Who actually pushes the «block» button at Tether
Blacklisting USDT is not a single decision but a two-tier system: the legal grounds (law-enforcement request, sanctions, court order) and the technical execution. We break down who really makes the call and why good-faith users still get hit.
When we say «Tether blacklisted an address», it's easy to imagine someone at Tether's office literally pressing a button. The reality is more complex: behind every blacklist is a two-tier system, and the entity that makes the decision is often not Tether itself.
In this article we break down who actually decides, while the Tether contract is just the final technical step. If you're interested in how blacklisting appears on-chain (preban → ban → destroy), the mechanics are covered in our separate article on anatomy.
The two-tier blacklist system
A USDT blacklist consists of two tiers.
Tier 1 — legal and operational. This is where the grounds for the action arise: requests from government agencies, sanctions, court rulings, internal conclusions of Tether's compliance team. There is no blockchain at this tier — there are documents, correspondence, requests, investigations.
Tier 2 — technical. Tether, through its administrative interface, calls the smart contract function (addBlackList), and the address is added to BlackList. From that moment, the block exists on-chain as the AddedBlackList event. This tier is public — anyone can observe it in real time.
Who actually initiates blacklists
Blacklist sources can be split into four categories.
1. Law-enforcement agencies
The main scenario. When law-enforcement agencies (FBI, local police, tax authorities, financial intelligence units) run an investigation involving USDT, they can ask Tether to freeze specific addresses. This may be part of a sanctions process, a confiscation in a criminal case, or a preventive measure during an investigation.
In these cases, Tether acts as a technical executor — not as the initiator. The decision is made in a different jurisdiction with a different procedure; Tether receives the request and performs the technical part.
2. Sanctions bodies and regulators
A blacklist can happen if the address is connected to the sanctions perimeter. This can include OFAC (US), UK, EU, UN sanctions, or other inter-state restrictive regimes. Tether has a compliance team that tracks sanctions lists and applies them at the USDT contract level.
An important detail: a sanctions blacklist may affect not only the address directly included in the SDN list, but also addresses linked to it through the chain. If funds passed through an address from a sanctions list, downstream addresses may come under suspicion.
3. Government orders
This category covers court orders, confiscation procedures, asset-freezing rulings in both criminal and civil investigations. Here Tether executes the will of a state body of a specific jurisdiction.
4. Internal risk assessment
Tether's terms of service include a clause under which Tether may freeze tokens if it considers it reasonable or necessary at its discretion. This wording is broad and leaves Tether room for blacklists without an explicit external request.
In practice, this includes cases where Tether's compliance team sees signs of fraud schemes (for example, after an exchange hack or phishing campaign) and blocks addresses on its own — sometimes before formal involvement of law-enforcement.
Why good-faith users also get hit
The most important practical takeaway from this article: a blacklist can affect a user not for their own actions.
Common scenarios where a good-faith user ends up in the blacklist:
- Received USDT from a counterparty whose history had connections to a sanctioned or fraudulent address;
- Used an exchange or service that suffered a hack or phishing campaign;
- The address was caught in a broader cluster during analytics by a compliance vendor;
- The address was previously used in an OTC trade through which risky funds passed.
In the world of USDT, you can't only control your own actions — you need to know the history of every address from which funds arrive. This is the new reality of compliance.
— The key practical risk
Further reading
- Anatomy of a USDT blacklist — technical mechanics: how preban becomes ban and where the «window of opportunity» is.
- Mass unban on 14 May 2026 — practical case: 497 addresses unblocked in 72 minutes. What it means and why a technical unblock ≠ legal rehabilitation.