SanctionsLookup

Data last synced:

CoinList Markets LLC OFAC Settlement: $1.2M (2023)

Last updated:

CoinList Markets LLC, a virtual currency exchange, settled with OFAC for $1,207,830 to resolve its potential civil liability for 989 apparent violations of the Ukraine-/Russia-Related Sanctions Regulations arising from processing transactions on behalf of users ordinarily resident in Crimea between April 2020 and May 2022. OFAC determined that the apparent violations were not voluntarily self-disclosed and were non-egregious.

Penalty Amount

$1,207,830.00

Enforcement Date

December 13, 2023

Rank in Top Penalties

#97

Case Details

Type:
Entity
Name:
CoinList Markets LLC
Country:
๐Ÿ‡บ๐Ÿ‡ธ United States
Industry:
Crypto
Address:
San Francisco, California
Penalty amount:
$1,207,830.00
Base civil monetary penalty:
$3,097,000.00
Max civil monetary penalty:
$327,306,583.00
Egregious case:
No
Apparent violations:
989
Voluntary self disclosure:
No
Case:
Settlement
Violation period:
April 19, 2020 to May 7, 2022
Program:
Ukraine-/Russia-Related Sanctions Regulations (URSR), 31 C.F.R. ยง 589.207
Enforcement date:
December 13, 2023

Nature of the Apparent Violations

CLM allows users to buy, sell, and otherwise trade in crypto tokens and other crypto assets, acting primarily as an intermediary. During onboarding, individuals must provide their country of residence, address, date of birth, phone number, selfie picture, and a photo of government-issued identification. Entities must provide incorporation documents, country of incorporation, company address, shareholder information, and signatory details.

During the relevant period, CLM maintained several sanctions compliance measures, including screening customers against OFAC and other sanctions lists, transactional monitoring, and blockchain analytics tools to identify touchpoints with high-risk jurisdictions and sanctioned wallet addresses. Beginning in February 2021, CLM instituted controls to deny access to users with IP addresses in sanctioned jurisdictions. By spring 2021, CLM's onboarding protocols also included an automated process to immediately reject applications from users presenting identification from, or providing a physical address in, a comprehensively sanctioned jurisdiction.

CLM's screening procedures nonetheless failed to capture users who represented themselves as resident of a non-embargoed country but provided an address within Crimea. CLM opened 89 accounts for customers who specified "Russia" as their country of residence while providing addresses in Crimea โ€” identifying a city in Crimea or the term "Crimea" in a separate data field. Because "Russia" appeared in the country-of-residence field, CLM's screening protocols did not recognize the Crimean references in the address field as indicating likely Crimea residence.

In providing financial services to these users between April 19, 2020 and May 7, 2022, CLM engaged in 989 apparent violations of the Ukraine-/Russia-Related Sanctions Regulations (URRSR), 31 C.F.R. ยง 589.207, totaling $1,252,280.

How OFAC Determined the Penalty

The statutory maximum civil monetary penalty applicable in this matter is $327,306,583. OFAC determined that the apparent violations were not voluntarily self-disclosed and were non-egregious. Accordingly, under OFAC's Economic Sanctions Enforcement Guidelines, the base civil monetary penalty amount equals the applicable schedule amount of $3,097,000. The settlement amount of $1,207,830 reflects OFAC's consideration of the General Factors under the Enforcement Guidelines.

In view of the individual facts of this case, including CLM's financial circumstances, $300,000 of the settlement amount will be suspended pending satisfactory completion of CLM's compliance commitments as agreed to by CLM as part of this settlement. As partial satisfaction of the settlement amount, CLM has also agreed to invest $300,000 in additional sanctions compliance controls, including enhanced screening controls and additional compliance staff.

Aggravating Factors

  • CLM failed to exercise due caution or care for its sanctions compliance obligations when it failed to institute internal controls able to flag accounts whose owners described themselves as resident of Crimea.
  • CLM knew or had reason to know it was conducting transactions on behalf of persons who were likely to be ordinarily resident in Crimea. Each of the users in question self-reported addresses at account opening specifying a city in Crimea, the word "Crimea," or both.
  • CLM's processing of transactions on behalf of users in Crimea harmed the integrity of the policy objectives of the URRSR. CLM conferred economic benefits to Crimea by processing 989 transactions totaling $1,252,280 over two years. There is no indication the transactions would have been licensable or involved humanitarian activity.

Mitigating Factors

  • OFAC has not issued a Penalty Notice or Finding of Violation to CLM in the five years preceding the earliest date of the transactions giving rise to the Apparent Violations.
  • CLM cooperated with OFAC's investigation by responding to questions, providing transaction data, and entering into tolling agreements.
  • The volume of Apparent Violations represents a very small percentage of the total volume of transactions conducted by CLM annually.
  • CLM undertook a number of remedial measures, including: updating its filter settings to automatically reject potential users who report a residential address with a Crimean city, even if there is no mention of the Crimea region by name, and regardless of the country of residence provided; implementation of IP geo-blocking to detect IP addresses in sanctioned jurisdictions and preventing users from accessing their accounts from those IP addresses; investing in new vendors for review and verification of identity documents and restricted party screening as well as in tools to detect the use of VPNs that can obscure users' location; and enhancing its training program and hiring additional experienced compliance personnel.

Compliance Takeaways

This case highlights the importance of integrating all available KYC and other relevant information into a company's screening process and broader compliance function. Certain firms providing virtual currency services have failed to ensure that their screening processes and broader compliance programs adequately incorporate customer information gathered from the onboarding process or through transactional information (such as IP location information). Ensuring that such data is gathered and employed using a risk-based approach is important to mitigate the risk of providing services to persons in sanctioned jurisdictions.

This enforcement action further emphasizes the importance for virtual currency companies and those involved in emerging technologies to incorporate risk-based sanctions compliance into their business functions, especially when the companies seek to offer financial services to a global customer base. An appropriate compliance program for members of the virtual currency industry will depend on a variety of factors, including the type of business involved, its size and sophistication, products and services offered, customers and counterparties, and geographic locations served. It should be predicated on and incorporate five essential components of compliance: (1) management commitment; (2) risk assessment; (3) internal controls; (4) testing and auditing; and (5) training. Members of the virtual currency and emerging technologies industries should incorporate sanctions compliance considerations at the development and beta testing stages. Delaying development and implementation of a sanctions compliance program can expose companies to a wide variety of potential sanctions risks.

Official Source Documents

This page summarizes an OFAC enforcement case based on the document archived below. SanctionsLookup assumes no liability for errors, omissions, or inaccuracies in the original documents, this summary, or any changes made to the source documents at any time.

Provided for informational purposes only and does not constitute legal or compliance advice. Always consult the source document directly rather than relying on this summary.

Archived on June 13, 2026

SHA-256: 1935549b168341cd3abc19bb3479ec52be7806e36623f422ab82da18227bd42b

More OFAC Cases