SanctionsLookup

Data last synced:

BitPay, Inc. OFAC Settlement: $507.4K (2021)

Last updated:

BitPay, Inc., a private company that offers a payment processing solution for merchants to accept digital currency as payment for goods and services, settled its potential civil liability for 2,102 apparent violations of multiple sanctions programs for $507,375. BitPay allowed persons who appear to have been located in the Crimea region of Ukraine, Cuba, North Korea, Iran, Sudan, and Syria to transact with merchants in the United States and elsewhere using digital currency on BitPay's platform, even though BitPay had location information, including Internet Protocol (IP) addresses and other location data, about those persons prior to effecting the transactions. The apparent violations implicated Executive Order 13685, the Cuban Assets Control Regulations, the North Korea Sanctions Regulations, the Iranian Transactions and Sanctions Regulations, the Sudanese Sanctions Regulations, and the Syrian Sanctions Regulations.

Penalty Amount

$507,375.00

Enforcement Date

February 18, 2021

Rank in Top Penalties

#136

Case Details

Type:
Entity
Name:
BitPay, Inc.
Country:
🇺🇸 United States
Industry:
Crypto
Address:
Atlanta, Georgia
Penalty amount:
$507,375.00
Base civil monetary penalty:
$2,255,000.00
Max civil monetary penalty:
$619,689,816.00
Egregious case:
No
Apparent violations:
2102
Voluntary self disclosure:
No
Case:
Settlement
Violation period:
June 10, 2013 to September 16, 2018
Program:
Executive Order 13685 of December 19, 2014, "Blocking Property of Certain Persons and Prohibiting Certain Transactions with Respect to the Crimea Region of Ukraine"Cuban Assets Control Regulations, 31 C.F.R. §515.201North Korea Sanctions Regulations, 31 C.F.R. §510.206Iranian Transactions and Sanctions Regulations, 31 C.F.R. §560.204Sudanese Sanctions Regulations, 31 C.F.R. §538.205 (SSR)Syrian Sanctions Regulations, 31 C.F.R. §542.207
Enforcement date:
February 18, 2021

Nature of the Apparent Violations

Between approximately June 10, 2013 and September 16, 2018, BitPay processed 2,102 transactions on behalf of individuals who, based on IP addresses and information available in invoices, were located in sanctioned jurisdictions. BitPay's payment processing service enabled merchants to accept digital currency as payment for goods and services; specifically, BitPay received digital currency payments on behalf of its merchant customers from those merchants' buyers in sanctioned jurisdictions, converted the digital currency to fiat currency, and then relayed that currency to its merchants.

While BitPay screened its direct customers (the merchants) against OFAC's List of Specially Designated Nationals and Blocked Persons and conducted due diligence on them to ensure they were not located in sanctioned jurisdictions, BitPay failed to screen location data that it obtained about its merchants' buyers. BitPay at times received information about those buyers at the time of transaction, including name, address, email address, and phone number. Beginning in November 2017, BitPay also obtained buyers' IP addresses. BitPay's transaction review process nonetheless failed to analyze fully this identification and location data. As a result, buyers who were located in Crimea, Cuba, North Korea, Iran, Sudan, and Syria were able to make purchases from merchants in the United States and elsewhere using digital currency on BitPay's platform.

This conduct resulted in apparent violations of Executive Order 13685 of December 19, 2014, "Blocking Property of Certain Persons and Prohibiting Certain Transactions with Respect to the Crimea Region of Ukraine"; the Cuban Assets Control Regulations, 31 C.F.R. §515.201; the North Korea Sanctions Regulations, 31 C.F.R. §510.206; the Iranian Transactions and Sanctions Regulations, 31 C.F.R. §560.204; the Sudanese Sanctions Regulations, 31 C.F.R. §538.205 (SSR); and the Syrian Sanctions Regulations, 31 C.F.R. §542.207.

How OFAC Determined the Penalty

The statutory maximum civil monetary penalty applicable in this matter is $619,689,816. OFAC determined that BitPay did not voluntarily self-disclose the Apparent Violations and that the Apparent Violations constitute a non-egregious case. Accordingly, under OFAC's Economic Sanctions Enforcement Guidelines, the base civil monetary penalty amount applicable in this matter is $2,255,000. The settlement amount of $507,375 reflects OFAC's consideration of the General Factors under the Enforcement Guidelines.

Aggravating Factors

  • BitPay failed to exercise due caution or care for its sanctions compliance obligations when it allowed persons in sanctioned jurisdictions to transact with BitPay's merchants using digital currency for approximately five years, even though BitPay had sufficient information to screen those customers.
  • BitPay conveyed a total of $128,582.61 in economic benefit to individuals in several jurisdictions subject to OFAC sanctions, thereby harming the integrity of those sanctions programs.

Mitigating Factors

  • BitPay had implemented certain sanctions compliance controls as early as 2013, including conducting due diligence and sanctions screening on its merchant customers, and formalized its sanctions compliance program in 2014.
  • BitPay made clear in its training to all employees, including senior management, that BitPay prohibited merchant sign-ups from Cuba, Iran, Syria, Sudan, North Korea, and Crimea, as well as trade with sanctioned individuals and entities.
  • BitPay is a small business that has not received a penalty notice or Finding of Violation from OFAC in the five years preceding the date of the earliest Apparent Violation.
  • BitPay cooperated with OFAC's investigation into these Apparent Violations.
  • BitPay has represented that it has terminated the conduct that led to the Apparent Violations and undertook the following measures: blocking IP addresses that appear to originate in Cuba, Iran, North Korea, and Syria from connecting to the BitPay website or from viewing any instructions on how to make payment; checking physical and email addresses of merchants' buyers when provided by the merchants to prevent completion of an invoice if BitPay identifies a sanctioned jurisdiction address or email top-level domain; and launching "BitPay ID," a new customer identification tool mandatory for merchants' buyers who wish to pay a BitPay invoice equal to or above $3,000, requiring an email address, proof of identification/photo ID, and a selfie photo.
  • As part of its agreement with OFAC, BitPay has undertaken to continue its implementation of these and other compliance commitments.

Compliance Takeaways

This action emphasizes that OFAC obligations apply to all U.S. persons, including those involved in providing digital currency services. Companies that facilitate or engage in online commerce or process transactions using digital currency are responsible for ensuring that they do not engage in unauthorized transactions prohibited by OFAC sanctions, such as dealings with blocked persons or property, or engaging in prohibited trade or investment-related transactions.

To mitigate such risks, administrators, exchangers, and other companies involved in using digital currencies should develop a tailored, risk-based sanctions compliance program. OFAC's Framework for OFAC Compliance Commitments notes that each risk-based sanctions compliance program will vary depending on a variety of factors, including the company's size and sophistication, products and services, customers and counterparties, and geographic locations, but should be predicated on and incorporate at least five essential components of compliance: (1) management commitment; (2) risk assessment; (3) internal controls; (4) testing and auditing; and (5) training. Within that framework, this enforcement action emphasizes the importance of screening all available information, including IP addresses and other location data of customers and counterparties, to mitigate sanctions risks in connection with digital currency services.

Official Source Documents

This page summarizes an OFAC enforcement case based on the document archived below. SanctionsLookup assumes no liability for errors, omissions, or inaccuracies in the original documents, this summary, or any changes made to the source documents at any time.

Provided for informational purposes only and does not constitute legal or compliance advice. Always consult the source document directly rather than relying on this summary.

Archived on June 13, 2026

SHA-256: e56efa9c9b7931889b710e8186904ce44e9da277b643cb3e524235fb17026708

More OFAC Cases