Showing posts with label Tornado Cash. Show all posts
Showing posts with label Tornado Cash. Show all posts

Friday, April 11, 2025

If it's crypto it's not money laundering

It appears to be official now. According to the U.S. Department of Justice, when illicit activity is routed via crypto infrastructure, then it no longer qualifies as money laundering.

Earlier this week the Department of Justice's deputy attorney general Todd Blanche sent out an internal staff memo saying that the digital asset industry (read: crypto) is "critical to the nation’s economic development." (Editor's note: it's not.) As such, staff have been instructed to stop targeting crypto platforms such as exchanges, mixers like Tornado Cash and ChipMixer, and offline wallets for the "acts of their end users." 

What does "the acts of their end users" mean? Further clarity arrives deeper into Blanche's memo. It helpfully draws attention to how cartels operating in the fentanyl trade often use digital assets. This is well known. Tether, for instance, is a popular payments platform in the fentanyl trade. (See here, here, and here). And yet, the Department goes on to explain that while it will continue to pursue cartels, terrorist organizations, and other illicit enterprises for their financial crimes, it "will not pursue actions against the platforms that these enterprises utilize to conduct their illegal activities."

This marks a radical departure from long-established financial law on Planet Earth, where financial institutions are generally held responsible for the "acts of their end users," and are pursued when criminals use them to "conduct their illegal activities." It's what's known in law as money laundering.

Money laundering is a two-sided crime. There's the first leg: a criminal who has dirty money. And there is the second leg: the criminal's counterparty, a financial intermediary (a bank, crypto exchange, remittance platform, money courier, or helpful individual) who processes the dirty funds. Both legs are prosecutable. That's precisely what happened to both TD Bank and its cartel-linked customers when they were charged last year. Financial providers are held liable for the crimes of their users.

The same two-sidedness goes for sanctions evasion. There is the sanctioned party and there is the financial platform that facilitates their evasion. Both are indictable.  

If, as Blanche suggests, digital asset platforms are no longer to be targeted for the "acts of their end users," that's effectively saying that the second leg of a money laundering or sanctions violation is no longer a violation, at least not when a crypto platform is involved. So if cartel deposits dirty money at an exchange like Binance which facilitates their crypto transactions, the exchange won't be pursued. Only the cartel will be.

In effect the entire technology has been handed a get-out-of-money-laundering-jail-free card. A detached observer could safely assume that crypto platforms will respond by easing up on their compliance measuresthey won't be indicted, after allwhich, in turn, will allow more bad actors to make use of their services.

The memo provides more details. It's quite likely that both the ongoing Tornado Cash case (which I've written about extensively) and the ChipMixer case will be dropped, as the memo explicitly states that the Department will no longer target mixing and tumbling services. Tornado Cash, a smart-contract based mixer, operates with a large proportion of its infrastructure running through automated code, whereas first-generation mixers like ChipMixer are entirely human-operated. The latter had mostly disappeared thanks to a series of successful criminal convictions, but will spring back into action as the threat of indictment recedes—leading to more anonymity for the entire system, including for criminals.

The memo's prohibition against Department lawyers targeting "offline wallets" likely refers to "unhosted wallets," which presumably applies to stablecoins—a highly popular type of crypto token pegged to national currencies. Stablecoin users can either hold balances of a stablecoin like Tether or USDC in unhosted format, within their personal crypto wallets, or hold them with the issuer for redemption into actual dollars, in which case they become "hosted." The implication seems to be that if unhosted stablecoins are used by bad actors, the issuers themselves won't be targeted. It's a fantastic policyif your goal is to encourage fentanyl cartels to use stablecoins.

This decriminalization of crypto money laundering is a ratification of how much of the crypto ecosystem already operates. Just last week, for example, I wrote about stablecoin issuers like Tether and Circle allowing Garantex, a sanctioned Russian exchange, to hold balances of their stablecoins. The issuers seem to believe that providing access to illicit end users like Garantex is legal. And now, it seems, the government has confirmed their view by no longer targeting unhosted wallets for the "acts of their end users."

Now that we've explored some of the immediate legal and technical consequences of this decision, it's worth asking: who on earth benefits from this sudden shift in policy? Because clearly most people will be made worse off. 

I'm only speculating, but here's who this policy may be designed to appease and/or reward:

  • Trump-voting libertarians who have arrived at the odd belief that money laundering shouldn't be a crime.
  • San Francisco crypto entrepreneurs who want to create financial platforms on the cheap, without the burden of building expensive compliance programs to prevent criminals usage. These entrepreneurs also want their crypto platforms to have access to bank accounts, but banks have been hesitant due to the high risk of crypto-based money laundering. Now that crypto has immunity, banks no longer have to worry. Crypto entrepreneurs voted for Trump, funded him, and are a big part of his administration. This is their payback.
  • Trump himself who seems intent on building a murky authoritarian system of bribery and patronage à la Putin or Orban. This system requires money laundering-friendly financial infrastructure, and the Department's memo may be an early step to creating it. (The Trump family, with its many crypto-based entrepreneurial efforts, is also part of the second group.)

In the long term, banks and other traditional providers may benefit, too. With crypto-based finance now unburdened of a major law, every single financial provider operating outside of this crypto-friendly zone, such as traditional banks and fintechs, will be incentivized to switch their database infrastructure over to crypto in order to qualify for this loophole. That means shifting your Wells Fargo U.S. dollar savings account over to a blockchain-based dollar saving account. Doing so will allow banks and fintechs to cut compliance costs and increase their profits.

Once the entire financial sector has migrated through the loophole, it will no longer be a crime to launder funds for criminals. And with mixers no longer being charged by the Department of Justice, that means blanket anonymity for everyone.

As far as the public's welfare goes, the memo is awful. Like theft and fraud, money laundering is immoral and should be punished. Giving one stratum of society a free pass from any law, whether that be money laundering or theft or murder, erodes trust in government and the financial-legal system.

