News
Platform news and market context
News
Platform news and market context
New UK National Security Act Poses 14-Year Prison Risk for Crypto Firms Handling Funds from Designated Groups
A new UK law effective July 17 exposes crypto firms and UK-linked individuals to prison sentences of up to 14 years for handling value from designated entities, such as Iran's IRGC. The legislation poses unique challenges for the industry, as the irreversibility of blockchain transfers and delayed wallet attribution create significant criminal liability risks.

A new criminal liability for businesses and individuals tied to the United Kingdom came into force on July 17, following the UK's official designation of Iran's Islamic Revolutionary Guard Corps (IRGC). This action creates a significant criminal exposure for any UK-linked person or business that either receives or continues to hold value that has been supplied by or on the group's behalf.
Under the designation instrument, the IRGC was one of the first three organizations to be included in Schedule 6A of the National Security Act 2023.
New Offenses and Severe Penalties
The legislation introduces a section 17C offense, which can result in a prison sentence of up to 14 years. This applies when an individual obtains, accepts, or retains a qualifying material benefit and has knowledge—or, given other information available to them, "ought reasonably to know"—that the benefit originated from the designated body.
The law distinguishes between different actions. A conviction on indictment for the section 17C(1) offense, which involves the act of obtaining, accepting, or retaining the benefit, carries a maximum sentence of 14 years and a potential fine. A separate offense under section 17C(2), which covers agreeing to obtain, accept, or retain such a benefit, has a maximum penalty of 10 years in prison and a possible fine. While the official Home Office announcement broadly describes the regime as carrying up to 14 years, the statutory text provides this more detailed split.
It is important to note that the rules allow for judgment. An Iran-linked payment is not automatically illegal, and a Schedule 6A designation does not, on its own, trigger the asset freezes or dealing restrictions mandated by UK sanctions. The critical questions revolve around whether the value can be definitively traced to the IRGC and what the recipient knew at the time. Any freezing of stablecoins would necessitate separate action by an issuer or another legal authority.
Broad Scope Encompasses Crypto Assets
Although the law does not explicitly mention crypto assets, its language is intentionally broad to include them. It applies to "money or anything of value" that is supplied either "directly or indirectly," including through corporate entities. This wording is wide enough to bring stablecoins and other on-chain transfers under its purview.
The phrases "by or on behalf of" and "directly or indirectly" are particularly significant in a market characterized by intermediaries. A payment is not required to originate from a wallet explicitly labeled "IRGC" or from an entity using the group's name. The chain of provision can flow through companies or other intermediaries. However, the presence of an Iranian counterparty, an Iran-linked wallet, or a crypto payment alone does not prove that the IRGC supplied the benefit. A prosecution would still be required to establish both the connection to the designated body and the necessary mental element of knowledge.
Sending value to a designated body is addressed through a different legal path. Section 17B of the Act covers conduct intended to materially assist a designated body with its UK-related activities. It also applies to actions likely to provide such assistance when the person knows, or should reasonably know based on available information, that it is likely to do so. The offenses of receipt and assistance are distinct, each with its own elements, and neither imposes a blanket ban on all crypto activity related to Iran.
The Blockchain Conundrum: Attribution and Timing
For exchanges, custodians, issuers, payment businesses, or any UK user, the central operational challenge becomes wallet attribution and timing. A blockchain network can settle an incoming transfer before the recipient has any opportunity to refuse it. Furthermore, an address might only be linked to a designated body at a later date.
This creates a scenario where the crucial questions are: what was known about the wallet and counterparty, when did that information become available, and what actions were taken regarding the value afterward? Section 17C(1) extends beyond direct payments, also applying when a person secures or accepts a benefit for another party or retains a benefit that has already been received. The key legal test remains whether the benefit originated from a designated body and if the recipient knew or should reasonably have known about the connection.
The Office of Financial Sanctions Implementation’s (OFSI) cryptoassets threat assessment, which deals with sanctions rather than this new designated-body offense, acknowledges that crypto firms cannot reject incoming blockchain transactions. The assessment also points out that addresses can be attributed retrospectively and that analytics tools can uncover historical direct or indirect exposure. These observations highlight the same technical sequence that UK-linked recipients must now address. A deposit can finalize before a custodian has reliable identity information for the sending wallet, and new intelligence could later connect that address—or a cluster of related addresses—to a designated body after the transaction is complete. An initially unidentified receipt is not a crime by default; instead, the timeline of events becomes crucial evidence.
