Skip to main content

This site is for educational purposes only. Nothing here constitutes financial advice.

Topic 98 of 179

Tornado Cash Mechanics and OFAC Context

How Tornado Cash's Merkle tree deposit-and-mix architecture worked, the August 2022 OFAC sanctions, the 2024 Van Loon ruling and the March 2025 delisting, and the broader question of sanctioning immutable smart contracts.

Beginner
8 min readUpdated July 2026Block Clarity Hub Editorial Team

What Tornado Cash Did

Tornado Cash was a smart-contract-based privacy protocol on Ethereum. Users deposited fixed denominations (0.1, 1, 10, 100 ETH; various USDC amounts) into the protocol; later, they withdrew the same denomination to a different address, breaking the on-chain link between deposit and withdrawal. Between deposit and withdrawal, the funds mixed with other users' deposits in the same denomination. The privacy came from the anonymity set — many users depositing and withdrawing the same denomination made it hard to link specific deposits to specific withdrawals.

Why the Design Worked

The protocol used a Merkle tree to track deposits. When you deposited, your commitment (hash of a secret) was added to the tree. When you withdrew, you proved you knew a secret that hashed to one of the commitments in the tree — without revealing which commitment. This ZK proof let you withdraw without linking to your specific deposit. The math was elegant. The fixed denominations meant every withdrawal looked identical to every other, maximising the anonymity set.

August 2022 OFAC Sanctions

August 8, 2022: OFAC designated Tornado Cash smart contract addresses as SDN-listed entities. This meant US persons couldn't interact with the contracts under sanctions law. The action was novel — sanctioning a smart contract (immutable code, not a company) was legally unprecedented. Multiple developers were subsequently arrested (Alexey Pertsev in Netherlands, others). The community and legal advocacy pushed back; the 5th Circuit ruled in November 2024 that OFAC exceeded its authority (Van Loon v. Treasury), and on March 21, 2025 the Treasury formally removed the Tornado Cash smart contracts and front-end from the SDN list — so the sanctions on the protocol itself are no longer in effect. Individually-sanctioned developers and ongoing criminal cases remain, so the broader legal landscape stays complex.

  • Deposit + delay + withdraw pattern with ZK proof unlinking
  • Fixed denominations maximised anonymity set
  • August 2022 OFAC SDN designation was novel legal step
  • Van Loon ruling (Nov 2024) + Treasury delisting (Mar 2025) removed the protocol sanctions

Key Takeaways

  • Tornado Cash used Merkle tree + ZK proofs to enable private mixing
  • Fixed denominations were critical to anonymity set size
  • August 2022 OFAC action was legally unprecedented
  • Van Loon (2024) + the March 2025 delisting ended the sanctions on the protocol itself

Related Content

The Four-Year Crypto Cycle

The empirical history of Bitcoin's roughly four-year boom-bust cycles, the halving-driven structural explanation, and the debate about whether the cycle pattern persists in the institutional era.

Halving Market Behaviour

How Bitcoin price has actually behaved around halvings (2012, 2016, 2020, 2024), the structural reasons behind the patterns, and what to expect from the 2028 halving.

Monero Privacy — Deep Dive

How Monero's ring signatures, stealth addresses, and Bulletproof range proofs combine to provide default-on privacy for every transaction, and the regulatory pressures the project faces.

Zcash Architecture

How Zcash uses zk-SNARKs to enable optional shielded transactions, why Sapling was the breakthrough that made shielded pool usage practical, and how Halo2 removed the trusted setup.

Aztec and Railway — Ethereum Privacy Layers

How Aztec's zkRollup and Railway's stealth-address system approach privacy on Ethereum from different architectural angles, and what shipping ZK-based Ethereum privacy actually looks like.

Lightning Network — Deep Dive

How Lightning's payment channels enable instant Bitcoin transactions, the routing challenges that shape the network's topology, and why LN adoption has grown more slowly than early forecasts suggested.

Liquid Network

How Liquid is a Bitcoin sidechain with faster settlement, confidential transactions, and asset issuance — and where it fits in the Bitcoin scaling ecosystem alongside Lightning.

Validium, Plasma, and State Channels

The scaling designs that lost to rollups — Validium (off-chain data), Plasma (mass exit games), and state channels (bilateral off-chain) — and why understanding them helps make sense of current rollup design.

References & further reading