More broadly, society's money laundering laws are a key defence against all types of other crimes. The so-called predicate offences to money laundering such as robbery, human smuggling, and corruption become much more tricky to carry out when, thanks to money laundering laws, the financial system does its best to shut them out. The dissuasive effect engendered by this effort stops many would-be criminals from ever leaving the licit economy. Take away those laws and the case for becoming a criminal becomes much more persuasive.

Thursday, December 5, 2024

Tornado Cash un-OFAC'ed


The next chapter in the Tornado Cash saga just dropped. Last week a court ruled last that Tornado Cash, a bot that can be used for obfuscating crypto, is safe from being sanctioned.

I first wrote about Tornado Cash in 2021, before its legal troubles began, warning of the risks ahead. I've been tracking Tornado's legal saga since then. (See here | here | here ). The saga serves as a bellwether for how financial services hosted on blockchains are to be sliced and diced under existing laws, in particular the crucial anti-money laundering statutes and sanctions laws. More generally it foreshadows how autonomous techno-beings, many of which don't yet exist, are to be treated by the law.

In the newest chapter of the saga, a court ruled that America's sanctions authority, the U.S. Treasury's Office of Foreign Assets Control (OFAC), does not have the authority to sanction a certain type of smart contract, or string of autonomous code, that undergirds Tornado Cash: its so-called immutable contracts.

Recall that in August 2022, OFAC sanctioned Tornado Cash, which accepts traceable crypto from users and returns it in untraceable format. Tornado had been used by the sanctioned North Korean hacker group Lazarus to obfuscate its financial tracks. OFAC listed Tornado Cash's website tornado.cash along with 53 Ethereum addresses.

The sanctions were relatively effective. Americans could no longer use the bot without risking fines or imprisonment. Those who had funds deposited in Tornado had to ask OFAC for special permission to withdraw them. In the months after the sanctions were announced, usage of the privacy bot plunged and the amount of crypto deposited fell by over half.
 
After two different sets of plaintiffs challenged OFAC's actions in court, the appeals court in one of the cases returned a verdict last week. An immutable smart contract is "unownable, uncontrollable, and unchangeable—even by its creators," and therefore it doesn't qualify as property. Because OFAC's sanctioning power is limited to that which is property, it follows that OFAC cannot sanction immutable smart contracts.

This not-property ruling only applies to twenty immutable Tornado Cash contracts that were on OFAC's sanctions list. Tornado's mutable contracts, those that can be controlled and changed, remain property—and thus can stay on the list of sanctioned contracts. Unless OFAC wins on appeal, it will presumably have to unsanction those twenty immutable contracts.

Now, it's possible that as long as the remaining sanctioned mutable contracts are crucial to the functioning of the Tornado Cash bot, the revised sanctions blacklist will still have an effect. And if OFAC adds other key mutable Tornado Cash smart contracts to its list (say like the contracts allowing governance, which for some reason were not originally sanctioned), American users will continue to steer clear of Tornado Cash, the bot's anonymizing capacities remaining lower than otherwise, thus diminishing its ability to serve North Korean interests. 

But if not, what can OFAC do? 

Sanction users, not code

I've already done a bit of digging on this question. In response to the sanctions, I wrote an article in late 2022 entitled: How to stop illegal activity on Tornado Cash (without using sanctions) The gist was to explore alternative tools for countering illicit activity on Tornado rather than the blunt tool of sanctioning its actual smart contracts. What I suggested was to apply pressure to the users of the smart contracts. "Rather than punishing code, penalize the people who use the code."

The logic goes like this. Any user who deposits crypto to Tornado Cash, even someone with clean crypto, is providing North Korea with prohibited financial services, the Tornado bot being the means by which the two sides are connecting as counterparties. Whether intentional or not, a user's deposits broaden the anonymity set of Tornado Cash, or its ability to obfuscate larger amounts of illicit funds sourced from sanctioned counterparties like Lazarus.

Think of it as sanctioned North Korean users passing on sanctions taint to all other Tornado Cash users by virtue of everyone interacting via the same bot, Tornado Cash. This taint spreads to those who deposited their crypto (clean or dirty) to Tornado at the same time as Lazarus and/or those who have continued to deposit to it in light of the known fact that the North Korean group regularly deposits stolen funds to the platform.

OFAC issues a public alert stating that any foreigner can and will be sanctioned if their funds interact with North Korean funds on Tornado Cash. In response, some foreign users will risk being designated and continue to engage with Tornado. Many will not. As for U.S. users, OFAC can threaten them with potential civil monetary penalties if they aid North Korea using Tornado as their a tool. A $10,000 fine for interacting with sanctioned North Korean actors via the Tornado Cash bot will probably discourage most usage.

Another core set of Tornado Cash users who OFAC has legal leverage over are the relayers—real life individuals who provide an extra layer of privacy to Tornado Cash users. (I explain here why relayers are necessary for full privacy). OFAC can threaten foreign relayers with sanctions and U.S.-based relayers with civil monetary penalties.

Pressuring these various groups of users won't stop Tornado Cash code from functioning, but it will certainly constrain the activity it facilitates, and thus make it harder for North Korea to anonymize its funds. And it is consistent with the court's not-property ruling because users, not contracts, are being targeted.

I'm not saying that OFAC will follow this playbook, or that it should, but it certainly is an option. There is another route, though, and that is to go to Congress and ask for the ability to put sanctions on immutable entities. 

More broadly, Tornado Cash may just be the first in an emerging population of unownable and uncontrollable techno-beings—bots, machines, drones, androids, AI agents,  automatons, and golems—that operate independently of human control, many of which will end up doing very dangerous things. Society may want the legal ability to protect its members from these immutable contraptions, including by sanctioning them.

For instance, imagine the following scenario...

