SanctionsLookup

Data last synced:

Exodus Movement, Inc. OFAC Settlement: $3.1M (2025)

Last updated:

Exodus Movement, Inc., a U.S. financial technology company, settled with OFAC for $3,103,360 to resolve 254 apparent violations of the Iranian Transactions and Sanctions Regulations. Exodus provided customer support services to users in Iran which, in certain instances, helped such users access third party digital asset exchanges through Exodus's proprietary wallet software. In some instances, while aware of U.S. sanctions, Exodus staff recommended that these users obscure their location in Iran using Virtual Private Networks (VPNs) to avoid the sanctions compliance controls implemented by such exchanges.

Penalty Amount

$3,103,360.00

Enforcement Date

December 16, 2025

Rank in Top Penalties

#69

Case Details

Type:
Entity
Name:
Exodus Movement, Inc.
Country:
๐Ÿ‡บ๐Ÿ‡ธ United States
Industry:
Crypto
Address:
Omaha, Nebraska
Penalty amount:
$3,103,360.00
Base civil monetary penalty:
$4,774,400.00
Egregious case:
Partial
Apparent violations:
254
Voluntary self disclosure:
No
Case:
Settlement
Violation period:
October 17, 2017 to January 4, 2019
Program:
Iranian Transactions and Sanctions Regulations ("ITSR")
Enforcement date:
December 16, 2025

Nature of the Apparent Violations

From October 17, 2017 through January 4, 2019, Exodus provided technical and support services on 254 occasions to Exodus Wallet users who identified themselves as located in Iran, in apparent violation of ยง560.204 of the Iran Transactions and Sanctions Regulations (ITSR). Exodus Wallet is proprietary software allowing users to generate and store private keys to send and receive digital assets; Exodus contracted with third-party exchanges to offer their services through the wallet and did not itself process any digital asset exchange transactions. Exodus also maintained a customer support unit that handled user inquiries via email, and part of its standard approach was to recommend VPNs for privacy and security.

Exodus provided these customer support services despite its own Terms of Use prohibiting users in embargoed countries, including Iran, from using Exodus Wallet. However, Exodus failed to notify or train employees on these sanctions-related prohibitions and implemented no practical mechanism to prevent use of the wallet in sanctioned jurisdictions for a significant portion of the relevant time period.

In April 2018, one of Exodus's third-party exchange partners ("Exchange A") announced it would adjust service offerings by jurisdiction to comply with U.S. regulations and began using IP blocking to deny access to users in Iran. By May 2018, Exodus's CEO and management were aware that Exchange A's blocking was a measure to comply with U.S. sanctions. Despite this awareness, on 12 occasions, Exodus customer service staff explicitly acknowledged to users in Iran that Exchange A and other exchanges blocked Iran-based customers due to U.S. sanctions or U.S. laws, yet nevertheless recommended VPNs to circumvent those controls. For example, on May 24, 2018, an Exodus customer service staff member told an Iran-based user: "When you create an exchange with Exodus, it just forwards your current IP address to [Exchange A]. I expect that [Exchange A] will not be able to detect you are from Iran if you use a VPN to change your IP address."

OFAC determined that these 12 instances constituted willful and reckless conduct and were egregious. In addition to ยง560.204, the 12 egregious instances also violated 31 C.F.R. ยง560.203 of the ITSR, as Exodus's VPN recommendations evaded or avoided, had the purpose of evading or avoiding, caused a violation of, or attempted to violate the prohibitions of the ITSR.

How OFAC Determined the Penalty

OFAC determined that the apparent violations were not voluntarily self-disclosed. Of the 254 apparent violations, 12 were egregious and 242 were non-egregious. Under OFAC's Economic Sanctions Enforcement Guidelines, 31 C.F.R. part 501, Appendix A, the base civil monetary penalty for the 12 egregious apparent violations equals the sum of the statutory maximum civil monetary penalty for each, totaling $4,532,400. The base civil monetary penalty for the 242 non-egregious apparent violations equals the sum of the applicable schedule amount for each, totaling $242,000. The total base civil monetary penalty is $4,774,400.

After consideration of the General Factors under the Enforcement Guidelines, OFAC reached a settlement amount of $3,103,360. As partial satisfaction of the settlement amount, Exodus agreed to invest $630,000 in additional sanctions compliance controls.

