IRGC Designation Exposes UK Crypto Firms to 14-Year Prison Risk
The UK’s IRGC designation activates a new criminal offense under the National Security Act, putting crypto exchanges and custodians at risk of 14-year sentences.
The UK’s formal designation of Iran’s Islamic Revolutionary Guard Corps took effect July 17, 2026, activating a new criminal offense under the National Security (State Threats) Act 2026 that exposes any UK-linked person or business receiving IRGC-connected value to up to 14 years in prison – and because blockchain transactions settle before wallet attribution can be confirmed, exchanges, custodians, and payment processors now carry timing risk they cannot fully control at the point of receipt.
Section 17C: What the Offense Actually Requires
The IRGC became one of the first three bodies added to Schedule 6A of the National Security Act 2023 under a new designation instrument, according to the UK statutory instrument published July 17. The new section 17C(1) offense applies when a person obtains, accepts, or retains a qualifying material benefit and knows – or in light of other matters known to them ought reasonably to know – that the benefit came from the designated body. The maximum sentence on conviction on indictment is 14 years and a possible fine.

A related offense under section 17C(2) – agreeing to obtain, accept, or retain the benefit – carries a lower ceiling of 10 years. Separately, section 17B covers conduct intended to materially assist a designated body in carrying out UK-related activities, including conduct that is merely likely to provide that assistance when the person knows or ought reasonably to know of that likelihood. Receipt and assistance are distinct offenses with distinct elements.
The law never explicitly mentions crypto assets, but its wording is broad enough to capture them. It covers money or anything of value supplied directly or indirectly, including through companies – language that pulls stablecoins and other on-chain transfers within scope. The words by or on behalf of and directly or indirectly are operationally significant in a market built around intermediaries, where the chain of provision can run through multiple entities before reaching a UK-registered exchange or custodian.
The law preserves some defenses. A financial benefit is excluded when it represents reasonable consideration for goods or services, provided delivering those goods or services is not itself an offense. Separate provisions cover qualifying legal obligations, public functions, and humanitarian activity conducted consistently with internationally recognized standards. Their application is fact-specific and will require legal review case by case.
On-Chain Settlement Makes Timing the Hard Compliance Problem
The structural difficulty here is mechanical, not procedural. A blockchain network settles an incoming transfer before a custodian can refuse it, and a wallet address may be linked to a designated body only after the transaction achieves finality. An initially unidentified receipt is not automatically criminal – but the timeline of what was known, and when, becomes potentially decisive evidence in any prosecution.
The Office of Financial Sanctions Implementation cryptoassets threat assessment, which addresses sanctions rather than the new designated-body offense, noted that crypto firms cannot reject incoming blockchain transactions and that addresses may be attributed only after settlement – with analytics capable of identifying historical direct or indirect exposure after the fact. That observation describes the identical technical sequence that UK-linked recipients now need to manage under section 17C.

According to the CryptoSlate analysis of the designation instrument, a defensible compliance record may need to document the transaction timestamp, wallet risk data available at that moment, counterparty information, when an attribution alert first emerged, the basis and confidence level of that alert, whether the value remained accessible, and what action was taken after escalation. Receipt and retention can also occur at different legal points: network finality may prevent unwinding the original transfer, while account-level or token-level controls can still affect what happens to the value afterward.
An Iranian counterparty, an Iran-linked wallet, or a crypto payment alone does not establish that the IRGC supplied the benefit – the prosecution still needs the designated-body nexus and the required mental element. But the evidentiary burden of demonstrating that nexus does not exist, or that the recipient lacked the requisite knowledge, now sits with firms operating in real time against attribution data that is inherently retrospective. That asymmetry is the compliance exposure.
Who Is Actually in Scope
Section 17C’s geographic reach extends beyond conduct on UK soil. It applies when the benefit is provided in or from the UK, when the actor is a UK person, or when a specified Crown connection exists. UK persons include UK nationals, individuals resident in the UK, bodies incorporated under UK law, and unincorporated associations formed under UK law. That definition brings the exposure well beyond regulated trading venues.
UK-linked exchanges and custodians face the clearest exposure because they receive and hold customer assets at scale. Payment processors, OTC desks, merchants, and other businesses that facilitate or retain on-chain value also fall within the review population. Some stablecoin issuers – depending on token architecture and legal authority – retain the ability to restrict token use after an attribution is confirmed, which may affect their obligation calculus. Ordinary UK-linked users who receive value are subject to the same designated-body nexus and knowledge threshold, though the enforcement priority will clearly lie with institutional actors.

The government’s impact assessment states the Act creates no new business reporting duty. It nevertheless considers businesses that receive, hold, or transfer funds on behalf of a designated body, and encourages use of existing suspicious-activity and consent processes. The designation does not itself trigger asset freezes or dealing restrictions under UK sanctions – that would require separate action from a stablecoin issuer or another legal authority. But a single Iran-linked crypto flow can now sit at the intersection of financial-sanctions exposure and a state-threats offense simultaneously, depending on the facts and counterparties involved.
What Comes Next for Crypto Compliance Frameworks
As additional foreign-state proxies are designated under Schedule 6A, the same receipt-of-benefit exposure can extend beyond Iran to other designated bodies. Each new designation would require UK-linked firms to consider whether prior transactions involved relevant benefits and what was known at the time. The regulatory pressure on wallet providers is intensifying across multiple jurisdictions – a dynamic already visible in the security and compliance demands now confronting firms handling wallet-level access at scale.
The government’s impact assessment also signals future guidance updates for financial services and potential alignment with EU and US state-actor sanctions typologies. For compliance teams, the immediate operational priority is establishing what wallet risk data was available at each transaction timestamp – and ensuring that post-attribution escalation procedures are documented well enough to support the argument that the knowledge threshold under section 17C was not met at the time of receipt. The law does not require perfection; it requires a demonstrable, reasoned response to information as it became known.
Follow CoinNews on X and Telegram for ongoing regulatory and market updates.