Data last synced:
Last updated:
ShapeShift AG, a digital asset exchange incorporated in Switzerland, settled with OFAC for $750,000 to resolve its potential civil liability for apparent violations of multiple OFAC sanctions programs. Between December 10, 2016 and October 9, 2018, ShapeShift engaged in digital asset transactions on its exchange platform with users located in Cuba, Iran, Sudan, and Syria, resulting in apparent violations of the Cuban Assets Control Regulations, the Iranian Transactions and Sanctions Regulations, the Sudanese Sanctions Regulations, and the Syrian Sanctions Regulations.
Penalty Amount
$750,000.00
Enforcement Date
September 22, 2025
Rank in Top Penalties
#120
ShapeShift operated an online platform that allowed users to exchange a variety of digital assets, with ShapeShift as the sole counterparty. To engage in a transaction, a user specified the asset they were offering ShapeShift and the asset they sought to purchase, certified they were the beneficial owner of the digital asset, and provided their wallet address. Once ShapeShift received the user's digital asset at a ShapeShift wallet, ShapeShift sent the equivalent value of the requested digital asset from ShapeShift's own inventory to the user's wallet. All exchanges occurred "on chain" and each transaction is publicly available immediately after completion. At the platform's peak, ShapeShift engaged in as many as 20,000 daily transactions, and customers could exchange at least 79 different digital assets.
Although incorporated in Switzerland, ShapeShift was headquartered in Denver, Colorado, and most of its main officers and employees were U.S. persons who directed, controlled, and coordinated the corporation's activities from the United States. ShapeShift's senior leadership resided in the United States and operated out of ShapeShift's Denver, Colorado, office, an arrangement described in ShapeShift's Swiss incorporation filings. ShapeShift's U.S.-based engineers created and regularly maintained the software code and programming necessary for the proper functioning of the platform, including the algorithms that executed transactions on ShapeShift's platform. Additionally, ShapeShift was registered as a foreign corporation in good standing with the Colorado Secretary of State.
During the relevant period, ShapeShift had no sanctions compliance program in place to screen users or transactions for a nexus to sanctioned jurisdictions. ShapeShift did not screen for designated or blocked users for some time, despite possessing at all relevant times at least some Internet Protocol (IP) address information and conceding that the IP addresses were the "only available indicator" that ShapeShift collected regarding a party's location.
Between December 10, 2016 and October 9, 2018, in 17,183 instances, ShapeShift exchanged digital assets valuing $12,570,956 with users located in Cuba, Iran, Sudan, and Syria, resulting in 39 apparent violations of section 515.201(b) of the Cuban Assets Control Regulations (CACR), 16,839 apparent violations of section 560.204 of the Iranian Transactions and Sanctions Regulations (ITSR), 33 apparent violations of section 538.205 of the Sudanese Sanctions Regulations, and 272 apparent violations of section 542.207 of the Syrian Sanctions Regulations. Only after ShapeShift received an administrative subpoena from OFAC did it adopt a sanctions compliance program.
OFAC determined that ShapeShift did not voluntarily self-disclose the Apparent Violations and that the Apparent Violations constitute a non-egregious case. Accordingly, under OFAC's Economic Sanctions Enforcement Guidelines, 31 C.F.R. part 501, Appendix A, the base civil monetary penalty applicable in this matter equals the applicable schedule amount of $39,515,000. The settlement amount of $750,000 reflects OFAC's consideration of the General Factors under the Enforcement Guidelines.
This case highlights that digital asset companies, like all financial service providers, are responsible for ensuring that they do not engage in transactions prohibited by OFAC sanctions, such as providing services to persons in sanctioned jurisdictions. This action also highlights the importance of adopting remedial measures to address compliance gaps promptly after discovering such issues. Like other previous OFAC settlement actions involving the digital asset industry, this case highlights the importance of integrating all available user information into a company's screening process. Certain firms providing digital asset services have failed to ensure that their screening processes and broader compliance programs adequately incorporate customer information gathered from the onboarding process or through transactional information such as IP location information. Ensuring that such data is gathered and employed using a risk-based approach is important to mitigate the risk of providing services to persons in sanctioned jurisdictions.
This case also highlights how foreign-incorporated companies may be subject to U.S. jurisdiction. Specifically, foreign-incorporated entities may be considered a U.S. person pursuant to OFAC sanctions regulations when their physical headquarters and overall business operations are located within the United States.
Finally, this enforcement action emphasizes the importance for digital asset companies and those involved in emerging technologies to incorporate risk-based sanctions compliance into their business functions, especially when the companies seek to offer financial services to a global customer base. OFAC's Sanctions Compliance Guidance for the Virtual Currency Industry explains that OFAC strongly encourages a risk-based approach to sanctions compliance. An appropriate compliance program for members of the digital asset industry will depend on a variety of factors, including the type of business involved, its size and sophistication, products and services offered, customers and counterparties, and geographic locations served. Critically, members of the digital assets and emerging technologies industries should incorporate sanctions compliance considerations at the development and beta testing stages. Delaying development and implementation of a sanctions compliance program can expose companies to a wide variety of potential sanctions risks.
This page summarizes an OFAC enforcement case based on the document archived below. SanctionsLookup assumes no liability for errors, omissions, or inaccuracies in the original documents, this summary, or any changes made to the source documents at any time.
Provided for informational purposes only and does not constitute legal or compliance advice. Always consult the source document directly rather than relying on this summary.
Archived on June 13, 2026
SHA-256: 1066718a51aea8e06d26f894186d7bb929534c098521ed5f02bfb8665fd21cd9