If you run an actual service without KYC/AML, uh, yeah, you are probably f'd.
If you have specific knowledge that a sanctioned-by-OFAC north korean hacking group is using your service to launder hundreds of millions and you do nothing, you are definitely screwed.
They might have hosted some user interface code; I don't know. They would have been able to shut down or modify anything they were actually hosting. They could have created alternative contracts, and maybe encouraged somebody to use them. But the basic already-running Tornado Cash contracts are immutable and unstoppable without shutting down all of Ethereum.
If anything, something like Monero or ZCash seems to have less cover, because if the developers of those release modified code, and if they succeed in actually getting the bulk of the users to use it, they really can change the way the whole chain works. Although if they tried to remove all anonymity, all that would probably happen would be that somebody would fork the project.
No, but the US could start arresting validators on AML charges, and no doubt, many people here would support this too.
> They might have hosted some user interface code; I don't know.
That's just a static website though talking only to your wallet app. Somewhat similar to the fight around whether the piratebay is culpable for copyright violations. Many geeks used to support the piratebay.
The TC interface is hosted on IPFS. Can IPFS gateway operators not blocking the content be arrested on AML charges?
They could go after people for accepting and building on top of other people's blocks with such transactions in them. But I suspect they'd prefer not to have to do that, because the more rarefied the "interactions" they try to enforce against, the more chance they have of courts telling them they're beyond their statutory authority, or conceivably even of authority they actually do have getting repealed.
I haven't looked into it in any detail, but I suspect their authority for the Tornado sanctions is actually pretty shaky. They can sanction any entity, but it's not clear, to me at least, that a smart contract is an "entity" in the sense intended by the legislation they're presently relying on for all of this. That means that after all the lawsuits shake out, they may have to ask for new legislation to give them authority. I suspect they'd eventually get that authority, but it's harder to sell it to legislators if anybody can say you've been overreaching.
Clarification on edit: Their authority for the sanctions against interacting with the smart contracts looks weak. I don't know about the company or the people; those may be fully within their authority, depending on what they were actually doing. But the smart contracts are the heart of the whole thing. And OFAC seems to be trying its best to muddy the distinction.
In practice, they are being charged with conspiracy, and the conspiracy is mostly about running the website with the UI, not about the smart contracts (as i read it). they seem to have been careful not to try to charge them for creating some ethereum contracts.
Conspiracy does not require that they could have done something later to stop the conspiracy from completing.
The crime of conspiracy was complete when they committed an overt act (towards the overall criminal act). Once that was done, you lose.
Here, the overt act cited is paying for the website :)
In this case, the thing to do is to withdraw before an overt act.
If you successfully withdraw, you are no longer chargeable with conspiracy, even if the act later completes.
The model instruction for the defense of withdrawal looks like this: "“(1) One of the defendants, (Defendant’s name), has raised the defense that he withdrew from the agreement before any overt act was committed. Withdrawal can be a defense to a conspiracy charge. But Defendant has the burden of proving to you that he did in fact withdraw.
(2) To prove this defense, Defendant must prove each and every one of the following things:
(A) First, that he completely withdrew from the agreement. A partial or temporary withdrawal is not enough.
(B) Second, that he took some affirmative step to renounce or defeat the purpose of the conspiracy. An affirmative step would include an act that is inconsistent with the purpose of the conspiracy and is communicated in a way that is reasonably likely to reach the other members. But some affirmative step is required. Just doing nothing, or just avoiding the other members of the group, would not be enough.
(C) Third, that he withdrew before any member of the group committed one of the overt acts described in the indictment. Once an overt act is committed, the crime of conspiracy is complete. And any withdrawal after that point is no defense to the conspiracy charge.
(3) If Defendant proves these three factors by a preponderance of the evidence, then you must find him not guilty. Preponderance of the evidence is defined as “more likely than not.” In other words, the defendant must convince you that the three factors are more likely true than not true."
So, for example, for the charge related to running the website, "stop paying for website, tell others this is not okay, cut off all support and help you can" seems likely have been enough to withdraw here, even if you couldn't stop others from using it because it's immutable.
Some of the developers probably even know about specific illegal acts by specific actors. And the illegal activity has been happening throughout the lifetimes of those systems, with plenty of overt acts during any given developer's personal involvement.
So if the Tornado Cash people were conspiring with their users to launder money, how are the Monero or ZCash people not conspiring with their users to launder money? What's the required threshold of coordination or participation? In both cases, you're basically looking at somebody sticking some software out there and letting other people use it.
It's possible that Tornado had more active participation in specific incidents, but if so, what aspects of that participation matter? If it's a matter of hosting the UI, well, many the Monero and ZCash developers probably also run nodes, so they're actively operating systems that are accepting and relaying obscured transactions, with no attempt to filter out illegal ones. And they can't exactly claim they're ignorant about that.
I'm not claiming Tornado Cash is or was not a conspiracy, but if it is, then it seems hard to say that Monero or ZCash isn't.