A Russian AI-guided assassin bot

If a Russian assassin is regularly poisoning people (including U.S. citizens) for criticizing Putin, OFAC can sanction that assassin, thus preventing any American entity from dealing with him and blocking all of his accounts, his car, and his interests in various companies. That might not stop the assassin, but it'll make his job more difficult. In doing so, OFAC is simply fulfilling its mandate to use its sanctioning powers to protect Americans.

Say the assassin creates an artificial intelligence and imbues it with all of his assassin's lore, providing it with an artificial body and then throwing away the keys, rendering the robot immutable. The court's recent not-property ruling suggests that while OFAC can ably defend Americans from the flesh and blood assassin, it cannot protect them from the assassin's immutable killing robot—even though the robot performs the precise same killing function as the living assassin using the exact same techniques.

This is obviously an incongruity, one that seems like it should be fixed. Or is there a specific reason why we should provide legal safe harbor to all unownable and uncontrollable techno-beings? Feel free to explain in the comments.

In any case, OFAC's efforts to apply its national security mandate to Tornado Cash are probably not over. Let's see how it responds. Some sort of resolution is important because we are still in the early stages of being inundated with self-guided autonomous agents.

Monday, November 25, 2024

How my views on financial privacy have evolved over a decade

I began exploring the topic of financial privacy and payment anonymity in the early days of this blog. Over the past decade, my views have shifted significantly—here's how and why.

Rereading my earliest mentions of financial privacy, they now seem a bit... idealistic? extreme? For instance, in my 2014 post entitled Fedcoin, a central-bank issued digital currency, I suggested that the product should be 100% anonymous, like coins and banknotes.

Criminals would undoubtedly exploit unlimited anonymous digital currency, as I acknowledged in a 2018 article entitled Anonymous digital cash. But I figured that the bad guys would find their own ways to transact anyways, say through their own mafia-created payments system, so central banks may as well go forward with anonymous digital currency, the benefits to civil society of unlimited e-cash ultimately outweighing the cost.

I wouldn't support these same ideas today, or would at least modify them, as I'll show further down.

But idealistic and extreme aren't quite the right words. I think that I was right, at least when looking at things from a certain vantage point, but it was still early in my blogging career and I hadn't yet explored other vantage points

To be clear, financial privacy, or the ability to make transactions anonymously or near-anonymously, isn't just something that criminals require. It's crucial for regular folks, too, and in my earlier blog posts I spent a lot of time detailing why this is so. After a cashier dropped my card behind the counter (and potentially skimmed it?), I wrote that cash provides buyers with a "shield from everyone else involved in a transaction" in my 2016 post In praise of anonymous money. And I still agree with that, and to this day always pay with cash when the store I'm at feels a bit sketchy. I worry that this shield will disappear as cash usage continues to decline.

Civil society's need for private transactions isn't just a weird fringe view. In a 2018 entitled Money is privacy, I described the work being done on privacy and payments by Federal Reserve researchers Charles Kahn, James McAndrews, and William Roberds. Licit transactions can unintentionally evolve into a long-term relationship, they write, including clawbacks, extraterritorial rulings, and new forms of product liability. To boot, personal information linked to digital transactions can be stolen in data breaches.
 
According to the three Fed researchers, the ability to transact anonymously converts a potentially thorny transaction into a one-and-done relationship. Licit payments that might have otherwise been deemed too dangerous can proceed, the extra trade making the world better off. (See also my 2020 article Central banks are privacy providers of last resort.)

As for crypto, I've described blockchains as dystopian hellscapes or panopticons, because every single transaction is mapped out for all to see. That makes blockchains just awful places to carry out conventional business. Firms require a degree of secrecy in order to hide their corporate strategies and tactics from competitorsbut the medium doesn't permit secrets. Blockchains need more privacy. (See my 2022 post DeFi needs more secrecy, but not too much secrecy, and the right sort of secrecy). 

So what changed?

Starting in 2018, I focused more on studying fraud, including ransomware, tax evasion, and gift card schemes. I found gift card fraud particularly intriguing: semi-anonymous payment systems linked to Google Play and Apple iTunes have enabled an entire industry of scammers, including IRS and tech support fraudsters, to launder stolen funds. Network operators like Google and Apple, as well as major retailers such as Target and Walmart, quietly profit from all of this fraud. (See Gift Cards: When Good Products Do Bad Things [2021] and In-game virtual items as a form of criminal money [2019].)

Which led me to my next big truth: if privacy is crucial, so is the necessity of criminalizing money laundering.

Money launderers are the financial intermediaries who, knowing full well that a customer's funds are dirty, conduct transactions with them anyways, in a way designed to disguise its source.

The willful laundering of a criminal's money is an extension of the original crime, making a launderer just as morally and ethically culpable as the criminal they are helping. By facilitating the final release of illicit funds, the money launderer enables the crime to fulfill its purpose, completing the damage caused by the initial offense—be it theft, extortion, or human smuggling. This is why the launderer's actions deserve to be criminalized. (See A short and lukewarm defence of anti-money laundering standards from 2021).

The crime of money laundering bears a striking resemblance to the centuries-old crime of fencing—the art of accepting and redistributing stolen property. (See my 2024 post "I didn't launder the cash, your honor. The robot did") In earlier times, thieves were responsible for reselling their stolen goods themselves. However, by the 17th century, this task was often outsourced to specialized intermediaries, or 'fences.' At first, there was no legal term for this crime, but in 1692, England formally criminalized fencing, and deservedly so.

Thinking more about the crime of money laundering led me to become more critical of stablecoins, for instance. From 2014-2018 my articles on stablecoins were mostly neutral or positive, but now my posts focus on the fact that stablecoin issuers, by turning a blind eye to those using their platform, have allowed themselves to become launderers for all types of criminals. (Among others, see my 2019 post From unknown wallet to unknown wallet and my 2023 post Why do sanctioned entities use Tether?)

