CASE STUDY

Case study: digital asset exchange

Key facts

ShapeShift AG, a digital asset exchange incorporated in Switzerland but operating out of Denver, has agreed to pay a $750,000 settlement for apparent violations of U.S. sanctions against Cuba, Iran, Sudan, and Syria. Between 2016 and 2018, the company processed over $12 million in transactions for users in these jurisdictions because it had no sanctions compliance program in place. OFAC determined the case was non-egregious, but highlighted significant aggravating factors, including ShapeShift's failure to exercise a minimal degree of caution by ignoring the IP address data it collected. The agency noted that ShapeShift had "reason to know" its users were in sanctioned jurisdictions and that its actions harmed the integrity of U.S. sanctions programs by providing economic benefits to prohibited persons. The significantly reduced penalty reflects the company's cooperation, its financial constraints, and the fact that it is now a defunct entity.

Compliance recommendations

  • Foreign incorporation is not a shield: Entities incorporated abroad are still subject to U.S. jurisdiction if their headquarters, senior management, or business operations are located within the United States.
  • Utilize the data you have: It is insufficient to merely collect customer data; you must actively screen all available information, especially IP addresses and geolocation data, to block users from sanctioned jurisdictions.
  • Build compliance early: Do not wait for a subpoena to start your program; compliance controls should be integrated during the development and beta testing stages of your product.
  • Remediate immediately: If you discover compliance gaps, taking prompt remedial action—such as implementing mandatory screening or blocking high-risk IP addresses—can be a significant mitigating factor.
Compliance checklist for digital asset exchanges:

  • Assess U.S. nexus beyond incorporation Do not assume foreign incorporation protects you; you are subject to U.S. jurisdiction if your headquarters, senior executives, or key operations are located in the United States.
  • Screen all users before allowing transactions Implement mandatory screening of every new customer against OFAC’s SDN List and other relevant sanctions lists prior to providing services.
  • Use IP data for geo-blocking Actively utilize the IP address data you already collect to identify and block users attempting to access your platform from sanctioned jurisdictions like Cuba, Iran, and Syria.
  • Implement daily customer rescreening Establish an automated process to rescreen your existing customer base daily to capture any new additions or updates to sanctions lists.
  • Build compliance controls early Integrate sanctions compliance measures, such as screening tools and risk assessments, during the software development and beta testing stages of your platform.
  • Maintain internal blacklists Create and enforce a blacklist of specific digital asset addresses known to be associated with malign activity or sanctions targets.
  • Monitor on-chain activity Leverage public blockchain data to monitor transactions and identify potential connections to illicit addresses or patterns.
  • Secure management commitment Ensure senior leadership is actively involved in compliance and understands their responsibility to prevent services to sanctioned persons, regardless of the company's size.
  • Adopt proactive remediation Do not wait for an administrative subpoena or enforcement action to implement a compliance program; proactive adoption can mitigate penalties.
Made on
Tilda