Investors sue Treasury Department for blacklisting crypto platform Tornado Cash
nytimes.com
nytimes.com
> “Today, Treasury is sanctioning Tornado Cash, a virtual currency mixer that launders the proceeds of cybercrimes, including those committed against victims in the United States,” said Under Secretary of the Treasury for Terrorism and Financial Intelligence Brian E. Nelson. “Despite public assurances otherwise, Tornado Cash has repeatedly failed to impose effective controls designed to stop it from laundering funds for malicious cyber actors on a regular basis and without basic measures to address its risks. Treasury will continue to aggressively pursue actions against mixers that launder virtual currency for criminals and those who assist them.”
For much more on this, see the legal analysis by Coincenter: https://www.coincenter.org/analysis-what-is-and-what-is-not-...
Note that FinCEN does pay attention to this sort of distinction, and says that software providers are not subject to money laundering regulation.
I feel like your trying to say NK and Tornado should be able to do illegal activities that harm people. Just because you don’t like the police or something.
Do you have any data to back this claim? Also, should banks be banned if their customers are doind shady things outside of using their services?
As for data, just as a first-order estimate, check out the rekt leaderboard [1] and see how many of the stories end with "and the stolen funds were routed through tornado, fin." If all crypto-adjacent crimes are reported to FBI at some point I am sure they have a much clearer statistics, but even as a civilian you can see that it's not small.
Who decides who the mafia is?
On the other hand, if you don't trust FBI, the law, or the courts to do the right thing, you have a different problem entirely, at which point none of what I say should matter to you.
I can trust law enforcement to do its job. Heck I might even trust it to do the right thing when it comes to gray areas / methods they use. But... I can definitely disagree with some laws. In fact, people doing something because it's law without critically thinking about it has worse consequences than disagreeing with the law.
Sarcasm aside, I think Bitcoin functionally bears much more resemblance to a distributed bank than to distributed cash. It's not perfect resemblance, and there are people who disagree with me. Just saying that it's cash isn't sufficient evidence to convince me, even if the speaker happens to be the inventor.
This is likely because you don't understand what a bank is, or that you don't understand what bitcoin is, or a combination.
If you're interested in bank-like things that use bitcoin, you could learn more about fedimint.
If you're interested in what bitcoin is, you could just read the white paper[0].
I've tried to look into Fedimint, just because I thought it would help me understand your misconceptions about banks. I will admit to not fully understanding what they are up to, but assuming my scam radar had a false positive it seems to be a privacy-oriented sidechain service. That... doesn't seem particularly relevant here?
Banks have accounts, right? Does bitcoin have accounts?
You mean physically? Plenty of banks (especially online banks and investment banks) don't physically store any more cash than something like a jewelry store. Physical storage is hardly a core characteristic of banking; I've never been to a branch of any of my current banks. If you don't mean physically, I can't see how this is different than "have accounts"...
> Banks have accounts, right? Does bitcoin have accounts?
An account is just a ledger of credits and debits coupled with some form of access control. How is a bitcoin address meaningfully different from an account? Keep in mind that not all accounts are interest bearing, and it's very possible (even common) for one individual to have multiple accounts.
still waiting.
> How is a bitcoin address meaningfully different from an account?
Well, for one, it's only an address. Not a ledger.
Bitcoin transactions point money at one or more address. Transactions, you might argue, are one-off ledgers. But then bitcoin is just a collection of those transactions & relevant/necessary data to support them them, compiled & validated using a variety of mathematic calculations.
My answer is still "no (but many banks don't either)", as I said in my previous reply. Unless you mean digitally, but that's just "having accounts". If you mean digitally, then my answer is "obviously yes".
> Well, for one, it's only an address. Not a ledger.
What? The entire mechanical basis of Bitcoin (the blockchain) is a ledger (big database of timestamped transactions) with a somewhat unusual timestamping and tamper proofing mechanism. Each transaction has a set of associated addresses. I was going to say that this is not meaningfully different from individual account ledgers, but actually, this is literally how transaction history would be stored in an RDBMS. It's not different at all.
The existence of this (public) ledger is what creates the demand for things like Tornado Cash in the first place.
> Bitcoin transactions point money at one or more address.
Banks can facilitate transactions between arbitrary whole numbers of accounts also (off the top of my head: 1- paying interest; 2- payment; 3+- escrow)
> bitcoin is just a collection of those transactions & relevant/necessary data to support them them, compiled & validated using a variety of mathematic calculations.
Yes. Functionally, that results in a (limited) bank. Or at least, it's closer to that than it is to cash.
But you must open an account with a bank, and deposit money before they can process transactions for you.
There's no way to deposit money *into* bitcoin. Bitcoin is money.
> Each transaction has a set of associated addresses.
Yes, and you suggested addresses are the equivalent of accounts. They are not.
> Banks can facilitate transactions between arbitrary whole numbers of accounts also (off the top of my head: 1- paying interest; 2- payment; 3+- escrow)
Accounts, which hold money, are a tool of banks[0]. Bitcoin doesn't have accounts. Bitcoin is not a (limited) bank. It is a distributed digital cash system.
"Bitcoin uses peer-to-peer technology to operate with no central authority or banks; managing transactions and the issuing of bitcoins is carried out collectively by the network."[1]
0 - https://www.fdic.gov/about/learn/learning/banks.html 1 - https://bitcoin.org/en/
I have not deposited money into my bank account in many years. I have, instead, had money transferred to my account from other accounts. This is not only possible in Bitcoin; without it, Bitcoin would be useless. It's quite possible to open an account at a traditional bank with a transfer from another account; for online and investment banks, this is usually the only way to do it.
> Yes, and you suggested addresses are the equivalent of accounts. They are not.
Still waiting for you to tell me how they are not. It seems obvious to me that they are functionally equivalent, and I have made a case for why. An address is an identifier associated with a transaction history and access control. An account number is an identifier associated with a transaction history and access control.
You have made no corresponding case for why they are not, apart from citing your belief and citing PR from bitcoin.org. The former is convincing of what you believe, but it is not convincing with respect to the functioning of Bitcoin or banks. The latter is convincing of what bitcoin.org wants me to believe, but it is not convincing with respect to the functioning of Bitcoin or banks.
https://bitcoinmagazine.com/culture/doctor-bitcoin-jailed-fo...
You just can't win with these people.
It's also weird that the Treasury Department has such influence over crypto when it is supposed to be decentralized. The anger is clearly misplaced.
In very much the same way, if you are running a money transmitting business, you need to register with the government and follow the government laws. Otherwise, you risk going to jail. It's not rocket science. Just because it is on the internet doesn't make it a whole new thing.
Since when is driving a car without registration or license a felony?
Running a whole operation around driving without a license is what tornado cash is more similar to, not accidentally forgetting your license once, which is what the misdemeanor is for.
[1] https://casetext.com/statute/texas-codes/penal-code/title-7-...
Using your analogy, an instance of TC on private property would not be licensed.
And as an aside:
>Driving a car requires a license and registration of the vehicle.
Patently false.
Bob's Traditional Bank would be sanctioned here, because transacting with North Korea in that way is what triggers these sanctions. This is why Tornado is being sanctioned. The privacy thing may or may not be illegal, despite its ineffectiveness, but the transacting with North Korea thing definitely is.
Using volume of illegal activity cannot be the primary factor in categorizing a platform.
What percentage of activity in an E2EE chat application like Matrix is illicit? If a significant but minority percentage of its use is facilitating criminal discussion, should those open protocols also be sanctioned?
[1] https://dune.com/poma/tornado-cash_1
[2] https://www.eff.org/deeplinks/2022/08/code-speech-and-tornad...
The land of free speech is obsessed with being able to trace money as it travels. No surprise they would go after a service whose explicit purpose is to break the chain of custody on money.
https://www.reuters.com/article/us-usa-switzerland-tax/ex-sw...
https://www.justice.gov/usao-sdny/pr/manhattan-us-attorney-c...
https://www.justice.gov/opa/pr/former-ubs-banker-charged-hel...
This wasn't mainstream news, but neither was the sanctioning of Tornado cash. You just happened to hear about one but not the other.
This is where the “privacy on the blockchain should be a basic right” argument comes in, and what the plaintiff appears to be arguing.
The facts about Tornado cash are terrible: pretty much everyone using it is either doing something provably illegal or trying to avoid being found, you have to go out of your way to use it (and pay an extra fee), and it's been part of a large number of bad news stories about crypto theft. A minimum of 10% of its throughput is provably due to frauds and thefts, and probably a lot more. It is not an exaggeration to say that many people's life savings have been funneled through Tornado cash into the wallets of criminals. In comparison, numbered Swiss bank accounts likely had more legitimate use than Tornado cash.
In comparison, the facts about Monero, Zcash, and the Wasabi BTC wallet (another mixer, but attached to a wallet) are a lot better. Privacy is free and/or the default option with those services, and they are a little more like cash: lots of victimless crimes (darknet sales, etc.), some use by ransomware attacks, but also a lot of legitimate use.
This lawsuit has a nonzero chance of throwing out the baby (privacy on blockchains) with the bathwater (tornado cash).
