AMLConsensus · course
Programme · Lesson 11.5
Section 11 · Lesson 11.5 · case study

Sanctions Against Tornado Cash: When Code Fell Under Sanctions

Sanctions are usually imposed on people, companies, or countries — on those who can be arrested, fined, or coerced into something. But in the summer of 2022 the United States did what it had never done before: it added a program to the sanctions list. Not a person, not a firm, but a set of smart contracts — autonomous code running on the blockchain on its own. Thus began the story of Tornado Cash — a case that wove together the laundering of Lazarus's billions, a fundamental dispute about the right to privacy, and the legal "gray zone" we are still in to this day.

▶ Video case study: the Tornado Cash sanctions (English narration).

August 2022: an unprecedented decision

In August 2022 OFAC (the U.S. Treasury's Office of Foreign Assets Control) imposed sanctions on Tornado Cash — the most well-known mixer on the Ethereum network. We have already examined the mechanics of mixers: Tornado accepts deposits in fixed denominations (0.1 / 1 / 10 / 100 ETH), mixes them in a common pool, and lets funds be withdrawn to a new address, cryptographically breaking the "input↔output" link.

The uniqueness of the sanctions was not in what was sanctioned, but in what the object of the sanctions is. Tornado Cash is not a company with an office and a director. It is a set of autonomous smart contracts that, once published, run on their own, without an operator who could be "switched off." For the first time in history, a smart contract fell under sanctions rather than a person or an organization. This raised a question to which there is still no single answer: how do you sanction code that answers to no one and that can neither be arrested nor stopped?

Sanctioned Tornado Cash mixer address

The Tornado Cash smart contract in a blockchain explorer: uniform deposits of a fixed denomination and a sanctions label. It is precisely this kind of autonomous code that became the object of OFAC sanctions.

The Ronin connection: why Tornado specifically

The sanctions against Tornado Cash did not arise out of nowhere. As we saw in the Ronin case study, it was precisely through Tornado Cash that the Lazarus group laundered the stolen $625M. The mixer was a key link in the laundering conveyor of the North Korean hackers — and in their other operations too. From the U.S. point of view, a tool systematically used to launder the money of a hostile regime's state cyber group represents a national security threat, regardless of whether it is a "live" operator or autonomous code.

Lazarus thefts
Ronin $625M and others
Tornado Cash
laundering in a common pool
OFAC sanctions
August 2022: code in the SDN list

The privacy dispute: two truths

Here the case stops being purely technical and turns into a philosophical dispute that split the community. The problem with Tornado Cash is that privacy is a double-edged tool.

On one side is the obvious evil: the mixer is ideally suited to laundering stolen goods, and Lazarus actively used it. On the other side, privacy has entirely legitimate uses. The public nature of the blockchain is not only a boon for investigators but also a problem for the ordinary user: if someone knows your address, they see your entire balance and your whole transaction history. Not everyone wants their salary, donations, or purchases visible to the whole world.

The most well-known argument in defense of such use was made by Vitalik Buterin, co-founder of Ethereum. He publicly stated that he himself used Tornado Cash for anonymous donations to Ukraine. The logic is simple: had he donated from an open address linked to his name, it could have exposed the recipients and put them at risk. This is a vivid example of the fact that privacy is needed not only by criminals but also by people with entirely legal motives.

Vitalik Buterin publicly acknowledged that he used Tornado Cash for anonymous donations to Ukraine — as an example of a legitimate use of privacy.

— Vitalik Buterin's public position (paraphrase)

Thus arises a dilemma that has no simple solution. Banning the tool entirely means punishing legitimate users for the sins of criminals. Allowing it means leaving open a laundering channel for Lazarus. It is precisely on this contradiction that all the legal uncertainty around mixers rests.

2024: the court limits the sanctions

The legal vulnerability of OFAC's decision showed itself in court. The sanctions against autonomous code triggered lawsuits: critics argued that you cannot sanction a program the same way you sanction a person or a company, since a smart contract has no "owner" to whom the restrictions apply, and that this affects the rights of law-abiding users.

In 2024 a court limited part of the sanctions, marking out that very legal "gray zone." This is not about laundering suddenly becoming legal, but about a subtler question: whether existing sanctions mechanisms are applicable, in their original form, to autonomous code. The exact boundary between "sanctioning an organization" and "sanctioning lines of code" turned out to be legally unclear — and this dispute continues.

Don't get it mixed up. The court's 2024 limitation of part of the sanctions is not an indulgence for mixers. From the standpoint of practical AML screening, the passage of funds through Tornado Cash remains a red flag of maximum strength: the money's history is severed, its origin cannot be confirmed. The legal dispute is about how the state should properly frame sanctions against autonomous code, not about "mixed" funds having become clean. For compliance, the risk has gone nowhere.

What this means for screening practice

The Tornado Cash case is the ideal conclusion to the section on high-profile cases, because it ties together almost everything we have studied.

What this case teaches. Tornado Cash shows that cryptocurrency regulation has entered uncharted territory: for the first time, autonomous code that cannot be arrested or switched off fell under sanctions. It is at once a powerful tool against laundering (it was precisely through Tornado that Lazarus laundered) and the subject of a real dispute about the right to privacy, which has legitimate uses — such as the anonymous donations to Ukraine that Vitalik Buterin spoke of. The court's 2024 limitation of part of the sanctions outlined a "gray zone" but did not overturn the practical takeaway for screening: any contact of a wallet with a mixer is a red flag of the maximum, because it is impossible to confirm the cleanliness of a severed history. The AML specialist must keep both sides in mind: both the legal subtlety and the hard practice of risk.

What to take away from this lesson

  • PrecedentAugust 2022: OFAC sanctioned a smart contract (Tornado Cash) for the first time, rather than a person or a company.
  • The Ronin connectionIt was precisely through Tornado Cash that Lazarus laundered the stolen funds — and this became the pretext for the sanctions.
  • The privacy disputeVitalik Buterin acknowledged using Tornado for anonymous donations to Ukraine — an example of a legitimate use.
  • The gray zoneIn 2024 a court limited part of the sanctions; the legal question of sanctions against autonomous code remains open, but the mixer risk for AML does not.

With this we close the block of modern cases. In the next case study we will return to the origins — to the collapse of the Mt.Gox exchange in 2014 and to the story of how independent researchers, over years, unraveled the disappearance of 850,000 bitcoin piece by piece.

The facts are presented from open sources. The materials are for educational purposes.