Crypto Mixer Tornado Cash: How Institutions Assess Risk

Crypto Mixer Tornado Cash: How Institutions Assess Risk

Prepared by the editorial team. Updated August 31, 2026.

Research Notice: This guide is part of our fintech research series examining blockchain privacy tools and their regulatory context. It is informational and educational only, is not legal, financial or compliance advice, and does not endorse or instruct the use of any mixing service. Laws differ by jurisdiction and change over time; verify current rules for your location.

Crypto mixer Tornado Cash is treated by regulated firms as a risk input rather than as a legal status, and the difference explains most of the apparent contradictions readers encounter. A name can be absent from every sanctions list and still generate alerts at a bank, because the two systems are answering unrelated questions.

What does a risk-based program actually assess?

It assesses the likelihood that a given customer or transaction involves proceeds of crime, and it allocates attention accordingly. A risk-based program does not attempt to review everything equally. It sets a risk appetite, scores relationships against it, applies heavier scrutiny where scores are high, and documents why each decision was made.

The approach is required rather than optional in most major jurisdictions. Supervisors expect a firm to understand its own exposure, write down its methodology, apply it consistently and evidence the outcome. What they do not do is publish a universal threshold, which is why two well-run institutions can look at the same customer and reach different conclusions without either being wrong.

For digital assets the inputs are unusually rich and unusually ambiguous at once. A public ledger lets a firm see the entire transaction history behind an incoming transfer, which no bank has ever had for cash. What the ledger does not supply is identity, so every judgment depends on attribution data that maps addresses to real-world counterparties, and that mapping is produced by commercial vendors with differing methods.

How does direct exposure differ from indirect exposure?

Direct exposure means the customer transacted with the flagged counterparty itself. Indirect exposure means the funds passed through one or more intermediate addresses first. The distinction matters because the strength of the inference collapses as the distance grows, and a firm that treats the two identically will either over-alert or miss the cases that matter.

The number of transfers between the flagged source and the customer is usually called the hop count, and it is the single most consequential setting in an exposure model. At one hop the customer received value that came straight from the counterparty. At five hops the connection may be entirely incidental, because value flows through exchanges, bridges and market makers that touch enormous numbers of unrelated parties.

Firms handle this by weighting exposure so that it decays with distance and by treating certain intermediaries as breaking the chain altogether. Those choices are policy decisions rather than facts about the blockchain, and different institutions make them differently. A useful discipline is to ask what an exposure figure would look like under a different hop setting before treating it as a finding.

Why do analytics providers disagree about the same address?

Because their outputs are the product of proprietary attribution work, not readings from the ledger. Vendors differ on which addresses they assign to which entity, on how confident they need to be before publishing an attribution, on how they weight indirect exposure, and on how quickly they revise a database when new evidence arrives.

Attribution quality varies within a single report as well as between vendors. Some addresses are known with near certainty because a service published them or a court filing confirmed them. Others are grouped by heuristics that infer common control from spending patterns, and those inferences are usually sound but occasionally wrong. A score that presents both kinds with the same confidence hides a real difference.

Timing adds a further gap. Databases are updated as investigations conclude and as classifications are revisited, so an address that was unlabelled last year may carry a label today, and a label applied in 2022 may reflect a legal position that has since changed. A firm that stores only the final score, and not the date and the reasoning, cannot later explain a decision that looked correct when it was made.

How can you read an analytics risk label critically?

You establish what the score measures, check whether the exposure is direct or indirect, read the attribution behind the label, compare against a second source where one exists, and record the score, the date and your reasoning. This is a review method for compliance and research readers and is not advice about any particular relationship.

Step 1: Establish what the score is measuring

Find the vendor’s definition of the score before interpreting it, because some labels describe attribution of a counterparty while others describe a modelled probability, and the two support different conclusions. A number with no stated definition should not drive an outcome.

