CryptoReal
CASE FILE — Aug 9, 2022

When Code Gets Blacklisted: The Tornado Cash Sanctions Fallout

Tornado Cash, long the most contested application built on Ethereum, has finally run out of runway. Earlier efforts to appease regulators evidently weren't enough to hold off enforcement action.

At its height the mixer held more than $1 billion in deposits and became the preferred venue for laundering stolen crypto. It's well documented that North Korean actors have relied on the anonymity it offers — the Ronin bridge theft of $540 million is one such case — yet many still argue the tool itself deserves protection.

The question this raises: absent sanctions, what alternative exists for preserving on-chain privacy, and where should any carve-outs end?

On August 8, 2022, the US Treasury added Tornado Cash and a set of its smart contract addresses to the OFAC Specially Designated Nationals and Blocked Persons list.

The designation makes it a criminal offense for any US person — citizen, resident, or company — to transact with the listed addresses, which held roughly $437 million in ETH, WBTC, and stablecoins at the time.

Because the offense falls under strict liability, prosecutors need not demonstrate that a user knew about the sanctions or intended to violate them — mere interaction with the addresses is enough to establish guilt.

Treasury's own language describes the SDN list as covering "individuals and companies owned or controlled by, or acting for or on behalf of, targeted countries," plus others such as "terrorists and narcotics traffickers" who fall under non-country-specific programs.

Under that framing, Tornado Cash effectively becomes a stand-in target for anyone who fits OFAC's criteria — sweeping in ordinary users who sought privacy for entirely lawful reasons.

Data from a chart published by Chainalysis indicates that illicit sources account for under 30% of total deposits into the protocol.

Notably, this marks the first occasion a piece of software — rather than a person or organization — has been formally sanctioned.

By framing the action around widely reviled bad actors like terrorists and drug traffickers, regulators can present the move as a straightforward win against criminal activity online.

With state-backed hacking groups now operating more openly, it becomes politically easy to target tools like Tornado. Yet the officials driving the crackdown appear to misunderstand what they're actually banning. Secretary of State Blinken appeared to conflate Tornado Cash with the Lazarus Group itself in a public statement the day before.

Sums referenced in this case file

The people setting these rules seem unable — or unwilling — to distinguish between malicious actors and the neutral infrastructure they sometimes abuse.

Still, however easy these justifications are to mock, they carry real costs for ordinary users' privacy. In a fully transparent ledger system, anyone wanting to break the on-chain link between addresses has essentially two paths: non-custodial mixers, or centralized exchanges — and recent history shows that handing custody to a CEX brings its own serious risks.

Plenty of legitimate reasons exist for using a service like Tornado Cash. Privacy, at bottom, is a basic right, regardless of whether that argument satisfies regulators.

The sanction announcement immediately raised a string of previously abstract questions. Will every address that has ever touched the contracts be treated as tainted? Is the $437 million in TVL now effectively frozen? Are people who donated through GitCoin suddenly criminal actors?

OFAC's execution of the sanction left much unresolved. The list of targeted addresses appears to have been pulled directly from Etherscan's labeling, including Tornado Cash's GitCoin donation address, and covers only Ethereum mainnet contracts — even though the protocol also runs on BSC, Arbitrum, and Optimism.

More than 400 addresses and counting have already received tainted funds from the banned contracts, raising the prospect of doxxed wallets being deliberately 'salted' with dirty funds, potentially opening the door to extortion attempts.

It's also unclear whether the taint could extend beyond individual wallets to entire liquidity pools or protocols that later interact with them.

The fallout was immediate. Microsoft-owned GitHub took down the Tornado Cash repository in its entirety and removed the accounts of its contributors, while GitCoin suspended the project's grant.

Circle moved just as quickly, freezing roughly $75,000 in USDC held in Tornado's contracts along with the $150 that had been donated via GitCoin — despite having earlier pledged to "legally fight" any blanket blacklisting.

It raises an uncomfortable question: how long before Circle simply requires KYC on every address before funds can move at all?

The broader pattern here suggests an establishment reacting to something it doesn't fully understand by trying to dismantle it. If the industry wants to stay ahead of governments protecting their own interests, it needs to shore up the weak points in its own infrastructure — starting with the risk that centralized stablecoin issuers can be pressured into freezing funds at will, which could inflict serious damage on what's supposed to be decentralized finance. A genuinely decentralized stablecoin paired with a robust anonymity solution looks like the logical response to this exposure.

That said, it would be naive to assume crypto can simply code its way around societal rules indefinitely. Criminal activity does occur within cryptocurrency — but applying OFAC's logic consistently would also mean targeting cash and the internet itself.

For the community, prioritizing privacy over pure profit may be what determines whether crypto becomes a genuine tool of financial autonomy, or instead the most effective surveillance apparatus ever built. Choosing to opt out of a system built to monitor and control shouldn't automatically be treated as a criminal act.

The moment to embrace privacy — while it remains an option — is now.

PrivacySanctionsTornado Cash
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.