Treasury officials should leave Tornado Cash alone for the sake of national security

Published at: Dec. 5, 2022

One of the most powerful moments in a new crypto user’s journey happens the first time they send a sizable amount of money to their private wallet. It’s an awe-inspiring, serious moment — and it’s a little scary to experience the power and personal responsibility of the technology firsthand with your own real money.

A second powerful moment occurs when the same user is introduced to a block explorer, looks up their address and sees that same transaction there on the blockchain for all to see.

There are competing visions of what Bitcoin (BTC), Ether (ETH) and other cryptocurrencies will achieve. They may be the future of gold, payments, currency or bank accounts. But no matter your crypto vision, none can work without achieving the same level of privacy enjoyed by cash or, at a minimum, credit cards. While credit card companies conduct unparalleled surveillance on our financial life, at least our transactions are not viewable on a public ledger.

There are a number of tools to achieve privacy available in crypto, from privacy coins to mixers and conjoining transactions on the Bitcoin blockchain. These tools are used by everyday users, and in some cases, they are used by bad actors — just like cash. Or to be more precise, crypto and crypto privacy tools are used by criminals with less frequency than cash.

Crypto is safer than fiat.Chainalysis: Transactions involving illicit addresses represented just 0.15% of cryptocurrency transaction volume in 2021.United Nations: estimated money laundered globally in one year is 2-5% of global GDP, or $800B - $2 trillion in USD.Sources

— CZ Binance (@cz_binance) May 6, 2022

The United States Treasury Department’s Office of Foreign Assets Control sanctioned one particular project, Tornado Cash, that was the most effective privacy tool on Ethereum. Much has been written about the sanction and the threat represented by sanctioning code as speech, and two lawsuits have been filed to push back against OFAC’s efforts.

What has been lost in the FTX drama over the last few weeks is the deft maneuvering that OFAC has engaged in to improve its strategic position in the litigation. On Nov. 8, OFAC “redesignated” Tornado Cash “on the basis of new information.”

Two significant legal challenges brought forward a few weeks prior that poked holes in OFAC’s designation are the likely source of the “new information.” OFAC can only sanction groups, not computer code, and OFAC seems to be pushing a novel theory in its second designation that the decentralized autonomous organization around Tornado Cash was part of a group, even though the DAO had no power to change the code since the admin key was burned.

Supporters of the designation argue it was overall a fair trade to achieve national security goals. The stated reason for the designation was that Tornado Cash “obfuscated the movement of over $455 million stolen in March 2022” by North Korean hackers.

But did it really? Privacy tools require a large anonymity set to work. That’s the only way that small transactions by ordinary users can hide in a large crowd. And it works only if privacy tools are used correctly, without privacy mistakes like making mirror transfers into and out of shielded assets within a short timeframe.

Related: My story of telling the SEC ‘I told you so’ on FTX

Consider that when North Korean hackers made that specific transfer, it represented 20% of the entire Tornado Cash pool. The sheer volume of ETH North Korea was trying to move through the Tornado Cash protocol meant that it wasn’t obtaining any meaningful privacy by using the tool. It evokes a comical vision of Godzilla trying to cover himself with a fig leaf.

The Treasury Department would have achieved more for national security by allowing North Korean hackers to maintain a false sense of confidence and continue using the tool while it surveilled their transactions using statistical tracing analysis. What OFAC achieved instead amounts to little more than national security theater.

Meanwhile, it has done real harm to the Ethereum blockchain. One example, as noted by Ethereum co-founder Vitalik Buterin, is that Tornado Cash anonymized donations to support Ukraine. If the Treasury Department’s sanction against Tornado Cash is allowed to stand, it can sanction anything from computer code and applications to specific assets.

Related: Coinbase is fighting back as the SEC closes in on Tornado Cash

Almost as if on cue, former Treasury official Juan Zarate argued in a recent interview that the Treasury Department should use the Patriot Act more “creatively” to sanction entire classes of assets in crypto. It’s a short step from there to sanctioning gold coins or other everyday assets.