At this point, you may be able to see my conundrum.    

If, like fencing, money laundering should be criminalized (and indeed it is illegal in most parts of the world), that collides with my prior belief in the importance of financial privacy. After all, the only way for a banker, money transfer agent, or stablecoin issuer to be safe from a money laundering charge is to show that they did a good faith job collecting enough personal information to ensure that they weren't dealing with criminals. And giving up personal information is necessarily privacy-reducing.

One way to resolve my conundrum would have been to pick a side and advocate for it, but I think both sides are important, so I've generally tried to find a compromise. Most of my writing on the topic over the last five or six years has been trying to wrestle with where to draw the line between financial privacy and the crime of money laundering. 

My compromise position has generally advocated a privacy safe harbour for small day-to-day transactions. But anything above a certain monetary ceiling needs to be identified in order to avoid a money laundering charge.

Here are some examples of my often clumsy attempts to balance the two ideals:

Balancing the two ideals rather than taking an either/or approach has led me to adopt a more comparative approach to thinking about financial privacy. I've begun to analyze cross-country differences in the intensity of financial surveillance as conducted by national financial intelligence units. Canada, for instance, has chosen a balancing point that is far more in favor of financial privacy (and accordingly more accepting of money laundering) than the U.S. has, as illustrated in my 2024 post Your finances are being snooped on. Here's how.

So that's where I've landed after ten years of writing about privacy. Hard-core privacy advocates and civil libertarians would probably describe me as a sell-out or a wishy-washy centrist because I'm willing to compromise on financial privacy. Fair enough. But I do wonder how many privacy advocates would go so far as to call for an all-out decriminalization of money laundering. Doing so would maximize privacy, but surely no privacy advocate thinks that bankers who clean money for the mob should by allowed to walk free. We are probably closer than they think.

I look forward to seeing how my opinions evolve over the next ten years, as I'm sure they will. Thoughts or comments?

Saturday, September 14, 2024

How should money laundering laws apply to DeFi?


Everyone agrees that money laundering laws apply to DeFi. The question is: how to apply them?

DeFi, or decentralized finance, is an emerging segment of the broader financial industry that delivers traditional financial services, say like trading or lending, using a novel type of databaseblockchains.

These blockchains allow people to create financial robots, or bots, that the public can engage with in order to get financial services. And not just any sort of bot. These are autonomous, unstoppable, non-upgradeable financial bots. They operate independently of humans; once its creator sets it free, the bot never needs the intervention of its creatoror anyone elseever again. The bot is unstoppable; once its code is live, it can't be erased, upgraded, or altered. The bot is incapable of deviating from its original code; it is forever locked in place.

(Most financial services provided on blockchains don't quite meet the strict standard described above. These "fake" DeFi bots are upgradeable and are driven by a human operator or team behind the scenes. The application of money laundering laws to fake DeFi bots is straight-forward. What I'm addressing in this post is the true DeFi bots, the ones that are autonomous, unstoppable, and non-upgradeable.)

Historically we haven't received our financial services from autonomous, unstoppable non-upgradeable agents. We've always gotten them from brick and mortar institutions like banks and brokerages. These institutions are run by human executives and employees who rely on a fairly malleable set of machine aids, like websites and Excel spreadsheets and SQL databases.

The application of money laundering law to banks and other financial institutions is well understood. If a bank consciously allows dirty money onto its platform, we punish the bank and the folks who run it. This follows from 18 U.S. Code § 1956, which says that anyone who knowingly conducts a transaction involving dirty money, and does so in a way to conceal its origin or disguise its control, can be punished with up to twenty years in jail for money laundering.

Here's the question: when financial services are provided through the mediation of autonomous, unstoppable, non-upgradeable bots, and not human-operated banks and brokerages, who does society punish when dirty funds are processed? What DeFi party is liable under 18 U.S. Code § 1956?

The bot itself is nonpunishable. It simply keeps on ticking. It's not a human and can't learn from punishment. So that's a dead-end.

There is no human operator or governor to punish (at least, not in the case of pure DeFi bots). The bot is 100% autonomous, operating without the aid of a human behind the scenes.

What about the creator? I've argued in a previous post on a particular DeFi bot, Tornado Cash, that it makes a lot of sense to hold the creators of unstoppable non-upgradeable financial bots accountable for money laundering, even if those creators are no longer involved with the bot in any way. To protect themselves from being charged with money laundering, creators will choose at the very outset to equip their financial bots with a means for screening out dirty funds, thus complying with the law. I'll let you read that post yourself.

There's another option. In a recent exchange with a member of congress, a DeFi lobbyist suggests that the users of unstoppable non-upgradeable financial botsnot the creatorsbe held liable for their own bad conduct. Here's the clip:

This is an interesting solution. Let's work out how money laundering law spreads into DeFi if a user-pays-the-price strategy is adopted.

Say that criminals regularly place dirty funds with a certain DeFi bot, perhaps a decentralized exchange (like Uniswap), in order to clean them, and this is a widely-known fact. Next, let's look at what happens when a user with licit crypto submits their funds to the same bot. By consciously allowing their clean funds to be commingled with dirty funds and swapped for them, these licit users have themselves become bad actors. After all, helping criminally-derived funds make a getaway is a crime: we call it money laundering.

Under this user-pays-the-price scenario, DeFi becomes radioactive. Anyone interacting with an unstoppable, non-upgradeable financial bot is playing with fire, since a potential money laundering charge is just around the corner.

In an effort to reduce the odds that they face a money laundering charge, users may try to shop around for bots that have been coded with filters for screening out bad actors. Creators may try to compete with each other to attract users by providing genuinely compliant bots.

The upshot is that whether society decides to makes creators of financial bots liable for money laundering, or users liable, the end result may very well be the same. Bots will be built with anti-crime devices, thus falling in line with society's money laundering laws. That's a good result.