Monero and TC are equal parts useful for non-criminals who are seeking privacy.
It's also worth noting the headline of that link: "Crypto Mixer Usage Reaches All-time Highs in 2022, With Nation State Actors and Cybercriminals Contributing Significant Volume"
Quoting from later in that study, "Overall, if we label cybercriminal organizations with known nation state affiliations, we can see that these groups make up a significant and growing share of all illicit cryptocurrency sent to mixers."
It's not 10-30% as you summarized. It's 12% last year increasing to 23% this year, or nearly doubling from a 1/8 to 1/4 share.
This source does not support the position that illicit traffic is an insignificant share of mixer traffic.
...and as much as I hate to say it, I do think the logic might be correct in both situations. (I say this as a heavy user of console emulators—albeit also as someone who does go through the trouble to legally dump his own games.)
One way to look at it is to say "I derived this rule based on what the ratio of licit to illicit usage is, thus it should apply everywhere." From that perspective, then yes, your observation that it would apply to both situations is correct.
Another way to look at it is "for this particular scenario, what is the optimal outcome?" If you're running a game console emulator for a system that's not being sold anymore, with games that are not being sold anymore, one could argue that that scenario would be net positive considering the lack of harm; in other words, you get to enjoy the game, while nobody gets hurt, so it's positive overall.
The first perspective is called "rule utilitarianism," while the latter is called "act utilitarianism," in case you want to learn more about those.
The regulation should be the existing Know Your Customer requirements plus a 100% traceable log subject to inspection, auditing and subpoena.
If someone owns a resource, no matter who they are, why shouldn't they be able to utilize it? If that resource was acquired with violent means such as human trafficking - then maybe our policing efforts should be to catch the perps trafficking humans, then they'll have everything they need to confiscate any and all resources those perps have.
This roundabout, lazy method of hurting innocent people in hopes that you only mostly hurt guilty people doesn't sit well with me and I don't think it's good for society to allow this kind of behavior.
Imagine that a hypothetical service is used at 99% for illicit transactions and 1% for legitimate ones. Is the best outcome for society to spend say 5 million dollars to shut down that service, or 500 million to figure out who is using that service maliciously and sue only the people who are using it maliciously?
All we can know for sure is that shutting down a white-market financial service or worse, blacklisting its users, has the guarantee that innocent people will be harmed.
Further: disrupting a single avenue of finances for the funding of illicit activity at best slows down the criminals. The overwhelming majority of crime is financed in fiat and the overwhelming majority of laundering happens in fiat, which can't be "shutdown".
It's simply ineffective and hurts innocent people. I'm not in favor of hurting innocent people even with modest efficacy and I don't believe that's what we're seeing here. I believe we're hurting innocent people with little to no efficacy.
From my perspective, an economically rational actor would want to minimize overall money transmission costs, so they'd avoid cryptocurrency mixers unless they had a particular reason to.
I'm sure there are other examples, but this is a good one off the top of my head and I personally have used mixers for this very purpose - to allow someone to pay me for a white-market trade without exposing how much crypto I owned in my wallet.
Thanks for sharing though, I hadn't thought of wanting to hide one's wallet balance from other people as a need.
With that in mind, if in fact it's impossible to stop, it seems rather arbitrary to pick and choose which products get targeted and serves no real purpose to even slow down the undesired behavior.
That's the reason checks or 200€+ bills are very rarely accepted anymore in businesses (in Europe at least), because they were very often fraudulent.
The hair you're attempting to split between "laundering" and "washing" does not exist in the financial world, and would not impress financial regulators.
It does to those who believe in financial privacy.
The government will not carve out a subset of crimes because of an unnecessary self-imposed restriction on financial privacy.
You can revoke that consent, as it is possible to become a citizen of no country, but I wouldn't recommend it.
But there is a collectively hashed-out social contract you accept by staying, and it should be of no surprise that the law takes that contract as table stakes and acts according to it.
Comparing your financial scheme to Jim Crow isn't the most distasteful thing I've seen on HN, but it's up there!
It's not my financial scheme, it's the social contract.
Comparing that to hiding your financial transactions so you avoid KYC is genuinely embarrassing.
Granted, that's assuming you're a valuable enough contributor to society that you'll find another country interested in taking you, one that won't similarly have expectations around "people in a society should pay taxes", but that's a you problem.
Or you can choose to live in a country that has a tax treaty with US; either way you get to deduct local tax rate paid so you're not double taxed.
Not true, this tool exists to provide privacy on an otherwise public ledger. Your tax assessor has no right to know about a transaction as soon as it occurs. A crime is only committed if you don't voluntarily declare it at a certain point in the future.
LE laziness and citizens conceding territory unnecessarily is creating a nanny state.
In other words: you can use a hot dog stand to launder money. But if you were to intentionally establish a hot dog stand for the purpose of laundering money, the government would be absolutely correct in seizing your stand.
Same goes for Tornado Cash. It was not designed for money laundering, although you could use it for that. If the US government finds cases of money laundering happening, take down the entities doing the money laundering instead of attacking a tool.
If you think Tornado Cash was designed for money laundering, please point us to the documents where this is mentioned. I've personally followed the development of the project, but never saw any mentions of money laundering at all, anywhere.
No one's going to advertise openly to the public "Assassination services here! Just call 1-800-KIL-THEM!"
And no one's going to put in public documents "we set up this company in order to facilitate money laundering."
Therefore, they intended it to be used to hide transactions from the US government. They could have also limited the service to not run on amounts larger than 10k?
Are you suggesting that there is no plausible reason to want financial privacy, outside money laundering?
By contrast, a hotdog stand is typically designed to cook and sell hotdogs and, in the rare instances where money laundering occurs, it's not a primary service the hotdog stand offers to clients, and will still get the owner arrested.
It does have other purposes, hiding transactions from the public, which I have used Tornado Cash for many times in the past.
> I used Tornado Cash (non-US citizen here) for hiding transactions from the public (not hiding from the government), and when I filed my taxes, I still accounted for everything that is stored there + transacted via Tornado Cash, just like I do for my bank account. Appendix contained instructions for how they could access the proof of my transactions and accounts to verify themselves.
Not sure why people think what I did should be illegal, I'm paying my taxes and declare everything just like everyone else, but somehow I shouldn't be allowed to hide my transactions from randoms on the internet?
You can do this. But it doesn’t come without risk.
If you kept using Tornado even after it was found Pyongyang used it to launder money, yes, you lose your money. It’s analogous to local law enforcement announcing a laundromat has been laundering money for the mafia, and then—months later–someone getting upset the clothes they dropped off have been seized. They may eventually get them back. But there is reasonable suspicion in the meantime.
https://www.icij.org/investigations/fincen-files/global-bank...
2) Because those are major, highly entrenched banks, they not only have the resources to ensure that stories about them engaging in bad behavior get swept under the rug (which doesn't mean "no coverage", but does mean they don't get covered as much as they might perhaps deserve), they also have the connections to make it very unlikely that they will face any kind of meaningful repercussions for this.
This is quite unfortunate, and a decidedly negative aspect of our current system. But the answer to it is not "so other companies like TornadoCash should be allowed to break the law with impunity, too!" It's "so we need to find ways to change our system so that we can genuinely hold accountable big banks and others who currently break the law with impunity."
This is what they’re doing. North Korea laundered money via Tornado Cash [1]. Authorities announced it and watched Tornado Cash do nothing. So it got sanctioned. Every other mixer is untouched.
[1] https://www.cnbc.com/2022/06/30/north-korea-likely-behind-10....
North Korea also used HTTP for navigating websites which helped them hack targets and also launder more money. Banning Tornado Cash is like banning the HTTP specification/IETF for that, instead of going after the group in North Korea doing the money laundering/hacking.
There was a team of developers earning compensation, hiring and firing. That’s more than just code.
Guns are quite literally just atoms. The context matters. Not all guns are illegal. But ones used to commit crimes will get lawfully seized. The code exists in context, and the developers’ actions and intentions are relevant. None of this is novel.
This is the kind of sociopathic irresponsibility that's too common in tech. "Oh, it's not my fault my lab-grown monster decided to terrorize the countryside!"
It's not illegal whatsoever to mix up my dollar bills with a group of other people and get the same amount out that I put in. Such a statement is ridiculous.
I don't think the crypto industry is lacking in funding enough to be able to hire lobbyists, so I'm not sure why we might blame a legislature that can't be experts in literally everything (setting aside the fact that they tend to be fuddy-duddies for other reasons, it's not even theoretically practical that they could be perfectly informed on everything) for not having made perfect laws around a new industry.
Furthermore, actions are not usually the things that are illegal. Usually the law prohibits actions which cause a specific effect. Like murder or pollution. You dont get one free murder every time you figure out a new way to kill people.
Here ya go.
By the by, all of this is to be known or planned out before becoming a money transmitter.
I.e., if you cannot do this, you are not legally allowed to serve as a money transmitter.
[1] https://www.justice.gov/archives/jm/criminal-resource-manual...
Here ya go.
If you use Pokemon cards in such a way as there is a reasonable expectation they may get converted back to dollary-dos, you are required to track that too. Sorry mate. Nice try. But no.
