Understanding Tornado Cash, Its Sanctions Implications, and Key Compliance Questions - Chainalysis (2024)

On August 8th, the popular Ethereum smart-contract mixer Tornado Cash was sanctioned by the U.S. Treasury’s Office of Foreign Assets Control (OFAC) for its role in laundering over $455 million worth of cryptocurrency stolen by the North Korean-linked hacking organization Lazarus Group.

Tornado Cash has mixed over $7.6 billion worth of Ether since launching in August 2019. Almost 30% of the funds sent through it have been tied to illicit actors.

However, given Tornado Cash’s unique qualities – its non-custodial nature, its smart contract-encoded design, and its decentralized development team – sanctions compliance has been more complicated in this case than in past situations. That’s why we’ve written this guide: to provide clarity where we can and pose questions where they remain.

We cover:

  • How Tornado Cash works
  • OFAC’s designation of Tornado Cash
  • Sanctions compliance challenges for:
    • Centralized crypto businesses
    • DeFi platforms
    • Mining and staking pools
    • Web3 infrastructure providers
    • Crypto wallet providers
    • Stablecoin issuers
  • How organizations use Chainalysis to manage sanctions risk

How Tornado Cash works

Crypto mixers like Tornado Cash are designed to create a disconnect between the cryptocurrencies that a user deposits and withdraws. At a high level, they work by pooling the funds deposited by many users together, shuffling them in a seemingly random fashion, and then subtracting a small service fee and returning the remaining funds to each depositor. Tornado Cash is no exception – though its details differ.

Tornado Cash: a decentralized, non-custodial smart contract

Technically speaking, Tornado Cash is a decentralized, non-custodial smart contract, which is distinct from other types of crypto mixers. Let’s define each of these words in the context of Tornado Cash:

  • Decentralized: Tornado Cash’s codebase is open source, and its operations are managed – at least in part – by a decentralized autonomous organization (DAO). This source code was published on Github until the platform removed its main repository following OFAC’s sanctions announcement. A cryptography professor at Johns Hopkins has since re-uploaded it on free-speech grounds.
  • Non-custodial: Tornado Cash does not gain custody over its users’ funds at any point during the mixing process.
  • Smart contract: At its core, Tornado Cash is just code running on various open public blockchains like Ethereum. Crucially, most of its smart contracts are designed in such a way that they cannot be changed or destroyed by anyone, including the Tornado Cash DAO.

An implication of Tornado Cash’s decentralization that regulators and crypto compliance teams should be aware of is that the protocol continues to operate, and that its front-end is still accessible on the InterPlanetary File System (IPFS) and over The Onion Router (also known as Tor). IPFS is a distributed, peer-to-peer protocol for storing and sharing data, while Tor is an open-source software package that enables anonymous communication and is colloquially known as “the dark web.”

How Tornado Cash mixes funds

By design, there are many ways to use Tornado Cash. The simplest approach—prior to OFAC’s designation—was to navigate to Tornado Cash’s web app and connect a crypto wallet. A slightly more involved approach is to download a version of the app to use from a computer. And the most sophisticated approach of all is to use a command line interface to interact with the protocol.

Tornado Cash’s mixing process

However an individual uses Tornado Cash, there are three key steps in the mixing process.

  1. The user generates a “deposit note” on their local device and shares a cryptographic hash of it in a transaction with their chosen Tornado Cash pool contract. This note is sort of like a claim check you would get at a restaurant to prove that you own the coat you handed over – though in this case, the note is a long string of data that you’re asked to store/encrypt.
  2. The user’s funds are sent to the contract, which pools this deposit alongside the deposits of other users in the denominations specified by the contract, such as .1, 1, 10, or 100 ETH. The funds can remain in that pool for as long as the user would like. (Pools also exist for the tokens USDC, USDT, DAI, cDAI, and wBTC and assets on blockchains other than Ethereum.)
  3. The user, utilizing their secret deposit note and some nifty zero-knowledge cryptography, generates a transaction that proves they have the right to withdraw the deposited value. The user can then either withdraw the funds themself or have a “relayer” process the withdrawal on their behalf in exchange for a 0.05% to 0.2% fee. This relay transaction severs any direct connection between the user’s deposit and withdrawal.

For more on how Tornado Cash works, watch our video on Chainalysis Academy.