By the way, as far as I know charging money doesn't matter, and I'd put about zero weight on allegations about "running relayers", since there aren't any recognizable "relayers" in the system anyway. The government has a strong interest in ignoring how it actually works, and in muddying any potential distinctions between the automated actions of the smart contracts and the intentional actions of the developers. They've issued actual sanctions forbidding "any interaction with" the smart contracts themselves, and if they let those distinctions become significant, they run the risk of having to explain how the smart contracts are "entities" within their authority to sanction.
If the developers are running for a UI that helps, or paying for a UI that helps, or paying to run services that help get the money out, then i would say they may be on the hook for charges.
These all have to be knowing, btw. If you just donate somewhere and they do something bad with it, not your issue. If you donate somewhere, knowing they will do something bad with it, that's different :)
You are correct that charging money or not doesn't really matter, it just gets used to show they profited from the illegal enterprise overall.
As for further lines, if all they did was write some Ethereum contracts and let them loose, I doubt someone would come after them. If they are making it easy by building UI/services around it, without any KYC/AML, and then the UI/services get used to launder money, then yes, they are likely on the hook.
I also doubt the government wants to start a case about interaction with smart contracts - it would be very muddy and possibly set bad precedent, at least right now. They would rather take cases like the one you see here, where someone did something more than make an ethereum contract, and the facts don't look great, and prosecute those.
Maybe sometime later if they win a bunch like this they will go after more complex cases around smart contracts, but you generally want to ease courts into this sort of thing if you want the best chances. It's not always possible, mind you.
If you look at early decisions in new fields where someone threw a really complex and hairy technology case at a court, the decisions are sometimes weird/strange. The courts do their best (and often hire special masters with expertise in the area and ....), but the legal system is a deliberately iterative one, and often takes iterations over years to get things to a stable point.
IANAL, and maybe DannyBee can correct me if I'm mistaken, but I think the answer to this is "Maybe they do and just haven't been charged yet." If there are a lot of independent people doing the same crime, they're not all going to be charged simultaneously. Each requires a separate investigation. Someone's going to be the first in line.
The USG can be legitimately accused of all kinds of gross excesses, but they can't be accused of not understanding the difference between these things. Pretending otherwise doesn't do any party any particular justice.
Tornado Cash was not designed to violate laws as per intent of the authors. Maybe it is your judgement of the design itself.
Whether or not it in fact does is something we may possibly find out (if the US plea-deal system doesn't prevent it). Even then, a guilty verdict might hinge on technicalities around the TORN token.
> As alleged, when it became clear that a sanctioned North Korean cybercrime organization was using the platform to launder hundreds of millions of dollars derived from cyber heists, Storm and Semenov turned a blind eye to the illicit activity and made public representations that they were compliant with sanctions laws.
Now, we don’t know how much evidence they have about that knowledge but federal prosecutors usually don’t bring cases like this speculatively. I would be surprised if they didn’t have specific example of them clearly being aware of that information and choosing not to act - for a relatively high-profile case they’re not going to want the embarrassment of losing.
EDIT: Tracking down the actual PDF has things like this:
> 59. ROMAN STORM, ROMAN SEMENOV, the defendants, and CC-1 were fully aware within days of the Ronin Network hack that the proceeds of the hack were in fact being deposited into the Tornado Cash service. For instance, on or about April 4, 2022, a reporter sent an email to an email address used by all three Tornado Cash founders asking for comment on the Ronin Network hack, in which the reporter included a link to a blockchain analytics website and stated that "it appears that these hackers are trying to use Tornado.cash to launder stolen funds."
> 67. ROMAN STORM and ROMAN SEMENOV, the defendants, and CC-1 well knew that the Tornado Cash service was continuing to launder proceeds of the Ronin Network hack held in the Lazarus Group's 0x098B716 Address. On or about April 30, 2022, SEMENOV sent a message to STORM and CC-1 through the Encrypted App with a link to a blockchain analysis showing that 15% of all of the deposits into the Tornado Cash service over the preceding three months had come from the Ronin Network hack. The analysis also showed that more than 90% of all the deposits into the Tornado Cash service for which a source could be identified during that same time period were attributable to criminal exploits.
https://www.justice.gov/media/1311391/dl
90% is a pretty large number, and that pattern of ongoing knowledge is significant, too. As an analogy, if I run a bike shop and some dude brings in a stolen bike, I’m not getting arrested but that’s not true if 90% of the bikes in my shop are from the same dodgy guys the cops are looking for.
Yeah, I'm sure the FBI needed to bring out their top detectives to find "evidence" that the Tornado Cash devs where not aware that criminals used their service. I guess they never googled themselves or talked to anyone ever.
This case isn't a dispute about the facts. It's a fight about if existing AML legislation can be stretched to include new types of financial actors on blockchains.
Most people here simply have no idea how Tornado Cash operated, don't care to ask themselves what the underlying principles should be, what kinds of obligations should be in miners, and would probably support the arrest of Vitalik Buterin on money laundering charges.