On this page
On August 8, 2022, the US Treasury sanctioned a piece of software — not a person, not a company, but a set of immutable smart contracts. Then a developer went to prison for writing that software. The Tornado Cash case is the strangest and most consequential crypto legal dispute to date: it tests whether privacy-preserving code is speech, whether immutable code can be “sanctioned,” and whether writing a tool that criminals also use makes you a criminal. The outcome shapes what privacy is allowed to look like on a public blockchain.
What Tornado Cash actually is
Tornado Cash is a — a smart contract that breaks the link between sender and recipient. The mechanism (simplified) is a zero-knowledge shielded pool:
- Deposit. You deposit, say, 1 ETH into the contract. The contract records a commitment (a hash of your secret + a nullifier). Your ETH joins a pool with everyone else's ETH of that denomination.
- Withdraw. Later, from a fresh address, you submit a proof that you know a secret corresponding to an unspent commitment — without revealing which one. The contract verifies the proof, sends you 1 ETH from the pool, and records the nullifier so the same commitment can't be spent twice.
The result: the ETH you withdraw is statistically unlinked from the ETH you deposited. Anyone watching the chain sees a deposit and a withdrawal, but cannot prove they're the same person. The cryptographic guarantees come from the ZK proof and the anonymity set (the larger the pool, the harder the link).
Crucially, the deployed contracts are immutable and permissionless: no admin key, no operator, no way to pause or shut them down. The deployers renounced control. This is the technical fact that makes the legal case strange — there is no “Tornado Cash Inc.” to sanction, only code running on a decentralized computer.
The timeline
Tap any event to expand its story.
The Tornado Cash smart contracts are deployed on Ethereum by a pseudonymous developer team. The core contracts are open-source and immutable; no admin keys, no upgrade path, no operator who can pause the system.
Tornado Cash becomes the most-used Ethereum mixer. Legitimate users (privacy-conscious individuals, charities, salary recipients) mix alongside the Lazarus Group and other attackers, who launder billions in stolen funds through the contracts.
The US Treasury’s OFAC adds Tornado Cash (including its smart contract addresses) to the Specially Designated Nationals list. US persons are prohibited from transacting with it. The sanctions list the code, not just a company.
Days after the sanctions, Tornado Cash developer Alexey Pertsev is arrested in the Netherlands, accused of facilitating money laundering by writing the code. The arrest sparks a debate about whether writing code can be a crime.
Coin Center and others sue the Treasury, arguing that sanctioning immutable code exceeds OFAC’s authority. In the US, a district court upholds the sanctions in 2023; on appeal, the Fifth Circuit rules in November 2024 that the immutable smart contracts are not “property” OFAC can sanction.
A Dutch court convicts Pertsev of money laundering and sentences him to 64 months. The verdict is the first criminal conviction of a developer for writing privacy-preserving smart contracts.
Why it was sanctioned
OFAC's justification was straightforward: the Lazarus Group (North Korean state hackers) and other criminal actors had laundered billions of dollars through Tornado Cash, including proceeds from major hacks (Ronin, Harmony, Nomad — see the Bridge Hacks deep dive). The Treasury argued that by mixing those funds, Tornado Cash “facilitated” sanctions evasion and money laundering, and that sanctioning it would cut off the laundering channel.
The immediate effect was chaotic. The sanctioned contract addresses were added to OFAC's SDN list. US persons — including, the Treasury initially implied, the users of the contracts — were prohibited from transacting with them. Some DeFi frontends blocked any wallet that had ever interacted with Tornado Cash. Innocent users who had used Tornado Cash for privacy (not crime) found their wallets effectively de-banked across the Ethereum ecosystem.
Why the case is legally strange
Three features of the Tornado Cash case make it unlike any previous sanctions action:
- Sanctioning code, not an entity. OFAC has sanctioned wallets and exchanges before. It had never sanctioned a piece of self-executing software running on a decentralized network — code that no one can turn off.
