OFAC blocks transactions with sanctioned wallets by law; FinCEN collects suspicious-activity reports but leaves the freeze decision to you.
On November 21, 2023, Binance paid the US Treasury $4.3 billion in a single announcement, split between two federal agencies that had spent years building two entirely separate cases against the same company. That split confuses more compliance teams than it should. Vendor decks routinely treat FinCEN and OFAC as interchangeable stamps of approval, and a lot of the confusion in crypto AML programs traces straight back to that assumption. One agency runs a blocklist you are legally required to enforce the moment you see a match. The other runs a reporting regime built around judgment calls, case files, and filing deadlines. Confuse the two and you either freeze customers who never touched a sanctioned address, or file nothing on the ones who should have triggered a report months ago.
What does OFAC actually check on a crypto wallet?
OFAC administers the Specially Designated Nationals list under the Treasury's sanctions authority, and the rule for crypto is unforgiving: any US person who deals with an SDN-listed address, directly or through a wallet it substantially controls, is in violation. There's no minimum amount. A single dollar routed through a sanctioned address counts. That obligation doesn't stop at the address itself, either. Treasury's fifty-percent rule extends the block to any entity a sanctioned party owns fifty percent or more of, even when that specific wallet never appears on the published list by name.
Plastron's own OFAC dataset currently tracks 780 addresses on that list, sitting inside a broader corpus of 3,901 labeled wallets covering scams, hacks, mixers, and known-illicit exchanges. On August 28, 2026, OFAC added another round of Iran-related and counter-terrorism designations to the SDN list, the kind of routine update that quietly changes which wallets are radioactive overnight. The question OFAC creates for anyone screening a wallet is binary. Is this address, or anything upstream of it, on the list. No SDN hit, no OFAC problem. How an address actually lands on that list matters more than most screening tools let on, since the fifty-percent rule pulls in wallets that never got named directly.
What does FinCEN require that OFAC doesn't?
FinCEN runs a completely different program: the Bank Secrecy Act, not a sanctions list. It requires crypto exchanges to register as money services businesses, build a full anti-money-laundering program, and file Suspicious Activity Reports and Currency Transaction Reports when the facts call for it. There's no address to match against a list here. A FinCEN violation is about whether the program itself was designed and run correctly, and that's a judgment call examiners make after the fact, not a lookup anyone can run in seconds. An exchange can pass every OFAC screen it ever runs and still draw a FinCEN enforcement action for failing to file SARs on activity any competent analyst would have flagged.
The clearest proof sits in one settlement. On November 21, 2023, Binance paid OFAC $968,618,825 to resolve 1,667,153 apparent sanctions violations. On the same day, it paid FinCEN $3.4 billion, including $150 million held in suspension, for Bank Secrecy Act program failures that had nothing to do with any specific SDN match. Same company, same announcement, two agencies, two separate theories of what went wrong. One number named a list. The other named a program that never worked.
Head-to-head
Put the two agencies side by side and the split stops being confusing. It comes down to what triggers action, not which one is more serious.
| Criterion | OFAC | FinCEN |
|---|---|---|
| Legal basis | Sanctions authority (IEEPA) | Bank Secrecy Act |
| What triggers it | A match against the SDN list, or a 50%-owned entity | Suspicious activity or a currency threshold |
| Obligation | Block or freeze immediately, no discretion | File a SAR or CTR; discretion is the job |
| Binance settlement, Nov 21, 2023 | $968,618,825 for 1,667,153 apparent violations | $3.4B, incl. $150M suspended, for BSA program failures |
| Who must comply | Every US person, not just exchanges | Registered money services businesses / VASPs |
| What a wallet screen like Plastron covers | Direct and indirect SDN exposure across a wallet's history | Not applicable - SAR/CTR filing lives inside the exchange's own program |
When is OFAC screening the whole job?
If you're an individual, a freelancer getting paid in crypto, or an OTC desk about to accept a transfer from someone new, you don't have SAR obligations. You're not a regulated money services business. OFAC is where your actual legal exposure lives, because receiving funds from a sanctioned address doesn't require intent to create a problem. Screen the wallet before you accept the transfer, not after support asks where the funds came from.