However, for pragmatic reasons my preference is to hold creators liable rather than users. My mental model of a prototypical retail user of financial services is a frazzled individual who doesn't have the bandwidth or knowledge to grasp exactly what they are doing with their money, because their time is divided between their family, jobs, education, church, hobbies, and other important things. What an awful burden to put on these people: "Oh, by the way, be careful where you get your financial services online, because you might be caught laundering money for the mob." Indeed, one of the advantages of dealing with a traditional bank is that a licit user needn't worry about this hazard.

Creators, on the other hand, are far fewer in number than users, are likely to be financially savvy, and probably have far more time to devote to the intricacies of financial law. And so the creator class will be better able to bear the burden of being targeted with the burden of a potential money laundering charge, and instigating the necessary compliance.

So if we had to choose who to be liable for the bad conduct flowing through unstoppable non-upgradeable financial bots, I say target creators, if possible, and not users. We all agree that money laundering laws apply to DeFithe end goal being bots that exclude criminalsbut placing the liability on users is an an inefficient and unfair way of extracting compliance.

Monday, June 10, 2024

"I didn't launder the cash, your honor. The robot did."

Crypto enthusiasts protest the trial of Alexey Pertsev

As the multiple Tornado Cash legal cases wend their way through courts in the Netherlands and the U.S., we continue to learn how society's money laundering laws will be applied to some of the more unique financial entities being created on the new technological medium of blockchains.

Last month Alexey Pertsev, a co-creator and co-administrator of privacy platform Tornado Cash, was found guilty of money laundering by a Dutch court. (The full decision translated into English is here). Meanwhile, Roman Storm and Roman Semenov, Pertsev's colleagues, are under indictment in the U.S. for engaging in money laundering, among other charges. Separately, Tornado Cash continues to be sanctioned by the U.S. Treasury.

In general, I think a guilty verdict is the right decision. It would have been dangerous to find Pertsev innocent, since to do so would have given all sorts of hardened money launderers  the mob, drug lords, and terrorist networks  the perfect techno-legal loophole for avoiding future money laundering charge. Shifts in the underlying technology used for disguising dirty money should not be enough to turn a crime into a non-crime.

Before I get into my reasoning, here's some context for people who are new to the issue of Tornado Cash.

Tornado Cash was introduced by Pertsev, Storm, and Semenov in 2019 as a means for crypto users to enjoy privacy, but it wasn't long before thieves and hackers began to regularly deposit large amounts of stolen crypto into the utility to be obfuscated. This was plain as day to anyone who was watching. Blockchains are radically transparent (that's why privacy tools like Tornado are needed) which meant that everyone could watch in real-time as criminal trails converged on Tornado Cash. 

Court cases in both the U.S. and the Netherlands reveal that Pertsev and his colleagues were well-aware that illicit activity passing through Tornado, yet they continued to work on the utility anyways. This is important because possessing a "knowing" state-of-mind is a key ingredient to being found guilty of money laundering. If he had had no idea that the money being disguised was dirty, Pertsev could not have been charged in the first place.

Criminals were not the only users of Tornado. Licit actors who wanted privacy also deposited funds into the entity, including Ethereum co-creator Vitalik Buterin. But the presence of good transactions amongst the bad ones doesn't dilute the seriousness of the alleged crime. All it takes to trigger a money laundering charge is a few dirty transactions. "C'mon! 82% of the money was licit!" is no alibi.

Tornado Cash is by no means the crypto economy's first privacy platform. The original generation of privacy tools, so called "mixers" or "tumblers," began to emerge in the early 2010s with the likes of ChipMixer, Helix, Bitcoin Fog, Sinbad, and Blender. Anyone who required anonymity could send their bitcoins to the platform owner, who would proceed to commingle, or "mix," all incoming bitcoins in a single address under their control, thus rendering them untraceable. After some time had passed, the platform owner manually re-sent the now obfuscated bitcoins to their original sender, less a fee.

Like Tornado Cash, the first generation of privacy utilities was used by both criminals and regular folks seeking privacy. None of these original mixers have had happy endings. The owners of Bitcoin Fog and Helix, Roman Sterlingov and Larry Harmon, were both found guilty of money laundering and are currently serving jail sentences. Minh Nguyen, the administrator of ChipMixer, has been indicted for money laundering and is on the FBI's most wanted cyber list. Blender and Sinbad have both been sanctioned by the U.S. government.

Source

By any legal standard, these bad endings were well-deserved. They may have been technological novelties, but ChipMixer, Helix, Bitcoin Fog, Sinbad, and Blender were very much text-book examples of money laundering. The owners of these entities knew that some of the transactions they were participating in involved proceeds derived from criminal sources, yet despite this knowledge they proceeded to disguise them anyways. The only thing new about Helix and the other first generation mixers was the medium they were disguising  bitcoin instead of cash or deposits.

And so professional mixers like Harmon and Nguyen join a long line of traditional money launderers  dirty bankers, drug cash couriers, crooked remittance shop owners, and hawala operators. The law shouldn't be fooled by technological novelty, and in the case of the first generation of mixers, it wasn't.

That these were textbook cases of money laundering isn't disputed by the crypto community. Crypto advocates are a vocal bunch, and while they have loudly voiced their complaints about the legal action taken against Tornado Cash, they have for the most part quietly accepted the punishments meted out to the first generation privacy platforms. A legal fundraiser to support the Tornado Cash accused, for instance, has raised hundreds of thousands of dollars; there have been no equivalent efforts to raise a legal defence for Harmon, Sterlingov, or Nguyen. Crypto lobbyists have gone to war for Tornado Cash by launching court appeals and filing amicus briefs in its support. But when it comes to defending the Bitcoin Fog or Helix operators, or challenging the government's sanctioning of Sinbad and Blender  crickets.