Society doesn’t countenance the sanctioning of things merely because criminals happen to use them. Criminals drive on roads. They use tools available at the hardware store. They use these things in furtherance of their crimes.

If OFAC’s vague sanction of “Tornado Cash” is allowed to stand, it can sanction any protocol or asset in crypto. And that threatens to destroy any meaningful vision of crypto’s future.

J. W. Verret is an associate professor at the George Mason Law School. He is a practicing crypto forensic accountant and also practices securities law at Lawrence Law LLC. He is a member of the Financial Accounting Standards Board’s Advisory Council, a member of the Zcash Foundation's board of directors, and a former member of the SEC Investor Advisory Committee. He also leads the Crypto Freedom Lab, a think tank fighting for policy change to preserve freedom and privacy for crypto developers and users.

This article is for general information purposes and is not intended to be and should not be taken as legal or investment advice. The views, thoughts and opinions expressed here are the author’s alone and do not necessarily reflect or represent the views and opinions of Cointelegraph.

Tags
Law
Usa
Related Posts
Crypto developers should work with the SEC to find common ground
Regulators are tasked with balancing between protecting consumers and creating environments where entrepreneurs and the private sector can thrive. When markets face distortions, perhaps due to an externality or information asymmetry, regulation can play an important role. But regulation can also stifle entrepreneurship and business formation, leaving society and its people worse off. The United States Securities and Exchange Commission has been particularly hostile against cryptocurrency companies and entrepreneurs. For example, SEC Chairman Gary Gensler has remarked that he views Bitcoin (BTC) as a commodity but that many other “crypto financial assets have the key attributes of a security.” He …
Technology / Aug. 30, 2022
Get ready for the feds to start indicting NFT wash traders
Studies show that most people who attempt to wash trade nonfungible tokens (NFTs) are unprofitable. But that doesn’t stop them from trying, which makes it a glaring regulatory and enforcement issue for the industry. In wash trading, manipulators buy and sell an asset between themselves to create the appearance that the asset is in higher demand and, therefore, worth more than it would be otherwise. With NFTs, wash trading is fairly straightforward: Imagine an investor holds $1 million in Ether (ETH). The investor mints an NFT and proceeds to sell it to themself for all the ETH they own. The …
Regulation / Aug. 31, 2022
Tornado Cash is the latest chapter in the war against encryption
The sanctions imposed by the United States government on Tornado Cash have reignited a public debate on privacy. For many in the relatively young crypto community, such an intervention by the federal government seems groundbreaking. However, tussles between the private sector and the state on the issue of privacy are far from new and can provide compelling insights on what we might expect next for privacy in the crypto industry. In the 1990s, Phil Zimmermann released Pretty Good Privacy (PGP), one of the first openly available public-key cryptography applications that featured end-to-end (E2E) encryption. Zimmerman’s creation prompted a criminal investigation …
Technology / Sept. 21, 2022
Anonymous crypto developers belong in prison — and will be there soon
In the months following the announcement of my company’s first experimental title, Cyberstella, visits to my personal LinkedIn profile increased by an astonishing 300%. What does this tell us about the rising trend of anonymous developers popping up in every Web3 community to spam users with investment opportunities and then disappear from the face of the Earth? Well, it spells out trouble for anonymous crypto developers who think they can get away with never putting their face where the money is, so to speak. The fundamental principle behind crypto investing is a two-step process: Issue your project’s native token, leverage …
Regulation / Dec. 14, 2022
Congress may be ‘ungovernable,’ but US could see crypto legislation in 2023
The United States House of Representatives finally elected a speaker last week, concluding a four-day, 15-ballot ordeal that left many wondering if political gridlock was now the new normal in the U.S., and if so, what the consequences would be. For example, were the concessions made by Republican Kevin McCarthy to secure his election as speaker ultimately going to make it difficult to achieve any sort of legislative consensus, making it impossible for the U.S. to raise its debt ceiling and fund the government later this year? Not all were optimistic. The House of Representatives will be largely “ungovernable” in …
Adoption / Jan. 12, 2023