Global Reach and Corporate Governance
The law has a broad jurisdictional reach. Section 17C can apply to conduct that takes place entirely overseas if the benefit is provided in or from the UK, if the person involved is a UK person, or if a specified Crown connection is present. The definition of UK persons is extensive, covering UK nationals, individuals residing in the UK, bodies incorporated under UK law, and unincorporated associations formed under UK law.
This wide net pulls in more than just regulated trading venues. While UK-linked exchanges and custodians are the most apparent examples due to their role in receiving and holding customer assets, others are also exposed. Payment processors, OTC desks, merchants, and other businesses may facilitate or retain on-chain value. Depending on their token architecture, some stablecoin issuers have the authority to restrict the later use of tokens following an attribution. Ordinary UK-linked users who receive value are also subject to the law, contingent on the same designated-body connection and knowledge threshold.
Corporate governance can directly influence this exposure. According to section 35 of the National Security Act 2023, a corporate officer can be held liable alongside the organization if a Part 1 offense is committed with the officer's consent or connivance, or if it is attributable to the officer's neglect. While directors are not automatically responsible for every flagged wallet, the stakes for escalation ownership and documented follow-up are now considerably higher.
Distinct from Financial Sanctions
It is critical to understand that Schedule 6A and UK financial sanctions operate as different legal functions. A government factsheet clarifies that an organization listed only under sanctions is not subject to the designated-body offenses unless it is also specifically designated for those offenses.
Adding an entity to Schedule 6A does not automatically activate the asset-freeze, non-dealing, and reporting duties that financial sanctions law mandates. It also does not alter stablecoin smart contracts. An issuer-level freeze requires a separate sanctions obligation, another legal justification, or action taken under the issuer’s own internal controls.
CryptoSlate’s earlier coverage of Tether freezing 134 wallets serves as an example of this technical layer. In that case, the issuer leveraged its control over the token to freeze addresses within a sanctions context. The new question posed by UK law is different: did a person accept or retain a benefit tied to a designated body with the required knowledge, even in situations where no issuer has frozen any assets? A compliance workflow designed only for sanctions therefore has a significant gap. Firms may need to distinguish a Schedule 6A attribution alert from an OFSI asset-freeze match and then decide which legal and operational escalation procedures are appropriate. A single wallet could raise concerns under both regimes, but the presence or absence of a sanctions freeze does not resolve liability under section 17C.
Defensible Records and Compliance Adjustments
For UK-linked crypto businesses that receive, hold, transfer, or facilitate value, a practical first step may be to review how existing controls document the timeline and rationale behind every decision. The Act does not prescribe a specific crypto-focused checklist, yet the nature of the offense and official risk materials suggest close scrutiny of how a business:
- Assesses counterparty risk at the time of a transaction.
- Documents transaction and counterparty data.
- Detects, escalates, and investigates attribution alerts.
- Records the basis and confidence level for those alerts.
- Manages access to the value after an alert.
- Documents its response and the reasoning behind it.
The government's impact assessment states that the Act does not create any new reporting duties for businesses. However, it does contemplate that businesses may receive, hold, or transfer funds on behalf of a designated body and encourages the use of existing suspicious activity and consent processes. Applying this same logic to crypto extends beyond what the law explicitly mandates.
UK cryptoasset exchanges and custodian wallet providers already function within an FCA anti-money laundering framework that requires proportionate transaction monitoring and internal escalation. Schedule 6A now introduces a separate stream of potential criminal exposure based on facts that these systems may uncover.
Statutory protections exist, such as for the reasonable consideration of goods or services (provided doing so is not an offense), reasonable excuses for retention, qualifying legal obligations, public functions, and certain humanitarian activities. However, their application is fact-specific and they do not provide a generic safe harbor for due diligence, unsolicited transfers, or network-level irreversibility. Filing a suspicious activity report or requesting consent through an existing process might be part of an escalation, but official guidance does not present either as an automatic defense against a section 17C charge. The analysis will always be tied to the benefit, its link to the IRGC, the facts known to the individual, and the subsequent actions taken.
Conclusion: The Evidentiary Challenge
Recipients are generally unable to reject or reverse an incoming blockchain transfer at the network level, although account-level or issuer-level controls may later restrict its use. The initial test of this designation in the crypto space will therefore focus on whether UK-linked recipients and intermediaries can construct a defensible record of attribution and knowledge as wallet intelligence evolves.
Effective July 17, the speed of a blockchain transaction, which settles in seconds, now contrasts sharply with the potential for a multi-year prison sentence based on an evidentiary timeline that firms must be prepared to defend.
Discussion about this post
No comment yet
Be the first to share your opinion!