This case of BitGo exposes how a U.S.âanchored digitalâasset platform, despite its technical capacity to track user locations, deliberately underâinvested in sanctionsâcompliance infrastructure, allowing sanctionedâjurisdiction actors to exploit Americanâlinked infrastructure for unmonitored crypto flows and thereby eroding the integrity of the U.S. financialâcontrol regime.
BitGo, a U.S.âbased digitalâasset wallet provider headquartered in Palo Alto, California, faced an enforcement action by the U.S. Department of the Treasuryâs Office of Foreign Assets Control (OFAC) for sanctionsâcompliance failures related to its nonâcustodial âhot walletâ service. Between approximately March 2015 and December 2019, BitGo processed 183 digitalâcurrency transactions for users whose IP addresses placed them in comprehensively sanctioned jurisdictionsâCrimea (Ukraine region), Cuba, Iran, Sudan, and Syriaâdespite having access to those IP data for security and login purposes. The company initially allowed account creation with only a name and email address, later adding a selfâreported country field without independently verifying location or implementing IPâbased geoâblocking or sanctionsâlist screening. As a result, BitGo enabled users in blocked jurisdictions to route virtual currency over U.S.âconnected infrastructure, effectively circumventing U.S. sanctions by failing to apply its own technical capabilities for compliance. OFAC characterized the case as nonâegregious, assessed a civil settlement of $98,830 for the 183 âapparent violations,â and required BitGo to adopt a formal OFAC Sanctions Compliance Policy, designate a sanctionsâcompliance officer, and implement IPâaddress blocking and sanctionsâlist screening. The case underscores how weak geolocation and sanctionsâcontrols on a U.S.âbased cryptoâwallet platform can create systemic vulnerabilities for sanctionsâevasion and potential moneyâlaundering, even when the underlying transaction values are small.