Thank you, come again.
I get it. It's frustrating. If only the means of exchange wasn't such a pivotal part of criminal enterprise, or people would just not do illegal things, we could have nice things. Alas, tis not the case.
If you don't, you're laundering. It's like a bunch of tech people waltzed into finance, ignored the entire history of the institution, and lessons paid for in blood, and expect everyone else to bend over backwards for them.
TC is made for privacy, which either is or should be a basic right.
Without tools such as TC if I send you money, show you some POAPs[1] I own, or otherwise interact in any way with my crypto, it is fairly simple to deduce or make educated guesses of how much crypto I own, who I send it to or from, and more. This has serious implications not only for privacy, but for safety reasons too.
TC makes it so you can transfer from your cold wallet to your hot wallet, without trivially revealing what your cold wallet is (and thus your funds).
Furthermore TC also allows you to keep a receipt of these anonymous transfers, so you can in the future prove the origin of your funds or reveal such transactions.
There are a lot of laws banning knives of various sizes and constructions. I'm not sure you picked the example you want.
There are plenty of knives that are designed to facilitate murder, and they are correspondingly regulated.
We don't regulate kitchen knives in that way, because they don't represent the same intent.
If your financial instrument leaks all of your transactions and makes you a target of criminal scrutiny, you should consider using a different instrument. Society is not going to throw the baby out with the bathwater to accomodate your public immutable ledger.
I'm pretty sure the majority of knives used for criminal activities are rather kitchen knifes.
Compare Tornado Cash with cash money and tell me how they are different. Being untraceable does not make it a criminal instrument or does it? Is it criminal to conceal your financial transactions from the government?
Regardless of whether this is true (which it probably isn't, at least in the US), it doesn't change the intent. We regulate different things differently based on their intended use.
This should cover your second question as well. Intent is what the government cares about in this instance. And yes, it is indeed illegal to conceal your transactions from the government, at least insofar as they concern money that the government is entitled to tax or review.
Probably because banning knives is ludicrous behavior, so there aren't better examples.
So you can see for yourself: https://en.wikipedia.org/wiki/Switchblade
But the core point is that societies will ban things that generate more harm than benefit, be it real or perceived. This is the crux of the gun debate in America right now.
So here's the context for TD AFAICT: crypto is a competitor to fiat currency and all the hegemony that comes with it. It is a power play, and power doesn't come for free, and often is ultimately paid for with blood. Governments aren't just going to let a new wild west open up on that without any say-so. I think crypto enthusiasts either don't understand the implications of the tech or reject them on philosophical grounds, which I sympathize with but understand that doesn't change the reality as far as every stakeholder is involved.
I'm not sure I 100% agree with the statement "crypto is a competitor". Sometimes it's a currency, sometimes it's a commodity but at the end of the day, it's a store of value that humans own.
US dollars deposited in a bank and crypto in a wallet are owned by the same people, so it cannot be a competitor. It's just another asset class. The fact that Coinbase is a publicly traded company shows that the US government 100% accepts crypto as what I've described.
What they do care about are items and processes who's main purpose is for illegal activities. Guns are a perfect example. You want to buy and register a gun from a licensed dealer, no problem. You want to buy one from a guy in a van and scratch off the serial number, that's a problem. In the eyes of the government, Tornado Cash is too much like the guy in the van.
It's actually quite challenging to find a decent pocket knife that's legal to carry here: if the blade locks in place, it's not legal. So pretty much any Leatherman or Gerber that's not one of the mini ones is out, and all the cheaper brands are the same. I've taken to carrying a Geekey[1] and a knock-off Raptor[2].
[1]: https://geekey.com/ -- although the feature being headlined is the one I'm least likely to use.
[2]: https://www.leatherman.co.uk/collections/raptor-rescue/produ..., literally a quarter of the price without the branding: https://smile.amazon.co.uk/gp/product/B08ZSV5644
Victorinox split their pocket knives into three categories: small, medium, and large. Only the large are comparable in size to multitools, and they all seem to have locking blades.
I'm actually pondering getting a basic medium-size pocket knife though, to complement what I'm carrying at the moment. Thank you for reminding me :).
> KEY TAKEAWAYS
> The Bank Secrecy Act (BSA) is U.S. legislation aimed at preventing criminals from using financial institutions to hide or launder money.
> The law requires financial institutions to provide documentation to regulators whenever their clients deal with suspicious cash transactions involving sums over $10,000.
> The law does not require documentation for every transaction over $10,000, but businesses must file Internal Revenue Service (IRS) Form 8300 if they receive more than $10,000 in cash from one buyer.
With the invention of paperless transaction, Government steps in and ensure every transaction record is there to show the party of the transaction. This happened, before the invention of the internet.
If you wanna fight, then you will have to undo all the legal changes.
Compare of the little loss of the privacy, and the possibility of funding the evil state like North Korea and its infamous neighbour. I would choose get rid of the evil country.
Damn, those goalposts moved like lightning. From "making it a bit harder for North Korea to get a bit of extra cash" to "abolishing the North Korean government" in a single sentence.
People going all pikachu face on this story is really weird as fuck. It was obvious this was going to happen.
That’s like saying TLS was designed to protect CP.
Privacy =/= laundering
People were breaking stupid laws from the 70s established after mass hysteria around drugs by one of the scummies US president ever. More than that, the tax man was not getting its cut.
Now to put things in perspective let's compare to some things US agencies have done in the past: https://en.m.wikipedia.org/wiki/Allegations_of_CIA_drug_traf...
Because there was all sorts of white washing like this. "It's drugs, but safer, and without the violence and crime!"
If you think that violence, crime are magically gone because of Silk Road, you'd be considered ignorant or naive. Production still happens in the same places, the poverty, corruption and violence-stricken areas.
It's just invisible to you now, because you don't have to worry about your dealer stealing from you, getting mugged, or buying from an unknown source, or being arrested.
All those people in Mexican and Colombian villages subject to the tyranny of the cartels... oh well.
All good then, I suppose.
Just go into the frigging villages and arrest the cartel leaders oh wait they are in cohort with the governments of those countries...
But let's not pretend that Silk Road is some panacea saying "Hey, violence-free drugs!"
I tend to be on the legalization side of the spectrum but the notion of Silk Road as some humanity-improving place, versus a method of making Ross rich is definitely in need of citation.
Want to eliminate production that happens in places with poverty/corruption/violence? Just make them legal. Seriously. Offer rehabilitation instead of jail. Other countries have done this and it work.
People talk a big game when it comes to "our freedoms" but real freedom is to be able to do whatever you want as long as you don't impact your neighbor/other.
I just don't think Silk Road (and its brethren) were a means to that end. It just hides a lot of the issue.
Because it would only remove the violence in our neighborhood and not the violence 1000s of miles away. This plan is not worth pursuing.
We can grant everything you said that the Silk Road may have only reduced violence in our immediate vicinity. That is still a huge success that should have been continued. Its not a failure for only reducing local violence.
That local win could have grown more globalized acceptance; reducing the niche cartels fill. Even if it had merely encouraged greater local production of illegal drugs that alone could have reduced cartel violence in Mexico.
Normally, there'd be an aspect of plausible deniability: torrent index operators can, for example, rightfully claim that they're facilitating legal filesharing, or that they're entirely agnostic to the content being shared (if all they're doing is sharing URLs). What's key in this case is that law enforcement claims that Pertsev was aware of the crimes his service was being used for. Whether or not that's actually true is up to a court to decide.
That's right: Government sanctioned open-source SOFTWARE. Are you sure you want this precedent set?
You should take a step back: "open source" does not rinse away the underlying properties of a service. I can't write and deploy a web application that contracts hitmen and use the MIT license as a defense; the latter simply isn't being litigated.
Tornado Cash in itself does is not launderying money because you still have to prove to the IRS how you got the money or the asset(i.e bills, invoice etc) and you still have to obey KYC rules. You can't just say the money is from Tornado Cash and be done with it.
Is the U.S Mint a money launderying service because it provides an untraceable method (cash) to conduct transactions?
Both the Treasury and Dutch authorities have reason to believe that Tornado Cash was operated with the intent of facilitating money laundering. It's up to a court to determine the veracity of that accusation.
In the mean time, yes: the government is allowed to halt activities that it believes are part of an active criminal scheme. Every country with a functioning legal system proscribes this, and establishes a broad swath of controls to ensure that the government can't indefinitely tie up resources.
It is my understanding, that $10,000 at the time this law was set, was about ¼ the price of a small home.
You don't get to shift regulatory burden to the consumer.
Really good question.
I'd say "if your privacy feature allows you to trade above the trigger limit (usually 10K USD/EUR/GBP) without having to state the source of your funds, then it's actually a money laundering feature"
I've worked in the finance industry, and I've worked with people who've seen bad guys turn up with suitcases full of other people's money. I'm totally happy that these regulations are in place.
You are wrong.
FINCEN "Money laundering involves disguising financial assets so they can be used without detection of the illegal activity that produced them."
WIKIPEDIA "Money laundering is the process of concealing the origin of money obtained from illicit activities such as drug trafficking, corruption, embezzlement or gambling, by converting it into a legitimate source."