- Immutable contracts aren't “property.” OFAC's authority to sanction comes from laws aimed at “property” in which a foreign person has an interest. If no one controls an immutable contract, no one has an interest in it — so the legal theory that animated the sanctions has been challenged. A US district court upheld the sanctions in 2023, but on appeal the Fifth Circuit ruled in November 2024 that the immutable Tornado Cash contracts are not “property” that OFAC can sanction; the Treasury then delisted them in March 2025.
- The developer prosecution. Alexey Pertsev was convicted in the Netherlands in 2024 of money laundering for writing the code. The court treated the open-source, immutable contract as a tool that “facilitated” crime, and held its author criminally responsible. This is a novel theory: it would be like holding the author of TLS liable for criminals using encrypted connections.
Privacy, crime, and the “dual-use” problem
The substantive question beneath the legal procedure is older than crypto: can a privacy tool be illegal because criminals use it? The cypherpunk answer is that privacy is a prerequisite for a free society, that cash has always provided it, and that the on-chain surveillance made possible by public blockchains is unprecedented (see the Cypherpunks deep dive). The law-enforcement answer is that, in practice, “privacy tools” on a public chain are dominated by criminal use, and that the legitimate users' loss is small compared to the harm of unchecked money laundering.
Both sides describe a real trade-off. On-chain analysis (see the Tracing module) does enable a level of financial surveillance that cash never did, and Tornado Cash's legitimate uses — shielding salaries, protecting dissidents, preventing front-running of large trades — are real. At the same time, the mixing pool was demonstrably used to launder billions in stolen funds, and the “it's just code” defense strains credulity when applied to a tool whose stated purpose is to make funds untraceable. There is no clean answer, which is why the case matters: whatever courts and legislatures decide will define what on-chain privacy is allowed to look like for a generation.
The state of play in 2026
Two major shoes dropped after the sanctions. First, the courts: in November 2024 the Fifth Circuit ruled that the immutable Tornado Cash contracts are not “property” OFAC can sanction, and on March 21, 2025 the Treasury delisted Tornado Cash — the sanctions are no longer in effect. Second, the developers: after his August 2023 arrest, co-founder Roman Storm went to trial and was convicted in August 2025 on one of the three counts he faced — conspiracy to operate an unlicensed money transmitting business. Meanwhile, Pertsev's Dutch conviction is on appeal, and forks and successors of Tornado Cash (including protocols designed to resist the specific legal theories used against it) continue to deploy. The fundamental question — whether open-source, immutable privacy-preserving smart contracts can be outlawed — has not been finally answered by any court, even though the sanctions themselves have fallen.
For the wider intersection of crypto, sanctions, and state power, see the Crypto & Nation-States deep dive and the Regulation module.
Key takeaways
- Tornado Cash is a privacy mixer: a set of immutable, permissionless smart contracts that use zero-knowledge proofs and shielded pools to break the on-chain link between depositor and withdrawer. No admin key, no operator, no shutdown path.
- In August 2022, OFAC sanctioned the contracts themselves — the first time the US sanctioned a piece of self-executing software. The move de-banked innocent users alongside criminals and triggered lawsuits over whether immutable code can be “property” subject to sanctions.
- In May 2024, developer Alexey Pertsev was convicted in the Netherlands of money laundering for writing the code — the first criminal conviction of a developer for writing privacy-preserving smart contracts. The verdict is on appeal.
- The case turns on the dual-use problem: privacy tools protect dissidents and ordinary users and launder stolen funds. There is no clean resolution; the outcome will shape what on-chain privacy is allowed to look like for years.
- The sanctions did not last: after the Fifth Circuit's November 2024 ruling, Treasury delisted Tornado Cash on March 21, 2025 — but the developer prosecutions (Pertsev's Dutch appeal; Storm's US conviction) continue to shape what on-chain privacy is allowed to look like. For the wider landscape, see the Crypto & Nation-States deep dive.