Data last synced:
Last updated:
Poloniex, LLC, a Delaware company that operated an online trading and settlement platform, settled with OFAC for $7,591,630 to resolve 65,942 apparent violations of multiple sanctions programs. Between January 2014 and November 2019, the Poloniex trading platform allowed customers apparently located in sanctioned jurisdictions to engage in online digital asset-related transactions—consisting of trades, deposits, and withdrawals—with a combined value of $15,335,349, despite having reason to know their location based on both Know Your Customer information and internet protocol address data. OFAC determined that the apparent violations were not voluntarily self-disclosed and were not egregious.
Penalty Amount
$7,591,630.00
Enforcement Date
May 1, 2023
Rank in Top Penalties
#45
Poloniex operations began in January 2014 by offering an online digital assets trading and settlement platform that allowed customers to fund their accounts and conduct trading activity. Sixteen months later, in May 2015, Poloniex implemented a sanctions compliance program providing for a review of KYC information for new customers in jurisdictions subject to comprehensive OFAC sanctions; existing customers were not retroactively screened in this manner. As a result, customers who had self-identified before May 2015 as residing in a sanctioned jurisdiction were generally able to continue using the platform.
Poloniex began monitoring IP address data in May 2015 to detect logins from sanctioned jurisdictions and conducted additional diligence on such logins, including contacting account owners, but did not begin implementing a block on such IP addresses until June 2017. Sanctions controls related to customers in the Crimea region of Ukraine were implemented only in August 2017.
Circle Internet Financial Limited acquired Poloniex in February 2018 and implemented additional internal sanctions compliance controls that significantly reduced the rate of additional Apparent Violations. Some Apparent Violations, primarily related to a small number of accounts opened by persons then located in Crimea, continued in 2018 and 2019.
As a result of these compliance deficiencies, between approximately July 28, 2015 and September 2, 2019, Poloniex processed 65,942 online digital asset-related transactions with a combined value of approximately $15,335,349 for 232 customers apparently located in sanctioned jurisdictions, predominantly in Crimea, but also in Cuba, Iran, Sudan, and Syria. These comprised: 57,263 apparent violations of section 1(a)(iii) of Executive Order 13685 (Crimea); 3,784 apparent violations of the Cuban Assets Control Regulations, 31 C.F.R. § 515.201; 1,466 apparent violations of the Iranian Transactions and Sanctions Regulations, 31 C.F.R. § 560.204; 3,428 apparent violations of the now-repealed Sudanese Sanctions Regulations, 31 C.F.R. § 538.205; and one apparent violation of the Syrian Sanctions Regulations, 31 C.F.R. § 542.207.
The statutory maximum civil monetary penalty applicable in this matter is $19,692,872,800. OFAC determined that the Apparent Violations were not voluntarily self-disclosed and were non-egregious. Accordingly, under OFAC's Economic Sanctions Enforcement Guidelines, the base civil monetary penalty amount equals the applicable schedule amount of $99,237,000. The settlement amount of $7,591,630 reflects OFAC's consideration of the General Factors under the Enforcement Guidelines.
Online digital asset companies, like all financial service providers, are responsible for ensuring that they do not engage in transactions prohibited by OFAC sanctions, such as providing services to persons in comprehensively sanctioned jurisdictions. To mitigate such risks, online digital asset companies should develop a tailored, risk-based sanctions compliance program. An appropriate compliance program will depend on a variety of factors, including the type of business involved, its size and sophistication, products and services offered, customers and counterparties, and geographic locations served. It should incorporate five essential components of compliance: (1) management commitment; (2) risk assessment; (3) internal controls; (4) testing and auditing; and (5) training.
This enforcement action emphasizes the importance for new companies and those involved in emerging technologies to incorporate sanctions compliance into their business functions at the outset, especially when the companies seek to offer financial services to a global customer base. It also highlights the importance of using all available location-related information for sanctions compliance purposes and integrating such information into a risk-based sanctions compliance program to mitigate the risk of providing services to persons in sanctioned jurisdictions. Companies implementing new compliance controls should also ensure that they apply those controls not only to new customers, but to existing ones as well.
This page summarizes an OFAC enforcement case based on the document archived below. SanctionsLookup assumes no liability for errors, omissions, or inaccuracies in the original documents, this summary, or any changes made to the source documents at any time.
Provided for informational purposes only and does not constitute legal or compliance advice. Always consult the source document directly rather than relying on this summary.
Archived on June 13, 2026
SHA-256: cde63c0ea255e3bb91b564e2cacd67b0faffeb6b85edf17614e833b53fce98e4