FinCEN vs OFAC: Which Agency Actually Freezes Your Crypto?

By Alexandr Kerya · · 8 min read

OFAC blocks transactions with sanctioned wallets by law; FinCEN collects suspicious-activity reports but leaves the freeze decision to you.

On November 21, 2023, Binance paid the US Treasury $4.3 billion in a single announcement, split between two federal agencies that had spent years building two entirely separate cases against the same company. That split confuses more compliance teams than it should. Vendor decks routinely treat FinCEN and OFAC as interchangeable stamps of approval, and a lot of the confusion in crypto AML programs traces straight back to that assumption. One agency runs a blocklist you are legally required to enforce the moment you see a match. The other runs a reporting regime built around judgment calls, case files, and filing deadlines. Confuse the two and you either freeze customers who never touched a sanctioned address, or file nothing on the ones who should have triggered a report months ago.

What does OFAC actually check on a crypto wallet?

OFAC administers the Specially Designated Nationals list under the Treasury's sanctions authority, and the rule for crypto is unforgiving: any US person who deals with an SDN-listed address, directly or through a wallet it substantially controls, is in violation. There's no minimum amount. A single dollar routed through a sanctioned address counts. That obligation doesn't stop at the address itself, either. Treasury's fifty-percent rule extends the block to any entity a sanctioned party owns fifty percent or more of, even when that specific wallet never appears on the published list by name.

Plastron's own OFAC dataset currently tracks 780 addresses on that list, sitting inside a broader corpus of 3,901 labeled wallets covering scams, hacks, mixers, and known-illicit exchanges. On August 28, 2026, OFAC added another round of Iran-related and counter-terrorism designations to the SDN list, the kind of routine update that quietly changes which wallets are radioactive overnight. The question OFAC creates for anyone screening a wallet is binary. Is this address, or anything upstream of it, on the list. No SDN hit, no OFAC problem. How an address actually lands on that list matters more than most screening tools let on, since the fifty-percent rule pulls in wallets that never got named directly.

What does FinCEN require that OFAC doesn't?

FinCEN runs a completely different program: the Bank Secrecy Act, not a sanctions list. It requires crypto exchanges to register as money services businesses, build a full anti-money-laundering program, and file Suspicious Activity Reports and Currency Transaction Reports when the facts call for it. There's no address to match against a list here. A FinCEN violation is about whether the program itself was designed and run correctly, and that's a judgment call examiners make after the fact, not a lookup anyone can run in seconds. An exchange can pass every OFAC screen it ever runs and still draw a FinCEN enforcement action for failing to file SARs on activity any competent analyst would have flagged.

The clearest proof sits in one settlement. On November 21, 2023, Binance paid OFAC $968,618,825 to resolve 1,667,153 apparent sanctions violations. On the same day, it paid FinCEN $3.4 billion, including $150 million held in suspension, for Bank Secrecy Act program failures that had nothing to do with any specific SDN match. Same company, same announcement, two agencies, two separate theories of what went wrong. One number named a list. The other named a program that never worked.

Binance's November 21, 2023 settlement, split by agencyOFAC - $968.6M (1,667,153 apparent violations)FinCEN - $3.4B (incl. $150M suspended)Same company, same day, two unrelated legal theories.
Binance's $4.3B settlement on November 21, 2023 split almost 4-to-1 in FinCEN's favor - proof the two agencies were penalizing different failures, not double-counting one.

Head-to-head

Put the two agencies side by side and the split stops being confusing. It comes down to what triggers action, not which one is more serious.

OFAC versus FinCEN: what triggers each agency and what it requiresOFACFinCEN- Sanctions list match- Suspicious activity or thresholds- Block or freeze immediately- File a SAR or CTR- No discretion allowed- Discretion is part of the job- Applies to every US person- Applies to registered MSBs/VASPs
OFAC's sanctions list creates a binary, no-discretion block. FinCEN's reporting regime runs on judgment, thresholds, and an ongoing program - a different kind of obligation entirely.
CriterionOFACFinCEN
Legal basisSanctions authority (IEEPA)Bank Secrecy Act
What triggers itA match against the SDN list, or a 50%-owned entitySuspicious activity or a currency threshold
ObligationBlock or freeze immediately, no discretionFile a SAR or CTR; discretion is the job
Binance settlement, Nov 21, 2023$968,618,825 for 1,667,153 apparent violations$3.4B, incl. $150M suspended, for BSA program failures
Who must complyEvery US person, not just exchangesRegistered money services businesses / VASPs
What a wallet screen like Plastron coversDirect and indirect SDN exposure across a wallet's historyNot applicable - SAR/CTR filing lives inside the exchange's own program

When is OFAC screening the whole job?

