{"id":23536,"date":"2022-08-09T18:02:13","date_gmt":"2022-08-09T18:02:13","guid":{"rendered":"https:\/\/davidgerard.co.uk\/blockchain\/?p=23536"},"modified":"2022-08-12T00:16:29","modified_gmt":"2022-08-12T00:16:29","slug":"us-sanctions-tornado-cash-and-crypto-shrieks-in-horror","status":"publish","type":"post","link":"https:\/\/davidgerard.co.uk\/blockchain\/2022\/08\/09\/us-sanctions-tornado-cash-and-crypto-shrieks-in-horror\/","title":{"rendered":"US sanctions Tornado Cash \u2014 and crypto shrieks in horror"},"content":{"rendered":"<p>Transactions on the Ethereum blockchain are completely traceable. Any transaction anyone ever made on Ethereum can be traced, all the way back to the launch of the project in 2015. Transactions are pseudonymous \u2014 but many users have been identified after the fact.<\/p>\n<p>Tornado Cash is a mixer \u2014 an Ethereum smart contract program that you can use to break the traceability of transactions on Ethereum. This is for privacy.<\/p>\n<p>Tornado Cash accepts deposits of ether (the currency on Ethereum) from one address and enables you to withdraw the ether from a different address. The smart contract works as a pool that mixes all deposits, using zero-knowledge proofs.<\/p>\n<p>If the ether is proceeds from a crime, then this is literally just money laundering.<\/p>\n<p>Tornado Cash was also used heavily by North Korea\u2019s Lazarus Group to launder stolen ether and help the country get hard currency.<\/p>\n<p>In what should come as no surprise to anyone whatsoever, Tornado Cash has been sanctioned by the US Office of Foreign Asset Control. [<a href=\"https:\/\/home.treasury.gov\/news\/press-releases\/jy0916\"><i>Treasury<\/i><\/a><i>; <\/i><a href=\"https:\/\/home.treasury.gov\/policy-issues\/financial-sanctions\/recent-actions\/20220808\"><i>Treasury<\/i><\/a>]<\/p>\n<p>This follows <a href=\"https:\/\/davidgerard.co.uk\/blockchain\/2022\/05\/15\/news-ust-fallout-central-african-republic-fallout-coinbase-custody-not-safe-in-bankruptcy-catalonia-and-russian-bitcoins\/\">previous sanctions on Blender.io,<\/a> another mixer, in May 2022 \u2014 also primarily because North Korea was using it. [<a href=\"https:\/\/home.treasury.gov\/news\/press-releases\/jy0768\"><i>Treasury<\/i><\/a>]<\/p>\n<p>OFAC posted a list of sanctioned Ethereum blockchain addresses \u2014 the addresses for the Tornado Cash smart contract.<\/p>\n<p>All ether that&#8217;s touched Tornado Cash is now tainted. US-touching crypto exchanges, such as Coinbase, will be expected to block tainted ether. Infura, the ConsenSys API that <a href=\"https:\/\/davidgerard.co.uk\/blockchain\/2022\/03\/04\/news-fca-versus-uk-crypto-infura-sanctions-on-ethereum-bitmex-reed-headed-for-trial-india\/\">almost all Ethereum transactions go through,<\/a> is also blocking ether that touched these addresses. Alchemy, a similar API, is doing the same. [<a href=\"https:\/\/cryptobriefing.com\/infura-alchemy-block-tornado-cash-following-treasury-ban\/\"><em>Crypto Briefing<\/em><\/a>] Circle, which issues the USDC stablecoin, has blacklisted all Tornado Cash addresses, and frozen 75,000 USDC. [<a href=\"https:\/\/cointelegraph.com\/news\/circle-freezes-blacklisted-tornado-cash-smart-contract-addresses\"><i>CoinTelegraph<\/i><\/a>]<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"https:\/\/davidgerard.co.uk\/blockchain\/2022\/08\/09\/us-sanctions-tornado-cash-and-crypto-shrieks-in-horror\/tornado_cash\/\" rel=\"attachment wp-att-23537\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-23537\" src=\"https:\/\/davidgerard.co.uk\/blockchain\/wp-content\/uploads\/2022\/08\/tornado_cash.png\" alt=\"\" width=\"340\" height=\"210\" srcset=\"https:\/\/davidgerard.co.uk\/blockchain\/wp-content\/uploads\/2022\/08\/tornado_cash.png 680w, https:\/\/davidgerard.co.uk\/blockchain\/wp-content\/uploads\/2022\/08\/tornado_cash-300x185.png 300w, https:\/\/davidgerard.co.uk\/blockchain\/wp-content\/uploads\/2022\/08\/tornado_cash-348x215.png 348w\" sizes=\"auto, (max-width: 340px) 100vw, 340px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<h3>But what about all the <i>good<\/i> uses?