Everyone knows some widely sanctioned actors sometimes use digital assets. DPRK hackers, various sanctions and capital control evaders, drug dealers and such use the system at least sometimes. This does not mean they are the main users, or anyone is courting them, or even that the digital assets scene has a bigger problem than traditional banking. Or that it does. But there is no dispute these folks are in the mix somewhere sometimes.
Certain aspects of the way digital assets work present unique challenges to service providers that want to be compliant. Here we are going to look at a few recent cases where large companies have been accused by large governments of sanctions problems. And rather than adjudicating if the companies did anything wrong we are going to explore how the "defenses" are in fact admissions about flaws in the design of these folks' systems. This is all a bit like reporting a bug in some software only to end up stuck in a long tedious circular conversation with a technology person who keeps telling you that is how the software works. "Yes, I know" you want to scream "but that is not what anyone wants it to do!"
Who Can Sanction
Many digital asset exchanges are based in offshore jurisdictions. Do the Seychelles and Palau have robust sanctions regimes and deeply inquisitive regulators? This does not really matter. What matters is whether an exchange's clients want access to the "global financial system." That "system" is shorthand for banks, asset managers, trust companies and lawyers in the United States, United Kingdom, European Union, Japan, Hong Kong and Singapore. Maybe you include Australia, Switzerland and the United Arab Emirates in there. Maybe you do not include Japan. Precise definitions vary.
There is a bit of grey around the edges depending on precisely what you want to do. For example: countries with small populations have, by definition, small local retail markets. So maybe you do not care about anywhere with under 10 or 20 or 30 million people. Maybe you do not care unless there is a large local USD bond market. Maybe you are fine with a local currency that is not widely-accepted but is reliably pegged to a widely-accepted currency. Or not. Whatever. Use cases vary. But roughly speaking, you are not able to use the "system" if the USA, UK and EU try to ban you.
Obviously Iranian exchanges based in Iran have no legal reason to care about US sanctions. They are Iranian. Iranian law is their top priority. But if the users care about access to the global system all of a sudden other legal frameworks are going to matter. DPRK hackers clearly do not care about foreign legal systems in the sense that they are fine violating foreign laws to make a profit. But they also clearly care to the extent their funds can be frozen based on foreign legal processes.
None of this discussion is about right and wrong or legal and illegal. If your exchange will freeze your account, or your stablecoin issuer will seize your funds, based on a casual request from XYZ's law ministry then you care about the opinions of politicians in XYZ no matter what you say in public. This is the reality on the ground.
HTX
HTX was sanctioned by the EU and UK for activity related to violating Russian sanctions. Whether or not HTX had anything to do with sanctions violations, or knew anything about them, or had any obligations to comply with EU and UK sanctions in the first place: this is a problem for HTX.
The UK sanctioned a Panamanian entity linked to HTX. Think about that. Most people think of HTX as "Chinese." It was at one time registered in the Seychelles . None of those places is part of the EU, UK or Russia for that matter. And few believe the EU or UK can or should be able to dictate what a Panamanian company does with Panamanians. The issue is that there are not so many Panamanians but there are a lot of EU- and UK-based folks HTX wants to deal with. Including banks and parts of the global financial system.
This presents a problem for HTX because it did not choose Panama and the Seychelles because it cares about their local markets. Those local markets are rounding errors. They were chosen because their general frameworks have few rules and leave it up to you to operate elsewhere in line with the rules elsewhere. Perhaps the best example of this is The Bahamas approach to offshore banking. There is a class of non-resident bank license which allows dealing only with non-residents. No cash machines. No local banking. No access to the local currency markets. You can have bank in your name and you can "bank" foreigners but you have essentially nothing to do with the local financial system. If you go look at the list in that link this status includes Royal Bank of Canada, UBS, Santander and other large banks that have a massive retail presence elsewhere. This type of license tells you nothing about whether the bank is doing a good or bad job. It only tells you the bank is happy to operate some businesses under this type of license.
