洞察

analysis / market analysis

OFAC制裁Iran BitBank:Exchange Sanctions Risk为什么不只是Wallet Screening

OFAC于9月17日制裁Iran Crypto Exchange BitBank。美国财政部称其在2026年6--7月促成数亿美元Bitcoin流向IRGC。案例说明Exchange Sanctions Risk必须同时检查Ownership、Developer、Counterparty与Wallet。

发布于 2026-09-18更新于 2026-09-18约 6 分钟

美国财政部OFAC于9月17日把Iran Crypto Exchange BitBank列入制裁。

同时被Designate的还有BitBank Software Developer Pishtaz Simorgh Electronic Trade Company,以及多名与被制裁Iranian Financier Babak Zanjani有关的Individual。

美国财政部称,BitBank在2026年6--7月被用于促成数亿美元Bitcoin转移至Iran's Islamic Revolutionary Guard Corps。

Treasury还称,一个此前已经被OFAC Designate的Maritime Authority使用BitBank转移收到的Payment。

这些属于美国政府在Sanctions Action中的指控与认定,并不是CEXVia独立司法结论。

但这个Case非常适合建立Exchange Sanctions Risk Framework。

Exchange Risk不只是Wallet Address

Crypto Compliance通常从Blockchain Analytics开始。

检查Wallet是否和Sanctioned Entity、Darknet、Hack Address产生Exposure。

这很重要,但不完整。

BitBank案例显示Sanctions Exposure可能同时存在于:

Beneficial Owner、Executive、Software Developer、Affiliate、Counterparty、Payment Flow、State-linked Entity和Wallet Address。

所以:

Entity Intelligence必须和Transaction Monitoring一起做。

Software Provider也可能进入Sanctions Perimeter

OFAC不只Designate BitBank。

还Designate它的Software Developer Pishtaz Simorgh。

Crypto Exchange依赖大量Modular Infrastructure:

Wallet、Matching Engine、Custody、Payment Provider、Liquidity Partner和Software Vendor。

如果关键Vendor本身属于Sanctioned Network,即使Counterparty没有直接和Headline Exchange互动,也可能产生Risk。

Vendor Due Diligence因此也是Sanctions Compliance。

50 Percent Rule让Ownership Mapping非常重要

OFAC Rule并不是"只查名单上的名字"。

如果一个Entity被一个或多个Blocked Person直接或间接持有合计50%以上,它通常也会被视为Blocked,即使名字没有单独出现在List里。

Crypto Exchange Ownership经常跨多个Holding Company、Jurisdiction和Brand。

因此只查Front-end Brand完全不够。

Blockchain Transparency并不能自动解决Attribution

Bitcoin Transaction公开,不代表Wallet Legal Owner公开。

Attribution仍然需要Offchain Evidence、Exchange Record、Infrastructure Link和Investigation Context。

所以Onchain Analytics可以提供Risk Signal,但Legal Conclusion还需要理解这个Address为什么被归属于某个Entity。

为什么这个Case超出普通Crypto Trading?

Treasury把BitBank和Shipping / State-linked Payment联系起来。

这提醒Compliance Team:

Exchange可能成为完全不同Economic Activity的Payment Infrastructure。

不仅是Token Trading。

还可能涉及Trade Settlement、Commodity Flow、Shipping、Cross-border Payment和Capital Control。

Why it matters

Sanctions Risk正在变成Exchange Architecture问题。

过去的简单模型:

Customer是不是Sanctioned?

现在必须变成:

Customer + Wallet + Counterparty + Ownership + Vendor + Liquidity Provider + Jurisdiction + Flow Pattern。

对于跨多个国家运营、Ownership不透明的Exchange,这尤其重要。

风险与反方观点

Sanctions Designation代表制裁政府的Legal Position。

其他Jurisdiction可能采用不同Rule。

因此Treasury的指控应该明确归因给OFAC,不能写成独立司法事实。

另外不能因为"与Iran有关"就自动判定Transaction Illegal。

Risk仍然需要Entity-specific和Transaction-specific分析。

What to watch next

看OFAC是否进一步公布Wallet、Stablecoin Issuer是否Freeze相关Address、Exchange是否Delist / Restrict BitBank-linked Entity,以及Software Provider是否成为更多Sanctions Action对象。

长期最重要的Lesson是:

Exchange Verification需要Entity Graph,不只是Wallet Risk Score。

FAQ

OFAC做了什么?

9月17日Designate BitBank、其Software Developer和多名相关Individual。

Treasury声称BitBank做了什么?

Treasury称BitBank被用于促成数亿美元Bitcoin流向IRGC,并属于更广泛Sanctions-evasion Network。

这是Court判决吗?

不是。这是美国财政部发布的Sanctions Action与相关指控。

为什么Developer也被制裁?

Treasury将Pishtaz Simorgh认定为BitBank Software Developer并视为相关Corporate Network的一部分。

Compliance最重要的Lesson是什么?

除了Wallet Monitoring,还必须检查Ownership、Affiliate、Vendor和Counterparty。