In August 2022 the US Treasury's OFAC sanctioned the Tornado Cash smart-contract protocol — an Ethereum-based privacy mixer — by adding its on-chain addresses to the SDN list. This was unprecedented: OFAC had not previously sanctioned autonomous code rather than people or organizations. The action raised three contested questions: whether autonomous code can be "property" subject to sanctions; whether writing privacy software constitutes aiding money laundering; and what the downstream chilling effect would be on Bitcoin privacy tools. Two 2024 events crystallized the Bitcoin-specific impact — the April indictment of Samourai Wallet's founders and the June voluntary shutdown of Wasabi Wallet's zkSNACKs coordinator. The November 2024 Van Loon v Treasury 5th Circuit ruling held that immutable smart-contract code is not "property" under IEEPA, a pro-privacy precedent whose reach to non-Ethereum tools remains contested. OFAC formally delisted Tornado Cash in March 2025 following that ruling; in 2025 the Bitcoin-specific criminal cases resolved unevenly — Samourai Wallet's founders pled guilty to an unlicensed-money-transmitting charge, while Roman Storm was convicted on that same count and the jury deadlocked (partial mistrial) on the money-laundering and sanctions charges. The sanctions are lifted, but developer-liability questions remain multi-position across legal, technical, and policy dimensions.
Why this note matters
The Tornado Cash sanctions and the broader privacy-tool regulatory landscape have substantively reshaped Bitcoin’s privacy-tool ecosystem. The note matters because:
- It surfaces the specific event-level controversy that has produced lasting effects on Bitcoin privacy practice
- It engages the Van Loon v Treasury legal precedent (November 2024) that partially resolved the legal-status question
- It catalogues the downstream effects on Bitcoin-specific privacy tools — Samourai indictment, Wasabi shutdown, broader chilling effect
- It articulates the multi-position dispute at multiple layers (legal; technical; policy; community-cultural)
- It connects the regulatory dimension to the operational reality for Bitcoin holders practicing privacy (see CoinJoin, Lightning privacy properties, KYC leakage)
The defensible position: the controversy is genuinely consequential for Bitcoin’s privacy stack and continues to evolve. Tracking the legal-and-regulatory trajectory is necessary for understanding the operational landscape Bitcoin privacy-tool users navigate.
What happened
A condensed event-level chronicle.
~2019-2022 — Tornado Cash development and adoption. Tornado Cash, an Ethereum-based privacy-mixing smart-contract protocol developed by Alexey Pertsev, Roman Storm, and Roman Semenov, sees substantial adoption. Architecture: users deposit ETH to a mixing pool; withdrawal addresses are unlinkable from deposit addresses via zero-knowledge cryptography. The protocol is autonomous (no operator can stop transactions once deployed); estimated $7+ billion in cumulative volume by 2022.
August 8, 2022 — OFAC sanctions Tornado Cash. US Treasury adds Tornado Cash’s smart-contract addresses to the SDN list. The action is unprecedented: OFAC had not previously sanctioned autonomous code. Treasury cites Tornado Cash usage by North Korean hackers (Lazarus Group) and other illicit actors, claiming approximately $455M in laundered funds traceable to the protocol. US persons are prohibited from interacting with the sanctioned addresses.
August-December 2022 — Initial reactions and legal challenges. Coinbase and other US entities block customer interactions with sanctioned Tornado Cash addresses. Coin Center, Coinbase, and adjacent privacy-rights organizations file legal challenges including the Van Loon v Treasury action. Roman Storm and Roman Semenov are subsequently indicted (August 2023; Storm specifically prosecuted in US Southern District of New York; Semenov is in Russia and not extraditable).
August 2023 — Roman Storm indictment. Storm is indicted on conspiracy to commit money laundering, conspiracy to operate an unlicensed money-transmitting business, and conspiracy to violate IEEPA sanctions. The case is among the first prosecutions of a software developer for writing privacy-tool code where the prosecution argues the developer is liable for downstream user actions.
