Sanctions are usually imposed on people, companies, or countries — on those who can be arrested, fined, or coerced into something. But in the summer of 2022 the United States did what it had never done before: it added a program to the sanctions list. Not a person, not a firm, but a set of smart contracts — autonomous code running on the blockchain on its own. Thus began the story of Tornado Cash — a case that wove together the laundering of Lazarus's billions, a fundamental dispute about the right to privacy, and the legal "gray zone" we are still in to this day.
▶ Video case study: the Tornado Cash sanctions (English narration).
In August 2022 OFAC (the U.S. Treasury's Office of Foreign Assets Control) imposed sanctions on Tornado Cash — the most well-known mixer on the Ethereum network. We have already examined the mechanics of mixers: Tornado accepts deposits in fixed denominations (0.1 / 1 / 10 / 100 ETH), mixes them in a common pool, and lets funds be withdrawn to a new address, cryptographically breaking the "input↔output" link.
The uniqueness of the sanctions was not in what was sanctioned, but in what the object of the sanctions is. Tornado Cash is not a company with an office and a director. It is a set of autonomous smart contracts that, once published, run on their own, without an operator who could be "switched off." For the first time in history, a smart contract fell under sanctions rather than a person or an organization. This raised a question to which there is still no single answer: how do you sanction code that answers to no one and that can neither be arrested nor stopped?

The Tornado Cash smart contract in a blockchain explorer: uniform deposits of a fixed denomination and a sanctions label. It is precisely this kind of autonomous code that became the object of OFAC sanctions.
The sanctions against Tornado Cash did not arise out of nowhere. As we saw in the Ronin case study, it was precisely through Tornado Cash that the Lazarus group laundered the stolen $625M. The mixer was a key link in the laundering conveyor of the North Korean hackers — and in their other operations too. From the U.S. point of view, a tool systematically used to launder the money of a hostile regime's state cyber group represents a national security threat, regardless of whether it is a "live" operator or autonomous code.
Here the case stops being purely technical and turns into a philosophical dispute that split the community. The problem with Tornado Cash is that privacy is a double-edged tool.
On one side is the obvious evil: the mixer is ideally suited to laundering stolen goods, and Lazarus actively used it. On the other side, privacy has entirely legitimate uses. The public nature of the blockchain is not only a boon for investigators but also a problem for the ordinary user: if someone knows your address, they see your entire balance and your whole transaction history. Not everyone wants their salary, donations, or purchases visible to the whole world.
The most well-known argument in defense of such use was made by Vitalik Buterin, co-founder of Ethereum. He publicly stated that he himself used Tornado Cash for anonymous donations to Ukraine. The logic is simple: had he donated from an open address linked to his name, it could have exposed the recipients and put them at risk. This is a vivid example of the fact that privacy is needed not only by criminals but also by people with entirely legal motives.
Vitalik Buterin publicly acknowledged that he used Tornado Cash for anonymous donations to Ukraine — as an example of a legitimate use of privacy.
— Vitalik Buterin's public position (paraphrase)
Thus arises a dilemma that has no simple solution. Banning the tool entirely means punishing legitimate users for the sins of criminals. Allowing it means leaving open a laundering channel for Lazarus. It is precisely on this contradiction that all the legal uncertainty around mixers rests.
The legal vulnerability of OFAC's decision showed itself in court. The sanctions against autonomous code triggered lawsuits: critics argued that you cannot sanction a program the same way you sanction a person or a company, since a smart contract has no "owner" to whom the restrictions apply, and that this affects the rights of law-abiding users.
In 2024 a court limited part of the sanctions, marking out that very legal "gray zone." This is not about laundering suddenly becoming legal, but about a subtler question: whether existing sanctions mechanisms are applicable, in their original form, to autonomous code. The exact boundary between "sanctioning an organization" and "sanctioning lines of code" turned out to be legally unclear — and this dispute continues.
The Tornado Cash case is the ideal conclusion to the section on high-profile cases, because it ties together almost everything we have studied.
With this we close the block of modern cases. In the next case study we will return to the origins — to the collapse of the Mt.Gox exchange in 2014 and to the story of how independent researchers, over years, unraveled the disappearance of 850,000 bitcoin piece by piece.
The facts are presented from open sources. The materials are for educational purposes.