Can a Multisig Wallet Get Sanctioned Like Any Other Address?

By Alexandr Kerya · · 6 min read

TL;DR - A multisig or Safe wallet gets screened and sanctioned exactly like a single-key address - OFAC has already frozen $344.2 million across two multisig-custody wallets tied to Iran's central bank.

A multisig wallet gets the same treatment as any other address once its number lands on a sanctions list. The extra signatures don't buy immunity, and most people who set up a 2-of-3 or 3-of-5 wallet for "extra security" never think about that until an exchange rejects a deposit. Screening tools, exchanges, and OFAC itself look at the address string on-chain. They don't care how many keys it takes to move the funds inside it.

Does a Multisig Wallet Get Screened Differently Than a Single-Key Address?

No. A wallet screening tool checks an address against sanctions lists, mixer-exposure data, and stolen-funds datasets - the same checks whether that address is an externally owned account (EOA) controlled by one private key or a smart contract requiring three signatures to move a single dollar. On Ethereum, a Safe (formerly Gnosis Safe) is a deployed contract with its own address, and that address goes through AML screening the same way a MetaMask address does.

Governance structure is invisible to a screening query. The tool sees a hex string and a transaction history. It doesn't know, or need to know, that moving funds out requires two of three hardware wallets to sign.

Diagram: a single-key EOA wallet and a multisig or Safe wallet both reduce to the same address string and transaction history once they reach a screening check for sanctions, mixer contact, and stolen funds.
A single-key wallet and a multisig wallet feed the same screening engine the same two inputs: an address and its transaction history.

The Iran Central Bank Case Shows What Actually Gets Frozen

In April 2026, OFAC designated two wallets tied to Iran's central bank, Bank Markazi, as blocked property. Both were multisig custody setups bridged across Ethereum and Binance Smart Chain. Tether coordinated with OFAC and US law enforcement to freeze approximately $344.2 million in USDT sitting inside them. TRM Labs' analysis of the case found the two addresses had collectively received roughly $370 million across about 1,000 transactions since March 2021, with less than 7% ever moved back out - reserve storage, not an active laundering pipeline.

The multisig structure didn't slow the freeze down. Tether can blacklist a USDT-holding address regardless of who or what controls the private keys behind it.

A follow-up action on July 16, 2026 added four more wallets, mostly on Tron, tied to the same Iranian central bank network and freezing roughly $131 million more (details in our earlier writeup). Combined, the two rounds put close to $475 million in blocked crypto tied to a single sanctioned institution.

Timeline: April 2026 OFAC designates 2 multisig wallets, $344.2 million frozen by Tether; July 16, 2026 adds 4 more wallets, mostly Tron, $131 million frozen; combined total approximately $475 million.
Two OFAC rounds against Iran's central bank in 2026 froze close to $475 million total, and multisig custody didn't slow either one down.

Why Doesn't Requiring Multiple Signatures Provide Cover?

Because the sanction attaches to the address, not to any individual signer. OFAC's SDN list entries name specific wallet addresses as blocked property. Once an address is listed, US persons and any exchange with US exposure are barred from processing transactions involving it - full stop, regardless of whether a "good faith" cosigner didn't know the wallet's history.

A signature threshold is a governance rule, not a compliance shield. It changes who can authorize a transaction. It does nothing to change how a screening engine or a stablecoin issuer treats the resulting address once it's designated.

Tornado Cash's August 2022 designation and its March 21, 2025 delisting worked at the protocol level - the smart contract itself was named, and using it tainted every wallet that touched it. The Bank Markazi case is narrower: two specific custody wallets, not a whole protocol. Both approaches land on the same lesson - OFAC designates addresses and contracts directly, and whatever governance sits behind them is beside the point.

Do Compliance Tools Reliably Spot That an Address Is a Contract Wallet?

Not always, and that gap causes its own friction. Distinguishing a smart-contract address from an EOA requires an on-chain code lookup, not just pattern-matching the address format - both look identical as 42-character hex strings. Some exchanges respond to that uncertainty by blanket-rejecting deposits from any contract address, sanctioned or not, purely to avoid the operational risk of a wallet type they can't fully model.

False positives are already a known weakness in heuristic wallet clustering, and multisig setups sit right in the blind spot - shared custody wallets, CoinJoin participants, and multisig treasuries all get flagged by association more often than single-key wallets with equivalent transaction histories. A DAO treasury Safe with one careless past counterparty can end up carrying the same risk score as the counterparty itself.

What Should You Actually Check Before Funding a Multisig Wallet?

Screen the multisig contract address itself before you deposit into it or accept funds from it, exactly as you would any other counterparty address. Then check the individual signer addresses where you can - risk can flow into a shared wallet through a single compromised or sanctioned cosigner just as easily as through the contract's own transaction history.

If you're moving funds out of a Safe or similar wallet toward a centralized exchange, expect more friction than a simple EOA withdrawal, not less. Compliance teams that can't cleanly verify beneficial ownership of a multisig tend to hold those withdrawals longer by default.

Etherscan will show you the multisig contract's raw transaction list and any token balances, but it won't tell you whether that address or its counterparties carry sanctions, mixer, or stolen-funds exposure. Screen a wallet address with Plastron to get that full risk picture - sanctions hits, mixer contact, and stolen-funds links across chains - free, before you sign anything.

FAQ

Can OFAC sanction a smart contract address, not just a person?

Yes. OFAC's SDN list already includes smart contract addresses and multisig custody wallets as blocked property, alongside individual and entity designations. The April 2026 Bank Markazi case designated the wallet addresses themselves.

Does a 2-of-3 multisig protect me if one cosigner turns out to be sanctioned?

No. If a cosigner's own address is later designated, exposure can extend to any shared wallet they helped control. Screening looks at the whole transaction graph, not just who initiated a given transfer.

Can funds inside a sanctioned multisig wallet still be moved?

Practically, no - once a stablecoin issuer like Tether blacklists the address, the tokens themselves stop being transferable regardless of how many valid signatures a transaction carries. Native ETH or BTC in a sanctioned address isn't frozen at the token level, but any regulated venue will refuse to touch it.

Do exchanges treat Safe wallet deposits differently from regular wallet deposits?

Often, yes. Some platforms add extra verification steps or reject contract-address deposits outright because they can't reliably confirm beneficial ownership behind a multisig, separate from any sanctions question.

Is a DAO treasury multisig exposed to the same screening as a personal wallet?

Yes. A DAO treasury Safe is just another address to a screening engine. Its risk score reflects its own transaction history and its counterparties' history, the same as any wallet Plastron's dataset of 3,901 labeled addresses and 780 OFAC SDN entries gets checked against.

Disclaimer: This article is for educational and informational purposes only and is not legal, financial, tax, or compliance advice. Crypto carries risk; you act on this information at your own risk. Always do your own research and consult a qualified professional before making decisions. Views are the author's own and do not constitute financial, legal, or investment advice.

About Plastron

Plastron is a free, non-custodial wallet screening tool. It checks Ethereum and six EVM chains for AML and KYT risk — sanctions exposure, mixer contact, and stolen-funds proximity — and returns a risk report in seconds. It reads public on-chain data only: it never takes custody of funds and never asks for private keys.

How Plastron works and who runs it →

Keep reading

OFAC Adds 4 New Crypto Addresses Tied to Iran's Central BankHow Does a Crypto Address Get Added to the OFAC Sanctions List?Why Passing the Chainalysis Oracle Doesn't Mean Your Wallet Is CleanEtherscan vs a Wallet Screening Tool: What It Won't Show You