April 24, 2024 — Samourai Wallet indictment. US Department of Justice indicts Keonne Rodriguez and William Lonergan Hill, co-founders of Samourai Wallet, on conspiracy to commit money laundering and operating an unlicensed money-transmitting business. The DOJ alleges Samourai’s Whirlpool CoinJoin and Ricochet tools processed approximately 100 million in money laundering. Samourai’s web infrastructure is seized; mobile applications removed from App Store and Google Play. The indictment is widely viewed as the Bitcoin-specific application of the post-Tornado-Cash enforcement framework.
June 2024 — Wasabi Wallet coordinator shutdown. zkSNACKs (the company behind Wasabi Wallet) announces voluntary shutdown of the Wasabi coordinator service, US-market exit, and discontinuation of consumer Wasabi product development. Public statement cites the post-Samourai-indictment regulatory environment as the proximate cause. The Wasabi software continues to exist but the canonical zkSNACKs coordinator is offline.
November 26, 2024 — Van Loon v Treasury 5th Circuit ruling. US 5th Circuit Court of Appeals rules that immutable smart-contract code is not “property” under the IEEPA statute that OFAC used to sanction Tornado Cash. The ruling is significant: it establishes that autonomous smart-contract code falls outside the sanctions regime that applies to ordinary property. Implications for non-Ethereum privacy tools (which often have human operators) are less clear; the precedent is most directly applicable to immutable autonomous code.
March 21, 2025 — OFAC delists Tornado Cash. Following the Van Loon ruling and the district-court remand, the US Treasury formally removes Tornado Cash’s smart-contract addresses from the SDN list, acknowledging the “novel legal and policy issues” the case raised. The delisting ends the sanctions themselves — a significant pro-privacy outcome — but does not resolve the separate criminal prosecutions of the developers, which turn on money-transmission and conspiracy theories rather than the sanctions listing.
April 2025 — DOJ crypto-enforcement pullback. A Deputy Attorney General memo directs the DOJ to deprioritize crypto-related prosecutions absent clear intent, and disbands the National Cryptocurrency Enforcement Team. The shift reshapes the enforcement backdrop but does not automatically dismiss the in-flight Samourai and Storm cases (below).
July–November 2025 — the Bitcoin-specific cases resolve unevenly. Samourai Wallet’s co-founders Keonne Rodriguez and William Lonergan Hill pled guilty in July 2025 to conspiracy to operate an unlicensed money-transmitting business (the money-laundering count was not pursued to trial); they were sentenced in November 2025 (Rodriguez to five years, Hill to four). Roman Storm’s trial concluded on August 6, 2025 with a split verdict — convicted on conspiracy to operate an unlicensed money-transmitting business (§1960), with the jury deadlocked (partial mistrial) on the money-laundering (§1956) and IEEPA-sanctions (§1705) counts; in March 2026 the DOJ moved for a retrial on the two deadlocked counts.
Ongoing as of 2026. The sanctions are lifted (OFAC delisting, March 2025); the Samourai case has resolved in guilty pleas and sentencing; Storm’s case produced a partial conviction with a retrial sought on the most serious counts. The Van Loon ruling stands as a substantial pro-privacy-tool precedent on the sanctions question, but the developer-liability question — whether writing and operating privacy-tool software is money transmission or conspiracy — remains live and contested. The broader privacy-tool ecosystem has been substantially reshaped (see CoinJoin): JoinMarket continues as the surviving sovereign Bitcoin CoinJoin tool, and community-operated coordinators provide partial replacement for the zkSNACKs Wasabi infrastructure. The chilling effect on new privacy-tool development is real but not absolute, and the regulatory backdrop is materially less hostile than at its 2024 low point.
The contested matters
Layer 1: Can autonomous smart-contract code be subject to sanctions?