The Tornado Cash legal cases have been more controversial than those of the first generation mixers thanks to a technical innovation in Tornado's construction. Most of us would consider this to be a relatively obscure change, but crypto enthusiasts see it as a defining one.

Harmon and his counterparts controlled their platforms outright, taking possession of the dirty crypto before manually sending it back to criminals in disguised form. Not so Tornado Cash. When it was built, a layer of automation was inserted between Tornado Cash's users and Pertsev and his colleagues.

Instead of sending their crypto to wallets controlled by the trio, as users did with Helix, crypto was now deposited by users into a set of automated pools. These pools were not managed on an ongoing basis by Pertsev and his colleagues. Rather, they were built using fully automated code on the Ethereum blockchain. Originally co-created by Pertsev in 2019, this code was frozen in time by the designers in early 2020, at which point it could no longer be upgraded or changed by anyone, even Pertsev. To this day the pools continue to operate, even though the Tornado Cash creators are either jailed or under indictment.
 
Other parts of the Tornado Cash platform are not so set-in-stone and remained under the control of Pertsev and his colleagues throughout. This includes the main website by which users accessed the automated pools, which was regularly upgraded over time, as well as the relayer service. (A relayer is a way to guarantee the privacy of Tornado Cash users). Pertsev and his colleagues profited from their ongoing control over the website and relayers.

The lawyers for Pertsev, Storm, and Semenov have argued that this layer of automated code exonerates the trio of money laundering. After all, if they no longer control what the utility is doing, then how can they be said to be operating a money laundering enterprise? The lawyers also argue that as writers of code, Pertsev, Storm, and Semenov are protected by speech laws, much like an author who has written a book. It is the code-is-speech claim that has particularity riled up the crypto community.

I don't like the idea of someone being sent to jail, but I think it's a good thing that the Dutch court chose not to accept these arguments.

Using go-betweens is a time-tested criminal strategy for distancing oneself from the crime. In more conventional money laundering operations, this strategy might involve separating the leader of a cash laundering operation from the actual dirty cash with a layer of underlings. In the age of crypto, no need to use living human underlings; just insert a buffer of unliving code.  

But the law shouldn't be fooled by artificial distances between a launderer and dirty money, whether those intervening layers be living people or code.

Allowing a buffer of automated code to absolve folks like Pertsev of money laundering would make it much easier to be a professional money launderer. Bad actors like Harmon and Sterlingov who have already been deemed by the courts to be criminals would suddenly have the perfect techno-legal loophole at their disposal if they decide to reengage in crypto laundering once their jail terms are up. Instead of manually running their operations as before, Harmon an Sterlingov could insert a mute layer of automated code between them and their illicit clients, their criminal mixing no longer being a crime.

But this would be an absurd state of affairs. A simple technological change to the way a criminal mixer administers their back office shouldn't convert them into a non-criminal.

The danger of the "it was the code that did it" defence extends beyond the crypto economy. In the much-larger traditional economy, laundering physical cash is a relatively common criminal profession. Take the fictional example of Marty Byrde, the star of Ozark. If the Tornado Cash defence were to be accepted in a court of law, then Byrde need only program a set of self-operating cash-handling robots to do most of his tasks for him, and he can get away scot-free. "I don't exercise any control over the packages of cash, your honor. The robots did!"

Or take the example of drug cash couriers, who run the risk of being convicted for money laundering when they move cash across the U.S.-Mexico border. Taking a cue from Tornado Cash, if a courier were to deploy an autonomous fleet of AI-powered drones instead, then when charged with a money laundering offence he or she need only invoke the now-standard defence: "it was the drones who controlled the cash, not me."

Taken to an extreme, the Tornado Cash defence means that money laundering effectively ceases to exist as a crime. All the culpability shifts onto the undead intermediaries, which can't be punished. This eclipsing of money laundering laws would be unfortunate. Professional money laundering is a key sector within the broader criminal economy, greasing the wheels for the entire enterprise. Without any legal defences against launderers, we are all much more vulnerable to crime-in-general.

In what follows, I want to provide a historical example of how the law should act when confronted with the changing tactics and technologies of money launderers.

Money laundering is a relatively new crime, but it has a much older predecessor in the crime of fencing, also known as receiving. The laws against fencing and money laundering are similar, the idea being to punish not the original criminals but the third-parties who knowingly participate in the crime by accepting dirty proceeds.

Any thief runs a big risk of being caught with stolen goods. At some point in the middle ages, specialized intermediaries, or fences, emerged to absorb this risk by accepting stolen property from professional thieves and redistributing it. Thieves could now offload their goods much quicker, thereby achieving a degree of safe harbor. For their part the fences themselves were safe from prosecution. After all, they hadn't committed the original theft, and accepting stolen property was not a crime.

The addition of specialized wholesalers to the thievery production process helped drive a rise in the incidence of theft, according to historian Rictor Norton. To close this loophole, fencing was criminalized in England in 1692. For the first time, a third-party who knowingly accepted stolen goods could be punished as an accessory to the original theft. The business of reselling hot property, risk-free until then, suddenly became much more dangerous.

The illegal fencing market quickly evolved new tactics. Enter Jonathan Wild, an incredibly successful launderer of stolen goods who, by the mid 1710s, is said to have been the "undisputed leader in the fencing business of London," according to marketing professor Ronald Hill. Wild evaded the 1692 anti-fencing law by never himself handling stolen property. Instead, he acted as an early version of Craigslist, but for stolen objects. He arm-twisted all of London's thieves to secretly report any robbery immediately to him, asking them to retain possession until he contacted them. At the same time, the unfortunate victims of those thefts were encouraged to approach Wild with requests to help locate their missing property.

Once Wild knew who was at both ends of a theft, he would pay the thief and tell him to return the goods to the victim using an anonymous porter. The happy victim got their stolen goods back, paying Wild a large reward for his troubles.

