Data last synced:
Last updated:
BitPay, Inc., a private company that offers a payment processing solution for merchants to accept digital currency as payment for goods and services, settled its potential civil liability for 2,102 apparent violations of multiple sanctions programs for $507,375. BitPay allowed persons who appear to have been located in the Crimea region of Ukraine, Cuba, North Korea, Iran, Sudan, and Syria to transact with merchants in the United States and elsewhere using digital currency on BitPay's platform, even though BitPay had location information, including Internet Protocol (IP) addresses and other location data, about those persons prior to effecting the transactions. The apparent violations implicated Executive Order 13685, the Cuban Assets Control Regulations, the North Korea Sanctions Regulations, the Iranian Transactions and Sanctions Regulations, the Sudanese Sanctions Regulations, and the Syrian Sanctions Regulations.
Penalty Amount
$507,375.00
Enforcement Date
February 18, 2021
Rank in Top Penalties
#136
Between approximately June 10, 2013 and September 16, 2018, BitPay processed 2,102 transactions on behalf of individuals who, based on IP addresses and information available in invoices, were located in sanctioned jurisdictions. BitPay's payment processing service enabled merchants to accept digital currency as payment for goods and services; specifically, BitPay received digital currency payments on behalf of its merchant customers from those merchants' buyers in sanctioned jurisdictions, converted the digital currency to fiat currency, and then relayed that currency to its merchants.
While BitPay screened its direct customers (the merchants) against OFAC's List of Specially Designated Nationals and Blocked Persons and conducted due diligence on them to ensure they were not located in sanctioned jurisdictions, BitPay failed to screen location data that it obtained about its merchants' buyers. BitPay at times received information about those buyers at the time of transaction, including name, address, email address, and phone number. Beginning in November 2017, BitPay also obtained buyers' IP addresses. BitPay's transaction review process nonetheless failed to analyze fully this identification and location data. As a result, buyers who were located in Crimea, Cuba, North Korea, Iran, Sudan, and Syria were able to make purchases from merchants in the United States and elsewhere using digital currency on BitPay's platform.
This conduct resulted in apparent violations of Executive Order 13685 of December 19, 2014, "Blocking Property of Certain Persons and Prohibiting Certain Transactions with Respect to the Crimea Region of Ukraine"; the Cuban Assets Control Regulations, 31 C.F.R. §515.201; the North Korea Sanctions Regulations, 31 C.F.R. §510.206; the Iranian Transactions and Sanctions Regulations, 31 C.F.R. §560.204; the Sudanese Sanctions Regulations, 31 C.F.R. §538.205 (SSR); and the Syrian Sanctions Regulations, 31 C.F.R. §542.207.
The statutory maximum civil monetary penalty applicable in this matter is $619,689,816. OFAC determined that BitPay did not voluntarily self-disclose the Apparent Violations and that the Apparent Violations constitute a non-egregious case. Accordingly, under OFAC's Economic Sanctions Enforcement Guidelines, the base civil monetary penalty amount applicable in this matter is $2,255,000. The settlement amount of $507,375 reflects OFAC's consideration of the General Factors under the Enforcement Guidelines.
This action emphasizes that OFAC obligations apply to all U.S. persons, including those involved in providing digital currency services. Companies that facilitate or engage in online commerce or process transactions using digital currency are responsible for ensuring that they do not engage in unauthorized transactions prohibited by OFAC sanctions, such as dealings with blocked persons or property, or engaging in prohibited trade or investment-related transactions.
To mitigate such risks, administrators, exchangers, and other companies involved in using digital currencies should develop a tailored, risk-based sanctions compliance program. OFAC's Framework for OFAC Compliance Commitments notes that each risk-based sanctions compliance program will vary depending on a variety of factors, including the company's size and sophistication, products and services, customers and counterparties, and geographic locations, but should be predicated on and incorporate at least five essential components of compliance: (1) management commitment; (2) risk assessment; (3) internal controls; (4) testing and auditing; and (5) training. Within that framework, this enforcement action emphasizes the importance of screening all available information, including IP addresses and other location data of customers and counterparties, to mitigate sanctions risks in connection with digital currency services.
This page summarizes an OFAC enforcement case based on the document archived below. SanctionsLookup assumes no liability for errors, omissions, or inaccuracies in the original documents, this summary, or any changes made to the source documents at any time.
Provided for informational purposes only and does not constitute legal or compliance advice. Always consult the source document directly rather than relying on this summary.
Archived on June 13, 2026
SHA-256: e56efa9c9b7931889b710e8186904ce44e9da277b643cb3e524235fb17026708