Tornado Cash 2.0: The race to build safe and legal coin mixers

7 June 2023

Cointelegraph By Max Parasol

When the U.S. government sanctioned coin mixer Tornado Cash, many thought it might spell the end for illicit crypto mixing services. But they’re back — and with a glossy new institutional sheen and legit use cases to help traders and funds keep their market moves a “trade” secret.

Tornado Cash is what is known as a “mixer,” a “coin anonymizer” that breaks the identifying links in blockchain transactions, providing a certain degree of anonymity for users.

The reasons people use coin anonymizers vary from criminality to ideology. Bad actors can use Tornado Cash to hide their naughty deeds, effectively laundering the proceeds of crime and preventing stolen crypto from being traced to them on the blockchain. That’s why the United States Department of the Treasury’s Office of Foreign Assets Control sanctioned the protocol last year.

But there are legitimate reasons for not wanting your every transaction tracked, and supporters argue that Tornado Cash provides important privacy infrastructure. But is it possible to build a privacy-preserving protocol that provides regulators with just enough information to know users are staying on the right side of the law?

Various developers are experimenting with redesigned mixers using ZK-proofs and believe there’s a way to make it happen.

“The mathematical machinery has been around for quite a while,” explains Matthew Niemerg, co-founder of Aleph Zero.

“It’s more about designing a solution that balances an individual’s privacy from the broader public while allowing the revealing of limited pieces of data to particular entities, such as banks or government agencies, using ZK-proofs. It takes time to design such a scheme and bring a product to market.”

But the big use case for these new coin mixers won’t be dodgy crypto thieves: It’ll be the big institutions and hedge funds, trying to get ahead of front-running bots and to keep their business dealings secret from competitors.

Bitcoin smoothie anyone?

How does Tornado Cash work?

Tornado Cash is an important yet controversial product in the Ethereum ecosystem. The decentralized, noncustodial privacy solution accepts ETH and ERC-20 deposits to muddy transactional histories by breaking the on-chain link between source and destination addresses. Send some coins in, take some different coins out.

Tornado Cash’s origin story is a fascinating account of true decentralization dreamers fighting the regulatory powers that be. Tornado Cash first launched in August 2019 but was initially “experimental software” because the original software developers retained control over user funds through a multisig wallet.

Example of a mixing transaction. (TarushTech-Medium)

In 2020, Tornado Cash’s developers burned their admin keys, turning the privacy tool into permissionless code. Tornado Cash was supposedly a truly perpetual persistent script, “completely trustless and unstoppable,” and the developers believed they were no longer responsible for the platform as the application operated as self-executing code.

Burning the admin keys had two goals. It removed the possibility of admin key “rug pull” risk, where a team member can steal all the funds out of the smart contract and disappear. And, in theory, the idea was that by burning their admin keys and relinquishing control to the ether, they’d be able to avoid potential legal ramifications.

Then they came for the Tornado Cash developers.

Tornado Cash has been the target of U.S. regulators.

In August 2022, Tornado Cash was the target of the U.S. Treasury’s Office of Foreign Assets Control (OFAC), which sanctioned the digital currency mixer for being a money-laundering tool. There was a lot of debate over whether it was possible to sanction a piece of code, and effectively, they went after the developers and U.S.-based users, who could qualify as a sanctioned entity. This led to accusations of clumsy law enforcement shooting the evangelicals.

Stopping Tornado Cash completely is beyond the Treasury’s ability at present. This is because open-source software built upon the Ethereum blockchain is accessible to anyone and runs mostly autonomously. Tornado Cash’s code is still accessible and can be easily copied and resurrected under different aliases and on other Ethereum Virtual Machine blockchains.

Developers have already forked Tornado Cash’s code to build Privacy Pools on the Optimism blockchain. Ameen Soleimani, co-founder and CEO of SpankChain — an adult service on-chain — was a notable supporter.

No one seems to have a solution for the regulators playing whack-a-mole, but many ordinary users are deterred by the idea of using sanctioned protocols or their offshoots.

Also read: Porn payments were supposed to be crypto’s killer app: Why have they flopped?

So, what’s next for crypto privacy that doesn’t offend the powers that be?