With Wild running circles around the law, Parliament passed an additional anti-fencing law in 1718 that punished anyone who took a reward under the pretence of helping a victim of theft, without actually prosecuting the original felon. In 1725, Wild was apprehended, tried, and condemned to death on the basis of this statute. 

A gallows ticket to view the hanging of Jonathan Wild (Wikipedia)

Now, a death sentence is extreme. But this is a good example of the law staying hip to both the changing technology of theft and its evolving division of labour. As the profession began to be subdivided into specialist thieves and an emerging class of allied wholesalers of stolen goods, lawmakers recognized that wholesaling was really just an appendage of theft, and thus fencing was criminalized. Later on, when fences like Wild adapted with new methods, the law kept up by finding additional means to reach fencing operations.

With Tornado Cash, we are at a "Jonathan Wild" stage of the modern money laundering profession's development. Control of dirty proceeds is being shifted to autonomous intermediaries so that the perpetrators can avoid prosecution. Much like how the law adapted in the 1700s to encompass Wild's tactics of distancing himself from dirty property, it will have to do the same with money launderers who use crypto code, autonomous robots, or AI drones to dissociate themselves. While I don't enjoy the idea of anyone spending time in jail, finding Pertsev guilty is part of that process.

Unlike Jonathan Wild, who was a criminal mastermind, Alexey Pertsev and colleagues seem to have bungled into the crime partly out of an ideological commitment to crypto ethics, the wider community unhelpfully egging him on. That doesn't mean he's not guilty, but it does suggest a lighter sentence than the 64-month one he received might be appropriate.

I've been arguing throughout this article that money laundering law should extend to innovative financial entities created on blockchains, such as Tornado Cash. I want to close by pushing back on this a bit.

A guilty verdict for Pertsev and his colleagues should not be tantamount to a ban the creation of autonomous financial institutions, particularly those focused on privacy. If a coder wants to create an open privacy mechanism for crypto, promote it, and financially profit from it, I think that he or she should have the right to do so, subject to the following condition. The code needs to include a component that screens out dirty crypto  and this filter shouldn't be a sham attempt, it has to be a genuine effort.  

While I think the law got it right in this instance, shame on lawmakers and law enforcement if they don't accommodate future generations of code-based entities (and their creators) that actually do make good faith efforts to freeze out dirty money.

Friday, April 19, 2024

Thoughts on the Tornado Cash defence and what happens when everyone adopts it


Payments companies are regularly punished for engaging in money laundering. MoneyGram, for instance, has has to pay multiple fines. Western Union was famously busted in 2017. Meanwhile, Cash App is being probed as we speak for inadequate anti-money laundering controls.

In the future, these companies may have in their grasp a very simple techno-legal trick that allows them to deal with dirty money and get away with it. All they need to do is transfer their entire IT apparatus from a regular set of databases onto "immutable" smart contracts hosted on blockchains.

This, at least, is what happens when you take the arguments put forward by the Tornado Cash defence team to their logical conclusion.

If you follow this blog, you'll know I've written a lot about Tornado Cash.

Cryptocurrency isn't private; it's radically transparent. The function that Tornado Cash serves is to accept traceable crypto from users, both licit and illicit, and return it to them in untraceable format. Beginning in late 2020, a steady stream of stolen crypto began to be moved by thieves onto Tornado Cash for the purposes of obfuscation. In effect, money laundering was now occurring on the platform. But who were Tornado Cash's money launderers? More specifically, someone was to blame for helping these thieves to disguise their tracks  who was this someone?

Last August the U.S. government indicted two people involved with Tornado Cash for conspiracy to commit money laundering.  I wrote about the government's indictment here. (They were also indicted for conspiracy to evade sanctions and the operation of an unregistered money transmitting business, but that's another story.)

Roman Storm and Roman Semenov, the accused, wrote the original smart contracts for Tornado Cash and exercised a degree of control over a key website for accessing those smart contracts. The government alleges that Storm and Semenov knew that the property being transferred to Tornado Cash was criminally derived, and that they also knew that the hackers wanted to disguise its source. Yet the duo conducted the financial transactions anyways. These three elements knowledge, the conducting of financial transactions, and the presence of unlawful money  are key ingredients to building a money laundering charge. (See specifically 18 U.S.C. § 1956(a)(1)B(i).)

Last week the defence lawyers for one of the accused parties, Roman Storm, filed a motion to dismiss the case, giving observers some initial insights into what arguments will be used to try and beat the government's money laundering charge. As I'll show, assuming these arguments are right, then a big chunk of the existing payments system has a fool proof plan for avoiding money laundering laws.

The distinction between the Tornado Cash front end and the actual Tornado Cash smart contracts looms large in the case, so let's touch on that briefly. The smart contracts are bits of code that reside directly on the Ethereum blockchain. This code allows users to deposit their trackable crypto to a pool along with many other users and then withdraw it, obfuscated. A front end, by contrast, is a regular website that allows users to interact with the smart contracts, and is hosted through a normal internet provider .

While users are free to interact directly with the Tornado Cash code, the most popular way to access Tornado was allegedly via the intermediation of the main website that was under the control of Storm and his colleagues.

The key argument made by Storm's lawyers is that the accused are not subject to the money laundering statutes because the money laundering statutes only apply to people who "conduct" what are defined as "financial transactions," and Storm did not conduct financial transactions.

The defence says that in order to show that someone was conducting a financial transaction it must be the case that control was exercised by that person over the actual criminally-derived funds. Storm may have had some control over the front end, but the defence claims this doesn't really matter because the front end itself did not exercise any control over the proceeds. "It did not access the funds directly," the lawyers argue. "It merely provided an interface to permit a user to interact with the smart contracts."  