<\/h3>\n<p>Privacy is a perfectly reasonable thing to want. Quite a lot of Ethereum users just used Tornado Cash to keep their non-sanctioned dealings private. Vitalik Buterin, the founder of Ethereum, donated ether to Ukraine\u2019s defence against the Russian invasion via Tornado Cash. [<a href=\"https:\/\/twitter.com\/vitalikbuterin\/status\/1556925602233569280\"><i>Twitter<\/i><\/a>]<\/p>\n<p>The problem is that crypto mixing services are <a href=\"https:\/\/davidgerard.co.uk\/blockchain\/2019\/05\/09\/fincens-guidance-on-crypto-business-models-are-you-a-money-transmitter\/\">explicitly considered money transmitters by FinCEN.<\/a> So making the transaction trail untraceable by any entity is a violation of anti-money-laundering (AML) law.<\/p>\n<p>There\u2019s also this weird delusion that if you put some dirty money in a box with clean money and shake it, then it all comes out as clean \u2014 and not that it all comes out as dirty.<\/p>\n<p>Nobody worried <i>too<\/i> much when the money laundering was small-time and the really bad guys weren\u2019t hammering it.<\/p>\n<p>But Tornado Cash was the favoured mixer of North Korea\u2019s state-sponsored hackers. For example, the <a href=\"https:\/\/davidgerard.co.uk\/blockchain\/2022\/04\/02\/blockchain-bridges-how-the-smart-contract-pinata-works-and-why-bridges-keep-getting-hacked\/\">\u201c$620 million\u201d in ether stolen from Axie Infinity by North Korea<\/a> was run through Tornado Cash.<\/p>\n<p>Crypto compliance firm TRM Labs estimates that North Korea funneled out \u201c$1 billion\u201d face value of ether via Tornado Cash. Small-time crooks are also fond of Tornado Cash \u2014 \u201cover 41% of all funds deposited to Tornado Cash in June and July 2022 were tied to hacks and other thefts.\u201d [<a href=\"https:\/\/www.trmlabs.com\/post\/u-s-treasury-sanctions-widely-used-crypto-mixer-tornado-cash\"><i>TRM Labs<\/i><\/a>]<\/p>\n<h3>How seriously does the US take sanctions?<\/h3>\n<p>Serious as a heart attack.<\/p>\n<p>As Congress just straight-up told Mark Zuckerberg in the Libra hearings in 2019 (<a href=\"https:\/\/davidgerard.co.uk\/blockchain\/libra\/\"><i>Libra Shrugged<\/i><\/a>, chapter 13):<\/p>\n<blockquote><p>The US government is understandably fond of the US dollar \u2014 as Juan Vargas (D, CA-51) put it, \u201cthe dollar is very important to use as a tool of American power, and also a tool of American values. So we would much prefer to put sanctions on a country than send our soldiers there. So when something threatens the dollar, we get very nervous.\u201d<\/p><\/blockquote>\n<p>Sanctions are seen as part of the national defense. If you write a program that tries to cleverly work around this, then you make yourself a target.<\/p>\n<p>Tornado Cash was sanctioned precisely because it was North Korea&#8217;s favourite ether launderette, and couldn&#8217;t or wouldn&#8217;t stop North Korea from using it to cash out.<\/p>\n<p>Tornado Cash did try to block sanctioned entities! In April, the Tornado Cash front-end was set up to use Chainalysis\u2019 oracle that blocks sanctioned Ethereum addresses as listed by OFAC. [<a href=\"https:\/\/twitter.com\/TornadoCash\/status\/1514904975037669386\"><i>Twitter<\/i><\/a>]<\/p>\n<p>But the bar for sanctions compliance is not \u201cyou tried a bit\u201d \u2014 sanctions violation is a strict liability offence. You have to be <i>effective<\/i> in blocking sanctioned entities. If North Korea can just keep pouring ether through your mixer, then you failed. And Tornado Cash did indeed fail.