That's easier said than done. It's drastically easier to catch crime by it's results (money) than in the act. Famously that's how Capone was caught. And what would be the advantage of that, to anyone? I doubt that erroneously flagged transactions are a real problem. Do you have any numbers on the matter?
It may have not happened to you, but I do not think it is as uncommon as you think. Parent is right. We are doing this backwards.
The teller is not allowed to disclose this to customer.
> Any numbers you will see might be from the government
In my experience, the board of directors of the bank get a monthly roll-up of the numbers.
There is an open question about whether publishing non custodial contract code on Ethereum counts as providing a service. If you post 10 lines of immutable code onto Ethereum, and some years later a user chooses to run this code on their machines for criminal behavior, should you be prosecuted?
The treasury ban is on the contract itself, not TC-based services that people might run.
for laundering money. You can't remove the key feature from metaproperties of the software and call the latter the "chief selling point."
You’re describing due process. That’s a feature. An AK-47 being metallic may be self evident. That doesn’t make it relevant to a murder investigation.
There are thousands of them in the U.S. and owned by innocents. It would be unreasonable to come after all AK-47 owners because one was used in a crime. Rather, it would be up to the cops to find other facts about the weapon, perhaps how much more metallic it looked than your standard AK, and in which spots. Wear marks can be just as revealing as serial numbers.
Every mixer isn’t sanctioned. Just the one used to launder money by Pyongyang. None of this is novel.
As someone who was excited by the original Bitcoin whitepaper back in 2011, zk-SNARKS was what excited me about cryptocurrency again in 2021.
At the absolute worst, they were agnostic to the presence of criminal activity. This is in contrast to Tornado Cash, which was repeatedly told that their service was being used to launder money.
There is no meaningful sense in which PGP could ever be said to "facilitate" terrorism in the same way that Tornado Cash is rightfully characterized as facilitating money laundering. PGP is a program that runs on your host, encrypting your email. Tornado Cash is a service, run by an individual who was warned to cease serving sanctioned entities, and failed to do so.
This is false. The (vast majority of the) Tornado Cash contracts were either deployed to Ethereum as immutable contracts, or updated in 2020 to revoke mutability (once the final zkSNARK parameters were included) [0], meaning that they could not later be updated by the user(s) that deployed them. Arguing that Tornado Cash is run by an individual means arguing that the entire Ethereum network is run by an individual. There was no way for a warned individual to comply with that warning.
[0] https://www.coincenter.org/education/advanced-topics/how-doe... - Section titled "Can Tornado Cash be removed or updated? If so, by whom?"
Thousands of little contracts doesn't absolve a financial institution from a few many-billion dollar illegal transfers, especially after they've been warned repeatedly.
Usually a smart contract protocol is a set of contracts working together, deployed to the blockchain, which provide application logic that executes regardless of who is interacting with it (via "transactions")
This is known as “chilling effect” in a legal context.
People who might otherwise want to use this for financial privacy would be wary, since if they deposit funds to the contract, they don't have any way to know if they'll be able to use the unlinked funds later if withdrawn.
Most customers of a canonical money launderer, a laundromat, don’t realise it’s a front. That doesn’t matter if the owner is laundering money.
Tornado laundered money for North Korea [1]. (It announced this months before the sanctions, a period in which the developers could have reacted but didn’t [EDIT: in any meaningful way].) That it was also obfuscating legitimate flows is frankly irrelevant.
[1] https://www.bloomberg.com/news/articles/2022-08-08/crypto-mi...
Not sure. Their problem. If the only option was shutting it down, that. It would have looked better, which could have prompted sympathetic legislation. At the very least, it would have likely avoided sanctions.
If that’s truly the case, shut down as in stop developing it and advise users to stop using it. Then the addresses get sanctioned and nobody is surprised.
Which does nothing in practice. Any AML lawyer would have advised them so. The fact that the service was designed to be incompatible with the law isn’t a get-out-of-jail card.
It’s not. Subpoenas require handing over what you have. If you don’t have it there is no obligation to disclose. Signal may run afoul of data-retention laws. But there are no such requirements in America.
I'm also not aware of what US law would have been violated by either
1. Coding and publishing the tornado source code
2. Deploying several instances to the blockchain in 2019.
There's no US prosecutions based on creating or operating tornado. The Dutch one has not charged the person they arrested yet, according to https://www.coindesk.com/policy/2022/08/24/alleged-tornado-d..., so I don't know what unlawful actions they think he's responsible for.
Plaintiffs' argument relies on Tornado Cash not being "a person, entity, or organization" [1]. The complaint declares OFAC exceeded its statutory authority, but provides no specifics. (The code cited in ¶ 9 [2] gives courts the authority to tell agencies not to do bad things. That isn't an argument for or against OFAC's specific actions in this case.)
In summary, it's a hope-and-a-prayer complaint. Maybe someone at OFAC fucked up the paperwork, thereby giving rise to some modicum of relief.
[1] https://storage.courtlistener.com/recap/gov.uscourts.txwd.11... ¶ 4
It's very basic software from a functionality perspective. You put coins into a pool, then at a later date, you take coins back out of the pool. That's all.
It's hard to ascribe specific intent to a system like that, beyond the intent to give people a tool to transact without the entire history of their account being broadcast publicly and permanently on the blockchain.
Like how far am I allowed to go to describe how you might launder money on a blockchain before I get arrested?
Doing what Tornado.cash does, is by definition, laundering, and if you didn't want your financial matters known to the world, mayhaps you should not have used a technology based on public ledger?
It just breaks the last model law enforcement is used to where they just siphon up all private financial data for their own uses.
Believe it or not, there is such a thing as a pointedly not implenented feature. This has been one of them, because it is the difference between essentially making financial crime tractable to investigate vs. not.
I'm not taking a side, just trying to make more obvious some of the more subtle nuance most people won't articulate for you, as it tends to be part of "the quiet part". You must employ 2nd and higher order thinking to the U.S. and international regulatory state.
My understanding is that the aegis of National Security isn't unwarranted sometimes. For example, if they know NK are bad guys here because one of their spies literally witnessed the laundering (as a secretary, paper-pusher, programmer, or similar) then there is no way to disclose the source. Even a "we have an eyewitness" will tip NK off to look into the people in the process (NK will be able to definitively rule out their technology being hacked, or a bug planted somewhere).
I saw a post recently about the fact that nobody could easily identify the users of pay phones in the past and how modern day lawmakers would probably ban them out of fear of anonimity. It showed just how much privacy the average person has lost over the years...there has to be pushback.
The sanctions followed Tornado being fingered as the laundering service used by Norrh Korea [1][2].
[1] https://hub.elliptic.co/analysis/the-100-million-horizon-hac...
[2] https://www.cnbc.com/2022/06/30/north-korea-likely-behind-10....
If it was publicly known that you had exactly 1 ton of legally acquired gold in your house, would you feel perfectly safe sleeping at night? Is there not 1 sicko out there that would be willing to torture your family to find the combination to your vault?
Plausible deniability exists here. It's called wanting privacy, and there's perfectly valid and non-criminal reasons to want privacy, despite repeated false claims.
Here is the problem. Many cryptos are not actually anonymous. If somebody has somebody's wallet address, they can look into tracing information about them like their net worth and their purchasing history. Even if you were smart enough to use a different wallet address for each transaction, you inevitably have to spend money to live or send money to others and then you can be traced. As tools grow more sophisticated and more data about wallet address ownership gets out there, the more at risk people will be. And once your identity gets out there, there's no shaking the ability to track it short of some form of mixing or obfuscation. In an of itself, mixing or trading to obfuscate your identity shouldn't be considered a crime or unreasonable in the slightest.
Which, as I understand it, mostly consists of not keeping it as a gold brick in their basement, and not living in a shitty neighbourhood. It's harder to rubber hose attack someone who isn't keeping all their wealth in a crypto wallet.
"Financial privacy" isn't a real thing, because you owe taxes on income and investments. Can you explain to me how your tax assessor is able, then, to properly identify your income and tax you on it as appropriate?
(Money laundering and tax evasion do not always go hand-in-hand. Many launderers pay taxes as a cost of doing business. Cryptocurrency mixers seem to treat tax evasion as a feature.)
Historically there is huge market for that.
We can argue over how easy it would be, but I would presume its possible for a government to switch over to taxing hard assets like land, machines, and shipments at ports rather than income and investment products if we decide those should be shielded by a right to privacy. Most of human history existed without a tax on income or loans (investments), an argument that a right cannot exists because of the present tax structure is like the ultimate status quo warrior-ing.
Your post is largely meaningless because, while this line is inarguably true, this also hasn't happened and so AML and KYC are still a thing--and there's precious little to indicate that anyone really cares about it aside from starve-the-beast conservatives and cryptocurrency enthusiasts, and that's not a majority.
If a country does decide so collectively, great! We haven't. So yeah, it's illegal, and the currently-fictive right to financial privacy remains so.
Now with USA fiat money there is no financial need to have personal income tax.
The legality under existing laws has nothing to do with whether the right exists or not if its a natural right.
