Tornado Cash Crypto and the Regulation of Privacy

Tornado Cash Crypto and the Regulation of Privacy

Prepared by the editorial team. Updated August 31, 2026.

Research Notice: This guide is part of our fintech research series examining blockchain privacy tools and their regulatory context. It is informational and educational only, is not legal, financial or compliance advice, and does not endorse or instruct the use of any mixing service. Laws differ by jurisdiction and change over time; verify current rules for your location.

Tornado Cash crypto enforcement is often described as a policy choice that could have gone another way, but the collision was structural rather than incidental. The anti-money-laundering system rests on two assumptions, that transactions can be traced and that an identifiable intermediary stands behind them, and a non-custodial privacy tool removes both. This article explains that collision and sets out the competing positions on what should follow.

What does the anti-money-laundering framework actually depend on?

It depends on chokepoints. The system does not monitor money directly; it obliges intermediaries such as banks, exchanges and payment firms to identify customers, keep records and report suspicious activity. Every substantive duty attaches to a person or firm that can be licensed, examined and penalised.

Traceability is the second pillar and it makes the first work. Records are only useful if an investigator can follow value from one identified party to another, which is why transfer messaging standards and retention requirements exist. The assumption is that money leaves a trail and somebody keeps it.

Public blockchains initially looked like a good fit for this model. Every transfer is permanently visible, so the trail is stronger than in conventional banking, and the regulatory work reduces to attaching identities where value enters and leaves the system.

Why does a non-custodial privacy tool collide with that framework?

Because it removes both pillars at once. A pooled design weakens the link between a deposit and a withdrawal, attacking traceability, and immutable contracts with no owner, no pause and no upgrade path leave no intermediary to license. The framework has no place to attach a duty, which is a structural mismatch rather than a drafting gap.

It is worth being precise about what is absent. No entity holds customer funds, because the contract releases each deposit against a proof and a nullifier rather than on anyone’s instruction, and no party can refuse a user, freeze a balance or produce a customer list.

Regulators responded by looking for the nearest available party, since duties presupposing an intermediary cannot bind a contract. Attention moved to those who wrote and promoted the software, to the DAO structures around it, and to relayers who submit withdrawal transactions for a fee. Each is a real person performing a function, which is what makes them reachable and their responsibility contested.

The same logic drove the sanctions route. Rather than regulate an intermediary that did not exist, Treasury designated the tool itself, an approach tested in Van Loon v. Department of the Treasury in November 2024, where the Fifth Circuit held that immutable contracts are not property capable of designation. Treasury removed the name from the sanctions list in March 2025, resolving the statutory question without resolving the policy problem.

What do the competing positions each actually claim?

One side argues that a tool built to defeat traceability, and used at scale by sanctioned actors, is a laundering instrument whose designers cannot disclaim the predictable result. The other argues that neutral software is not conduct, that financial privacy is an ordinary interest rather than evidence of guilt, and that liability aimed at developers deters lawful building.

Both positions rest on facts that are partly agreed. Pooled funds included proceeds of major thefts, and Treasury asserted in 2022 that more than seven billion dollars had been laundered since 2019, including over 455 million attributed to the DPRK-linked Lazarus Group. Researchers have disputed that seven billion figure, so it should be treated as an assertion rather than a finding.

The disagreement is really about attributing responsibility. If a system has no operator by construction, the question becomes whether those who built, funded, promoted or profited from it are close enough to its use to answer for it. That is a question about knowledge, intent and conduct, which is exactly what juries and courts have been asked to decide.

How can you map which regulator covers which activity?

You describe the activity in functional terms, list every jurisdiction it touches, match each function to a statutory definition, read the agency guidance behind that definition, and take the result to qualified counsel. The procedure below is a research method for orienting yourself, not a compliance opinion.

Step 1: Describe the activity in functional terms

Write out what actually happens, meaning who holds value, who instructs a transfer and who takes a fee, because regulators classify by function rather than by the label a product gives itself. Calling something a protocol rather than a service has no effect on this analysis.

Step 2: List every jurisdiction the activity touches

Note each country where users, developers, servers or counterparties sit, because obligations attach to connections rather than to where a project considers itself based. Several of the most consequential proceedings in this area arose in countries the participants did not live in.

