Blog
9 min readPublished July 25, 2026

OFAC’s New Zanjani Sanctions Show Wallet Risk Is Moving Into Infrastructure

Treasury’s July 24 action against Babak Zanjani’s network links digital asset exchanges, wallet services, gold-backed tokens, and settlement rails into one sanctions-risk map.

Stablecoins & Freezeable Assets
Sanctions & Wallet Screening
Monitoring
#wallet-risk
#tokenized-gold
#OFAC
#TRON
#tokenization
#USDT
#sanctions-screening
#Iran
OFAC’s New Zanjani Sanctions Show Wallet Risk Is Moving Into Infrastructure

On July 24, 2026, the U.S. Treasury’s Office of Foreign Assets Control added another layer to the Babak Zanjani sanctions story. This was not a simple name-and-shame update, and it was not just another Iran sanctions release. OFAC designated four individuals and nine entities that Treasury says supported Zanjani’s broader network across financial services, gold and diamond businesses, digital asset trading, transportation, and infrastructure projects.

For crypto risk teams, the important part is the shape of the network. Treasury’s release ties the new designations to Zedcex and Zedxion, the digital asset exchanges OFAC designated earlier in 2026. It also describes supporting companies in Turkey and the UAE, a digital wallet and transfer-services provider, exchange wallet support, NFT promotion, a diamond token, and Tala Token, an allegedly gold-backed digital asset linked to DotOne Gold Company.

That is exactly why this story matters to FreezeRadar readers. Sanctions exposure is no longer only about whether a wallet appears on a government list today. It is about whether a wallet, issuer-controlled token, exchange account, OTC desk, bridge route, or treasury counterparty is sitting near infrastructure that can become blocked property overnight.

What OFAC Actually Did on July 24

Treasury said the July 24 action targeted components of Zanjani’s post-prison commercial network. The release described Dot One Value Creation Group as a holding company involved in logistics, telecommunications, aviation, transportation, and digital assets. It also named DotOne Gold Company, which Treasury connected to Tala Token, an allegedly gold-backed token that reportedly passed through Zedcex infrastructure in early 2025.

OFAC also moved against entities that allegedly supported Zedcex and Zedxion outside Iran. Zedpay, based in Istanbul, was described as a financial technology company providing digital wallet and global transfer services and as being integrated into Zedxion’s platform. Zedx DMCC, based in Dubai, was described as acting on behalf of Zedcex, including with respect to exchange wallets. BZ Diamond, another Dubai entity, was described as supporting Zedxion projects through NFT marketplace promotion, a diamond token, and transactions with Zedxion and Zedcex wallets.

This matters because the action expands the perimeter from the exchange brand to the service layer around it. The January action put Zedcex and Zedxion on the sanctions map. The July action says the supporting rails also matter: wallet services, fiat settlement, commodity-linked token operations, related executives, and commercial wrappers that can make a sanctioned exchange look like a normal regional payments or real-world-asset business.

In practical terms, OFAC is not only asking the market to avoid a named exchange. It is showing that a compliance problem can sit inside an ecosystem of vendors, affiliated companies, token issuers, wallet infrastructure, and liquidity routes.

Why This Is an Infrastructure Story, Not Just an Exchange Story

The January 2026 designations were already a warning. Chainalysis described that action as OFAC’s first designation of digital asset exchanges specifically for operating in Iran’s financial sector, with Zedcex and Zedxion tied to IRGC activity. TRM Labs framed the same case as a shift toward infrastructure-level sanctions enforcement, noting that Treasury also identified high-volume wallet infrastructure associated with the exchanges.

The July action makes that warning more concrete. Treasury is now describing a network where digital asset trading is interlaced with business services that look adjacent rather than central. A payments company can provide wallet and transfer functionality. A Dubai entity can support exchange wallets. A gold company can stand behind a tokenized asset. A diamond dealer can promote a token or NFT marketplace while also touching exchange wallets.

For a wallet-risk team, that is the hard part. The risk can enter through a counterparty that is not obviously a sanctioned exchange in the user interface. It may appear as a tokenized commodity project, a payment service, a regional liquidity provider, or an exchange account used by a customer or supplier. The on-chain wallet may not yet be on a sanctions list, but the surrounding infrastructure can carry enough exposure to justify escalation.

This is also why direct list screening is necessary but incomplete. The question is not only “is this exact address sanctioned?” The better question is: “What infrastructure does this address rely on, and who controls or benefits from that infrastructure?”

The Stablecoin Angle: Clearing Rails Are the Real Prize

Earlier analysis of the Zedcex and Zedxion ecosystem repeatedly pointed to stablecoins, especially USDT on TRON, as the operational rail. TRM described Zedcex-linked infrastructure as functioning less like a normal retail exchange and more like a stablecoin clearing hub embedded in a sanctions-evasion network. Chainalysis noted that the January action included Tron addresses associated with Zedcex.

That does not make USDT or TRON uniquely problematic. It does explain why sanctioned networks gravitate toward the same features that legitimate operators like: deep liquidity, low fees, quick settlement, broad broker acceptance, and easy operational reuse. The operational risk is not that a stablecoin exists. The risk is that a controlled network can repeatedly use stablecoin liquidity as a settlement layer while presenting different faces to the market.

For treasury teams, this creates a more demanding monitoring problem. You may never knowingly trade with a sanctioned exchange. But a customer wallet may be funded through an intermediary that touches its infrastructure. A liquidity provider may source inventory from a broker with indirect exposure. A payment processor may route through a wallet service that is later designated. A tokenized-asset issuer may rely on commodity custody or settlement counterparties that become part of a sanctions action.