If you're an individual, a freelancer getting paid in crypto, or an OTC desk about to accept a transfer from someone new, you don't have SAR obligations. You're not a regulated money services business. OFAC is where your actual legal exposure lives, because receiving funds from a sanctioned address doesn't require intent to create a problem. Screen the wallet before you accept the transfer, not after support asks where the funds came from.

Screen the address with Plastron and you get direct and indirect SDN exposure across Ethereum and six other chains in one pass, the same kind of check an exchange runs before it lets a deposit post. For a one-off transfer, that single screen is proportionate. Nobody needs a case-management system to accept one payment.

When do you need FinCEN-level compliance too?

If you operate an exchange, a custodian, or anything that touches customer funds at scale, OFAC screening is necessary and nowhere near sufficient. FinCEN expects an ongoing program: KYC at onboarding, transaction monitoring that runs continuously, SAR filings inside statutory deadlines, and a compliance officer who can walk an examiner through every decision. None of that lives inside a wallet risk score, including the one Plastron returns for a single address.

A perfect OFAC record on every deposit does not excuse a program that never files a report on a customer moving funds through twenty small deposits a day. That gap is exactly what Binance's FinCEN bill was for, and it landed on the same day as a clean, itemized count of sanctions violations. Two agencies, two audits, one company. Losing sight of that distinction is how a compliance budget ends up entirely spent on sanctions screening while the SAR queue backs up unread.

FAQ

Does a clean OFAC screen protect an exchange from FinCEN enforcement?

No. OFAC and FinCEN look at different failures. An exchange can screen every wallet against the SDN list and still get fined by FinCEN for weak transaction monitoring, missed Suspicious Activity Reports, or a Bank Secrecy Act program an examiner judges inadequate.

Can an individual violate OFAC without ever dealing with an exchange?

Yes. OFAC's sanctions rules apply to every US person, not just regulated businesses. Accepting a transfer from a wallet that touches an SDN-listed address can create liability even for a one-off, peer-to-peer payment with no exchange involved.

How fast do OFAC's crypto designations change?

Often. Treasury adds new addresses to the SDN list in batches tied to specific enforcement actions, including an Iran-related and counter-terrorism round added on August 28, 2026. A wallet that screened clean last month can pick up new exposure without moving a single coin.

Does FinCEN maintain its own sanctioned-address list separate from OFAC?

No. FinCEN doesn't publish a sanctions list at all. That authority sits with OFAC. FinCEN's job is the Bank Secrecy Act side: registration, KYC, transaction monitoring, and SAR or CTR filing, which runs independently of whether any wallet involved ever touched the SDN list.

Verdict

Screening a wallet against the SDN list is the fast, free, binary check almost anyone can run before money moves, and for most individual transfers it's the entire compliance job. Building a program that satisfies FinCEN is a heavier, ongoing commitment that only kicks in once you're operating as a business handling other people's funds. The Binance settlement is the cleanest evidence that neither one substitutes for the other. Same $4.3 billion total, same day, two separate bills for two separate failures.

Pass the OFAC test with a perfect score, and you can still fail the FinCEN one with zero sanctioned wallets anywhere near your platform. Read a settlement line by line before you assume one tool covers both jobs.

Disclaimer: This article is for educational and informational purposes only and is not legal, financial, tax, or compliance advice. Crypto carries risk; you act on this information at your own risk. Always do your own research and consult a qualified professional before making decisions. Views are the author's own and do not constitute financial, legal, or investment advice.

About Plastron

Plastron is a free, non-custodial wallet screening tool. It checks Ethereum and six EVM chains for AML and KYT risk — sanctions exposure, mixer contact, and stolen-funds proximity — and returns a risk report in seconds. It reads public on-chain data only: it never takes custody of funds and never asks for private keys.

How Plastron works and who runs it →

Keep reading

OFAC vs EU vs UK: Which Sanctions List Actually Flags Your Wallet?How Does a Crypto Address Get Added to the OFAC Sanctions List?What Is the OFAC 50 Percent Rule and Does It Affect Your Crypto Wallet?Can Wallet Screening See Restaked ETH After the Kelp DAO Hack?