CryptoReal
CASE FILE — Sep 8, 2023

Privacy Pools Pitches Zero-Knowledge Compliance as Tornado Cash's Successor

As cash gives way to digital, traceable payments, a comprehensive record of nearly every person's financial activity is being assembled in real time — a dynamic that has made privacy preservation a core motivation across crypto's user base, from everyday holders and cypherpunks to political dissidents and even state-backed hacking groups.

Regulators versus privacy tech: an escalating conflict

Tension between blockchain-based privacy tools and financial regulators is not new, but it intensified sharply after the US Treasury sanctioned Tornado Cash last year. Since then, the outlook for on-chain privacy has continued to darken: developer Alexey Pertsev was arrested, followed last month by Roman Storm, and numerous front-ends adopted address screening — even against wallets that had simply been dusted with unwanted Tornado ETH. Tornado's own governance process was also compromised after a hidden "metamorphic contract" was slipped into a May governance proposal.

Despite alternative privacy tools existing, none has matched Tornado Cash's reach, largely because of how simple and well-understood Ethereum's original mixer became. No true successor has emerged in the time since the sanctions — until now, potentially.

A coalition of developers, researchers, and privacy advocates has put forward a modified approach intended to strike a balance: protect the anonymity of legitimate users while preventing bad actors from tainting the tool's reputation. The unresolved question, as ever, is who gets to define "legitimate."

Introducing Privacy Pools

Announced on Wednesday, September 6, 2023, Privacy Pools let users generate zero-knowledge proofs demonstrating that their withdrawn funds are not connected to illicit deposits. Per the project's documentation:

This design aims to be a crypto-native solution that allows the community to defend against hackers abusing the anonymity sets of honest users without requiring blanket regulation or sacrificing on crypto ideals.

The concept traces back to an idea Vitalik Buterin floated shortly after the Tornado Cash sanctions. It was built by RAI's Ameen Soleimani and presented alongside two researchers from the University of Basel. Soleimani had first teased the project back in March 2023, and an accompanying academic paper lays out both the technical design and possible use cases for balancing compliance and privacy.

Mechanism: proving association, not identity

At withdrawal time, a user can generate a zk-proof showing their funds trace back to a specific subset of pool deposits — one that excludes any deposits already flagged as illicit. Screening services, which today tend to blanket-flag all mixer withdrawals as tainted regardless of source, could instead reference these proofs to clear legitimate users.

The design supports customizable "association" and "exclusion" sets: a US-based user could prove compliance with US rules, an EU user with EU rules, and some users could satisfy both simultaneously. The paper also describes other possible applications, such as a consortium of banks maintaining a shared association set to prove collective KYC/AML compliance, or proving a funding link between two specific parties (a 1:1 association set) without exposing broader account-level connections.

A further claimed benefit: as legitimate association sets grow through community curation, the pool of "acceptable" funds available for a bad actor to hide among effectively shrinks, narrowing the effective anonymity set for illicit activity over time:

Over time as communities curate deposit lists, the anonymity set for hackers actually shrinks to include only those bad deposits, naturally hindering even the possibility of money laundering to occur.

The unresolved governance question

The core tension the authors acknowledge is who decides which funds count as "good." The paper concedes:

If there is a perfect consensus on which funds are "good" and which are "bad", the system will lead to a simple separating equilibrium

In practice, that consensus doesn't exist. While the protocol's support for custom, user-defined association sets keeps the underlying tool neutral, relying on individual users to build their own lists isn't realistic at scale — meaning most people will lean on lists curated by third parties. Notably, one of the paper's co-authors is Chainalysis's Chief Scientist, which telegraphs who is likely to end up filling that curator role.

The authors don't fully resolve what integration should look like in practice. On-chain proofs appear to be the most flexible option, though they would add to transaction costs; keeping the barrier to participation low is also seen as essential for preserving a sufficiently large anonymity set overall. As the paper puts it:

Having the proofs readily available on-chain, introduces additional transaction costs, but reduces the coordination effort, levels the playing field and mitigates the risk that screening tool providers could have a quasi-monopoly due to their knowledge of non-public proofs.

Reception and broader context

Critics could reasonably argue that leaving compliance firms like TRM and Chainalysis as the ultimate arbiters — effectively acting on instructions from government authorities — cuts against crypto's founding ethos, especially given the "block first, ask questions later" posture that followed the OFAC sanctions. Even so, for the majority of users who simply want ordinary privacy without being mistaken for a criminal or terrorist, the model represents a workable middle ground, even if it won't satisfy the most committed crypto-libertarians.

The paper's underlying argument is captured in this line:

In many cases, privacy and regulatory compliance are perceived as incompatible. This paper suggests that this does not necessarily have to be the case

As intermediaries become increasingly redundant, governments may keep seizing on any perceived downside of the technology to justify reasserting control over a system that has already moved past them. Tools like Privacy Pools are intended to remove some of that ammunition from critics who don't fully grasp how the technology works — criticism one commentator dismissed outright:

this is barbarbism and technological ignorance, pure and simple

Yet even good-faith compliance efforts have recently gone nowhere, reinforcing the view among some in the space that building privacy tools and letting users opt in is a more productive path than continuing to negotiate within a regulatory framework many see as unwinnable.

PrivacyRegulationTornado Cash
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.