OFAC’s designation of Tornado Cash

Tornado Cash can be a practical solution for legitimate users seeking financial privacy, like those who wish to donate to political causes without making the details public or those who wish to keep information about their wealth private. But it’s also attractive to cybercriminals seeking to launder money. Treasury’s press release announcing the Tornado Cash sanctions specifically pointed to Tornado Cash’s role in laundering over $455 million worth of cryptocurrency stolen from Axie Infinity’s Ronin Bridge protocol by the North Korea-affiliated hacking organization, Lazarus Group, and its receipt of funds stolen from Harmony Bridge and Nomad Bridge in June and August of this year. Since 2019, almost 30% of the funds sent through it have been tied to illicit actors, and the Democratic People’s Republic of Korea has been one of its chief beneficiaries.

The Tornado Cash addresses that OFAC included in the designation consist of deposit addresses, routing addresses, proxy addresses and more.

Sanctions compliance challenges

OFAC’s most recent guidance on virtual currency stated that each of the business types we discuss in this section, as well as any others that interface with the crypto industry, “are encouraged to develop, implement, and routinely update a tailored, risk-based sanctions compliance program. Such compliance programs generally should include sanctions list and geographic screening and other appropriate measures as determined by the company’s unique risk profile.”

However, there are open questions about how – and to what extent – certain categories of crypto industry protocols can comply with these sanctions. We address each of these categories below.

Centralized cryptocurrency businesses

OFAC has included 44 addresses as identifiers of Tornado Cash. Centralized crypto businesses subject to US jurisdiction are prohibited from interacting with these addresses.

DeFi platforms

A front-end web application that is used to interact with a DeFi protocol can block cryptocurrency addresses with exposure to Tornado Cash, but regulation has not yet stipulated whether such a block is needed at the protocol level or if such a block is even possible.

The tension here comes from the fact that at the protocol level, it is extremely difficult – or, depending on the protocol’s governance structure and how it has been designed, perhaps even impossible – to censor a transaction.

For example, the design of the Ethereum blockchain made it such that people were able to send an estimated $52,000 in small Tornado Cash payments to celebrities and industry figures in the wake of OFAC’s designation — none of whom were able to refuse receipt of these transactions. Now, these “dusting attack” targets have control of assets with exposure to Tornado Cash, which could have downstream compliance impacts.

Mining and staking pools

One open question for miners and mining pool operators is this: If you mine a block containing a Tornado Cash transaction, are you now in violation of OFAC regulations? And on proof-of-stake blockchains, what about validators and staking pools? In lieu of existing guidance, the largest Ethereum miner, Ethermine, stopped including Tornado router transactions in its blocks on August 9th, the day after OFAC’s designation was announced. But the question remains as to whether a pool is ultimately responsible for the transactions mined/validated within its blocks.

Web3 infrastructure providers

Two popular web3 infrastructure providers, Infura and Alchemy, now block Ethereum API access for Tornado Cash. This means that users can no longer connect to the Tornado Cash front-end using Alchemy or Infura APIs.

However, much like DeFi protocols, infrastructure providers may be unable to block user access at the protocol level, and it is unclear whether such obligations exist.

Crypto wallet providers

People operating centralized, custodial crypto wallets can screen and block transfers to the addresses identified in OFAC’s designation, but the obligations of non-custodial crypto wallet providers are less clear. An extreme interpretation could mean that non-custodial wallet providers might also need to block transfers to the sanctioned addresses, though this would be unprecedented.

Because it is impossible to block incoming transactions regardless of custodial status, users remain vulnerable to dusting attacks.

Stablecoin issuers

Circle, the issuer of USDC, has frozen all USDC held in OFAC-designated Tornado Cash addresses, but other stablecoin issuers like Tether have argued that it is not yet certain whether stablecoin issuers are obligated to freeze the assets held by sanctioned addresses.

How Chainalysis helps organizations manage sanctions risk

Chainalysis offers a complete compliance suite for cryptocurrency services – including those in DeFi – ranging from free, simple tooling to powerful, data-driven transaction monitoring. Customers should have maximum flexibility so they can design their compliance processes according to their own risk tolerance.

Our most basic solutions are designed with decentralized web3 protocols like DEXs, DeFi platforms, DAOs, and DApps in mind so they can easily validate that they aren’t interacting with cryptocurrency addresses associated with sanctioned entities. These tools include:

  • An API designed for web/mobile UIs and web servers: Users will receive an API key through which they can check if an address of interest is on the sanctions list or not. Click here to express your interest in the API.
  • An on-chain oracle designed for smart contacts: Users can call the Chainalysis oracle from another smart contract to check if an address is on a sanctions list. The Chainalysis oracle is deployed on most EVM chains like Ethereum, Avalanche, BSC, Polygon, Optimism, Arbitrum, Celo. Learn more about our on-chain oracle.

