A DeFi protocol's smart contract autonomously routes a stablecoin payment to a wallet address that — unknown to the protocol team — belongs to an entity on the OFAC SDN list. Here's the financial and legal aftermath.
A DeFi lending protocol builds a smart contract that automatically distributes yield to liquidity providers. One provider's wallet address was added to the SDN list 3 months ago, but the protocol's screening — which only checked wallets at onboarding — hasn't caught it. Over 6 months, $47,000 in yield is routed to the sanctioned wallet via 14 separate transactions.
A blockchain analytics firm flags the wallet in a routine compliance report to the protocol's banking partner. The bank freezes the protocol's fiat off-ramp account and files a suspicious activity report. The protocol team learns about the issue from their bank, not from their own monitoring.
| Factor | Impact on penalty |
|---|---|
| Base penalty (14 violations × statutory max) | $5.15M (statutory maximum) |
| No voluntary self-disclosure | +0% (base penalty stands) |
| Weak compliance program (screening only at onboarding) | +20% aggravating factor |
| Cooperation after discovery | -10% mitigating factor |
| No prior OFAC history | -10% mitigating factor |
| Final penalty | ~$250,000 – $500,000 (negotiated settlement) |
Continuous screening, not onboarding-only. The SDN list updates daily. A wallet that was clean at onboarding can be sanctioned tomorrow. Agentmail's API screens every transaction in real time — not just at onboarding — catching newly-sanctioned wallets before funds are routed.
Real-time OFAC screening for every agent transaction.
Get started →