I also fail to see how one could construct a right to privacy that would include communications but not include financial transactions especially exchanges of value done over a btc-protocol (or one of its descendants) that exchange value with pure speech.
If congress and/or the judiciary was full of privacy enthusiasts, then the tax law would be changed majority be damned.
I struggle to find a legitimate use case for hiding transactions from your bank and thus tax authority (assuming a developed country).
Bad assumption
Anonymous fundraising for political dissidents is the biggest use case I can think of.
You mean the banking system that freezes protesters' accounts when they do something doubleplusungood?
Personal choices that don't violate the rights of others shouldn't require any explanation to retain your rights. But it's not hard to think of a lot of reasons for somebody to use crypto over banks besides the state not being able to trivially shut you out of your life. There's other good reasons to choose crypto over banks, but that's a good one in my book.
There is a huge difference between sharing the details of your finances with a tax or other authority by default and them being able to compel you to provide such information if they have good cause to believe (and convince a court) that you are evading taxes.
The fact the government required six illegitimate things of me before breakfast does not make them legitimate, it just means the abuse has become normalised to the point that people start believing this shit is reasonable.
Having access to your money outside of banking hours is just one of many use cases I can think of off the top of my head.
Roe v. Wade
Interesting concept, but a few quick thoughts on this.
1) I'd only point out that there exists a point of view that that says that a baby's body is a separate life from a woman's body.
2) Such a constitutional protection would open up some very complicated issues when it comes to children, particularly with regards to sexuality.
3) Many of the same people who very eloquently speak out on personal choice in some medical matters "lost the plot" during Covid. Who can credibly make this argument and advocate for such a policy credibly?
By that point of view it would be reasonable to separate both bodies if one of them wishes to be left alone, so both can move on with their lifes. Equal rights.
The chief selling point of Tornado Cash was addressing the significant privacy problems inherent in a currency based on a public ledger. The idea that we should destroy privacy tools because criminals use them is ridiculous.
Also, law enforcement publicly announced Tornado was used to launder billions by North Korea [1]. Months ago [2]. Everyone continued as if nothing happened. This wasn’t based on hypotheticals.
[1] https://hub.elliptic.co/analysis/the-100-million-horizon-hac...
[2] https://www.cnbc.com/2022/06/30/north-korea-likely-behind-10....
There is a possibility that miners could collude not to authenticate blocks with tornado cash transactions in them, but that gets into some interesting game theory in a globally distributed system. Not every miner is subject to US law.
It's a very fascinating story.
https://www.coindesk.com/tech/2022/04/15/tornado-cash-adds-c...
(This is still new to me, please correct me if I'm wrong)
Even if the "vast majority" of stakers agree with the regulation, the regulation is ambiguous as to whether stakers are expected to refrain from including TC transactions in their own blocks, or actively orphan all blocks that include TC transactions. The latter hurts their staking revenue and effectuates a soft fork. (Staking revenue is hurt due to the inactivity correlation factor that the network uses to calculate rewards.)
If the regulation only demands the former, then the network will continue status-quo, except that TC transactions may take a couple minutes to be included instead of 12 seconds.
It is possible, via a hard work. Similarly as it was possible to transition from PoW to PoS. The question is, if there is political will for that. Clearly changing the protocol rules is possible has it has been done with ethereum in the past, including for censorship reasons (in the earlier hard fork the reason was to cancel a hack).
As a counterexample to the DAO hack, the parity multi-sig hack of 2017 resulted in over $160M worth of ether being frozen on-chain. There were calls to hard fork Ethereum to return it, but the hard fork was never tenable. That was barely a year after the DAO hack and fork.
Personally, I believe there is a zero chance that a hard fork based on Tornado Cash becomes viable. It's not nearly a big enough issue for enough users to care (and exchanges, and wallet software companies, and stakers). Why would the 90% of users who don't use Tornado Cash risk helping the other 10% perform some fork, knowing that the fork would add fuel to the mutability argument and set more precedent for mutability?
I’m not asking a rhetorical question. I’m genuinely confused as to the underlying legal principle about what’s being enforced here?
People who make technology should not be expected to add measures to it to make sure that nobody is ever able to use it to commit a crime. This kind of thinking would have resulted in guns being banned until technology exists for the gun itself to detect who was firing it and what it was being fired at, to prevent any crimes from occurring.
Why not? It's quite common, e.g. a lot of photocopiers have safeguards to prevent currency counterfeiting and will refuse to copy bank notes containing the EURion constellation and other common bank note markers. Pretty much any decent financial software will have sane defaults for audit trails, separation of duties, and so on to try and prevent fraud. Etc.
If you deliberately build something that can facilitate money laundering and ignore finance laws about KYC and mandatory reporting and and so on, you only have yourself to blame if you run into legal trouble. It doesn't matter if you don't like the law or think it shouldn't apply.
>This kind of thinking would have resulted in guns being banned until technology exists for the gun itself to detect who was firing it and what it was being fired at, to prevent any crimes from occurring
You'd have to ban all blades, any kind of explosives (mining), any kind of vehicle, etc. ... a creative person can misuse just about any technology to commit a crime. At some point it is simply not possible to build safeguards. How would you put access controls on a sharp rock?
I don't want to open the whole gun control can of worms, but down here in Australia we have strict firearm control and our firearm-related death rate is very low (0.92/100k population, vs. 10.95/100k for the USA [1]). It still happens of course, but the rate is low enough that strict technological controls wouldn't add much value. And I believe, though can't find the source I remember seeing a while ago, that a pretty big chunk of those are suicides / accidents and there is very low violent crime.
[1] https://worldpopulationreview.com/country-rankings/gun-death...
Do you believe that code is protected speech? Do you believe that people should be prosecuted for publishing source code that has the potential to be used maliciously if compiled and run?
We have a right to freedom of expression and opinion (Australia is party to the International Covenant on Civil and Political rights), but there are a number of areas where this can be restricted e.g. using a telecommunications network with intent to commit or facilitate a crime is forbidden.
I think probably writing/hosting the code might be ok (although Github et. al are certainly not obliged to host it), but deploying it to a cryptocurrency network would be where it becomes a problem. I don't think any reasonable person would believe that Tornado Cash wouldn't be used to commit money laundering offences, and intent does matter when it regards facilitating crime. I would also think that participating in a DAO (exercising voting rights or what have you) that controls a cryptocurrency tumbler would count as facilitating crime assuming you didn't immediately try to shut the thing down once it became clear it was being used for money laundering.
But, I am not a lawyer (and this is not legal advice). That's just my surface-level understanding.
Global banks that could facilitate the same thing would only consider doing it for the super-rich to hedge against the possibility of getting caught and fined. So are not open to the average person, hence people have no problem calling for them to be held to account.
Both should get the same treatment. That goes doubly for the global banks that have historically caused far greater problems than TC.
Banks can be fined and people can be imprisoned, but you can't fine or imprison software. The Treasury ban is a direct ban on software, which is a departure from precedent.
That's what makes this legal case unique, and why it's not simply a double standard.
These are some pretty astounding sums.
Privacy =/= laundering.
Tornado is/should be perfectly legal to use to pay IRL vendors without revealing the entire contents of your hot/cold wallets.
It’s also useful to move money between hot/cold wallets safely.
You have a fundamental misunderstanding of US law with regard to money laundering. Obfuscating the source of funds, by itself, is not money laundering. Money laundering requires a "predicate offense" - the money that is being laundered must be proven to have had an illicit source. Further, the entity accused of doing the "laundering" also must know that the source of funds is illicit before doing it. Intent to promote the carrying on of "specified unlawful activity" must also be proven in order for a money laundering conviction to occur. You can read the entire statute here [1].
Therefore, the "chief selling point" cannot be money laundering, at least under US law, because the contracts were deployed with no prior knowledge of how or by whom they would be used. One cannot form intent without prior knowledge. The chief selling point was anonymity, not money laundering, which has a highly specific legal meaning.
Structuring is one of the most common methods of facilitating money laundering.
No predicate offense required. It’s illegal all on its own.
Casinos are used as vehicles for structuring and money laundering every minute of every day - on a much larger scale than anything Tornado Cash could ever have achieved. They don't have the intent to aid in these activities though, which is why they are allowed to operate.
Casinos are allowed to operate because not only do they not have the intent to aid these activities, they happily track and report everything they're required which is just as much as a bank is required. They aren't the hotbed of money laundering you seem to think they are.
https://www.fincen.gov/resources/statutes-regulations/guidan...
I spent a fair amount of time in the gaming business, and I can tell you that this statement is patently false. Very little of it gets caught, because the people involved in such schemes know what the rules are and simply work around them. Casinos themselves also sometimes turn a blind eye to such activity when it is especially profitable for them. Example [1]. That occurred even with the reporting requirements.
[1] https://www.justice.gov/usao-cdca/pr/operator-venetian-resor...
Your original point was that casinos are allowed to operate because of their "lack of intent". I respond that it's actually because they're as heavily regulated as banks are. Your response is, "But sometimes they break the law!"
Who cares? Casinos are heavily regulated and most of the time they follow their regulations. Or they would be shut down.
