SanctionsLookup

Data last synced:

BitGo, Inc. OFAC Settlement: $98.8K (2020)

Last updated:

BitGo, Inc., a technology company that implements security and scalability platforms for digital assets and offers non-custodial secure digital wallet management services, settled 183 apparent violations of multiple sanctions programs for $98,830. The apparent violations arose from BitGo's failure to prevent persons apparently located in the Crimea region of Ukraine, Cuba, Iran, Sudan, and Syria from using its non-custodial secure digital wallet management service, apparently violating Executive Order 13685, the Cuban Assets Control Regulations, the Iranian Transactions and Sanctions Regulations, the Sudanese Sanctions Regulations, and the Syrian Sanctions Regulations.

Penalty Amount

$98,830.00

Enforcement Date

December 30, 2020

Rank in Top Penalties

#242

Case Details

Type:
Entity
Name:
BitGo, Inc.
Country:
🇺🇸 United States
Industry:
Crypto
Address:
Palo Alto, California
Penalty amount:
$98,830.00
Base civil monetary penalty:
$183,000.00
Max civil monetary penalty:
$53,051,675.00
Egregious case:
No
Apparent violations:
183
Voluntary self disclosure:
No
Case:
Settlement
Violation period:
March 10, 2015 to December 11, 2019
Program:
Executive Order 13685 of December 19, 2014, "Blocking Property of Certain Persons and Prohibiting Certain Transactions with Respect to the Crimea Region of Ukraine"Cuban Assets Control Regulations, 31 C.F.R. §515.201Iranian Transactions and Sanctions Regulations, 31 C.F.R. §560.204Sudanese Sanctions Regulations, 31 C.F.R. §538.205 (SSR)Syrian Sanctions Regulations, 31 C.F.R. §542.207
Enforcement date:
December 30, 2020

Nature of the Apparent Violations

Between approximately March 10, 2015 and December 11, 2019, BitGo processed 183 digital currency transactions totaling $9,127.79 on behalf of individuals who, based on their IP addresses, were located in sanctioned jurisdictions. The apparent violations related to BitGo's "hot wallet" secure digital wallet management service. Individuals located in Crimea, Cuba, Iran, Sudan, and Syria signed up for "hot wallet" accounts and accessed BitGo's online platform to conduct digital currency transactions.

At the time of the apparent violations, BitGo tracked its users' IP addresses for security purposes related to account logins but did not use this IP address information for sanctions compliance purposes. Prior to April 2018, BitGo allowed individual users to open an account by providing only a name and email address. In April 2018, BitGo amended its practices to require all new accountholders to also verify the country in which they are located, but BitGo generally relied on each user's attestation regarding their location and did not perform additional verification or diligence on the location of its users.

By failing to prevent users in these jurisdictions from accessing and using its services to engage in digital currency transactions, BitGo apparently violated Executive Order 13685 of December 19, 2014, "Blocking Property of Certain Persons and Prohibiting Certain Transactions with Respect to the Crimea Region of Ukraine"; the Cuban Assets Control Regulations, 31 C.F.R. §515.201; the Iranian Transactions and Sanctions Regulations, 31 C.F.R. §560.204; the Sudanese Sanctions Regulations, 31 C.F.R. §538.205 (SSR); and the Syrian Sanctions Regulations, 31 C.F.R. §542.207.

How OFAC Determined the Penalty

The statutory maximum civil monetary penalty applicable in this matter is $53,051,675. OFAC determined that BitGo did not voluntarily self-disclose the apparent violations and that the apparent violations constitute a non-egregious case. Accordingly, under OFAC's Economic Sanctions Enforcement Guidelines, the base civil monetary penalty amount applicable in this matter is $183,000. The settlement amount of $93,830 reflects OFAC's consideration of the General Factors under the Enforcement Guidelines.

Aggravating Factors

  • BitGo failed to exercise due caution or care for its sanctions compliance obligations when it failed to prevent persons apparently located in sanctioned jurisdictions to open accounts and send digital currencies via its platform as a result of a failure to implement appropriate, risk-based sanctions compliance controls.
  • BitGo had reason to know that some of its users were located in sanctioned jurisdictions based on those users' IP address data, which it had separately obtained for security purposes.

Mitigating Factors

  • BitGo is a relatively small company and has not received a penalty notice or Finding of Violation from OFAC in the five years preceding the date of the earliest transaction giving rise to the apparent violations.
  • BitGo cooperated with OFAC's investigation into these apparent violations.
  • BitGo represented that it has invested in significant remedial measures in response to the apparent violations and as part of its agreement with OFAC to implement compliance commitments intended to minimize the risk of recurrence of similar conduct in the future, including: hiring a Chief Compliance Officer and implementing an OFAC Sanctions Compliance Policy covering all BitGo services; IP address blocking and email-related restrictions for sanctioned jurisdictions; periodic batch screening; recordkeeping procedures for all financial records and documentation related to sanctions compliance efforts; a review of end-user agreements to ensure customer awareness of U.S. sanctions requirements; periodic review of screening configuration criteria; retroactive batch screening of all users against OFAC's Specially Designated Nationals and Blocked Persons List including blocked cryptocurrency wallet addresses; and mandatory employee certification and training on the OFAC Policy.

Compliance Takeaways

Companies involved in providing digital currency services should understand the sanctions risks associated with providing digital currency services and take steps necessary to mitigate those risks. Companies that facilitate or engage in online commerce or process transactions using digital currency are responsible for ensuring that they do not engage in transactions prohibited by OFAC sanctions, such as dealings with blocked persons or property, or engaging in prohibited trade or investment-related transactions.

To mitigate such risks, administrators, exchangers, and users of digital currencies should develop a tailored, risk-based sanctions compliance program. Each risk-based sanctions compliance program will vary depending on factors including the company's size and sophistication, products and services, customers and counterparties, and geographic locations, but should be predicated on and incorporate at least five essential components of compliance: (1) management commitment; (2) risk assessment; (3) internal controls; (4) testing and auditing; and (5) training. This enforcement action emphasizes the importance of implementing technical controls, such as sanctions list screening and IP blocking mechanisms, to mitigate sanctions risks in connection with digital currency services.

Official Source Documents

This page summarizes an OFAC enforcement case based on the document archived below. SanctionsLookup assumes no liability for errors, omissions, or inaccuracies in the original documents, this summary, or any changes made to the source documents at any time.

Provided for informational purposes only and does not constitute legal or compliance advice. Always consult the source document directly rather than relying on this summary.

Archived on June 13, 2026

SHA-256: 7a11b953e693ef5a558f949da20ca05b6f16675e974bab01e0ada95e675312ef

More OFAC Cases