Skip to main content

Sanctions Oracle

The RedStone Sanctions Oracle keeps sanctioned wallets out of your protocol. It publishes a screened list of designated addresses onchain, so any smart contract can check a counterparty with a single read call and refuse the transaction if the address is listed.

The list is maintained on a fixed schedule, aggregated from hundreds of official sources, and readable by anyone onchain.


Why Onchain Sanctions Screening​

Every institution moving value on public blockchains carries a sanctions obligation. OFAC rules apply to every person linked with the US and digital-asset transactions touching the US financial system, and the GENIUS Act requires permitted stablecoin issuers to maintain sanctions-screening and freezing capability. In the EU, the Transfer of Funds Regulation and EBA guidelines require CASPs to screen transfers against EU sanctions lists, with the AML Regulation adding supervision from 2027.

Regulators increasingly expect that control to sit inside the transaction itself, rather than in an offchain review that happens after settlement. A sanctions oracle makes this possible. Because the list lives onchain, a contract can screen a counterparty at execution time, the check is free to query, and because onchain state is preserved at every block, you can show exactly what the list contained when any transaction went through.


Background: The Chainalysis Sanctions Oracle​

Chainalysis launched the first free sanctions oracle in March 2022, and it was widely integrated across the industry. The list, however, was never updated frequently: ChainArgos found a May 2024 designation still missing 66 days later. Additionally, updates were controlled by a single externally owned account (one private key).

The last update to that contract (0x40C57923924B5c5c5455c48D93317139ADDaC8fb) was on 18 March 2026; the previous one was on 22 September 2025. In our review in September 2026, we found at least six wallets added to the OFAC sanctions list in the 20 May 2026 update that were not covered by the oracle at the time:

  • 0x038989cBB1710C72b9920Dc4Fa529158f463e72c
  • 0x14779CEC0B117d5194c750C55Ea1f42086631964
  • 0x32dA24Ca413F3E7B53145D4737e172C3bdF81e3e
  • 0xF2235D55b2950a0B1317469d72d07Ae65b2e27CB
  • 0x4F428c11Dc82388fa5136D636e613ad923Eb700B
  • 0xaC4cC4B68ea24BbFAAC8fD127B67Ed445ACcCE22

The RedStone Sanctions Oracle uses the same interface, so migrating is a one-line change. See Integration below.


How It Works​

Multi-sourced list. The oracle aggregates 463 official sanctions lists and regulator feeds through OpenSanctions, including OFAC, the EU, the UK, the UN, and others. No single entity decides who is listed.

Weekly update cadence. A reviewed batch of designations is published every week. The time of the last update is recorded onchain, which lets you define a staleness limit in your compliance policy and enforce it in code.

Cold wallet and multisig security. Every list update is signed from cold storage. Any change to the contract itself requires approval from a geographically distributed multisig, so no single key can alter the code.


Integration​

The oracle exposes the same isSanctioned(address) function as the Chainalysis contract. If you already integrate with Chainalysis, replace the contract address, and no other code changes are needed.

Contract address​

NetworkAddress
Ethereum Mainnet0x574Ad490fE8087B580DB227a8Ca7EfB7C19Dc8C4

Interface​

interface ISanctionsList {
function isSanctioned(address addr) external view returns (bool);
}

Example: blocking sanctioned addresses​

// SPDX-License-Identifier: MIT
pragma solidity ^0.8.20;

interface ISanctionsList {
function isSanctioned(address addr) external view returns (bool);
}

contract MyProtocol {
ISanctionsList public constant SANCTIONS_LIST =
ISanctionsList(0x574Ad490fE8087B580DB227a8Ca7EfB7C19Dc8C4);

error SanctionedAddress(address account);

modifier notSanctioned(address account) {
if (SANCTIONS_LIST.isSanctioned(account)) revert SanctionedAddress(account);
_;
}

function deposit(uint256 amount) external notSanctioned(msg.sender) {
// ...
}
}
warning

msg.sender only identifies the immediate caller, which may be a router or another smart contract rather than the end user. If your protocol needs to screen the actual beneficiary or depositor, pass that address to isSanctioned explicitly.

Additional functions​

Beyond the Chainalysis-compatible isSanctioned, the oracle exposes a batch check and the timestamp of the last list update:

interface IRedStoneSanctionsList {
function isSanctioned(address addr) external view returns (bool);
function areSanctioned(address[] calldata addrs) external view returns (bool[] memory);
function getLastUpdateBlockTimestamp() external view returns (uint256);
}

getLastUpdateBlockTimestamp() lets you enforce a staleness limit in code, so your contract stops accepting transactions if the list hasn't been updated within the window your compliance policy allows. Using the example above, with SANCTIONS_LIST declared as IRedStoneSanctionsList:

uint256 public constant MAX_LIST_AGE = 8 days;

error StaleSanctionsList(uint256 lastUpdate);

modifier notSanctioned(address account) {
uint256 lastUpdate = SANCTIONS_LIST.getLastUpdateBlockTimestamp();
if (block.timestamp - lastUpdate > MAX_LIST_AGE) revert StaleSanctionsList(lastUpdate);
if (SANCTIONS_LIST.isSanctioned(account)) revert SanctionedAddress(account);
_;
}

Migrating from Chainalysis​

If you followed the Chainalysis integration example, swap the address constant:

- address constant SANCTIONS_CONTRACT = 0x40C57923924B5c5c5455c48D93317139ADDaC8fb;
+ address constant SANCTIONS_CONTRACT = 0x574Ad490fE8087B580DB227a8Ca7EfB7C19Dc8C4;

Why RedStone Sanctions Oracle​

The Sanctions Oracle uses the same battle-tested RedStone infrastructure which has been running in production since 2021 with no downtime or mispricing incidents, securing billions of dollars in the most important onchain protocols. RedStone's data pipeline is also covered by ISO 27001-certified information security.


Get Started​

The Sanctions Oracle is live on Ethereum mainnet and can be integrated directly using the address above. To discuss deployment on other chains, custom list configurations, or your compliance requirements, contact the RedStone team.