And here we go back to the real original point... what regulations were Tornado Cash following? Were they ever following AML/BSA regulations? Did they do anything significant to attempt to comply with regulations that all money exchange companies have to comply with?
Seriously, take 2 minutes and read this:
https://home.treasury.gov/news/press-releases/jy0916
Your little example of Casino money laundering was $47 million and was touted as “the largest all-cash, up-front gambler the Venetian-Palazzo had ever had to that point,”.
Now read that link from treasury.gov:
Tornado Cash, which has been used to launder more than $7 billion worth of virtual currency since its creation in 2019. This includes over $455 million stolen by the Lazarus Group, a Democratic People’s Republic of Korea (DPRK) state-sponsored hacking group
It's not even comparable. $47 million is 0.6% of $7 billion. Tornado Cash's raison d'être was money laundering and it was right to shut them down.
It's another crazy concept of overreaching states and IRSes enjoying way too much power. They can arbitrarily decided what's structuring and what is not. Arbitrary decisions aren't how a democracy should work.
You want to prevent people doing these kind of transfers? Make it clear what the limits are. Don't come after people doing precisely what the limit allows several times: precise it can only be done once or x times over a certain time period.
That's by the way, how some laws do work. For example in France you're allowed to give your kids up to 150 K EUR of real estate (or something), tax and inheritance tax free, once every 15 years. After 15 years you're free to do it once again.
But putting limits and then attacking people respecting the limits? To me it's the sign of something deeply rotten in the state and that such laws exists isn't something that should be cheered.
On the other hand, depositing money is the normal status. Depositing what amounts to large sums over arbitrary periods of time is also normal. Directly to the point, the limit in place is not a restriction, but merely one that triggers mandatory reporting. The limit is very clear and absolute -- though at their discretion banks may report smaller transactions. Structuring is specifically about avoiding that limit and the accompanying questions and reporting.
So how would you rewrite this law to require mandatory reporting, but also not allow structuring? Because it's not apparently trivial how to achieve that goal any better than they did.
I feel like the signal-to-noise ratio must be terrible, especially as inflation gradually lowers the meaning of a $10,000 reporting limit. Selling a used car is enough to trigger a reportable amount of cash.
I'd think what we need is less magic numbers, and instead a better training/reporting ecosystem that insulates people with good intentions but gives them the right tools to identify criminal behaviour.
Actually expecting banks to know their customers at a personal level should be the goal.
I suspect, in contrast, everyone involved likes a fixed 10k limit because it provides a convenient liability hand-off. Compliance can be automated on a much greater level and they can say "we filled out the appropriate forms when required, how were we supposed to know that Hamas Cupcakes Inc was a front?"
So there are two possibilities.
1. You think the government shouldn't be allowed to track money laundering
2. You have a suggestion on improving money laundering tracking without anti-structuring laws
If you believe the government has a legitimate vested interest in stopping money laundering and you set a $10,000 limit before something must be reported, the reporting requirement might as well not exist if someone can deposit $9999.99 literally 100 times per day without a report being generated.
So what would your suggestion be on how to track money laundering? Or do you just think that's none of the government's business?
Something more reasonable may be: a limit of $10,000 per month (or any time frame) before mandatory reporting. That of course means dropping the hand wavy exception completely.
I'm concerned with (a)(1)(B)(ii), which concerns reporting requirements. The kind of financial transactions that Tornado Cash enables are fundamentally incompatible with the US's Federal reporting requirements.
My understanding of the Dutch criminal code (which is not great!) is that their standard is even weaker: it is sufficient to demonstrate mere concealment, not a failure to meet particular reporting requirements.
I don't know what Dutch law says with regard to intent/knowing participation, but I suspect that any system of laws in a civilized country would generally require it for criminal convictions.
The intent in question is manifested in Tornado Cash's design, which doesn't pass the malfeasance smell test: you can't absolve yourself of illegality by automating the illegality.
Given that it also has legitimate uses, I think that's a very difficult case to make. Also, with very limited exceptions, nearly all crimes in the US require intent and/or knowing participation. It's a fundamental tenet of our system. There is a reason that they aren't being prosecuted in the US, and those reasons are outlined above. Perhaps Dutch law is different enough to allow a conviction; time will tell.
I'd also point out that Apple's device encryption scheme was specifically designed so that Apple itself cannot unlock devices, which thwarts law enforcement subpoenas for assistance. They can legitimately throw their hands up in the air and say "we have no ability to help you" - and that's by design. It is not illegal to design systems in this way. It just shifts the legal liability for misuse onto the users, where it should be.
There are obviously workarounds without tornado cash but tornado cash is probably the cheapest option.
You're not addressing the point about "(a)(1)(B)(ii), which concerns reporting requirements".
If they cannot meet US law for reporting requirements, then they are breaking the law, right?
The fact that this statement is 100% completely wrong in totality is common knowledge.
I recently bought a kayak. In my state I'm required to register the kayak and have a registration sticker on it. If I was unaware of this, there is no, "Oopsie! Didn't know" defense.
This principle goes back to Roman law - ignorantia juris non excusat. You may have heard Thomas Jefferson saying the English version, "Ignorance of the law is no excuse". It's one of the favorite things for judges to say as they sentence people in criminal proceedings.
> as due process required that the defendant have notice of the crime at issue. The Lambert decision explicitly recognized this fair notice requirement as an exception to the general rule that ignorance of the law is no defense.
I’m not saying that necessarily applies here but clearly ignorance of the law can sometimes be an excuse, no?
The chief selling point of Tornado Cash is money laundering
Firmly disagree. The chief selling point of Tornado Cash is a mixer. Please see my reply to essentially this same misconception a month ago, which includes concrete, legal use cases:The same thing could be said about paper money.
This is also why cops willy-nilly decide to seize it if you have too much of it. There are countless examples of normal people who happened to have large sums of paper money, on their way to buy a vehicle, being stopped and their life savings being taken away through civil asset forfeiture.
It would in fact be better live in a country with financial privacy where assets form the tax base instead of income. In terms of convincing the public, I think time will do the former and education the later.
The flaw with this line of reasoning is that behaviors have changed. In the past, when the police did "police work", people had no choice but to meet in person to discuss their criminal enterprises. You could follow them, and listen in. Many illicit schemes also left a trail of paper that needed to be stored in physical space.
It's not that the police have gotten lazy, it's that if you expect criminals to hang out in a shady dockside speakeasy like they did when Al Capone ran the town, you're simply not going to find anything.
This is a real tricky problem to which I'm not sure there are good solutions. There's a mounting conflict of interest upholding the law on the one hand, and the interests of law-abiding citizens on the other.
So this isn't Tornado Cash "might be used for illegal purposes" so much as it's clear evidence they're failing to meet their legal obligations.
There's a larger point here too: as much as proponents tour crypto's extragovernmental status, it would take very little effort by governments to completely cripple any crypto assset in practical terms.
So as an individual, I convert my cash to e-coins through some e-coin dedicated ATM-like machine. And I can redeem my e-coins for cash at another e-coin-ATM somewhere else (maybe anywhere in the world).
Would coin pools like Tornado Cash then be acceptable? It would not be tied in any way to the credit or banking systems, it takes cash only, and then just a basic utility internet connection. Maintenance for the machines and paying the internet utility would just be a fraction of a percentage fee on each transaction.
Now all e-coins would simply exist as a privacy themed alternative ecosystem to cash.
Since we are not joining the U.S. financial system, these e-coins should not be expected to have any obligations to that system correct?
https://www.economist.com/finance-and-economics/2021/04/12/t...
https://en.wikipedia.org/wiki/Danske_Bank_money_laundering_s...
But to go back to the original query. It is just so much more easier to click couple of buttons than go somewhere and ask questions. It is cheaper too. The convenience trumps most of the other reasons. The same goes for privacy. The convenience killed it.
Also, who are these "investors"? They're speculators. When you speculate, there's risk involved. This is one of them. This case is an unnecessary burden on our legal systems, I hope it gets thrown out of court ASAP.
I'm all about privacy and anonymity of transactions personally, but tornado investors going all "surprised pikachu" right now after a more-than-previsible ban is a bit laughable...
?
What's your opinion of Tor?
https://www.coincenter.org/education/advanced-topics/how-doe...
The same is true with all the loto and gambling crypto sites. They run without any oversight and are blatantly breaking the law.
North Korean sanctions [1]. As well as virtually every jurisdiction’s AML laws. (Specifically, American and Dutch.)
[1] https://en.m.wikipedia.org/wiki/Sanctions_against_North_Kore...
That's the facade. In my experience, Bitcoin is still the main ecoin demanded in phishing/ransomware incidents, even when more privacy-friendly ecoins exist. A tumbler's purpose is distorting Bitcoin's public blockchain (one of its core tenets), and that's very attractive to criminals.
Mixers aren’t banned. A mixer that was used to launder money by North Korea was.
Banks which collect KYC and respond to criminal probes. Those that don’t absolutely get sanctioned.
Well, it's not banned, but over $10k USD in cash you need to fill out an IRS form 8300 [1] precisely to curb criminal use of cash. (Although I'd argue it should be upped and pegged to inflation as 10k isn't what 10k used to be.)
