Mixers on Bitcoin are usually centralized and operated by a person, so they get (and have been) cracked way more easily
It does not; these sanctions only apply to US Persons. Secondary sanctions mean that the Treasury can additional designate non US-Persons for breaches of the primary sanctions, but that is a heavy-handed tool and unlikely to happen to people who merely use Tornado Cash; regardless, no law was broken by such a person.
Lebanese man extradited from Morocco for violating sanctions on himself (!): see ruling justifying this on https://casetext.com/case/united-states-v-tajideen-1
It is trivial for the government to say that you directly or indirectly used some service operated by American company and therefore you are subject to American jurisdiction. Yes it’s unlikely to happen to any small time Tornado Cash user.
It also amounts to a general criminalization of financial privacy.
So hopefully the legal challenge succeeds.
However, actually running the code to facilitate North Korean hackers launder money and personally profiting off of it? That's not covered by the first amendment, and I sincerely urge you to not try to find that out in the hard way.
Who is "running" the code?
The US government, to this date, has not made an argument that the developers of Tornado Cash, who have deployed the code to the Network, have committed a crime; at least one of them seems to be living in the US.
Nor has the government made an argument that operators of Ethereum nodes are committing a crime; they might also be considered to be running the code.
What the government has done is, through sanctions, instituted restrictions on Americans interacting financially with the smart contract. This has nothing to do with "running code"; this is operating under the assumption that the Tornado Cash smart contracts are an entity that is party to financial transactions.
Whether they have the power to sanctions non-entities like a smart contract is what the suit intends to find out.
[0] https://www.trustnodes.com/2022/12/14/70-of-the-ethereum-net...
That last part is potentially defensible – bankers aren't charged just because a criminal stores money in a checking account – except that each KYC law not followed is not only its own offense but also a chance for prosecutors to argue that the decision not to do so was intentional and the operators knew their service was predominantly used by criminals. That's going to be an interesting case with potentially significant implications for the entire field.
To generalize, every user of a privacy protocol increases the protocol's anonymity set, and thus its utility to all users.
In other words, Tornado Cash shares this property with every other privacy protocol.
2. The guy who wrote the Tornado Cash code operated no aspect of the Tornado Cash smart contract. That operates entirely autonomously. It's code, deployed to a massively distributed blockchain, that any one can use to encrypt their transaction.
Your belief expressed in #2 is at odds with the charges specifically saying he profited from money laundering activity. We’ll see when that goes to court exactly what that meant and whether there’s evidence suggesting that he knew where those fees were coming from.
In any case, what is being criticized in this particular thread is OFAC prohibiting all Americans from using Tornado Cash code. This is unprecedented, and clearly outside OFAC's statutory powers to sanction "entities".
Despite the US Treasury's claims, Tornado Cash is not in any way an entity, as it is not controlled by any party. It is simply code, running autonomously on a massively distributed blockchain. When someone uses it, they are using zero knowledge proofs to encrypt their transactions. The fact that this act of encryption adds their activity to the same anonymity pool as criminal activity is no more an argument for banning this encryption protocol as it is for banning any other encryption protocol.