Tornado Cash Mark II has already launched:

What replaces Tornado Cash?

The metrics are simple: providing tech that ensures user privacy while satisfying the regulators’ Know Your Customer demands (so that banks can identify their customers for regulators). Easy.

The aforementioned Privacy Pools launched its early experimental code in March 2023 and has its sights set on becoming an improved Tornado Cash, but meeting regulatory demands is a tough ask. The solution works on a technical level but regulatory enforcement is perhaps likely at some point.

Read also


Features

Wild, Wild East: Why the ICO Boom in China Refuses to Die


Features

Tornado Cash 2.0: The race to build safe and legal coin mixers

Founding contributor Soleimani even tweeted that would be the case eventually. He argued that Privacy Pools is a kind of an experiment with the aim of helping “regulators understand a potentially more attractive equilibrium between privacy and regulation that we didn’t even know existed a few months ago.” He is referring to developments such as zero-knowledge proofs, a computational proof of a transaction that took place while anonymizing the terms of the transaction as used in private cryptocurrency Zcash and in a slightly different way in layer-2 protocols, such as StarkNet. But it’s not clear that will be enough for regulators.

Soleimani hints on Twitter the regulators will keep coming.

We need to poke back at the bear

Aleph Zero’s Niemerg says there needs to be pushback against the idea that privacy-preserving protocols are de facto illegal.

“If we want to live in a world with financial privacy, we need to poke back at the bear and say this new solution does what regulators want and point out that it’s better than the existing system,” he says, adding that mixers are needed by investors for security reasons, not just to prevent copy trades and counter trades. “There’s a personal security risk of having funds in an account attributed to you,” he says.

With a Ph.D. in mathematics, he believes the crypto community can deliver a legal solution using math. All the pieces are there. “Decentralized IDs and ZK proofs — there are various components necessary to build this,” he says.

Aleph Zero’s tech stack focuses on providing developers with the underlying tools and cryptographic primitives necessary to use ZK-proofs for multiparty computation for privacy-enhancing applications. For example, a mixer could use verified credentials combined with ZK-proofs to prove any person using the mixer at a given moment was not on any sanctions list and that all persons have been KYC’ed by a reputable third party. But the users and their transactions would remain anonymous. Niemerg says:

“Post-Tornado Cash, the industry has to be proactive and say, ‘We have solutions to combat terrorist financing and money laundering,’ which are the two main factors that concern regulators.”

“By constructing the provenance of transaction history using ZK-proofs combined with on-chain verified credentials, we can streamline and make compliance cheaper while providing more certainty to financial institutions regarding the provenance of funds but still adhere to the privacy of transactions related to people who are not directly a given financial institution’s customer.”

Further, he argues, crypto can be a better KYC system than the current one: “In other words, a financial institution should not be concerned with the private details of the customer of your customer. That is the current ruleset with cash. What we can do with cryptography nowadays is more than what’s required under the existing system.”

Coin mixers can be used to hide naughty deeds.

Chloe White, an international regulatory policy adviser in Dubai turned independent adviser to the crypto industry, agrees.

“Now is the time for policy advocates to come forward with creative win-win solutions,” she tells Magazine. “Discussions around privacy coins and mixers have tended to be somewhat binary and, in my view, quite outdated, given how the technology and industry have developed.”

The industry’s horror year of protocol and company collapses in 2022 has made the debate increasingly polarized, and White fears that governments and the industry are growing further apart.

“Crypto advocates often cite on-chain statistics from tracing companies that show illicit use to be a tiny fraction of total activity, but many policymakers don’t believe and won’t accept these statistics,” she says, apparently from first-hand experience.

Niemerg says the industry needs to be more proactive in dealing with policymakers.

“Part of becoming a more mature industry is that we need to engage regulators. Whether or not we like it, we have to put on our big boy pants and go in and lobby,” he says.

The responsibility is on us

Niemerg points out that the goals of regulators and the crypto community are often diametrically opposed.

Governments want to police crypto mixers.

“What do governments want? They don’t want anonymous peer-to-peer transfers. Their actual goal is just a straight-up ban on cash so they can monitor and tax every single transaction. Some people go so far as wanting to restrict ‘undesirable’ yet fully legal economic activity,” he says.

