest known activity.
Tether said it had helped U.S. authorities freeze approximately $550 million in USDT during 2026 across wallets linked by authorities to Iran's central bank and sanctions-evasion networks. The disclosure coincided with a Senate minority-staff report alleging shortcomings and delays in Tether's blacklisting of illicit wallets.
Tether blacklisted four additional Tron wallets holding more than $130 million in USDT. OFAC added those addresses to the Central Bank of Iran sanctions entry in the same update.
Chainalysis reported that freezes affecting Central Bank of Iran wallets totaled almost $475 million.
OFAC added the two previously blacklisted Tron addresses to its Central Bank of Iran sanctions entry.
Tether blacklisted two Tron addresses holding more than $344 million in USDT, preventing the wallets from spending or sending their USDT balances. The wallets were identified as linked to Iran's central bank and sanctions-evasion networks.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
thedefiant.io
Open sourceofac.treasury.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.