Step 3: Match each function to a statutory definition

Compare each function against the statutory definitions used in those jurisdictions, such as money transmission or virtual asset service provision, because the definition rather than the technology determines which regime applies. One activity frequently matches more than one definition.

Step 4: Read the agency guidance behind the definition

Find the published guidance or interpretive releases the agency has issued on that definition, because guidance often narrows or widens a statutory phrase in ways the text does not reveal. Guidance is also where you learn how an agency has treated comparable arrangements.

Step 5: Take the map to qualified counsel

Bring the completed map to a lawyer qualified in each jurisdiction rather than acting on it, because overlapping regimes make this an input to legal advice and not a substitute for it. The value of the exercise is that it makes the right questions askable.

Is the legal question settled in either direction?

No, and any confident summary overstates the record. Courts have addressed narrow slices of the problem, juries have reached partial verdicts, and an agency action was reversed on statutory grounds. None of this has produced a general rule about when building privacy software creates liability, and several proceedings remain open.

The American record illustrates the fragmentation. Van Loon held that immutable contracts are not designatable property, a ruling about sanctions authority rather than lawful conduct. In August 2025 a jury convicted Roman Storm on one count of conspiracy to operate an unlicensed money transmitting business and deadlocked on money laundering conspiracy and sanctions evasion conspiracy. A hung count is not an acquittal, and a retrial is scheduled for April 26, 2027 before Judge Katherine Polk Failla in the Southern District of New York.

Other threads are also live. A motion for acquittal filed in September 2025 was argued in April 2026 and remains undecided, so no sentence has been imposed on the single count. In the Netherlands, Alexey Pertsev was convicted in May 2024 and sentenced to 64 months, then conditionally released in February 2025 to prepare a pending appeal. The boundary is being drawn case by case rather than announced in advance, which is why counsel in the relevant jurisdiction matters more than any general summary.

The two positions side by side

The argument is easier to follow when the strongest version of each side is stated on the same issue rather than in separate places. The table pairs them without endorsing either, summarising positions taken in public debate rather than stating what the law requires.

Issue Case for regulating the tool Case against
Who the intermediary is Developers, promoters and relayers perform functions the framework assigns to intermediaries The contracts have no owner and cannot refuse or identify a user
Traceability Defeating the trail disables the reporting duties the system relies on Financial privacy is an ordinary expectation, not evidence of wrongdoing
Scale of misuse Treasury asserted very large laundered volumes, including Lazarus Group funds Those figures are contested and aggregate lawful with unlawful use
Fit with existing law A jury found conduct around the project reachable under money transmission law A court held the immutable contracts themselves could not be designated at all
Effect of enforcement Liability deters building tools whose predictable use is laundering Liability may fall on publishing code rather than on the people misusing it

Reading across the rows shows why neither side simply wins. Each column contains a claim the other has to answer rather than dismiss, and the unresolved cases are where those answers are being worked out.

Frequently asked questions

Are cash transactions treated the same way as on-chain privacy?

Not quite, and the comparison is where much of the argument sits. Cash is untraceable at the point of exchange but is constrained by physical limits and by reporting thresholds where it enters the banking system, whereas on-chain tools operate at digital scale with no equivalent friction.

Does writing or publishing code create legal exposure by itself?

That question is genuinely unsettled and is one of the sharpest disputes in this area. Prosecutions have focused on conduct alleged around a project rather than on publication in the abstract, but no court has drawn the boundary cleanly, so anyone in that position needs qualified counsel.

Do other countries regulate privacy tooling the same way?

No. Regimes differ substantially in how they define a regulated service and what they expect of developers, and a Dutch prosecution proceeded on national law independently of the US position. Readers outside the United States should treat their own national framework as the governing one.

Did the March 2025 delisting settle the regulatory question?

No. Removing a name from a sanctions list changes that list and nothing else, leaving money transmission, money laundering and other criminal statutes untouched. Financial institutions also continued applying risk-based controls to mixer-associated funds, because those controls never depended on list membership.

Leave a Comment

Your email address will not be published. Required fields are marked *