Step 2: Check whether exposure is direct or indirect

Determine whether the flagged relationship is a transaction with the counterparty itself or a connection several transfers removed, since indirect exposure is a much weaker signal about the party in front of you. Reports usually show this, though rarely in the summary line.

Step 3: Read the attribution behind the label

Look for how the counterparty was identified and when, because attribution rests on evidence of varying quality that ranges from confirmed service addresses to inference, and the report should say which applies. Where it does not, that absence is itself worth noting.

Step 4: Compare against a second source where you can

Check the same address or entity against another provider or dataset if your organisation has access to one, because disagreement between vendors is common and it is information rather than noise. Agreement between independent methods is meaningfully stronger evidence.

Step 5: Record the score, the date and your reasoning

Write down the label you saw, the date you saw it and why you did or did not act on it, because attribution databases are revised over time and a decision must be judged on what was available then. A qualified compliance professional should set the thresholds themselves.

Exposure categories and their typical weight

The table describes the categories most exposure models use and the reasoning usually applied to each. Each row names one category and how much weight it typically carries. It describes common practice rather than any institution’s actual policy, and thresholds differ widely.

Category What it describes Usual treatment
Direct exposure A transaction with the flagged counterparty Highest weight; typically triggers review
Indirect exposure, close A connection a small number of transfers away Weighted lower and read alongside other signals
Indirect exposure, distant A connection many transfers away Often discounted heavily or excluded by policy
Intermediary contact Value routed through a large regulated venue Frequently treated as breaking the chain
Attribution confidence How firmly an address is tied to an entity Modifies every category above it

Reading across the rows shows why a single headline percentage is a poor summary. The same underlying flow can produce very different figures depending on which categories a model counts and how far it looks.

Why are list status and risk assessment separate questions?

Because they are produced by different institutions for different purposes. A sanctions list states a legal prohibition attached to a name at a moment in time. A risk assessment is a firm’s own judgment about probable exposure to criminal proceeds, and it can be elevated for something that has never appeared on any list.

Tornado Cash is the clearest illustration available. It was designated in August 2022, an appeals court held in November 2024 that the immutable contracts were not property capable of designation, and Treasury then removed it from the list, an action recorded in the March 2025 OFAC notice. It is not currently designated, and yet mixer-associated flows continue to be scored as elevated risk by regulated firms.

Both facts are correct simultaneously, and readers who learn only one of them tend to draw a confident wrong conclusion. Delisting removed a specific prohibition tied to a specific name, while anti-money-laundering programs run on risk rather than on list membership and were never conditioned on the designation. Criminal proceedings against individuals also continued after the delisting, including a retrial scheduled for April 2027, which is a further reminder that a list is not a verdict.

The practical takeaway for anyone reading a compliance output is to check which question is being answered. A screening hit against a sanctions list and a high risk score from an analytics vendor look similar on a dashboard and mean entirely different things, and any decision that turns on the difference belongs with qualified compliance or legal advice.

Frequently asked questions

Can an institution be penalised for exposure it could not have seen?

Supervisors generally assess whether a program was reasonably designed and consistently applied rather than whether it achieved perfect detection. That is why documentation matters so much: a defensible file shows what was known at the time and why a decision followed from it. Specific exposure should always be discussed with counsel.

Do banks and crypto venues assess this the same way?

They apply the same risk-based logic but usually see different evidence, since a bank often observes only a fiat transfer from a venue while the venue observes the on-chain history behind it. The result is that the two form views of the same customer from very different vantage points.

Does an alert mean an account will be closed?

An alert is the start of a review rather than a decision, and most alerts are closed without action after examination. Outcomes vary widely by institution and by the risk appetite it has set, which is why two firms can reach different conclusions on identical facts.

Why do older reports still describe this name as sanctioned?

Much of the widely circulated material dates from between 2022 and early 2025 and was accurate when it was written. Undated commentary keeps ranking in search results, so any status claim should be confirmed against the current official list rather than a secondary source.

Leave a Comment

Your email address will not be published. Required fields are marked *