The next step on the compliance maturity journey is deeper address screening that includes powerful additional context like clustered addresses, more categories like stolen funds, fraud shops, darknet markets, and more. Address screening is for decentralized web3 organizations that want to harness the power of Chainalysis data to automatically prevent high-risk users from connecting to their platform. This demonstrates a more proactive risk and compliance approach with a fully programmatic solution.

The last stop on this maturity journey is powered by sophisticated real-time transaction monitoring via an easy-to-use interface and a real-time API. This capability is ideal for compliance organizations that need to reduce manual workflows and streamline how they share information with their banks and regulators.

This website contains links to third-party sites that are not under the control of Chainalysis, Inc. or its affiliates (collectively “Chainalysis”). Access to such information does not imply association with, endorsem*nt of, approval of, or recommendation by Chainalysis of the site or its operators, and Chainalysis is not responsible for the products, services, or other content hosted therein.

This material is for informational purposes only, and is not intended to provide legal, tax, financial, or investment advice. Recipients should consult their own advisors before making these types of decisions. Chainalysis has no responsibility or liability for any decision made or any other acts or omissions in connection with Recipient’s use of this material.

OFACSanctionsTornado Cash

Understanding Tornado Cash, Its Sanctions Implications, and Key Compliance Questions - Chainalysis (2024)

FAQs

Is Tornado Cash really untraceable? ›

They don't have to be the same person who made the deposit. This means that Tornado Cash makes it impossible to tell what crypto in a pool belongs to which person, and very difficult to tell who is sending crypto to whom (it could even be the same person using a different crypto wallet).

What happened with Tornado Cash? ›

Updated 9 am ET, May 14, 2024: A Dutch court has found Tornado Cash cofounder Alexey Pertsev guilty of money laundering and sentenced him to 64 months in prison.

How does Tornado Cash work? ›

How does Tornado Cash work? Tornado Cash enables users to anonymize their Ethereum transactions by a system of pools, which are also known as "anonymity sets." These pools are essentially Ethereum accounts managed by smart contracts that ensure users can only withdraw the amount they originally deposited.

Can Tornado Cash be traced? ›

Network Analysis. It's important to conduct network analysis when tracking money that was deposited or withdrawn from Tornado Cash wallets. By exploring transaction flows and connections between addresses, we can identify commonalities or clustering of addresses engaging with Tornado Cash.

Is Tornado Cash still banned? ›

This is a privacy tool used in EVM networks where all transactions are public by default. In August 2022, the U.S. Department of the Treasury blacklisted the service, making it illegal for US citizens, residents and companies to use.

Why is Tornado Cash blacklisted? ›

Why did the US Treasury sanction Tornado Cash? On August 8, 2022, Tornado Cash was sanctioned by the U.S. Treasury for allegedly failing to install sufficient controls to prevent it from laundering cash for harmful cyber actors on a regular basis.

Is Tornado Cash developer guilty of money laundering? ›

Tornado Cash Developer Found Guilty of Laundering $1.2 Billion of Crypto. Alexey Pertsev, cofounder of the crypto-anonymizing tool, has been sentenced to more than five years behind bars.

What is the successor of Tornado Cash? ›

Similar to Tornado Cash, Cyclone ensures users retain custody of their assets throughout the transaction process. With its foundation rooted in Tornado Cash's code, Cyclone Protocol offers a familiar alternative for users seeking similar privacy features.

Is Tornado Cash still online? ›

Tornado Cash has been added to Office of Foreign Asset Control's (OFAC) list of sanctioned internet services, shutting down a key privacy tool for Ethereum users, one frequently used by cybercriminals.

How much is the withdrawal fee for Tornado Cash? ›

The user can then either withdraw the funds themself or have a “relayer” process the withdrawal on their behalf in exchange for a 0.05% to 0.2% fee.

How do I withdraw money from Cash Tornado? ›

When a user is ready to withdraw their tokens, they first split their deposit note in half. One side acts like a “secret,” and the other acts like a “lock.” After that, the user prompts the Tornado Cash smart contract to withdraw. Along with the prompt, the user supplies: A hash (or encoded form) of the “lock”

Does Tornado Cash use ZK? ›

At the heart of Tornado Cash's privacy model lies the application of zero-knowledge proofs. This cryptographic technique enables users to prove the validity of a statement without disclosing the actual information behind it. In the context of Tornado Cash, zero-knowledge proofs play a pivotal role in transactions.