The OFAC position (and broader pro-sanctions argument):
- Tornado Cash facilitated substantial money laundering for North Korean actors and other sanctioned entities
- The sanctions regime must adapt to new technologies; immutable autonomous code that systematically enables sanctions evasion cannot be exempt from sanctions
- IEEPA’s broad statutory language covers “property” including digital assets; smart-contract addresses are “property” in this sense
- Sanctioning the addresses (rather than individuals) is necessary because the protocol is autonomous
The Van Loon position (5th Circuit November 2024 ruling):
- IEEPA’s “property” definition does not extend to immutable autonomous smart-contract code that no entity can control
- “Property” implies the possibility of control; truly autonomous code lacks the controllable-entity property
- OFAC exceeded its statutory authority in sanctioning Tornado Cash specifically
- The ruling does not address sanctions on identifiable operators (developers; centralised mixers); only on autonomous immutable code
The broader pro-privacy-tool position:
- The Van Loon ruling is correctly decided as a matter of statutory interpretation
- Sanctioning code rather than actors is structurally problematic for free-speech and innovation reasons
- Specific bad actors (Storm; Semenov) can be prosecuted under existing money-laundering frameworks without sanctioning the code itself
The contested empirical question: how much sanctions-evasion did Tornado Cash actually enable? OFAC’s $455M laundering figure is contested; alternative analyses produce lower numbers. The empirical question matters because the sanctions justification depends partly on actual harm caused.
Layer 2: When does writing privacy-tool software cross into money-laundering conspiracy?
The prosecution position (Storm/Samourai cases):
- Privacy-tool developers know their products are used for money laundering; specific marketing and user interactions establish the requisite mens rea
- The “I just wrote code” defense doesn’t apply when the developer’s specific actions enable laundering at scale
- Conspiracy charges are appropriate when developers actively facilitate users’ illegal activities
The defense position (and broader pro-privacy position):
- Writing privacy-tool software is constitutionally-protected expression analogous to writing books about encryption
- The “developers knew” framing is overstated; developers cannot control how users employ their tools
- Conspiracy charges against developers of legal tools used for some illegal purposes create chilling effects that suppress legitimate innovation
- The Samourai case specifically: Whirlpool was non-custodial; the developers did not custody user funds; the conspiracy-to-launder framing stretches the legal theory substantially
The Bitcoin-community position:
- Bitcoin privacy-tool development is socially valuable for legitimate purposes (protecting holders from chain-analysis-driven physical attacks per Common attack vectors; protecting against KYC-data-leak exploitation per KYC leakage)
- The legal framework that distinguishes legitimate-privacy-tool-development from illegitimate-money-laundering-facilitation is underdeveloped
- The post-Samourai chilling effect has materially affected Bitcoin’s privacy stack (see CoinJoin for operational impact)
Layer 3: What’s the impact on Bitcoin-specific privacy tools?
The empirical impact:
- Samourai Wallet seized April 2024; Whirlpool offline; Ricochet offline; mobile apps removed
- Wasabi Wallet coordinator voluntarily shut down June 2024; software continues but canonical coordinator offline
- JoinMarket continues operating (sovereign architecture; no central operator to indict)
- Sparrow Wallet continues offering CoinJoin functionality via community-operated coordinators
- New privacy-tool development has slowed but not stopped; specific projects continue with adjusted operational models
The community-cultural impact:
- Bitcoin privacy-tool developers operate under substantial legal-risk uncertainty
- Some developers have relocated jurisdictions or restructured operational models
- The “build privacy tools” career path is materially riskier than pre-2024
- The chilling effect is real but bounded; substantial development continues
The operational impact for Bitcoin holders:
- CoinJoin remains operationally feasible but with reduced UX and smaller anonymity sets
- The cost of practicing privacy has increased (in time, complexity, and some legal-uncertainty)
- The broader Bitcoin community’s commitment to privacy practice remains; the operational landscape has shifted unfavorably
Layer 4: Where does the legal landscape go from here?
