Data last synced:
Last updated:
Exodus Movement, Inc., a U.S. financial technology company, settled with OFAC for $3,103,360 to resolve 254 apparent violations of the Iranian Transactions and Sanctions Regulations. Exodus provided customer support services to users in Iran which, in certain instances, helped such users access third party digital asset exchanges through Exodus's proprietary wallet software. In some instances, while aware of U.S. sanctions, Exodus staff recommended that these users obscure their location in Iran using Virtual Private Networks (VPNs) to avoid the sanctions compliance controls implemented by such exchanges.
Penalty Amount
$3,103,360.00
Enforcement Date
December 16, 2025
Rank in Top Penalties
#69
From October 17, 2017 through January 4, 2019, Exodus provided technical and support services on 254 occasions to Exodus Wallet users who identified themselves as located in Iran, in apparent violation of ยง560.204 of the Iran Transactions and Sanctions Regulations (ITSR). Exodus Wallet is proprietary software allowing users to generate and store private keys to send and receive digital assets; Exodus contracted with third-party exchanges to offer their services through the wallet and did not itself process any digital asset exchange transactions. Exodus also maintained a customer support unit that handled user inquiries via email, and part of its standard approach was to recommend VPNs for privacy and security.
Exodus provided these customer support services despite its own Terms of Use prohibiting users in embargoed countries, including Iran, from using Exodus Wallet. However, Exodus failed to notify or train employees on these sanctions-related prohibitions and implemented no practical mechanism to prevent use of the wallet in sanctioned jurisdictions for a significant portion of the relevant time period.
In April 2018, one of Exodus's third-party exchange partners ("Exchange A") announced it would adjust service offerings by jurisdiction to comply with U.S. regulations and began using IP blocking to deny access to users in Iran. By May 2018, Exodus's CEO and management were aware that Exchange A's blocking was a measure to comply with U.S. sanctions. Despite this awareness, on 12 occasions, Exodus customer service staff explicitly acknowledged to users in Iran that Exchange A and other exchanges blocked Iran-based customers due to U.S. sanctions or U.S. laws, yet nevertheless recommended VPNs to circumvent those controls. For example, on May 24, 2018, an Exodus customer service staff member told an Iran-based user: "When you create an exchange with Exodus, it just forwards your current IP address to [Exchange A]. I expect that [Exchange A] will not be able to detect you are from Iran if you use a VPN to change your IP address."
OFAC determined that these 12 instances constituted willful and reckless conduct and were egregious. In addition to ยง560.204, the 12 egregious instances also violated 31 C.F.R. ยง560.203 of the ITSR, as Exodus's VPN recommendations evaded or avoided, had the purpose of evading or avoiding, caused a violation of, or attempted to violate the prohibitions of the ITSR.
OFAC determined that the apparent violations were not voluntarily self-disclosed. Of the 254 apparent violations, 12 were egregious and 242 were non-egregious. Under OFAC's Economic Sanctions Enforcement Guidelines, 31 C.F.R. part 501, Appendix A, the base civil monetary penalty for the 12 egregious apparent violations equals the sum of the statutory maximum civil monetary penalty for each, totaling $4,532,400. The base civil monetary penalty for the 242 non-egregious apparent violations equals the sum of the applicable schedule amount for each, totaling $242,000. The total base civil monetary penalty is $4,774,400.
After consideration of the General Factors under the Enforcement Guidelines, OFAC reached a settlement amount of $3,103,360. As partial satisfaction of the settlement amount, Exodus agreed to invest $630,000 in additional sanctions compliance controls.
This enforcement action emphasizes the importance of new companies incorporating sanctions compliance into their business functions and providing adequate employee training from day one of operations. This is especially crucial when companies provide access to financial services to a global customer base. Companies should screen for location information, particularly when available through IP addresses and information provided by customers (such as passports or when a customer self-identifies as being from a particular country). Such screening is particularly important in mitigating the risk of providing services to individuals in jurisdictions subject to sanctions.
Digital asset technology companies, like all financial service providers, are responsible for ensuring that they do not engage in conduct unauthorized by OFAC sanctions. To mitigate such risks, digital asset companies should develop a tailored, risk-based sanctions compliance program. An adequate compliance solution for members of the digital asset industry depends on a variety of factors, including the type of business involved, its size and sophistication, products and services offered, customers and counterparties, and geographic locations served, but should be predicated on and incorporate at least five essential components of compliance: (1) management commitment; (2) risk assessment; (3) internal controls; (4) testing and auditing; and (5) training.
This action also highlights the significance of management commitment to a sound compliance program. By internally acknowledging that a separate company was bound by sanctions regarding the transactions at issue without addressing the applicability of sanctions to Exodus's own business, management failed to prevent these apparent violations.
This page summarizes an OFAC enforcement case based on the document archived below. SanctionsLookup assumes no liability for errors, omissions, or inaccuracies in the original documents, this summary, or any changes made to the source documents at any time.
Provided for informational purposes only and does not constitute legal or compliance advice. Always consult the source document directly rather than relying on this summary.
Archived on June 13, 2026
SHA-256: 293a1aa8460b070d662a48feeb35825fbef781cc0e0d1a390541446d5168bfc8