|=[ DEEP DIVE :: PROTOCOL FILE 003 ]=

TORNADO CASH

TORNADO CASH · IMMUTABLE

The canonical non-custodial mixer on Ethereum: fully decentralized, immutable contracts that break the onchain link between deposit and withdrawal using zk-SNARKs. Deployed December 2019, and currently at the centre of the defining legal fight over whether autonomous code can be sanctioned.

MAINNET ZK IMMUTABLE FIXED DENOMINATIONS DELISTED 03.2025

DEPLOYED — 12.2019 · ETHEREUM MAINNET

$578.3M
TVL
≈ 304,000 ETH equiv.
~$7.6B
Lifetime volume
pre-sanction, per forensic analyses
21.03.25
OFAC delisted
sanctioned 08.08.2022
0.1–100
ETH pool ladder
+ DAI · USDC · USDT · WBTC
1,114
Trusted-setup contributions
MPC ceremony, 05.2020

DEFILLAMA

DEPLOYED 12.2019 CORE CONTRACTS IMMUTABLE CHAINS MAINNET + 6 GOVERNANCE EFFECTIVELY FROZEN SINCE 2023 RELAYERS THIN BUT LIVE US SANCTIONS DELISTED 21.03.2025 *the core ETH/ERC-20 pools are non-upgradeable; TORN governance and the frontends are separate, mutable layers; a distinction that decided a federal case

ONE NOTE, ONE PROOF, NO LINK

Every deposit in a pool is identical, and uses zk-SNARK to withdraw yours without revealing your deposit.

01 Deposit.

Pick a pool: a fixed size, 0.1 / 1 / 10 / 100 ETH or an ERC-20 ladder. Your wallet generates a secret note locally; only its hash (the commitment) goes onchain, into the pool's Merkle tree.

02 Wait.

The anonymity set is every unspent deposit in the pool; withdrawing minutes after depositing, when yours is one of few, largely defeats the purpose. Patience is a protocol feature here.

03 Prove.

To withdraw, your browser builds a Groth16 zk-SNARK: this note's commitment is in the tree, and its nullifier hasn't been spent. The proof reveals nothing about which deposit is yours.

04 Withdraw.

To a fresh address. Because a fresh address has no ETH for gas, a relayer can submit the transaction for a fee taken from the withdrawal. The relayer never sees or controls your secret.

THE FLOW

NOTES ARE STILL MONEY

The note is the only credential that can ever withdraw the deposit. Lose it and the funds are gone; leak it and they're someone else's. There is no account, no recovery, no support desk; that's what non-custodial means here.

The pre-sanction UI also included a compliance tool: with your note you could generate a report proving the origin of a specific withdrawal, a primitive ancestor of the proof-of-innocence idea Privacy Pools later formalized.

TRADE OFFS

The cryptography held; the crowds and the stewardship didn't:

THE SET IS THIN TODAY

A mixer's privacy IS its crowd, and usage never durably rebounded after the sanction era; today's activity is a small fraction of the 2021–22 peak (per an October 2025 arXiv study and CertiK's 2025 reporting). The contracts and the maths are unchanged, but a smaller crowd means weaker practical privacy than the design promises.

METADATA HEURISTICS

Every documented deanonymization came from metadata heuristics: timing correlation, denomination sequences, address reuse, careless funding of the withdrawal address. The protocol hides the deposit-withdrawal link; your habits around it are what an analyst reads.

NO STEWARD AT THE WHEEL

There is no core team, governance has been effectively frozen since a 2023 takeover of the DAO's upgradable layer, and the UIs are community-run. The immutable pools were untouched by both that incident and a 2024 frontend compromise; the lesson stated as a property: protocol immutability ≠ frontend safety. Verify the frontend you use, or use the CLI.

Support pcaversaccio and his drive to lock Tornado Cash governance.

THE COMPLIANCE REALITY

Delisted or not, Chainalysis, TRM and Elliptic still flag Tornado-touched funds, and regulated venues treat them accordingly. Expect friction depositing withdrawn funds at exchanges. This is exactly the problem the successor generation set out to solve; see below.

WHAT CAME AFTER

The 2025–26 generation exists precisely because of Tornado's failure mode: keep the privacy, screen out the illicit funds, prove innocence without deanonymizing.

PRIVACY POOLSSUCCESSOR

The direct ideological successor: the same zk deposit-withdraw model plus association sets: withdrawals prove membership in a screened set of clean deposits, and rejected deposits can always exit via ragequit. Mainnet 31.03.2025; Vitalik deposited on day one.

RAILGUNSUCCESSOR

The shielded-balance answer: arbitrary amounts, private DeFi, and Private Proofs of Innocence (11.2023): prove shielded funds aren't from known illicit sources without revealing anything else. Where Tornado had a compliance tool bolted onto the UI, Railgun made assurance protocol-level.

START HERE

THE CONTRACTSUSE

The pools are immortal on mainnet and can't be turned off. Frontends are community-run (IPFS/ENS mirrors); verify what you're using, or skip UIs entirely with tornado-cli. And mind step 02: the wait and your metadata discipline do the real work.

DOCS & CODEREAD

The community GitBook covers the protocol; tornado-core has the contracts, the withdraw circuit and the whitepaper; all restored to the original GitHub org after the delisting. Audited by ABDK (crypto, contracts and circuits).

KNOW THE CONTEXTFIRST

Read the legal arc above before using it, know your local rules, and understand that regulated venues still flag Tornado-touched funds. For most 2026 use cases the successor protocols give you the privacy with far less friction.

Evaluating Tornado Cash but not sure if it fits your product? Talk to Ben.

TALK TO BEN →

FILE UNDER — DEEP DIVES

NEXT READS

KOHAKU the EF wallet stack after the PSE shutdown CLOAKED — STEALTH WALLET receiving-first wallet: a fresh stealth address per payment, Privacy Pools to spend FILEVERSE E2E-encrypted, local-first docs and sheets from the Ethereum ecosystem

DEEP DIVES · RESEARCH · WORK WITH ME