Open legal questions:
- The Storm retrial on the deadlocked money-laundering and sanctions counts will materially shape developer liability for privacy-tool code; the §1960 (unlicensed money transmission) convictions of Storm and the Samourai founders already establish that operating a mixing/CoinJoin service can be charged as money transmission
- Whether the §1960 money-transmission theory extends to non-custodial software authors is the live doctrinal question the Samourai guilty pleas left unlitigated
- Other jurisdictions (EU MiCA implementation; UK financial regulation) develop adjacent frameworks with different legal-precedent landscapes
- The Van Loon ruling’s specific scope (immutable autonomous code only) may be extended or narrowed by subsequent rulings
The legislative landscape:
- Congress has not addressed the privacy-tool regulatory framework directly
- Various proposed bills would clarify (in either pro-privacy or anti-privacy directions); none have advanced
- The 2024 administration’s policy posture is more crypto-favorable than predecessor administrations; specific Bitcoin-privacy-tool implications are unclear
The international landscape:
- EU MiCA implementation produces adjacent regulatory framework
- Russia, China, others have their own frameworks (mostly more-restrictive)
- The privacy-tool development community can operate from non-US jurisdictions with different legal landscapes
- Cross-jurisdictional dynamics are increasingly relevant
Layer 5: The broader implications for Bitcoin’s privacy-resistance properties
The controversy intersects with broader Bitcoin-community questions:
- Is privacy a core Bitcoin property? Most maximalist voices say yes; privacy is part of Bitcoin’s value proposition
- Can Bitcoin maintain privacy-tool ecosystem under regulatory pressure? The 2024 events suggest partial-but-meaningful pressure exists
- What’s the right development-community response? Operational restructuring; jurisdictional diversification; legal-defense funding (Coin Center, EFF, others); continued tool development with adjusted risk-tolerance
- What’s the right holder-community response? Adopting available privacy tools; supporting privacy-tool development; engaging policy debates; refusing the “if you have nothing to hide” framing
Where the dispute stands (as of 2026)
- Tornado Cash sanctions: resolved — OFAC formally delisted the protocol in March 2025 following Van Loon (immutable code not “property”); applicability of the property reasoning to non-immutable, human-operated tools remains contested
- Storm prosecution: partial conviction (August 2025) on the unlicensed-money-transmitting count; mistrial on the money-laundering and sanctions counts; DOJ moved for a retrial on the deadlocked counts (March 2026)
- Samourai prosecution: resolved — both founders pled guilty (July 2025) to conspiracy to operate an unlicensed money-transmitting business and were sentenced (November 2025)
- Bitcoin privacy-tool ecosystem: materially reshaped but not destroyed; JoinMarket and community-operated coordinators continue
- Regulatory trajectory: materially less hostile than 2024 — sanctions lifted, DOJ crypto-enforcement deprioritized (April 2025) — but developer-liability precedent (via §1960) is the live open question
- International landscape: divergent; cross-jurisdictional dynamics increasingly relevant
- Likely 2026-2030 trajectory: the §1960 developer-liability question and the Storm retrial are the principal data-generating events; Bitcoin privacy-tool development continues with adjusted operational models
Counter-arguments and tensions (criticisms of how this note frames the controversy)
“The ‘chilling effect’ framing may be overstated”
The framing concern: Two prosecutions and one voluntary shutdown don’t constitute a comprehensive chilling effect. JoinMarket continues; community coordinators continue; new privacy tools are in development. The “ecosystem reshaped” framing may overstate the impact.
Response: Partially valid. The impact is real but bounded; the ecosystem has adapted; substantial development continues. The note attempts to characterize both the impact and the resilience; readers should weight these appropriately. The chilling-effect framing captures something real even if the magnitude is contested.