Aggravating Factors

  • On at least 12 occasions, Exodus staff appeared to willfully violate OFAC sanctions on Iran in acknowledging that Exodus's exchange partners prohibited Iranian users from accessing exchange services while recommending the customers use VPNs to circumvent the exchanges' compliance controls. Such conduct, in conjunction with Exodus's broader awareness of U.S. sanctions on Iran, indicates Exodus's knowledge that such conduct constituted or likely constituted a violation of U.S. sanctions.
  • In other instances, Exodus acted with reckless disregard for U.S. sanctions requirements when it provided customer support services to persons located in Iran on 254 occasions while being generally aware of prohibitions on providing services to Iran, as reflected in its Terms of Use and its CEO's communication to customer support personnel. In doing so, Exodus ignored numerous warning signs that its conduct was prohibited.
  • Exodus management and staff had actual knowledge that Exodus provided customer support services to users in Iran given that such users generally identified their location in Iran to Exodus staff.
  • Exodus's conduct was contrary to longstanding U.S. policy directed at denying Iran access to the U.S. and international financial system, including digital assets. These services enabled persons in a comprehensively sanctioned jurisdiction to conduct digital asset transactions using U.S. services and informed them how to obscure their location in Iran, undermining blocking controls implemented by Exodus's exchange partners seeking to comply with U.S. law.

Mitigating Factors

  • Exodus invested millions of dollars in enhancing its sanctions compliance program and took other remedial actions in response to the Apparent Violations. These efforts have included adopting a standalone Export Control and Sanctions Compliance Policy, hiring additional compliance personnel, improving internal compliance policies and procedures, implementing third-party automated sanctions screening and other wallet address monitoring tools, and implementing mandatory sanctions compliance training for all Exodus staff. Exodus also updated the sanctions compliance representations and warranties in agreements with third-party exchange providers and implemented technical measures to prevent dealings with sanctioned cryptocurrency addresses.
  • Exodus provided substantial cooperation to OFAC over a yearslong investigation, including by responding promptly to OFAC's requests for information, providing large volumes of data regarding the Apparent Violations, participating in witness interviews, submitting internal communications, and executing statute of limitations tolling agreements.
  • Exodus has not received a penalty notice or Finding of Violation from OFAC in the five years preceding the date of the transactions giving rise to the Apparent Violations. Exodus was also a small company at the time of the Apparent Violations. The volume of the Apparent Violations represents a fraction of a percent of the total number of downloads of the Exodus Wallet and customer support inquiries annually during the relevant time period.

Compliance Takeaways

This enforcement action emphasizes the importance of new companies incorporating sanctions compliance into their business functions and providing adequate employee training from day one of operations. This is especially crucial when companies provide access to financial services to a global customer base. Companies should screen for location information, particularly when available through IP addresses and information provided by customers (such as passports or when a customer self-identifies as being from a particular country). Such screening is particularly important in mitigating the risk of providing services to individuals in jurisdictions subject to sanctions.

Digital asset technology companies, like all financial service providers, are responsible for ensuring that they do not engage in conduct unauthorized by OFAC sanctions. To mitigate such risks, digital asset companies should develop a tailored, risk-based sanctions compliance program. An adequate compliance solution for members of the digital asset industry depends on a variety of factors, including the type of business involved, its size and sophistication, products and services offered, customers and counterparties, and geographic locations served, but should be predicated on and incorporate at least five essential components of compliance: (1) management commitment; (2) risk assessment; (3) internal controls; (4) testing and auditing; and (5) training.

This action also highlights the significance of management commitment to a sound compliance program. By internally acknowledging that a separate company was bound by sanctions regarding the transactions at issue without addressing the applicability of sanctions to Exodus's own business, management failed to prevent these apparent violations.

Official Source Documents

This page summarizes an OFAC enforcement case based on the document archived below. SanctionsLookup assumes no liability for errors, omissions, or inaccuracies in the original documents, this summary, or any changes made to the source documents at any time.

Provided for informational purposes only and does not constitute legal or compliance advice. Always consult the source document directly rather than relying on this summary.

Archived on June 13, 2026

SHA-256: 293a1aa8460b070d662a48feeb35825fbef781cc0e0d1a390541446d5168bfc8

More OFAC Cases