Freezeable assets intensify the consequence. When exposure lands in USDT, USDC, PAXG, XAUt, or another issuer-controlled asset, the question is not only whether law enforcement can trace it. It is whether an issuer, exchange, custodian, or compliance desk can restrict movement once a legal or sanctions trigger is clear enough.

Tokenized Gold Is No Longer a Side Detail

Gold-vault shelves inside the U.S. Bullion Depository at Fort Knox

Image: “Gold Vault, U. S. Depository, Fort Knox, Ky” from Wikimedia Commons, public domain in the United States due to publication without copyright notice. Used here as editorial context for gold custody and tokenized-commodity risk, not as a depiction of DotOne Gold or Tala Token.

The most distinctive part of the July release is the commodity-token angle. Treasury connected DotOne Gold Company to Tala Token, an allegedly gold-backed digital asset. It also named BZ Diamond’s support for Zedxion digital asset projects, including a diamond token and NFT marketplace activity.

That matters because tokenized real-world assets are often marketed with a different emotional pitch than stablecoins. Gold-backed tokens are presented as conservative, collateralized, physical, and treasury-friendly. But the operational reality is harsher: a tokenized asset inherits the risk of the issuer, the custodian, the reserve asset, the corporate owner, the redemption path, and the wallets through which the token moves.

If a gold-backed token is tied to a sanctioned network, the problem is not solved by pointing to the gold. The reserve asset may be real and still be controlled by a blocked person, routed through sanctioned infrastructure, or dependent on a redemption process that compliant institutions cannot touch. The token can be technically transferable while economically impaired. It can also become toxic collateral for counterparties that accepted it without understanding the issuer-control layer.

This is directly relevant to FreezeRadar’s coverage of PAXG freeze risk, XAUt wallet risk, and issuer-controlled assets. The lesson is not that all tokenized gold is suspect. The lesson is that reserve-backed tokens require entity due diligence and wallet monitoring at the same time. Custody, redemption, sanctions status, wallet provenance, and downstream liquidity are one risk system.

Why List-Based Screening Misses the Middle of the Network

Crystal Intelligence’s separate work on Iran-linked wallets makes the operational lesson sharper. Its analysis argued that static list checks can miss wallets that process institutional-scale volumes from mostly uncategorized origins and then route funds systematically to high-risk infrastructure, Iranian VASPs, bridges, Tether-blacklisted wallets, and non-KYC exchanges.

This is the gap most teams underestimate. A wallet can look clean at intake because it has no direct sanctions hit. It can become risky after two more questions: where did the funds come from, and where did the wallet repeatedly send value? In infrastructure cases, behavior often matters before attribution is complete.

A defensible monitoring program should therefore separate three layers:

  1. Direct sanctions and blacklist status.
  2. Infrastructure proximity, including exchange-attributed wallets, payment services, bridges, OTC desks, and issuer-controlled token contracts.
  3. Behavioral indicators, including concentrated volume, short holding windows, repeated routing to high-risk services, cross-chain path breaks, and exposure to known sanctions-evasion clusters.

The Zanjani action touches all three. Treasury named people and entities. Earlier actions and analytics reporting identified exchange wallet infrastructure. Related on-chain analysis showed patterns that ordinary one-hop list checks would miss.

What Wallet, Treasury, and Compliance Teams Should Do Next

First, update counterparty review files when an action expands beyond a named exchange. If your team only added Zedcex and Zedxion in January, the July action means you should also review named supporting entities, executives, payment-service relationships, and commodity-token links.

Second, screen flows around stablecoin inventory rather than only the wallet you control. A receiving wallet can be clean while its inbound source has exposure to sanctioned exchange infrastructure. This is where two-hop exposure analysis and upstream provenance checks become operationally useful rather than academic.

Third, treat tokenized commodities as issuer-controlled assets, not as neutral “gold on-chain.” Reserve claims do not remove sanctions, ownership, custody, or redemption risk. A token can represent a physical asset and still depend on a blocked or high-risk control plane.

Fourth, document escalation thresholds before a crisis. If a wallet has indirect exposure to a newly designated exchange wallet, does treasury pause acceptance? Does compliance request source-of-funds documentation? Does the business move to enhanced monitoring? Does legal review the relationship? These decisions should not be improvised after funds arrive.

Finally, avoid overcorrecting. Not every wallet that touched a regional exchange or bridge is part of a sanctions-evasion network. The right response is not blanket panic; it is better evidence. Combine official list checks, issuer-blacklist intelligence, entity attribution, transaction behavior, and asset-control knowledge into one review.

Key Takeaway

OFAC’s July 24 Zanjani action is important because it shows the next shape of crypto sanctions risk. The target is no longer only the wallet address or the exchange homepage. It is the operating system around the exchange: wallet providers, settlement channels, tokenized commodity issuers, NFT and token promotion, executives, offshore entities, and commercial ventures that keep liquidity moving.

For FreezeRadar users, the practical lesson is simple: wallet risk is becoming infrastructure risk. If your monitoring stops at direct sanctions hits, you will see the cleanest part of the picture and miss the machinery behind it. The next generation of stablecoin and tokenized-asset risk work has to ask who controls the rails, which wallets act as clearing points, and how quickly issuer-controlled assets could become restricted if that infrastructure is designated.