”The ‘autonomous code can’t be sanctioned’ framing is too narrow”
The framing concern: The Van Loon ruling addresses a specific narrow question (immutable smart-contract code under IEEPA). Treating it as a broader pro-privacy-tool victory overstates its scope. Most Bitcoin privacy tools have human operators who remain subject to existing prosecution frameworks.
Response: Real concern. The note attempts to characterize Van Loon’s narrow scope; the broader implications for Bitcoin’s privacy-tool ecosystem are mixed at best. Readers should understand that Van Loon protects autonomous immutable code, not human operators of privacy tools.
”The ‘developers knew’ question is conflated”
The framing concern: The Samourai and Storm prosecutions hinge on specific allegations of operational behavior (specific marketing; specific user interactions; specific knowledge of illicit use). Treating these as broadly representative of “privacy-tool developer prosecution” conflates case-specific facts with the broader category.
Response: Real. The note attempts to characterize the prosecution patterns without overstating their scope. Specific cases may turn on specific facts; the broader legal-precedent implications depend on how courts rule. Readers should engage specific cases on their specific facts.
”The legitimate-use vs illicit-use empirical question matters”
The framing concern: The OFAC sanctions justification depended on the empirical claim that Tornado Cash was substantially used for money laundering. Pro-privacy-tool arguments often elide this empirical question. If the empirical claim is true, the policy framework needs to address it; if false, the sanctions framework is built on a false premise.
Response: Valid concern. The empirical question (how much actual illicit use?) is genuinely contested but does not fully determine the policy question (what’s the right framework for privacy-tool regulation?). The note attempts to surface the empirical contestability without taking a final position on the magnitudes.
”The Bitcoin community’s policy engagement may be underdeveloped”
The framing concern: Bitcoin’s privacy-tool community has engaged the legal landscape primarily through defense-of-development rather than active-policy-development. A more sophisticated policy-engagement strategy might produce better outcomes than reactive legal defense.
Response: Real concern. Coin Center, EFF, and adjacent organizations have engaged the policy landscape; the broader Bitcoin community’s policy-engagement is variable. The note describes the current state without prescribing the optimal strategy.
Verdict: Sanctions resolved in privacy’s favor (2025 delisting); developer-liability question still live after the split Storm verdict; ecosystem materially reshaped
The Tornado Cash sanctions and the broader privacy-tool regulatory landscape constitute one of the most operationally-consequential contemporary controversies. The Van Loon ruling and the subsequent March-2025 OFAC delisting resolved the sanctions question substantially in privacy’s favor; the Storm split verdict and the Samourai guilty pleas leave the developer-liability question — via the unlicensed-money-transmitting theory rather than sanctions — genuinely unresolved; the Bitcoin privacy-tool ecosystem has been materially reshaped.
A serious assessment:
- Tornado Cash sanctions legal status: resolved — Van Loon plus the March-2025 OFAC delisting lifted the sanctions
- Developer liability for privacy-tool code: live and contested — Storm convicted on §1960 (money transmission) with a mistrial on the graver counts and a retrial sought; Samourai founders pled guilty to the same §1960 theory
- Bitcoin privacy-tool ecosystem: reshaped but not destroyed; substantial adaptation
- Regulatory trajectory: materially less hostile than 2024 (sanctions lifted; DOJ crypto-enforcement deprioritized) but §1960 developer exposure persists
- International landscape: divergent; cross-jurisdictional development continues
- Long-horizon trajectory: the §1960 developer-liability question will materially shape Bitcoin’s privacy properties at the practical level
This is a controversy worth tracking actively. The Storm retrial and the §1960 developer-liability precedent will be the principal data-generating events going forward.
Open questions for further development
- The Storm retrial on the deadlocked counts will further inform the developer-liability framework; what outcomes would substantially change the precedent set by the §1960 conviction?
- The Samourai case resolved in guilty pleas without litigating the non-custodial-software defense; what would a future defendant need to establish to test the §1960 theory at trial?