[1] https://www.irs.gov/businesses/small-businesses-self-employe...
Edit: See https://en.wikipedia.org/wiki/Haynes_v._United_States for NFA. Thanks below for Leary.
I think the 5th has been restricted enough by the courts that it literally only matters if you EXPLICITLY invoke it. (At least this is my understanding of Berghuis v. Thompkins.)
Similar for the NFA case - they can't get then for the failure to register, but they can still get them for manufacturing/possessing it (especially since it was amended after the ruling).
>they can't get then for the failure to register
A criminal filing an 8300 would be effectively "registering" their illegally owned money, including the source from who the money is received.
"and that you couldn't pay that tax without registering"
The form 8300 actually requires you to state both counterparties of the illegal transaction, which goes well within furnishing evidence useful in incriminating yourself. It's far more incriminating than the annual tax return, which shows an aggregate yearly amount rather than granularity of single transaction (or collection of "associated"-transaction) along with the date and name of both counterparties and a host of other details.
Honestly, why can't we just have the government know every single website we visit immediately? We all have nothing to hide
If a VPN is used to help North Korea, and the developers won’t or can’t shut it down, yes, it will be sanctioned. More broadly, speech is generally protected under U.S. law in a way financial transactions are not.
Obscuring the source of a transaction is not always money laundering.
My credit card would suck if everyone I did business with knew about all my present and future transactions too.
How is HN so consistently cryptophobic?
Imagine the reaction you’d get here suggesting say, E2EE is “explicitly a product for {crime}”. You’d be rightly mocked, but throw in crypto and it’s like 75% of the people here lose basic reasoning skills. I’d be less frustrated if it wasn’t so common.
Mixers are designed to facilitate money laundering. You can claim it’s for legitimate privacy, etc but it doesn’t change the fact that it’s money laundering.
A mixer concealing the public address of clean money is not nefarious in any way and should be perfectly legal.
For E2EE,you describe the base level capability: Secure message between two parties.
For Mixers, you describe an act that the capability of making money hard to trace enables: Money laundering. If you applied a similar argument to E2EE (as many have and will keep doing), encrypted communications are a way for people to do illegal things away from the eyes of the law. Trade illegal items, send banned/illegal/questionable content, etc.
From a pure capability standpoint, mixers, like E2EE, are a way to secure XYZ activity (Which happens to be money transfer) from prying eyes.
You're drawing a distinction between illicit and privacy-seeking transaction and I'm saying the act of obscuring the source is all that matters.
Or if your employer pays you, and decides to kick you out because he doesn’t agree with some transactions you made?
It is always the same charade in which a government tells you that by banning x they will solve y. Or that by removing any form of privacy to everyone (but themselves) they will solve y.
In the end they never solve it, even worse the people in charge of the surveillance (banks in this instance for money laundering) are repeatedly caught actively taking part in the laundering and they occasionally get punished by "fines" that are rarely enough to discourage them from continuing.
So people want to take their privacy back now and tear down means ridiculous theatricals we call AML/KYC/KYB procedures. Obviously governments aren't happy, they are welcome to try to stop us.
It should be shut down.
If a smart contract does something illegal, the person who deployed it has no more responsibility than if someone does something illegal with encryption software downloaded from Github. The only responsible part you could really argue for is the Ethereum node operators, since they're the ones actually carrying out the illegal computation. But is the government really going to outlaw the Ethereum network?
They will most likely view the smart contract and its wallet as one entity, despite that being technically not how it works technologically. Because as many people have tried and failed to figure out over the years, laws are interpreted by juries and judges, not computers. Technological roadblocks are things they don't have any problems jumping over, and deliberately trying to add roadblocks like that with the imagination they're untouchable also tends to piss them off even more.
If this was true, Internet pornography would have been successfully squashed by the existing obscenity laws that heavily regulated pornographic material.
Pornography isn't illegal in the US, it's pretty well-regulated, and once the Internet started entering mainstream culture, it quickly adapted to the existing legal framework and culture that was already there.
This is, of course, a very US-centric view, but so is a lot of early Internet history, along with its culture.
I'm sorry, but this isn't true. At the early onset of the web there were a huge number of state and local laws regulating obscene material. Many states even tried to explicitly regulate Internet pornography:
> Between 1995 and 2002, almost half of the states were considering bills to control internet pornography, and more than a quarter of states enacted such laws.[1]
Along similar lines, sex toys were prohibited or heavily regulated in a number of US states before 2000. The technological reality of e-commerce means that the vast majority of the enforcement of those laws became impossible, and sex toys are de facto legal in every jurisdiction in America.
[1]https://en.wikipedia.org/wiki/United_States_obscenity_law
If I rig up my car to explode when someone walks by whistling the right tune, am I without responsibility? I didn't blow up the car.. the car blew itself up.
Obviously I'm at fault. There is no debate here. Any automation you create is acting on your behalf - and you are liable for it. If I hire a hitman.. I am guilty of murder.
AI or software isn't some clever loophole here. If you deploy an autonomous money laundering system.. you are doing money laundering.
Mechanical devices are not protected as speech.
> If I hire a hitman.. I am guilty of murder.
SCOTUS has already carefully defined this in the Brandenburg test. Speech is only not protected when it results in direct, imminent lawless action. And SCOTUS has consistently ruled that the boundary for the test is extremely concrete. (Contrary to popular opinion yelling fire in a crowded theatre is actually protected by Brandenburg under the First Amendment.)
Sending a text message to a hitman telling him to "wack Tony at midnight" fails the Brandenburg test because it leads to imminent lawless action. But you can literally publicly advocate for an ideology to overthrow the United States government and murder millions of people, and that's Constitutionally protected because there's no imminent lawless action.
Writing and publishing open source software is Constitutionally protected, because the simple act of publishing software does not lead to imminent lawless action. Even if it's reasonable to assume that the software will likely be adopted for illegal purposes. Again this isn't hypothetical, SCOTUS has consistently ruled that the government cannot restrict the ability to publish instructions on how to make pipe bombs or 3D printed guns.
He's saying just because you set up an ATM in the middle of a city and say, and then say feel free to wash your illegal cash here to do some money laundering.
The act of it being on blockchain and "decentralized" wont make a difference, anyone offering said "launder ATM" could be convicted of a crime.
SCOTUS has consistently required an extremely high bar to regulating speech, so it's simply not enough to say "well we regulate this other non-speech thing, what's the difference".
Executing code isn't free speech. The code may be. The execution not so much.
If you want to make the argument that the persons executing the code are liable, than it should be the Ethereum network nodes, not the developer who deployed the smart contract. As it stands, it's pretty unlikely that the Treasury department has the political capital or the operational reach to shut down Ethereum. And that's why blockchain is different.
Trying to find a loophole in the law by trickery is why we use human courts - the judge can still find you guilty and punish the living crap out of you for abetting money laundering.
They haven't though. Tornado Cash is still happily running. If you post your address here, some kind soul might even send you some ETH via Tornado Cash right now. They have asked regulated financial institutions to not receive ETH that came directly from Tornado Cash. That's it; that's all that they can do. While that puts a damper on people converting directly between ETH and USD at such institutions, it does bugger all for people conducting small/informal transactions
"I sell x to y, y can only use crypto, y will be persecuted if I don't obscure my transactions from z, so therefore this is a good thing"
Yes we can all do the hypothetical "dissident in AUTHORITARIAN_COUNTRY needs to buy x and will totally be persecuted otherwise" but I want an actual production example not a moral whataboutism.
> One plaintiff in the lawsuit is a crypto investor who used Tornado Cash to send funds to support the Ukrainian war effort, hoping to preserve his anonymity and avoid retaliation from the Russian government.
Also I should've read the full article first.
not rare, 12,000+ unique users on just the ethereum network alone
only a handful would be from large scale hacks, a bigger handful from phishing
even the treasury's estimates were that less than 20% of use was illicit, it is a totally new standard to vilify it based on whatever it is vilified for
I would assume making a nontrivial donation in fiat privately is also very difficult.
A better example might be to pay for a legal service without revealing your entire wallet balance to that service.
They kill people wherever they want to kill people, and it's entirely reasonable to be afraid even if you don't live in Russia.
They all do it for privacy. Someone with a publicly labelled address doesn't want people watching them to know they're making a large purchase, so funds go in through tornado cash, and out to a new address nobody is looking at.
If you are not aware, Tornado Cash already comes with tools to solve investigative zeal, anyone audited can prove the prior source of funds with Tornado Cash, at which point the investigator can tell if they were clean or not, as opposed to just assuming because they aren't familiar with "a concrete example of mixing crypto revenues in a way that is not clearly illegal"
https://storage.courtlistener.com/recap/gov.uscourts.txwd.11...
So if I for instance withdraw 100 million from an exchange, in a completely legal manner, and then visit a store or webshop to buy something with the same funds, then the store now knows that I have 100 million dollars?
Mixing can be used for self protection.
The more common this example of legitimate use becomes, the less useful it is, defeating the purpose.