Governments seek to police the on- and off-ramps to crypto ecosystems, and that is understandable, he argues, as these are the integration points with the traditional financial system. “Banks partially evolved into service companies for ensuring the privacy of our transactions. But it is important to note that judges may be able to approve court orders when needed for law enforcement in crypto, too.”

Crypto transactions are currently more traceable than cash, for example. Chainalysis, a blockchain analysis firm, reported that, in the first month of the war, the Ukrainian government received more than $56 million in crypto donations, mostly Bitcoin and Ether. That’s another use case why mixer advocates argue privacy mixers for individuals are needed.

“What will regulators accept as a compliance solution?” is the question Niemerg says we need to be asking ourselves. “The math and tech should make regulators comfortable, but this requires ongoing discourse and education.”

Crypto mixers have all sorts of uses.

Privacy solutions are needed

Demonstrating a clear and legitimate use case for crypto mixers that helps institutions make money and therefore helps bootstrap the economy is probably the best bet to get regulators onside. And there are signs this is starting to emerge.

Forget dodgy individuals using coin mixers via a Tor browser from an internet cafe in Nigeria, hedge funds, banks and superfunds also need privacy, as all their transactions can currently be seen on-chain. We already accept there needs to be an aspect of “commercial in confidence” in business dealings, and privacy protocols can help make this a reality with blockchain technology.

“So, what’s next after Tornado Cash? asks Jemma Xu, founding contributor at Portal Gate. “Decentralized, compliant and anonymous solutions that stop the bad guys but let the good guys in,” Portal Gate is a new compliant and private DeFi solution that is coming out of stealth mode, backed by Melbourne crypto fund Apollo Crypto. She envisages it as a core piece of decentralized financial infrastructure.

“We are building a compliant, decentralized dark pool, leveraging ZK-based compliance oracles for permissioned access.”

“Portal Gate’s core mission is to build an institutional-grade DeFi solution that allows legitimate users to transfer, trade and transact on-chain in a compliant manner whilst protecting their privacy on-chain.”

Xu adds that funds making crypto trades in a competitive environment need to keep those trades secret, so the protocols aim to minimize “returns erosions from alpha leakages and front-running bots. It is very hard to trade on-chain with size at the moment, particularly for assets other than the major cryptocurrencies. Portal Gate is here to solve that.”

Portal Gate is a DeFi startup bringing private, legal dark pools to the industry.

Users are onboarded to the platform under standard Know Your Customer and Know Your Business and, thereafter, can trade anonymously. This is a very different use case from Tornado Cash and one that may appease regulators while helping to grow the crypto industry.

Xu says their dark pool development is led by a highly regarded technical founder who previously designed and implemented one of the top Web3 protocols. The core development team is mainly made up of experts in cryptography. Perhaps fittingly, they have chosen to remain anonymous, although Xu tells Magazine additional details.

Read also


Features

Bitcoin payday? Crypto to revolutionize job wages… or not


Art Week

Immutable Trash: Crypto Art Revisits Arguments on Censorship and Meaning

Progress in decentralized dark pools has been challenging due to both technical difficulties and a lack of on-chain liquidity. But since the 2020 DeFi Summer, which saw an explosion of on-chain liquidity, the team believes compliant and private DeFi infrastructure is now possible, and they have the expertise to implement a solution.

These use cases are legitimate, Xu says, highlighting that dark pools are frequently used in traditional finance trading among Wall Street banks. Unlike a traditional centralized dark pool where the dark pool owner (typically an institutional bank or market maker) can route orders to benefit its own traders ahead of its clients, a decentralized dark pool relies on a trustless network to match orders and settle on-chain. This provides traders with a unique venue to trade with hidden prices and order size and know they are trading against KYC/KYB’ed users, so they do not need to fear that trades are tainted. Currently, DeFi trading is in what the professionals call “lit pools” where orders are publicly submitted on-chain and trade intentions are known.

“If I trade using lit pools like Uniswap or aggregators of lit pools like 1inch, once I submit an order, it takes time for the blocks to confirm and order to settle. This means that in the interim time period, my trading intention is known and my order can be easily front-run using MEV bots.”

The lowdown on how crypto mixers work.

So, Portal Gate’s target market is “institutional grade funds and institutions who are happy to be compliant but don’t want their trading and investment decisions to be made public. This is a legitimate use case. And Portal Gate was built with that user use case in mind.” It is projected that a majority of its users will be institutional funds and liquid on-chain traders.

In the meantime, other jurisdictions are making Tornado Cash clones easier to use.

What is ‘legal and safe’ anyway?

There is a fundamental disagreement about the legitimacy of privacy technologies, at a time when the world’s major powers — the federal government of the United States and China — are arguably doubling down on their efforts to leverage the financial system as an arm of state surveillance and economic control.

White notes, however, there are jurisdictions taking an alternate route to the traditional privacy coin ban lists. She points to regulatory approaches in New York and Dubai as “examples of how the technology neutrality principle can be applied to tackle the problem differently.” White, who led the development of key aspects of Dubai’s policy framework, argues that “principles-based rules” are what is needed in this space.

“Even an asset such as Zcash can be compatible with Anti Money-Laundering requirements,” she explains, adding, “It all depends on how the assets are used and the context surrounding the users and their transaction.” New York’s financial watchdog, the Department of Financial Services (NYDFS), acknowledged when they greenlisted Zcash for trading on the (for now) U.S.-based exchange Gemini.

In its press release at the time, the NYDFS said, “The Zcash network supports two kinds of transactions, transparent and shielded… the privacy provided by Zcash does not prevent regulated entities from fulfilling their regulatory obligations, including customer due diligence, transaction monitoring, record-keeping, and reporting suspicious transactions.”

Crypto is under scrutiny in the United States.

However, as crypto becomes an increasingly politicized issue in the United States, some observers fear that the NYDFS will backflip on its policy stance.

Given the industry’s young, internet-native and highly mobile workforce, White says entrepreneurs are flocking to jurisdictions like Dubai and Hong Kong where governments want to provide a pathway to licensing.

“Two years ago, the industry was more motivated and passionate about participating in policy development, but now, many founders are experiencing lobbying fatigue — they will not wait endlessly for clarity in their operating environment,” she says. With a few exceptions like Coinbase’s Brian Armstrong and Messari’s Ryan Selkis, most CEOs are not willing to call out the hypocrisy of the current approach and would rather quietly leave home instead.

White says this is reflected in the types of calls she receives now at her new international advisory firm Riskmastery.xyz.

“By far, the single most popular enquiry I’ve received this year is from startup founders asking how they can set up and obtain licensing in Dubai.”

The Dubai government’s new crypto regulator Virtual Asset Regulatory Authority (VARA) launched a full set of licenses in February, including rules on anonymity-enhanced digital assets and transactions. It allows for the use of privacy coins and tools if they are fully compliant with national and global money laundering and terrorism financing laws.

How the evolutionary process for mixers unfolds will ultimately come from the choices of founders, investors and state regulatory bodies. DAOs are also now a logical option for operating these mixers, as legal liability can theoretically be limited, governance rules can be set, and governments have someone to contact when the need arises. But the demand is there, and legitimate use cases make mixers a necessary crypto-native product that will be around with or without regulators’ blessings.

Coin mixersportal gate

Read also

  

You might also like

South Korea’s Democratic Party sets up ‘Digital Asset Committee’  
South Korea’s Democratic Party sets up ‘Digital Asset Committee’  

The largest political party in South Korea, the Democratic Party, has launched a Digital Asset Committee focused on developing cryptocurrency policies and promoting industry growth.The committee held its inaugural meeting at the National Assembly Members’ Hall in Seoul on May 13, the local news agency News1 reported.During its first meeting, the committee highlighted the importance of resolving regulatory uncertainty and addressing burning issues like stablecoin regulation amid the push for US-dollar stablecoins by the US government.The new committee joins similar organizations in South Korea, including the Virtual Asset Committee launched in late 2024 and another public-private crypto task force introduced in 2022, both initiated by the Financial Services Commission (FSC).Exchanges like Upbit and Bithumb involvedThe leadership of the Digital Asset Committee includes South Korean officials and politicians, such as National Assembly Chairman Min Byeong-deok, who joined the committee as chairman.Additionally, the organization features standing general election committee Chairman Yoon Yeo-joon, Muksanism Committee Chairman Maeng Seong-gyu, National Assembly member Kim Byeong-gi and former National Assembly Chairman Kim Jeong-woo.Digital Asset Committee Chairman Min Byeong-deok, Yoon Yeo-jun, Maeng Seong-gyu and Kim Jeong-woo (from left to right). Source: News1According to a report by ChosunBiz, the committee will also include participation of executives from major local exchanges, including Upbit, Bithumb, Coinbit and Gopax.Criticism of “one-exchange, one bank” ruleAt the opening meeting, committee Chairman Min expressed concerns regarding limitations of South Korea’s current one-exchange-one-bank rule, implying that crypto exchanges are restricted to collaborating with only one lender.“There are clear shortcomings to the one exchange, one bank principle,” Min reportedly said, adding that the committee is working with regulators to resolve the issue.The chairman also mentioned discussions about which regulators should supervise the stablecoin industry and whether stablecoins should be subject to a licensing or reporting system.Related: South Korea presidential front-runner pledges to approve Bitcoin ETFs“There is also a point of contention as to whether the Bank of Korea or the FSC should handle the regulation,” he reportedly said.The news came shortly after a Bank of Korea executive expressed concerns over the issuance of the South Korean won-backed stablecoins.“Stablecoin has a great impact on the implementation of central bank policies such as monetary policy, financial stability, and payment settlement,” Bank of Korea’s Koh Kyung-chul reportedly said at a conference on May 12.“The negative impact on the central bank’s policy implementation should be minimized by the central bank’s practical intervention in the approval stage,” he added.Magazine: Finally blast into space with Justin Sun, Vietnam’s new national blockchain: Asia Express

Arizona governor kills two crypto bills, cracks down on Bitcoin ATMs  
Arizona governor kills two crypto bills, cracks down on Bitcoin ATMs  

Arizona Governor Katie Hobbs vetoed two key cryptocurrency-related bills that aimed to expand the state’s involvement in digital assets while signing a strict regulatory measure targeting Bitcoin ATMs.On May 12, Hobbs rejected Senate Bill 1373, which sought to establish a Digital Assets Strategic Reserve Fund. The fund would have allowed Arizona to hold crypto assets obtained through seizures or legislative allocations.“Current volatility in cryptocurrency markets does not make a prudent fit for general fund dollars,” she stated in her veto letter. “I have already signed legislation this session which allows the state to utilize cryptocurrency without placing general fund dollars at risk,” she added.That decision followed her veto of Senate Bill 1025 — the more ambitious “Arizona Strategic Bitcoin Reserve Act” — on May 3. It would have authorized up to 10% of the state’s treasury and retirement funds to be invested in Bitcoin and other digital assets.According to data from bitcoinlaws.io, 26 US states have introduced strategic crypto reserve bills, with 18 of them currently active. Hobbs also vetoed Senate Bill 1024, which would have permitted state agencies to accept cryptocurrency payments for taxes, fines and fees via approved service providers.Although the proposal attempted to shield the state from direct exposure to price volatility, Hobbs said it still introduced “too much risk.”Source: State of Arizona, Office of the GovernorRelated: Taiwan lawmaker calls for Bitcoin reserve at national conferenceHobbs approves Bitcoin ATM billOn May 12, Hobbs approved House Bill 2387, which introduces new consumer protection rules for cryptocurrency kiosk (ATM) operators, aiming to reduce fraud and improve transparency.The bill mandates that kiosks display clear, multilingual warnings about common crypto scams and require users to acknowledge these risks before completing transactions. Operators must also provide detailed receipts that include transaction data, contact information, fees and refund policies.Furthermore, the bill caps transactions at $2,000 per day for new customers and $10,500 per day for returning users after 10 days. Kiosk providers must also offer 24/7 toll-free customer service and post the number visibly on each machine.Under the bill, if a new user is tricked into sending crypto under false pretenses and reports it with proof within 30 days, they are entitled to a full refund, including fees.According to CoinATMRadar, there are currently 20 active Bitcoin ATMs in Arizona. Notably, Hobbs has not entirely closed the door on digital assets. On Wednesday, she signed House Bill 2749, which updates Arizona’s unclaimed property laws to include digital assets.The legislation allows the state to retain unclaimed cryptocurrencies in their original form rather than liquidating them into fiat currency.Magazine: Bitcoin eyes ‘crazy numbers,’ JD Vance set for Bitcoin talk: Hodler’s Digest, May 4 – 10

Nasdaq-listed GDC plans to buy Bitcoin and TRUMP memecoin for $300M  
Nasdaq-listed GDC plans to buy Bitcoin and TRUMP memecoin for $300M  

GD Culture Group (GDC), a Nasdaq-listed holding company focused on livestreaming, e-commerce and artificial intelligence-powered digital human technology, plans to raise up to $300 million for a cryptocurrency treasury reserve.In a May 12 statement, GDC and its subsidiary, AI Catalysis, announced entering into a common stock purchase agreement with a British Virgin Islands limited liability company to sell up to $300 million of its common stock.The proceeds from the stock sale will be used to fund the firm’s crypto treasury, which will include purchases of Bitcoin (BTC) and the Official Trump (TRUMP) token.“Under this initiative, and subject to certain limitations, GDC intends to allocate a significant portion of the proceeds from any share sales under the facility to the acquisition, long-term holding, and integration of crypto assets into its core treasury operations,” the company said in the announcement. GDC described the strategy as a move to align with the broader “decentralization transformation.”GDC stock price, 1-year chart. Source: NasdaqFounded in 2016, GDC is a micro-cap company with a current $34 million market capitalization, according to Nasdaq data.Related: Multi-wallet usage up 16%, but AI may address crypto fragmentation gapGDC’s chairman and CEO, Xiaojian Wang, said the initiative builds on the company’s strengths in digital technologies and positions it for a blockchain-powered industrial shift.“GDC’s adoption of crypto assets as treasury reserve holdings is a deliberate strategy that reflects both current industry trends and our unique strengths in digital technologies and the livestreaming e-commerce ecosystem,” Wang said.The stock offering was announced over a month after the firm received a noncompliance warning from Nasdaq related to its stockholders’ equity. The notice indicated that the firm reported stockholders’ equity of only $2,643, well below the minimum requirement of $2.5 million.The firm was given until May 4 to submit a plan to comply with the listing requirements. If accepted by Nasdaq, the compliance plan will allow up to 180 days from the notification period to comply with the requirements.The Nevada-based company joins a small but growing group of public firms that are allocating part of their balance sheets to crypto assets. Related: Crypto speculation dominates $600B cross-border payments: BIS reportTrump token dinner planned for top holdersGDC’s announcement coincides with an upcoming high-profile event tied to the Trump token project. The 25 largest holders of TRUMP tokens are set to attend a private dinner at the White House on May 22.However, the TRUMP memecoin project said in a May 12 X post that it has stopped considering additional purchases for the dinner and that the attendees had been notified to apply for background checks.According to data provided on the project’s leaderboard, the top 220 wallets held more than 13.7 million tokens as of May 12, worth about $174 million at the time of publication.Top 10 TRUMP memecoin holders as of May 12. Source: TRUMP memecoin projectSome US lawmakers have criticized the dinner. Republican Senator Cynthia Lummis reportedly said that the idea of the US president offering exclusive access for people willing to pay “gives [her] pause.”Crypto regulation experts also fear that the Trump family’s crypto endeavors may trigger more regulatory scrutiny by the US Securities and Exchange Commission, as politically affiliated memecoins introduce a new challenge for crypto legislation.Magazine: Uni students crypto ‘grooming’ scandal, 67K scammed by fake women: Asia Express

Open chat
1
BlockFo Chat
Hello 👋, How can we help you?
📱 When you've pressed the BlockFo button, we automatically transfer to WhatsApp 🔝🔐
🖥️ Or, if you use a PC or Mac, then we'll open a new window to load your desktop app.