- The legislative landscape may shift; what specific legislative proposals would clarify the framework, and what’s their realistic political viability?
- International jurisdictions develop divergent frameworks; how does cross-jurisdictional privacy-tool development evolve, and what’s the realistic Bitcoin-community engagement?
- The intersection with broader Bitcoin-community policy engagement (Coin Center, EFF, Bitcoin Policy Institute) is partly developed but could be strengthened; what’s the realistic path?
Canonical sources for this note
Primary legal documents:
- OFAC Tornado Cash sanctions (August 8, 2022) — initial SDN listing
- Van Loon v Department of the Treasury — 5th Circuit ruling (November 26, 2024) on immutable smart-contract code property status
- US v Storm — S.D.N.Y. indictment (August 2023); ongoing proceedings
- US v Rodriguez et al. (Samourai indictment) — S.D.N.Y. (April 24, 2024); ongoing proceedings
- IEEPA statute and OFAC regulations
- Various legal challenges and amicus briefs (Coin Center, Coinbase, EFF, others)
Policy and regulatory commentary:
- Coin Center — extensive analysis of Tornado Cash sanctions and adjacent privacy-tool regulation
- Electronic Frontier Foundation (EFF) — privacy-tool development engagement
- Bitcoin Policy Institute — Bitcoin-specific policy engagement
- Various Treasury Department reports and OFAC guidance
Coverage of specific events:
- Tornado Cash sanctions and the privacy-tool community response (CoinDesk, August 2022)
- Samourai Wallet founders indicted (CoinDesk, Bitcoin Magazine, others; April 2024)
- Wasabi Wallet coordinator shutdown (zkSNACKs announcement; June 2024)
- Van Loon ruling explained (Coin Center, EFF analyses; November 2024)
- Bitcoin Optech newsletter ongoing coverage
Coordinated context:
- See CoinJoin in the Privacy practice cluster for operational impact on Bitcoin CoinJoin tools
- See KYC leakage for the broader chain-analysis-and-regulatory-engagement context
- See Lightning privacy properties for adjacent privacy-tool dimension
Adjacent academic and policy analysis:
- Various Stanford CIS, Yale ISP, EFF policy papers on encryption and privacy-tool regulation
- Coin Center papers on cryptocurrency-and-privacy regulation
- Bitcoin Magazine policy-engagement coverage
As of 2026: OFAC delisted Tornado Cash (March 2025); the Samourai prosecution resolved in guilty pleas (July 2025) and sentencing (November 2025); the Storm trial produced a split verdict (August 2025, §1960 conviction with a mistrial on the graver counts) and the DOJ is seeking a retrial; Van Loon stands; the Bitcoin privacy-tool ecosystem operates with adjusted operational models.
Related notes
Within the Controversies section:
- Strategic Bitcoin Reserve political debates — adjacent regulatory-and-political dimension
- Bitcoin controversies — the section sub-MOC
Privacy practice cluster (Self-custody section 4):
- CoinJoin — operational impact of the Tornado Cash sanctions and Samourai/Wasabi events on Bitcoin CoinJoin tools; load-bearing for understanding the post-2024 operational landscape
- KYC leakage — adjacent threat-model dimension
- Lightning privacy properties — adjacent privacy-tool dimension
- Address reuse and chain analysis — adjacent threat-model dimension
- Practical self-custody and sovereignty — the section sub-MOC
Criticisms-section adjacency:
- Custody concentration risks — adjacent institutional-pressure dimension
- Criticisms of Bitcoin — the section sub-MOC
Regulation section:
- Will be the natural home for adjacent regulatory-controversy treatment
- Regulation policy and geopolitics
Adjacent thinker pages:
- Jameson Lopp — practitioner perspective on privacy practice
- Adam Back — cypherpunk privacy advocate
- Pieter Wuille — Bitcoin Core; engaged with privacy-tool development
- Peter Todd — Bitcoin protocol contributor
The sub-MOC home: