A secondary effect of sanctions is indicating what the regulators do and do not consider illegal. Up until now, it was at least marginally possible to state "But I didn't know it was illegal. TornadoCash was doing the exact same thing for years and never got into trouble". After this ruling, that excuse no longer applies and that might dissuade a lot of people who might otherwise be tempted to run a mixer of their own.
Also, reputation counts for a lot when it comes to mixers. A mixer that has existed for years is probably legit, a mixer that started up yesterday is a lot more likely to be a rugpull. Even if it will come down to whack-a-mole with the Treasury sanctioning new mixers as they pop up, it might be very difficult for any individual mixer to build up enough reputation to attract significant business.
TC utility is diminished by other fact - TC is blocked on exchange level, exchanges do not accept funds coming from TC smart contract.
(And as any programmer will tell you, just because you have the source code available does not automatically mean you can see where it has a tricky edge case with massive security implications. The obfuscated C contests are proof of that)
For most contracts they link actual source code to make inspection even easier - large part of trust in the system comes from the fact that contracts are inspectable.
What is interesting here, though, is that Tornado Cash doesn't run anything: they may as well not exist as an entity anymore. It also isn't a blockchain and doesn't have nodes: third parties thereby also don't run Tornado Cash.
Tornado Cash, instead, is one of many random contracts executing on Ethereum (as well as third-party Ethereum-like constructs; some/many of those are pretty damned centralized, with servers that process and store transactions, so I am gong to concentrate on Ethereum itself as it is the most interesting).
So, with the smart contract of Tornado Cash -- as Tornado Cash isn't a group of people or a company: it is just code -- having been sanctioned, if you are a miner and mine a block on Ethereum that includes a transaction that touches Tornado Cash, is that now illegal? I feel like this is how the concept of sanctions would normally play out in meat space with real people, to prevent the sanctioned services from being utilized.
If so, and I think this is where it "gets good": let's say 99% of miners care about the sanctions, and 1% don't... when you mine a block, you choose a parent for that block; arguably now, if you actively chose to accept a parent block that includes a Tornado Cash transaction, that should also be illegal (due to being sanctioned).
We don't have a good framework in place for sanctioning contracts by address, contract itself, or by effect.
I'm expecting a push toward laws will evolve to make calling mixers illegal, but that will likely hit some 1st amendment push back. If money is speech, then is it free if it has no privacy?
Note: It is exceedingly rare for the free money to actually be so.
I'm not a lawyer, but I don't think it follows that every financial transaction is a 1st amendment issue, just because spending money to promote a message is protected.
- It will not be legal for miners to run/"execute code on behalf of" smart contracts from the sanctioned list, which can be downloaded from the Treasury web site and is updated regularly. This is very akin to how the sanctioned people list works currently.
- The treasury will maintain a list of blockchain addresses that are known to contain tainted coins and all businesses need to verify they don't accept business when the payment comes from one of those. A little bit more tricky since you can send money from any wallet to any other one, but still this is how a lot of the current sanctions already work. You could imagine this being only applicable for companies with a banking or exchange license or something like that. Perhaps it would become a part of regular auditing done by accountancy companies.
- (Possibly the most likely depending on how much lobbying the crypto industry manages to get in) Miners don't have to do anything, but all crypto exchanges with users in the USA (in this case, I'd expect the EU and other big jurisdictions to develop similar rules over time) are forbidden from transacting with a list of addresses belonging to contracts available from the Treasury.
Options 2 and 3 are very similar, but 3 is scoped only to exchanges. Since the majority of users is not sophisticated enough to transact without exchanges, this seems like it would give the most bang for the buck for the Treasury. More sophisticated launderers could be tracked on a case-by-case basis if needed.
One thing I think is not very likely to happen is for the Treasury to say: "Oh well! Those crypto rascals outsmarted us by running their money laundering smart contracts on the Eth VM, so we guess money laundering is fine now".
In general, most of the supposed value of cryptocurrency seems to be that everyone looks the other way when parties do things that look like or are illegal but take the money anyway. Functionality, cryptocurrency is very similar to e-gold, and I see no reason it should be allowed to do the same things just because it’s somewhat decentralized.
This has come up in other contexts before, most famously the idea of using OP_RETURN to embed child pornography into the Bitcoin blockchain.
An Ethereum client must download and execute all transactions in each block in order to determine if that block is valid, and thus learn current state of the system. The client can't know if this "illegal" transaction has been executed until it actually executes it. As an operator you don't have any choice, other than simply turning everything off and "rugging" all your customers.
So let's say you're Coinbase. You have billions of dollars of other people's money, innocent people's money, in your custody. If you refuse to process blocks that contain transactions involving sanctioned entities, or that contain illegal child pornography, you destroy those billions of dollars of assets.
You're not going to make billions of dollars of assets unspendable. Not a snowball's chance in hell. You will process those blocks as the protocol requires. Doing otherwise would be as ridiculous as Google turning off its entire search engine merely because some of its automated actions technically violate laws from time to time. It would be like Intel razing a whole semiconductor fab to the ground because it learned that some of the sand used in creating some wafers was sold by a sanctioned country.
There is absolutely no way the US government is going to demand that kind of destruction of value as a matter of compliance.
This is, in fact, exactly the kind of thing Governments tend to exist for.
Seems pretty obvious from the statement that doing business that includes this Tornado Cash entity will infect your business with criminal liability.
Reply again?
Edit: there is some "sort of" precedent. DeCSS was illegal.
