TL;DR - Paying a ransomware demand in Bitcoin can breach OFAC sanctions on a strict-liability basis, so you can be penalised even if you did not know the wallet was on the SDN list.
A ransomware crew encrypts your files and asks for Bitcoin. Paying feels like the fast way out, but it can create a second problem on top of the first: a sanctions violation. Many ransomware groups and the wallets they use are on the US Treasury sanctions list, and sending them money can expose you to enforcement even when you had no idea who was on the other end. This is the part that catches victims, insurers, and incident-response firms by surprise.
What does OFAC strict liability mean for a ransom payment?
The Office of Foreign Assets Control, the sanctions arm of the US Treasury, runs the Specially Designated Nationals list, usually shortened to the SDN list. Sending value to anyone on that list is prohibited for US persons, and the prohibition extends to crypto wallet addresses that OFAC has attributed to a sanctioned actor.
The detail that surprises people is strict liability. OFAC can impose civil penalties for a sanctions breach even when the payer did not know, and had no reason to know, that the recipient was sanctioned. Intent is not a defence. If the wallet you paid traces back to a designated group, the payment can count as a violation on its own terms, whether you paid directly or through a third party who handled the transfer for you.
If the receiving wallet traces to a designated actor, the transfer can be a sanctions breach on a strict-liability basis, no knowledge required.
This is why a ransom is never only a commercial decision. The advisory that OFAC published in 2020, and updated in 2021, warned plainly that facilitating a ransomware payment to a sanctioned entity may violate its regulations, and that warning reaches the victim, the insurer, the bank, and any digital-forensics firm that moves the funds.
Which ransomware wallets are actually sanctioned?
OFAC does not just name groups in the abstract. When it designates a ransomware actor, it often publishes the specific cryptocurrency addresses tied to that actor, and those addresses go straight onto the SDN list alongside names and aliases.
The pattern has been building for years. Evil Corp, the group behind the Dridex malware, was designated in 2019. In 2021 OFAC sanctioned the SUEX and Chatex over-the-counter exchanges for laundering ransomware proceeds, listing crypto addresses for both. In 2022 it sanctioned the Garantex exchange for the same reason. Each designation pinned concrete wallet addresses that became off-limits the moment they were published.
Each milestone added named crypto addresses to the SDN list, so a wallet can be sanctioned by attribution, not only by who controls it today.
The takeaway is that a ransom wallet does not announce itself. It is an ordinary string of characters until you compare it against the published lists, and the lists grow with every new designation.
How do you check a ransom address before you pay?
The first instinct is to look the address up manually. A block explorer such as Etherscan shows the balance and the transaction history of a wallet, and you can read the raw SDN list that OFAC publishes to look for a match. That works for a single direct hit, but it misses two things: addresses that are sanctioned by attribution rather than by an exact published string, and exposure that reaches the wallet indirectly through intermediaries. Rather than checking one source at a time, screen the address with Plastron to see sanctions, mixer, and stolen-funds exposure across Ethereum and six chains at once.
Screening before you act changes the decision. If the address comes back clean, you have a documented record that you checked, which matters to your bank and your insurer. If it lights up against a sanctioned cluster, you have just avoided turning a bad week into a federal sanctions matter. Either way the check costs nothing compared with the downside of paying blind.
What should you do if you already paid?
If the money is already gone, the priority is disclosure rather than silence. OFAC has signalled that self-reporting a payment, and cooperating with law enforcement, are treated as significant mitigating factors when it weighs an enforcement response. Hiding the payment removes that credit and makes the situation worse.
Practically, that means contacting law enforcement quickly, looping in counsel who handle sanctions matters, and preserving every record of the incident and the transfer. Screening the recipient address even after the fact helps too, because it tells you and your advisers whether the payment touched a designated entity, which shapes how you report and what exposure you carry. The goal is a clear, documented account of what happened, not a guess.
FAQ
Is it illegal to pay a ransomware demand?
Paying a ransom is not automatically illegal in the US, but it becomes a sanctions violation if the recipient is on the OFAC SDN list. Because liability is strict, you can be penalised even if you did not know the wallet was sanctioned, which is why screening first matters.
How would OFAC even know I paid a sanctioned wallet?
Blockchain transactions are public and permanent. Analytics firms and exchanges trace flows to and from designated addresses, and when sanctioned funds move through a regulated exchange the link surfaces. A payment that looked private at the time can be reconstructed long afterward.
Does using an incident-response firm or insurer remove my liability?
No. A sanctions breach can attach to anyone who facilitates the payment, including insurers and forensic firms, and using an intermediary does not shield the original payer. Everyone in the chain has the same reason to screen the address first.
Can a ransom wallet be sanctioned even if it is not on the published list yet?
Yes. OFAC attributes addresses to designated actors, and an analytics provider may flag a wallet as part of a sanctioned cluster before any single string appears in the raw list. That is why an exact-match lookup against the SDN file alone is not enough.
Disclaimer: This article is for educational and informational purposes only and is not legal, financial, tax, or compliance advice. Crypto carries risk; you act on this information at your own risk. Always do your own research and consult a qualified professional before making decisions. Views are the author's own and do not constitute financial, legal, or investment advice.
About Plastron
Plastron is a free, non-custodial wallet screening tool. It checks Ethereum and six EVM chains for AML and KYT risk — sanctions exposure, mixer contact, and stolen-funds proximity — and returns a risk report in seconds. It reads public on-chain data only: it never takes custody of funds and never asks for private keys.