Offshore finance is not inherently good or bad or well-run or poorly-run. But it is lightly supervised and generally has only limited local access. This means reputation in larger banking centers matters a lot. When you have a massive head office in a banking center you can likely expect the regulators there to help you out in times of trouble. In our favourite example of this, the Swiss government intervened to help UBS when it was caught in a gigantic US tax problem nearly 20 years ago. Having a supportive home regulator is helpful. Or, in the words of the Swiss parliament's official report:
Such a massive financial intervention by the Confederation for the benefit of a private enterprise as is constituted by the first measure, is of extreme momentousness for Switzerland.
At the WEF, which took place in late January 2009, the Head of the FDF [Switzerland's Finance Ministry] tried to persuade the American President’s personal adviser to accept a solution in mutual respect for both legal systems.
The Head of the FDF again explained the gist of the letter to the [USA] Attorney General and succeeded in having the deadline for data disclosure extended. An attempt on the part of the President of the Confederation [Switzerland's head of state] to reach the American President at this time is said to have failed.
If your finance minister is able to get another country's law minister on the phone, but your head of state cannot get their head of state on the phone, it is obvious what that means. You are being told no as nicely as possible. But UBS got the maximum amount of home regulator support it could ever have expected.
Now reread those quotes but imagine the country trying to help is tiny and instead of taxes the underlying problem is related to a large ongoing military conflict. And if you are based offshore and a large banking center accuses you of being complicit in sanctions violations which support that larger center's opponent in an ongoing military conflict? You are not likely to get whatever the equivalent of the President of the Confederation is "to reach the American President" or for your contacts at the local regulator to successfully convince the banking center's head of state's advisors of the merits of your position. Light touch regulation generally means light support. That is the deal. They are not supervising you very much so why should they expend credibility on your account?
Binance
This is one is heavier. The EU and UK have substantial Russia sanctions regimes related to EU and UK support for Ukraine in the ongoing Russia-Ukraine conflict. But Binance was gratuitously included in US court paperwork connected to Iran sanctions violations . The US is currently directly engaged in hostilities with Iran. And the allegations directly concern, per US government public statements, activities:
intended to finance the Government of Iran and Iranian military components, including Iran’s Islamic Revolutionary Guard Corps (“IRGC”), a designated terrorist organization.
We say "gratuitously" because the papers at issue here are about asset seizure and do not require any mention of Binance to make their point. The allegations are straightforward:
Two Chinese companies, Blessed Trust and Hexa Whale, used trading accounts at the UAE-based cryptocurrency exchange Binance to launder the proceeds of black-market sales of Iranian oil, funneling the illicit funds to the Government of Iran, its agents, and/or its proxies, where they were used to finance terrorist and other activities of the Iranian government.
This could simply have said "Exchange-1" or left out the "cryptocurrency exchange" bit entirely. The claim is these companies laundered funds and the government wants to seize those funds. The only way to read this is the US government wanted to put "Binance" and "finance terrorist and other activities of the Iranian government" in the same sentence. Notice also the somewhat-gratuitous use of "Chinese." These are Hong Kong-based companies. And, again, where they are based is irrelevant to the underlying allegations. Nobody is complaining they violated the local rules.
This is all compounded by the documents elsewhere using the codenames "entity A" and "U.S. bank." Sometimes the use of these codename is funny. There was a famous document years ago that referred to Trump as "Individual-1." We have made fun of these code names before. Sometimes it is clear the authorities wanted everyone to know who they are talking about but for some reason are not able to name them publicly. We specifically wrote about issues at Gemini where the government referred to “Gemini Principal-1” and “Gemini Principal-2.” Gemini is, famously, run by the Winklevoss twins. Those codenames were clearly intended to let everyone know the twins were the people involved.
But here the government named Binance. This is the latest salvo in a long-running dispute between the two sides. Binance has consistently denied wrongdoing. And in this case the US government's claims seem to amount to, at most, willful blindness or negligence or just a generally deficient compliance framework. Here we will refer to our own remarks quoted in the New York Times about Binance processing of funds straight out of the ByBit hack:
Even a bad — maybe even defective — screening tool would spot that.
To be 100% clear: the alleged Iranian transactions are more complex than the ByBit laundering out of THORChain to which that quote refers. The Iranian transactions were not wildly more complex. But there were more hops and the sizes less egregious.
The US government has not sanctioned Binance here. And it has not taken any direct legal action against Binance in relation to these transactions. But the gratuitous naming of the exchange is already a black mark when it comes to accessing financial services. It is obvious you do not want your company name in the same sentence as "terrorist" and that being so named raises your perceived risk everywhere.