<\/p>\n<p>The Tornado Cash code is open source, so it\u2019s trivial to set up another copy \u2014 and there are plenty of other instances out there. What they lack is liquidity \u2014 there\u2019s no volume of other transactions to hide yours in. It&#8217;s about liquidity \u2014 not code.<\/p>\n<p>There are other mixers. Railgun attempts to be an Ethereum privacy system, also using zero-knowledge proofs \u2014 and has named principals. [<a href=\"https:\/\/www.railgun.org\"><i>Railgun<\/i><\/a>]<\/p>\n<p>If Railgun can\u2019t keep sanctioned entities out, then it too is screwed.<\/p>\n<p>If ether transactions touch the world of actual money \u2014 which they do \u2014 then your Ethereum mixer needs to deal <i>effectively<\/i> with sanctioned entities, or you too will be in trouble.<\/p>\n<h3>Honestly, there are so many laws <i>(rugpulls DAO)<\/i> that nobody can be expected to even know which ones they\u2019ve broken <i>(launders 100k ETH for North Korea)<\/i>, it&#8217;s a Kafkaesque bureaucratic nightmare <i>(assaults Congress with an AR-15)<\/i><\/h3>\n<p>Just as nobody should have been surprised by the sanctions, nobody should have been surprised by the bad takes on the sanctions from the cryptocurrency world.<\/p>\n<p>The bad takes were all variations of the fundamental fallacy of cryptocurrency: that you can code your way around the rules of society.<\/p>\n<p>Sure you can, temporarily \u2014 but if you don&#8217;t achieve regulatory escape velocity (<i>e.g.,<\/i> Uber or BitTorrent), it won&#8217;t end well for you.<\/p>\n<p>Tornado Cash was a completely standalone program, with <i>no<\/i> human control \u2014 a truly decentralised autonomous entity. This, of course, makes it a <a href=\"https:\/\/davidgerard.co.uk\/blockchain\/the-dao\/\">sitting duck for attackers.<\/a> But they seem to have coded it pretty solidly. (I mean, it hasn&#8217;t been hacked <em>yet.<\/em>)<\/p>\n<p>Part of the outrage was at lead developer Roman Semenov\u2019s GitHub account being disabled, along with the Tornado Cash code repository: [<a href=\"https:\/\/twitter.com\/semenov_roman_\/status\/1556717890308653059\"><i>Twitter<\/i><\/a>]<\/p>\n<blockquote><p>My @GitHub account was just suspended [<i>shrug<\/i>] Is writing an open source code illegal now?<\/p><\/blockquote>\n<p>Semenov\u2019s question suggests that, despite his obvious intelligence and coding ability, the guy is an idiot in ways that just turned out to be critical. He was just \u201cwriting an open source code\u201d in the same sense that Ross Ulbricht of the Silk Road was just running a website, or illegal pornography is just an innocent sequence of ones and zeroes.<\/p>\n<p>For what it\u2019s worth, GitHub specifically bars sanctioned entities in its terms of service: [<a href=\"https:\/\/docs.github.com\/en\/site-policy\/github-terms\/github-terms-of-service#c-acceptable-use\"><i>GitHub<\/i><\/a>]<\/p>\n<blockquote><p>You may not use GitHub in violation of export control or sanctions laws of the United States or any other applicable jurisdiction. You may not use GitHub if you are or are working on behalf of a Specially Designated National (SDN) or a person subject to similar blocking or denied party prohibitions administered by a U.S. government agency.<\/p><\/blockquote>\n<p>The reason is that sanctions law specifically targets vendors:<\/p>\n<blockquote><p>These prohibitions include the making of any contribution or provision of funds, goods, or services by, to, or for the benefit of any blocked person and the receipt of any contribution or provision of funds, goods, or services from any such person.<\/p><\/blockquote>\n<p>If you&#8217;re going to set up a money laundering system, perhaps the site run by defense contractor Microsoft isn&#8217;t the best place to host your code.