TL;DR - Screen a contractor's wallet for sanctions, mixer, and stolen-funds exposure before every crypto payroll run - OFAC sanctions liability is strict, so paying a listed address makes you liable even if you never checked.
On August 9, 2026, OFAC's SDN list grew by 13 more digital-currency addresses in a single batch, spanning Ethereum, Bitcoin, Tron, and Solana. Run payroll in stablecoins and one of your contractors' wallets could sit closer to that list than you think - it didn't exist in its current form a month ago.
Before you start
This checklist runs the moment you add a new contractor or vendor to a crypto payroll cycle: a first payment, a recurring monthly run, or a one-off invoice for a large project. You need one thing before you start - the exact destination wallet address, confirmed in writing, and the network it lives on.
A manual check is possible. Open the address on Etherscan, scroll the transaction history, and look for anything that stands out. That shows you what moved, not what it means - spotting a mixer contract or a sanctioned cluster by eye takes practice most payroll teams do not have. Instead of reading a raw transaction list, screen the wallet with Plastron and get sanctions, mixer, and stolen-funds exposure back as one risk score before a single stablecoin leaves your treasury.
Every contractor payment passes through a wallet screen first, then splits into a clean payout or a held, escalated review.
What happens if you pay a sanctioned wallet?
You become the one holding the liability. OFAC treats sanctions violations as strict liability - the agency does not need to prove you knew the destination address was tied to a designated entity, only that the payment happened. A payroll run that clears a listed wallet is a compliance and legal problem the moment the transaction confirms.
Plastron's own dataset carries 3,901 uniquely labeled addresses flagged for sanctions, mixer, scam, and stolen-funds exposure, cross-checked against the full OFAC SDN list, which Treasury updates daily. A contractor's wallet can be clean on Monday and listed by Friday. That is the part most payroll checklists skip - screening once at onboarding and never again.
One screen. Every run. Not just the first one.
The checklist
Run these steps in order, before any contractor payment - stablecoin or otherwise - leaves your wallet.
Collect the wallet address in writing, tied to the contract or the invoice, not a screenshot from a chat thread.
Confirm the network - Ethereum mainnet, a layer-2, or another chain - matches what you actually plan to send.
Screen the address before the first payment goes out, checking sanctions, mixer, and stolen-funds exposure in one pass.
Check it specifically against the OFAC SDN list - a direct match means the payment stops, no exceptions.
Log the screening result, the timestamp, and who approved the payment in your compliance file.
Re-screen before every recurring batch run - Treasury does not wait for your payroll calendar.
Re-screen immediately if a contractor asks you to send to a new address or a different network.
Escalate a flagged wallet to a hold and a manual review, not straight to a payment.
How often should you re-screen a contractor's wallet?
Every recurring cycle, not just once. A clean screen at onboarding tells you nothing about a wallet's exposure three payroll runs later, because the address keeps transacting with new counterparties in between. Treat re-screening as part of running payroll, the same way you would confirm an invoice total before you approve it.
High-value or recurring contractors get a screen before every batch. One-off vendors need it once, right before the single payment goes out. The trigger is the same either way - a payment about to leave your wallet, not a reminder that fires once a year.
What if a payment already went out to a flagged wallet?
Stop moving the funds and document everything. Do not forward the payment along to another wallet or an exchange - that adds another hop with your name on it, and it does not clear the exposure. Record the transaction hash, the screening result, and any correspondence with the contractor about that wallet.
A distant, low-severity hit usually just means keeping better records going forward. A direct match to the OFAC SDN list means stopping before anything else moves, the same day, with your compliance counsel on the call. See how the August 9 batch broke down by chain for what a fresh designation actually looks like.
FAQ
Do I need to screen a contractor I have paid before without any issue?
Yes. A wallet's exposure is not fixed at onboarding - it changes every time the address transacts with someone new, so a clean result from six months ago says nothing about today.
Is asking a contractor for their wallet address before the first payment unusual?
No. It is the crypto equivalent of confirming a bank routing number before a wire, and most contractors expect the request without hesitation.
My payroll platform already claims to screen wallets - do I still need to run this checklist?
Ask what "screening" covers in your contract before you rely on it. Some platforms check sanctions lists only and skip mixer or stolen-funds exposure entirely, which leaves a real gap.
Does a clean screening result protect me if OFAC lists the address later?
It shows reasonable due diligence at the time of payment, which matters for how a regulator views the incident. It does not undo a payment sent before the listing - which is why re-screening before every run matters more than a single check at onboarding.
Disclaimer: This article is for educational and informational purposes only and is not legal, financial, tax, or compliance advice. Crypto carries risk; you act on this information at your own risk. Always do your own research and consult a qualified professional before making decisions. Views are the author's own and do not constitute financial, legal, or investment advice.
About Plastron
Plastron is a free, non-custodial wallet screening tool. It checks Ethereum and six EVM chains for AML and KYT risk — sanctions exposure, mixer contact, and stolen-funds proximity — and returns a risk report in seconds. It reads public on-chain data only: it never takes custody of funds and never asks for private keys.