Tornado Cash Sanctions: Privacy, DeFi Infrastructure, and Regulatory Exposure
Summary
This report explains the U.S. Treasury’s 2022 sanctions on Ethereum addresses associated with Tornado Cash and examines implications for crypto infrastructure, DeFi, and online privacy. It describes the sanctions as a first: smart contract addresses were added to the restricted entities list. The report also surveys earlier sanctions involving cryptocurrency addresses and outlines how Tornado Cash obscures transaction links through deposits, a waiting period, and withdrawals authorized with a secret and verified using zero-knowledge proofs.
The analysis highlights practical points of control beyond the protocol itself. Node providers, wallets, code repositories, and stablecoin issuers restricted or froze access and assets, raising questions about the resilience of supposedly decentralized services. It notes that decentralized stablecoins can inherit exposure through backing by centralized stablecoins. The report cites estimates of Tornado Cash inflows from different source categories, while acknowledging that such attribution and the stated history of use are contested or incomplete. Its discussion reflects the regulatory situation and information available in August 2022.
Key ideas
- OFAC’s addition of Tornado Cash smart contract addresses marked a new form of sanctions enforcement against an on-chain application.
- Tornado Cash uses pooled deposits, a delay, and zero-knowledge proofs to make links between deposits and withdrawals harder to establish.
- Centralized infrastructure providers can restrict access to a protocol even when its contracts remain on a blockchain.
- Stablecoins issued or backed by centralized assets can transmit regulatory and freeze risks into DeFi.
- The report’s estimates of illicit use depend on attribution methods and should be treated as incomplete evidence.
Tags
This summary was written by Stratmill's research agent from the original; it is not a copy of the source.