If it becomes common for crypto known to have come from Tornado to be there because the person is concealing ownership of a large amount of crypto, the store can infer the same thing the previously could see on-chain: this person probably has a large amount of crypto. And then all the same risks apply, albeit with a minor unknown as to the amount.
But since we're basically talking about a "rubber hose" attack here it doesn't really matter if they can directly see it on-chain, they're still going to assume it and likely do the same thing.
I see the need for privacy in this instance.
It is code.
And how exactly does your bank account publish your transactions to the public?
Tornado Cash allows you to sever the tie between addresses on the Ethereum blockchain, so I don't have to have my transactions public, all while still being able to legally declare my taxes as if I didn't use Tornado Cash at all.
It would certainly be worse for crypto if it were illegal to buy sell ETH and friends because their networks host Tornado protocol. I see this attempt to moderate the network itself as “going easy” on crypto investors.
The crux of the issue comes down to moderation. In a sufficiently large and complex network, moderation becomes a necessity not an option. This won’t be the last case.
Regulators generally strike when sufficiently popular technology makes it sufficiently easy to perform sufficiently damaging illegal activity.
For example, Section 230 of the Communications Decency Act provide safe harbor provisions: 'No provider or user of an interactive computer service shall be treated as the publisher or speaker of any information provided by another information content provider'.
It doesn't matter if I run a site with 10 users or 100 million users: the law's provisions and protections are the same.
You are right that regulators generally strike when there is a critical mass. However, my 2c is that this is not backed by statue, and US Treasury does not have the right to sanction software code. They can certainly sanction users who use TC for money laundering, but code itself?
That's like sanctioning PGP or end-to-end encryption...
For example, it’s impossible to run a social network website of 100 million users without users uploading illegal content. Moderation is a necessity to avoid being taken down by the feds for hosting illegal content.
I agree that treasury doesn’t have the right to sanction code. They do have the right to ban exchanges from exchanging ETH. However, nobody wants that, so they’d rather try and extend their powers to effectively become ETH moderators.
If they don’t succeed, I’d expect more heavy handed attempts by other branches of government.
I don’t think the government will ever give up, in large part because I think there is political capital and mandate to regulate crypto (just not ban it). If crypto crashes even further, a full ban might be possible some day.
13 years later we’re all caught up in surface-level details like “is this cryptocurrency thing a security” and “is this cryptocurrency mixer money laundering” meanwhile the basic premise/existence of cryptocurrency has been accepted de-facto.
surface-level regulations just kick the can down the road. beneath that surface is still a massive challenge to the state, only more diffuse, and that interior shapes the surface much more than the other way around. governments need to make up their mind: are they OK with yielding control over the money system, or not?
right now the answer looks like “yes, but we’re going to drag the process out”, which is sort of the worst thing for everyone. drawn-out wars hurt everyone. US ought to either ban cryptocurrency (private currencies) altogether, or step aside and let it happen.
Can someone explain to me why people don't just exchange crypto for monero and then back if they want to "wash" it?
It's also arguably more private than monero. Tornado uses zk math instead of coinjoin; tornado also sticks to only a few values (1 eth, 10 eth, 100 eth...) which minimizes traceability
As far as I can tell, being sanctioned like this makes it illegal for US companies and people to do business with you. So I think in either case it would be users who were prosecuted?
Enforcement is always the even messier bit of these broad and badly defined laws...
And I think we should commend him for that
since there really are consequences for his relationship with the government and Coinbase’s relationship with the government
The president has much discretion here. That was the whole idea of IEEPA. I think the best case outcome of this lawsuit to crypto is that courts just toss it. Worse case is that IEEPA is effectively amended to say that a DAO is a person.
https://storage.courtlistener.com/recap/gov.uscourts.txwd.11...
I don't know if this is the sort of thing a court can do but it seems like the obvious solution to eliminate the damages to the plaintiffs while keeping the sanction in place.
The suit doesn't represent that Tornado Cash itself is a legal person, in fact it represents the opposite. "Tornado Cash" is not the plaintiff.
The former obscures financial transactions, and the latter obscures communications, but there's a similar principle in play.
That's not really any reassurance in the long term, if they find a better/different solution that goes out the window.
No. Despite attempts to conflate code on a blockchain with code as a concept, the code comprising Tornado Cash hasn’t been banned. You can publish it. Hell, you can re-deploy it, though that would be stupid.
Tornado Cash is just a coin mixer implemented through smart contracts yes? The 'coins' themselves already enjoy some first amendment protection by being built on top of the protected encryption protocols. The smart contract itself is just another communication protocol defined in code. So it seems patently obvious that TC is allowed to exist under U.S. law.
The only remaining question is whether anyone can be allowed to use it. We actually have to get deep into first amendment jurisprudence to answer that question. Generally speaking all speech is permitted but, when it is paired with conduct, the conduct can be regulated by time, place, and manner. This at first appears a simple distinction for us. Users of TC or any e-coin standard are _conducting_ transactions. But this is thorny.
Commerce used to be conducted entirely physically with an exchange of cash. Then it was done with an exchange of electronic funds on a banks balance sheet; essentially a change on two different excel spreadsheets. But the btc-protocol and its derivatives don't function like this. They use a ledger. When we transact in e-coins we don't exchange anything. No digital coins fly from my computer to yours or vice versa. Rather all that happens is a message is sent to a public server which contains enough information to allow that server to determine that we both agreed to send that specific message. The server then updates the ledger and publishes this change to other servers hosting the ledger so there is agreement that we exchanged value.
It's not actually 100% clear that when communicating this way we have conducted anything. Sending encrypted messages like this has been determined to be first amendment protected activity as pure speech. Indeed we wouldn't have an internet today if it weren't. Having a message be encrypted inherently provides privacy and precludes restrictions on a message's content. Even when that message's content includes information to exchange value. Citizen's United also has some precedent over whether speech + conduct regarding money transactions are permitted speech when that speech is political in nature.
This leaves us only with the few recognized non-speech categories with which to regulate pure speech:
> lewd, obscene, or pornographic content; defamatory content; insulting or “fighting words”; expressive content that tends to inflict injury; speech that incites an immediate illegal conduct such as riot or violence; speech that poses an imminent threat to public safety or national security; false or misleading commercial advertising; and perjury.
There are a few categories here that may help us. Inciting immediate illegal conduct and imminent threat to public or national security. To qualify as incitement to illegal or a threat to public safety the speech has to pass the 'clear and present danger' test. This test has two parts:
* first, the speech must impose a threat that a substantive evil might follow
* second, the threat is a real, imminent threat.
This test is extremely hard to meet and just because the TC protocol is may be or even if it is likely to be used for money laundering it will likely never rise to the threshold of this test in a U.S. court. Cases where speech does meet this threat are specific threats or instructions. If TC included specific instructions on how to evade law enforcement then that may qualify.
This leaves only threats to national security as a legal basis. We have to begin by saying that many of the use of national security as a means to restrict the rights of Americans has an extremely checkered past. These were the arguments that bullied journalists under the red scare, interned the Japanese in WWII, attempted to stifle the pentagon papers after the Vietnam War, maintained the patriot act of 2001, lead to secret courts with secret evidence, torture, suspension of habeas corpus, etc. However, the standards for what constitutes a threat to national security have been much degraded in the past two decades. You could probably convince a judge or even SCOTUS that the use of TC by foreign hostile powers like North Korea and its potential to be used as a tool of terrorism from the likes of Iran and ISIS constitute a threat to national security. But arguing this not only degrades your moral character, it is also unlikely to be effective in the long term. We did reinstate habeas corpus, we un-interned the Japanese, and we did publish the Pentagon papers. Hopefully we will also get rid of the Patriot Act in the coming decades. And even if TC was determined to be a threat to national security, that determination would likely one day be reversed as an understanding of the technology and its necessity aged into the judicial system.
Courtesy of https://web3isgoinggreat.com/?id=coinbase-funds-lawsuit-agai...
https://www.law360.com/articles/1528566/coinbase-backs-suit-...
Anonymity is not a crime
Just watch how quickly this comment will disappear or get downvoted.
Could you please stop creating accounts for every few comments you post? We ban accounts that do that. This is in the site guidelines: https://news.ycombinator.com/newsguidelines.html.
You needn't use your real name, of course, but for HN to be a community, users need some identity for other users to relate to. Otherwise we may as well have no usernames and no community, and that would be a different kind of forum. https://hn.algolia.com/?sort=byDate&dateRange=all&type=comme...
I suppose the lawsuit is a good thing. The government will have to defend their decision in court which will strengthen their position regardless.
It's not an organization. This is more like the FBI banning GPG because terrorists use it.
FTA:
> They contend that the Treasury Department lacks the authority to restrict access to a software program.
This is the point. No one would have batted an eye if OFAC sanctioned addresses that used TC to launder money. Nobody would have batted an eye if the FBI prosecuted criminals for using GPG to plot a crime.
But what happened here is akin to the FBI, using powers that it hasn't been granted in law, to ban GPG.
https://en.wikipedia.org/wiki/Pretty_Good_Privacy#Criminal_i...
The SEC is well-funded, has a strongly supported mandate, and has a long arm. They are playing a long war of attrition.