The direct ideological successor: the same zk deposit-withdraw model plus association sets: withdrawals prove membership in a screened set of clean deposits, and rejected deposits can always exit via ragequit. Mainnet 31.03.2025; Vitalik deposited on day one.
|=[ DEEP DIVE :: PROTOCOL FILE 003 ]=
TORNADO CASH
TORNADO CASH · IMMUTABLEThe canonical non-custodial mixer on Ethereum: fully decentralized, immutable contracts that break the onchain link between deposit and withdrawal using zk-SNARKs. Deployed December 2019, and currently at the centre of the defining legal fight over whether autonomous code can be sanctioned.
DEPLOYED — 12.2019 · ETHEREUM MAINNET
DEFILLAMA
ONE NOTE, ONE PROOF, NO LINK
Every deposit in a pool is identical, and uses zk-SNARK to withdraw yours without revealing your deposit.
Pick a pool: a fixed size, 0.1 / 1 / 10 / 100 ETH or an ERC-20 ladder. Your wallet generates a secret note locally; only its hash (the commitment) goes onchain, into the pool's Merkle tree.
The anonymity set is every unspent deposit in the pool; withdrawing minutes after depositing, when yours is one of few, largely defeats the purpose. Patience is a protocol feature here.
To withdraw, your browser builds a Groth16 zk-SNARK: this note's commitment is in the tree, and its nullifier hasn't been spent. The proof reveals nothing about which deposit is yours.
To a fresh address. Because a fresh address has no ETH for gas, a relayer can submit the transaction for a fee taken from the withdrawal. The relayer never sees or controls your secret.
THE FLOW
NOTES ARE STILL MONEY
The note is the only credential that can ever withdraw the deposit. Lose it and the funds are gone; leak it and they're someone else's. There is no account, no recovery, no support desk; that's what non-custodial means here.
The pre-sanction UI also included a compliance tool: with your note you could generate a report proving the origin of a specific withdrawal, a primitive ancestor of the proof-of-innocence idea Privacy Pools later formalized.
THE LEGAL ARC
The defining legal story in onchain privacy, stated factually.
Donate to Roman Storm and Alexey Pertsev.
Where things stand: using the contracts is no longer a US sanctions violation per se, but delisted ≠ exonerated. Laundering criminal proceeds through a mixer is still laundering everywhere, most forensics tools still flag Tornado-touched funds. Developer liability is still ongoing: Pertsev appealing, Storm awaiting retrial, Semenov at large and still sanctioned.
The Ethereum Foundation are bringing Tornado Cash back into the spotlight, with their Kohaku initiative.
| DATE | WHAT HAPPENED |
|---|---|
| 08.08.2022 | OFAC adds Tornado Cash to the SDN list, the first-ever sanctioning of autonomous code. Frontend seized, GitHub org suspended, USDC in pools blacklisted. |
| 08.2023 | SDNY indicts developers Roman Storm and Roman Semenov on money-laundering, sanctions and §1960 conspiracy counts. |
| 14.05.2024 | Dutch court convicts developer Alexey Pertsev of money laundering: 64 months. Released to electronic monitoring 02.2025; appeal pending as of 07.2026. |
| 26.11.2024 | Fifth Circuit reverses in Van Loon v. Treasury: immutable smart contracts are not "property" under IEEPA; no one can own, control or alter them, so OFAC exceeded its authority. The holding covers only the immutable pools; frontends and upgradable layers sit outside it. |
| 21.03.2025 | OFAC formally delists Tornado Cash: frontend and 100+ contract addresses removed from the SDN list. Semenov stays individually listed. Treasury reserved the right to re-designate under another theory. |
| 06.08.2025 | Storm verdict, SDNY: convicted on one count (conspiracy to operate an unlicensed money-transmitting business, §1960); hung jury on the two 20-year counts. Sentencing not yet held. |
| 04.2026 | Retrial on the hung counts set for 26.10.2026, contingent on a pending Rule 29 acquittal motion. 66 organisations petitioned DOJ to drop the case. |
TRADE OFFS
The cryptography held; the crowds and the stewardship didn't:
THE SET IS THIN TODAY
A mixer's privacy IS its crowd, and usage never durably rebounded after the sanction era; today's activity is a small fraction of the 2021–22 peak (per an October 2025 arXiv study and CertiK's 2025 reporting). The contracts and the maths are unchanged, but a smaller crowd means weaker practical privacy than the design promises.
METADATA HEURISTICS
Every documented deanonymization came from metadata heuristics: timing correlation, denomination sequences, address reuse, careless funding of the withdrawal address. The protocol hides the deposit-withdrawal link; your habits around it are what an analyst reads.
NO STEWARD AT THE WHEEL
There is no core team, governance has been effectively frozen since a 2023 takeover of the DAO's upgradable layer, and the UIs are community-run. The immutable pools were untouched by both that incident and a 2024 frontend compromise; the lesson stated as a property: protocol immutability ≠ frontend safety. Verify the frontend you use, or use the CLI.
Support pcaversaccio and his drive to lock Tornado Cash governance.
THE COMPLIANCE REALITY
Delisted or not, Chainalysis, TRM and Elliptic still flag Tornado-touched funds, and regulated venues treat them accordingly. Expect friction depositing withdrawn funds at exchanges. This is exactly the problem the successor generation set out to solve; see below.
WHAT CAME AFTER
The 2025–26 generation exists precisely because of Tornado's failure mode: keep the privacy, screen out the illicit funds, prove innocence without deanonymizing.
The shielded-balance answer: arbitrary amounts, private DeFi, and Private Proofs of Innocence (11.2023): prove shielded funds aren't from known illicit sources without revealing anything else. Where Tornado had a compliance tool bolted onto the UI, Railgun made assurance protocol-level.
START HERE
The pools are immortal on mainnet and can't be turned off. Frontends are community-run (IPFS/ENS mirrors); verify what you're using, or skip UIs entirely with tornado-cli. And mind step 02: the wait and your metadata discipline do the real work.
The community GitBook covers the protocol; tornado-core has the contracts, the withdraw circuit and the whitepaper; all restored to the original GitHub org after the delisting. Audited by ABDK (crypto, contracts and circuits).
Read the legal arc above before using it, know your local rules, and understand that regulated venues still flag Tornado-touched funds. For most 2026 use cases the successor protocols give you the privacy with far less friction.
Evaluating Tornado Cash but not sure if it fits your product? Talk to Ben.
TALK TO BEN →