SanctionsLookup

Data last synced:

ShapeShift AG OFAC Settlement: $750K (2025)

Last updated:

ShapeShift AG, a digital asset exchange incorporated in Switzerland, settled with OFAC for $750,000 to resolve its potential civil liability for apparent violations of multiple OFAC sanctions programs. Between December 10, 2016 and October 9, 2018, ShapeShift engaged in digital asset transactions on its exchange platform with users located in Cuba, Iran, Sudan, and Syria, resulting in apparent violations of the Cuban Assets Control Regulations, the Iranian Transactions and Sanctions Regulations, the Sudanese Sanctions Regulations, and the Syrian Sanctions Regulations.

Penalty Amount

$750,000.00

Enforcement Date

September 22, 2025

Rank in Top Penalties

#120

Case Details

Type:
Entity
Name:
ShapeShift AG
Country:
πŸ‡¨πŸ‡­ Switzerland
Industry:
Crypto
Address:
Denver, Colorado
Penalty amount:
$750,000.00
Base civil monetary penalty:
$39,515,000.00
Egregious case:
No
Apparent violations:
17183
Voluntary self disclosure:
No
Case:
Settlement
Violation period:
December 10, 2016 to October 9, 2018
Program:
Cuban Assets Control Regulations (CACR)Iranian Transactions and Sanctions Regulations (ITSR)Sudanese Sanctions RegulationsSyrian Sanctions Regulations
Enforcement date:
September 22, 2025

Nature of the Apparent Violations

ShapeShift operated an online platform that allowed users to exchange a variety of digital assets, with ShapeShift as the sole counterparty. To engage in a transaction, a user specified the asset they were offering ShapeShift and the asset they sought to purchase, certified they were the beneficial owner of the digital asset, and provided their wallet address. Once ShapeShift received the user's digital asset at a ShapeShift wallet, ShapeShift sent the equivalent value of the requested digital asset from ShapeShift's own inventory to the user's wallet. All exchanges occurred "on chain" and each transaction is publicly available immediately after completion. At the platform's peak, ShapeShift engaged in as many as 20,000 daily transactions, and customers could exchange at least 79 different digital assets.

Although incorporated in Switzerland, ShapeShift was headquartered in Denver, Colorado, and most of its main officers and employees were U.S. persons who directed, controlled, and coordinated the corporation's activities from the United States. ShapeShift's senior leadership resided in the United States and operated out of ShapeShift's Denver, Colorado, office, an arrangement described in ShapeShift's Swiss incorporation filings. ShapeShift's U.S.-based engineers created and regularly maintained the software code and programming necessary for the proper functioning of the platform, including the algorithms that executed transactions on ShapeShift's platform. Additionally, ShapeShift was registered as a foreign corporation in good standing with the Colorado Secretary of State.

During the relevant period, ShapeShift had no sanctions compliance program in place to screen users or transactions for a nexus to sanctioned jurisdictions. ShapeShift did not screen for designated or blocked users for some time, despite possessing at all relevant times at least some Internet Protocol (IP) address information and conceding that the IP addresses were the "only available indicator" that ShapeShift collected regarding a party's location.

Between December 10, 2016 and October 9, 2018, in 17,183 instances, ShapeShift exchanged digital assets valuing $12,570,956 with users located in Cuba, Iran, Sudan, and Syria, resulting in 39 apparent violations of section 515.201(b) of the Cuban Assets Control Regulations (CACR), 16,839 apparent violations of section 560.204 of the Iranian Transactions and Sanctions Regulations (ITSR), 33 apparent violations of section 538.205 of the Sudanese Sanctions Regulations, and 272 apparent violations of section 542.207 of the Syrian Sanctions Regulations. Only after ShapeShift received an administrative subpoena from OFAC did it adopt a sanctions compliance program.

How OFAC Determined the Penalty

OFAC determined that ShapeShift did not voluntarily self-disclose the Apparent Violations and that the Apparent Violations constitute a non-egregious case. Accordingly, under OFAC's Economic Sanctions Enforcement Guidelines, 31 C.F.R. part 501, Appendix A, the base civil monetary penalty applicable in this matter equals the applicable schedule amount of $39,515,000. The settlement amount of $750,000 reflects OFAC's consideration of the General Factors under the Enforcement Guidelines.