How anonymous is Tornado Cash? ›

It is anonymous in that the coins/tokens you receive from it, is difficult to trace back to the source. For example, you have 100 laundered BTC in Wallet A and you put them through Tornado Cash app. Meanwhile 200 other people are also putting their 100 BTC through the app.

Is Tornado Cash non custodial? ›

Tornado Cash is a non-custodial Ethereum and ERC20 privacy solution based on zkSNARKs. It improves transaction privacy by breaking the on-chain link between the recipient and destination addresses.

Do Tornado Cash on any chain? ›

Tornado Cash supports a number of different cryptocurrencies, and runs on a number of different networks - although the vast majority of transactions are made in ETH, deposited to the version of Tornado Cash running on the Ethereum Blockchain.

How private is Tornado Cash? ›

Despite the founder's arrest, Tornado Cash provides users with full privacy. The platform's special mixing feature allows people to hide where their money comes from and where it goes.

Can stolen cash be traced? ›

If a criminal has been caught with stolen banknotes, the serial numbers will be checked by looking at a list that has been compiled of all the serial numbers of marked bills, making it easier for law enforcement to crack down on any illicit activities.

Can cash transactions be traced? ›

Although many cash transactions are legitimate, the government can often trace illegal activities through payments reported on complete, accurate Forms 8300, Report of Cash Payments Over $10,000 Received in a Trade or Business PDF. Here are facts on who must file the form, what they must report and how to report it.

Top Articles
How to Import Your Crypto Keys Using A Recovery Phrase [2023] | BitPay
Why does gpg's secret and public key have the same keyid?
Cpmc Mission Bernal Campus & Orthopedic Institute Photos
Jack Doherty Lpsg
Martha's Vineyard Ferry Schedules 2024
Top Financial Advisors in the U.S.
Konkurrenz für Kioske: 7-Eleven will Minisupermärkte in Deutschland etablieren
Mcoc Immunity Chart July 2022
Co Parts Mn
Embassy Suites Wisconsin Dells
B67 Bus Time
Hover Racer Drive Watchdocumentaries
Regal Stone Pokemon Gaia
Trini Sandwich Crossword Clue
Love In The Air Ep 9 Eng Sub Dailymotion
Operation Cleanup Schedule Fresno Ca
Immortal Ink Waxahachie
Eva Mastromatteo Erie Pa
All Obituaries | Buie's Funeral Home | Raeford NC funeral home and cremation
If you bought Canned or Pouched Tuna between June 1, 2011 and July 1, 2015, you may qualify to get cash from class action settlements totaling $152.2 million
Wgu Academy Phone Number
Reptile Expo Fayetteville Nc
Ups Print Store Near Me
Craigslist Houses For Rent In Milan Tennessee
R&S Auto Lockridge Iowa
Workshops - Canadian Dam Association (CDA-ACB)
Page 2383 – Christianity Today
Cognitive Science Cornell
Studentvue Calexico
Rek Funerals
Hoofdletters voor God in de NBV21 - Bijbelblog
Have you seen this child? Caroline Victoria Teague
Flixtor Nu Not Working
Serenity Of Lathrop - Manteca Photos
Robot or human?
Gwu Apps
Unifi Vlan Only Network
craigslist | michigan
Topos De Bolos Engraçados
Academy Sports New Bern Nc Coupons
Craigslist Freeport Illinois
Dcilottery Login
Nid Lcms
Nina Flowers
Avance Primary Care Morrisville
How To Customise Mii QR Codes in Tomodachi Life?
Child care centers take steps to avoid COVID-19 shutdowns; some require masks for kids
Florida Lottery Powerball Double Play
The Sports Academy - 101 Glenwest Drive, Glen Carbon, Illinois 62034 - Guide
Syrie Funeral Home Obituary
Asisn Massage Near Me
Latest Posts
Article information

Author: Dr. Pierre Goyette

Last Updated:

Views: 6689

Rating: 5 / 5 (70 voted)

Reviews: 93% of readers found this page helpful

Author information

Name: Dr. Pierre Goyette

Birthday: 1998-01-29

Address: Apt. 611 3357 Yong Plain, West Audra, IL 70053

Phone: +5819954278378

Job: Construction Director

Hobby: Embroidery, Creative writing, Shopping, Driving, Stand-up comedy, Coffee roasting, Scrapbooking

Introduction: My name is Dr. Pierre Goyette, I am a enchanting, powerful, jolly, rich, graceful, colorful, zany person who loves writing and wants to share my knowledge and understanding with you.