Notably, the US refers to Binance as UAE-based. Binance has a history of wandering around the world and yes it is currently based in the UAE. The UAE is a part of the ongoing US-Iran conflict that underlies the conduct and seizure claims at issue here. The conflict is complex and we are not writing about politics here. But it is simply a fact Iran fired missiles at the UAE, the UAE's airports were closed at various times during the conflict and the UAE has closed its embassy in Tehran.
There was absolutely no reason to include the location of Binance's HQ in the DOJ press release except to send a message. The court documents do not even mention the UAE. And there is obviously some limit to the perceived support of Iranian activities the UAE will tolerate by a licensed entity while the country is dealing with incoming Iranian fire. We are not suggesting what is alleged is anywhere near that limit (or not–this is a column not an intelligence briefing). But we also do not think the US has played all of its cards yet. Or that this saga is over.
If we had to guess there are non-public discussions concerning these issues and the naming of Binance was part of those negotiations. Or, to borrow what seems an appropriate phrase given the proximity of the activities discussed in this column to ongoing military conflicts, maybe this is just battlefield preparation.
Permissionless Strict Liability
Sanctions rules, almost universally, are structured as "strict liability." This means you are liable for transacting with an outlaw actor whether or not you knew who they were. And whether or not you tried to avoid dealing with them.
In practice every sanctions regime considers the reasonableness of your procedures and checks and so on. The more bad volume you do: it's worse. The better your procedures: it's better. If a bank you transact with takes active measures to conceal the identity of their customer: their problem and not yours. That is the deal everywhere.
Permissionless systems complicate this calculation. If you accept money from known entities and you can see the addresses their money came from but you cannot tell who owns those addresses what are you supposed to do?
This is fundamentally different than permissioned systems like traditional finance. Every bank on every transfer network has a known identity. This does not mean every time a bank receives a transfer it knows who owned every account involved anywhere in that transfer. But it knows who it can ask and who is responsible. This is not how blockchain tracing works. When tracing back through a DEX sometimes the honest situation is "we do not know who owns this and we have nobody to ask." Requiring 100% knowledge all the time is requiring a permissioned system. That works but defeats the purpose of all this machinery. So what are we do to?
In the end what is going to matter is how solid your procedures look, how many times someone bad sneaks through, and how much your regulator backs you up. If you do not have a home regulator, or operate within a regime like the Bahamian one described above that is explicitly very-light-touch. then the third leg provides no support. This matters.
Lessons
Both HTX and Binance have the same two basic weakness here. One: they do not hold licenses essential to their businesses in the jurisdictions where they need them. There are license gaps. And two: their businesses are too close to actors that are considered radioactive in the jurisdictions where those gaps lie.
If you have a license and make a reasonable effort to comply with the terms: the regulator issuing that license will usually back you up. The Swiss did not support UBS because they thought UBS was perfect. UBS was, and is, a gigantic bank with operations all over the world. Given the size it cannot possibly be perfect. But the Swiss wanted to support their banks, defend the reasonableness of their licensing and supervision regimes, and prevent damage to UBS which, given the size, would inevitably result in damage to Switzerland as a whole.
The countries where Binance and HTX are based have a lot less at stake on those fronts. The "S" in UBS stands for Switzerland. Solid banks and safe asset management are core parts of the Swiss economy. Yes the UAE and Panama are meaningful offshore financial services centers. But finance in Switzerland is oil in the UAE and the canal in Panama. They care, but finance is not core to the national identity or structure of the entire place like it is in Switzerland. Binance only moved to the UAE recently. Panama does not feel any great affinity for HTX entities. Would it be marginally bad for the "home" jurisdictions here? Maybe. Maybe the result is enforcement makes them look good. Who knows. Either way it is not a big deal.
There is no way either of these companies is as systemically, or reputationally, important as UBS in Switzerland. And by operating without the shield of licenses these companies have more risk in the extreme. Sure, by not having licenses and much active supervision there is far less chance of consequences for "minor" problems. All the risk sits way out there at the extremes of the distribution. And it sure looks like we are going to find out soon how that goes.