<\/p>\n<p>Some outraged crypto advocates have suggested that the action against Tornado Cash shows the need for a decentralised alternative to GitHub. This demonstrates the rule that you will never find anyone who knows less about technology than a crypto guy talking about technology \u2014 because that would literally just be <a href=\"https:\/\/en.wikipedia.org\/wiki\/Git\">git<\/a>, the version control system that GitHub is named for, and which was created specifically not to require any central controlling entity. (Also, git would <a href=\"https:\/\/davidgerard.co.uk\/blockchain\/business-bafflegab-but-on-the-blockchain\/\">count as enterprise blockchain<\/a> if you squint.) But centralisation is more economically efficient, so the Tornado Cash guys used GitHub when they absolutely didn\u2019t have to.<\/p>\n<p>The Tornado Cash website was served from Amazon AWS, and is also down. docs.tornado.cash is still up, served from gitbook.io.<\/p>\n<h3>What happens next<\/h3>\n<p>The shutdown of Tornado Cash was completely predictable. If you thought this would just be allowed to keep running, you have greatly misunderstood the world.<\/p>\n<p><a href=\"https:\/\/davidgerard.co.uk\/blockchain\/2021\/11\/24\/regulatory-clarity-extreme-edition-anti-money-laundering-and-crypto-fatf-ofac-fincen\/\">I\u2019m not in fact a fan of the present anti-money-laundering regime<\/a> \u2014 even if you think it&#8217;s a good idea, it doesn\u2019t do its job very well at high levels, and it causes tremendous inconvenience to ordinary consumers.<\/p>\n<p>But I do know that the AML regime exists, it&#8217;s powerful, and nerdy tech arguments about who touches which bit of code in what ways aren&#8217;t going to do a damn thing about it. This is a political problem.<\/p>\n<p>In the meantime, I look forward to the defiant crypto libertarian guys furiously trying all the clever workarounds they can possibly think of to code around the Tornado Cash sanctions. Imagine four libertarians on the edge of a cliff, all queueing up to jump and become the next <a href=\"https:\/\/davidgerard.co.uk\/blockchain\/tag\/virgil-griffith\/\">Virgil Griffith.<\/a><\/p>\n<p>&nbsp;<\/p>\n<br><br><div align=\"center\"><p><a href=\"https:\/\/www.patreon.com\/bePatron?u=8420236\"><img src=\"https:\/\/davidgerard.co.uk\/blockchain\/wp-content\/uploads\/2021\/10\/become_a_patron_button.svg\" alt=\"Become a Patron!\" title=\"Become a Patron!\" width=217 height=51><\/a><br><p style=\"align:center;\" class=\"patreon-badge\"><i>Your subscriptions keep this site going. <a href=\"https:\/\/www.patreon.com\/bePatron?u=8420236\">Sign up today!<\/a><\/i><\/p><\/div>","protected":false},"excerpt":{"rendered":"<p>The fundamental fallacy of cryptocurrency: that you can code your way around the rules of society.<\/p>\n","protected":false},"author":1,"featured_media":23537,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[3139,2957,650,82,2958,858,2326,3138,3140,1796,745,403,1865,264],"class_list":["post-23536","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorised","tag-aws","tag-blender-io","tag-circle","tag-ethereum","tag-github","tag-north-korea","tag-ofac","tag-railgun","tag-roman-semenov","tag-tornadocash","tag-united-states","tag-us-treasury","tag-usdc","tag-vitalik-buterin"],"jetpack_featured_media_url":"https:\/\/davidgerard.co.uk\/blockchain\/wp-content\/uploads\/2022\/08\/tornado_cash.png","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/posts\/23536","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/comments?post=23536"}],"version-history":[{"count":29,"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/posts\/23536\/revisions"}],"predecessor-version":[{"id":23590,"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/posts\/23536\/revisions\/23590"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/media\/23537"}],"wp:attachment":[{"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/media?parent=23536"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/categories?post=23536"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/tags?post=23536"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}