Aggravating Factors

  • ShapeShift failed to exercise a minimal degree of caution or care for its sanctions compliance obligations when it failed to implement internal controls to prevent users located in sanctioned jurisdictions from conducting transactions on its platform.
  • ShapeShift had reason to know that such users were located in sanctioned jurisdictions, including on the basis of IP address data.
  • ShapeShift conveyed economic benefit to persons in several jurisdictions subject to OFAC sanctions and thereby harmed the integrity of multiple OFAC sanctions programs.

Mitigating Factors

  • ShapeShift was a relatively small company at the time of the Apparent Violations and has since ceased operations. Accordingly, ShapeShift is unlikely to engage in any further transactions that could result in violations. As a defunct concern, moreover, ShapeShift is in a highly constrained financial condition.
  • ShapeShift has not received a Penalty Notice or a Finding of a Violation from OFAC in the five years preceding the earliest date of the transactions giving rise to the Apparent Violations.
  • ShapeShift cooperated with OFAC's investigation by timely responding to each request for information and entering into tolling agreements.
  • The volume of Apparent Violations represents a small percentage of the total volume of transactions conducted annually by ShapeShift.
  • After discovering the violations, ShapeShift undertook a number of remedial measures as part of its revised sanctions compliance program, including: requiring mandatory screening of new customers and procedures for identifying and denying access to users with IP addresses linked to sanctioned jurisdictions; requiring screening of new and current customers against an internal blacklist of digital asset addresses associated with malign activity, including digital asset addresses designated by OFAC; daily rescreening against updated versions of the SDN List; and implementing sanctions-related training.

Compliance Takeaways

This case highlights that digital asset companies, like all financial service providers, are responsible for ensuring that they do not engage in transactions prohibited by OFAC sanctions, such as providing services to persons in sanctioned jurisdictions. This action also highlights the importance of adopting remedial measures to address compliance gaps promptly after discovering such issues. Like other previous OFAC settlement actions involving the digital asset industry, this case highlights the importance of integrating all available user information into a company's screening process. Certain firms providing digital asset services have failed to ensure that their screening processes and broader compliance programs adequately incorporate customer information gathered from the onboarding process or through transactional information such as IP location information. Ensuring that such data is gathered and employed using a risk-based approach is important to mitigate the risk of providing services to persons in sanctioned jurisdictions.

This case also highlights how foreign-incorporated companies may be subject to U.S. jurisdiction. Specifically, foreign-incorporated entities may be considered a U.S. person pursuant to OFAC sanctions regulations when their physical headquarters and overall business operations are located within the United States.

Finally, this enforcement action emphasizes the importance for digital asset companies and those involved in emerging technologies to incorporate risk-based sanctions compliance into their business functions, especially when the companies seek to offer financial services to a global customer base. OFAC's Sanctions Compliance Guidance for the Virtual Currency Industry explains that OFAC strongly encourages a risk-based approach to sanctions compliance. An appropriate compliance program for members of the digital asset industry will depend on a variety of factors, including the type of business involved, its size and sophistication, products and services offered, customers and counterparties, and geographic locations served. Critically, members of the digital assets and emerging technologies industries should incorporate sanctions compliance considerations at the development and beta testing stages. Delaying development and implementation of a sanctions compliance program can expose companies to a wide variety of potential sanctions risks.

Official Source Documents

This page summarizes an OFAC enforcement case based on the document archived below. SanctionsLookup assumes no liability for errors, omissions, or inaccuracies in the original documents, this summary, or any changes made to the source documents at any time.

Provided for informational purposes only and does not constitute legal or compliance advice. Always consult the source document directly rather than relying on this summary.

Archived on June 13, 2026

SHA-256: 1066718a51aea8e06d26f894186d7bb929534c098521ed5f02bfb8665fd21cd9

More OFAC Cases