Oh I totally get that, but...
I reasonably believe in good-faith that it hasn't been categorically proven to be illegal. The reasons for this may seem obvious to many, but just it's not for anybody else then I'll give at least one persuasive argument. Illicit activity happens through legitimate financial transactions. For example, if I trade somebody a pizza for $10, how am I to know that $10 wasn't used in a criminal activity, ever, in the total existence of those note's circulation? And further, by using cash at all, as a concept insofar that cash is not rigorously tracked while in circulation, that the whole cash money system is illegal... Cash based economies to a great extent protect the privacy of participants. Those machines that make change, I suppose that's money laundering, and I would suppose they are laundering money for someone, but also... they be making legitimate 20x quarters from a $5 bill in a coin operated business setting. The quarter change making machine is the physical analog of a crypto mixer, but it's perhaps a bad example. Because making change for the sake of privacy is an unlikely activity, albeit a reasonable legitimate (if you ask me) activity.
I honestly would love to see more court precedence set on some of these so-called "structuring" laws where somebody intentionally "structure" or "laundered" money for the honest-to-goodness sake of legitimate privacy, or even for somehow being a form of free speech, something like that... to strike away some of these absurd regulatory powers before a panel of jurors.
There's lots of court precedent for this. Courts have overwhelmingly found that the goverment's desire to access transactional data for tax compliance outweighs any right to privacy.
Courts generally find that just because there might be legitimate reasons to do something with money that doesn't override the requirement to keep records for for tax purposes.
No, it shows the exact opposite - that mixers are legal and the government has to utilize a completely arbitrary executive power to ban particular mixers.
1. The amount of money you can mix depends on the scale of the mixing operation
2. It's easy to build something that looks like a mixer but at some point steals the deposited money.
The feds don't have to prevent all mixers from operating. They just have to kill the biggest, most trusted players.It’s actually not easy to create a new mixer because the whole idea is that you need a fair volume of legitimate traffic. If you set one up and nobody uses it, you see no benefit. If only criminals use it, you’ve created a great lead generator for the authorities. If you’re sufficiently conspiratorial in mind, blocking the best known mixer would be a great way to drive traffic to new mixers which they secretly run.
Mixer program code is publicly deployed and is run on-chain by the block validators. How would government secretly run a mixer?
2. Compromising someone’s project - want to bet someone wouldn’t agree to “accidentally” make a bug in exchange for a shorter sentence? (I’m not saying everyone who works on these are drug dealers or something but I’d bet there are a lot of cases for tax evasion threats given the ideology)
3. Mixers are critically dependent on having enough volume to meet demand but using one adds cost and persecution risk so most people don’t use them. If you knew someone like the DPRK was trying to launder a large amount of money, they’d be limited based the number of other participants – especially as news like today’s tells everyone that using a mixer means a non-trivial risk of permanently tainting the tokens you launder. If you started submitting transactions to and from your own wallets, you could make the analysis problem easier by ensuring that most of the participants are secretly known to you.
Eventually, they'll just KYC the whole chain to your wallet because it's much cheaper to do. If you can't prove that your chaincoins are clean, you can't convert them to usable money.
As in, deploy contract, yes. As in, have enough liquidity to both “mix” (aka launder) money and provide sufficient anonymity, no, that’s a network effect which is largely winner-take-all. The largest mixers will be the safest and most effective but then also the biggest targets. As you go down the list, they get less likely to be sanctioned but more likely to be unsafe/honeypots/ineffective.
Sure thing. Send me your money and I will absolutely 100% for sure send back the same amount but anonymized.
No, it’s really not. Mixers need liquidity, which means they need popularity and volume. That’s not overnight.
Sanctions enforcement tends to pay for itself. It's hard to create new mixers from prison or when your bank accounts keep getting frozen. (It's easy to set up a cash business and launder money. Most people don't do it. It's still a thriving industry.)
You don't need a lot of resources to run your own.
This is true of all money laundering. Any business that takes cash has everything it needs to cook the books to show phantom income.
TC clones can probably fly under the radar with a small transaction volume, but any attempt to launder large sums would get caught pretty quickly (with standard forensic accounting techniques used to trace the beneficiaries).
Plus, there is not really a way to tell who creates a smart contract if you cover your tracks well enough.
This sanctions stuff is smoke and mirrors for the government to try and convince themselves they are capable of doing something.
The most realistic approach is for major chains to go POS and the major validators and other important pieces of the puzzle to need a lot of resources to the point where they become businesses and are on the governments radar (and by extension they would need to comply with regulations).
But because everyone knows that is a natural consequence of POS, it is exactly why no reasonable person would be on board with a transition to it.
>But because everyone knows that is a natural consequence of POS, it is exactly why no reasonable person would be on board with a transition to it.
You described mining - public companies operating big industrial warehouses with miners. PoS is the opposite - it needs next to zero physical resources. No reasonable person can support PoW unless they support totalitarianism. There's no way to make PoW resistant to government interference.
"Sir, the hacker groups seem to love this thing we've only recently identified as 'FOSS.' It's surfacing to be an existential threat to our CONOPs. I'm requesting your approval to authorize immediate sanctions against the FOSS threat."
'Oh, shucks, there's no rule that says a dog can't play baseball, or that you can't use open source to do financial crime, I guess we can't sanction people who use it for money laundering!'
We already know that the US has technology to track mixed transactions.
But no details have been published on the mechanics of this “de-mixing”.
Possible it has to do with sloppy change address reuse in Wasabi?