As for the smart contracts, Storm clearly had no control over them. He had relinquished control back in May 2020, when a trusted setup ceremony ensured that no further changes could be made to the code. At that point, the smart contracts worked automatically. Bad actors only discovered Tornado Cash several months after the ceremony, at which time Storm had long gone. Furthermore, the smart contracts didn't actually control the funds, say Storm's lawyers, it was users of Tornado Cash who controlled the funds within the pool.

So, there you have it. The government's money laundering charge against Storm and Semenov requires locating a person or institution who is in control of the dirty funds and conducts financial transactions with them, says the defence. But it isn't the accused who exercised this control, it is the users who did so, via the intermediation of a set of financial automatons, the smart contracts.

For the philosophically crypto-pilled, the defence's arguments will make sense, since according to this view crypto is a revolutionary force for good, one destined to "break" what they see as a corrupt and old-fashioned financial system. For this breaking to happen, crypto shouldn't be forced to conform to the same old laws as stodgy payments companies like Western Union. New laws, or new ways of looking at old laws, should be shaped around crypto.

But to the non-crypto pilled, a successful defence of Storm and Semenov is quite concerning. As described by Bruce Schneier and Henry Farrel, it could potentially mean that anyone who wants to facilitate illegal activities would have a strong incentive to copy Tornado Cash, effectively turning their operation into a "golem"  a deathless artificial being run on smart contracts  and then throwing away the keys to avoid the law.

More specifically, by shifting their entire IT infrastructure over to smart contracts or some other equivalent automaton, payments institutions like MoneyGram that are currently subject to the money laundering statutes (and have already been punished under them several times) might be able to avoid future prosecution. If criminals start using the autonomous MoneyGram robot to make payments, MoneyGram can simply say: "The robot allowed them to do it, not us!" As for the official MoneyGram front end, even if the mob becomes a happy customer MoneyGram needn't worry since the front end is nothing but a filmy gauze between users and the autonomous robot, the company never actually controlling the funds (although according to the Tornado Cash lawyers the front end can continue to safely generate a profit for its owners!)*

The money laundering statutes  18 U.S.C. § 1956 and § 1957  are two of democratic society's key legal bulwarks against criminal behaviour. In a world in which the Tornado Cash defence prevails and payments companies adopt it as a techno-legal shield against money laundering charges, 1956 and 1957 become much less effective  and not because we decided to soften them via a democratic process, but because financial institutions found sneaky ways to get around the rules.

Mind you, the money laundering statutes wouldn't disappear entirely. The Tornado Cash defence's point is not that there is *no* money launderer. Rather, their argument is that it is the users of Tornado Cash, the public, who had "exclusive control," and not Storm and Semenov, so the latter duo aren't the guilty parties. Taking this control theory further, if the government wants to charge anyone with money laundering, it should probably be trying to target folks like Vitalik Buterin, a member of the public who regularly put his funds into Tornado Cash and thus potentially participated in the concealment of unlawful proceeds deposited by criminals.

What a dangerous financial tool to make available to the public!

Right now, I can safely transfer $1000 to Western Union without having to worry about commingling my $1000 with a criminal and thus facing a potential money laundering charge. The company takes on that liability for me. But if Western Union stops performing this legal responsibility by building financial automatons to which everyone has open access, both good and bad actors, then I am suddenly at risk of being a counterparty to criminals when I transfer $1000 to Western Union, and that could turn me into a money launderer. Money launderers can face up to 20 years in prison.

For users, a Western Union transfer suddenly becomes the financial equivalent of handling nuclear waste or operating a five-story crane. It's a task most people can't, and shouldn't, handle. Given the inherent legal risks, it's possible that the market will never widely adopt financial services delivered in the form of robots or golems or immutable smart contracts, preferring to stick with the traditional safe intermediaries who take on the burden of compliance. Or not?

Storm's lawyers may win this particular case. Their logic certainly seems sound, but I'm no lawyer. If so, there's a good argument to be made for lawmakers to consider modifying the definitions of words like "conducting" and "financial transactions" found under the money laundering statutes to prevent future efforts to use the Tornado Cash techno-legal trick. If  by merely swapping the technology used to deliver financial services a payments institution can suddenly avoid the law and offload legal responsibility onto users, that's probably a hole that needs closing.


* MoneyGram would still be able to financially profit from the combination of smart contracts and a front end, much like how Storm and Semenov did with Tornado Cash, by finding canny ways to use their control over the front end. According to the indictment, Storm and Semenov, along with others who had control over the front end, curated a list of "relayers"  third parties who provided users with bolstered privacy protection  and then extracted resources from relayers who wanted the privilege of getting on the list.

This profit motive can't help prove that Storm was engaged money laundering, says the defence, since there are many examples of criminals using "lawful tools for unlawful ends," and even though the tools' developers have "profited from that use" those developers were not punished.

Saturday, December 16, 2023

The long arm of OFAC and its reach into the Ethereum network

Coinbase, the U.S.'s largest crypto exchange, is openly processing Ethereum transactions involving Tornado Cash, a piece of blockchain infrastructure that was sanctioned by the U.S. government last year for providing mixing services to North Korea. 

Over the last two weeks Coinbase has validated 686 Tornado-linked transactions, according to Tornado Warnings. I've screenshotted the table below:

This table shows how many blocks each validator has proposed that includes a transaction that has interacted (either depositing or withdrawing) with Tornado Cash contracts in all denominations, or with TORN tokens. Source: Tornado Warnings by Toni Wahrstätter

This is awkward for everyone involved.

First, it's embarrassing for the agency that administers U.S. sanctions, the U.S. Treasury's Office of Foreign Assets Control, or OFAC. OFAC clearly states that U.S. based persons are not to transact with sanctioned entities unless they have a license. Yet here is America's largest crypto exchange interacting with a sanctioned entity, Tornado Cash, without a license.

OFAC can look away and pretend that nothing unusual is happening, which is pretty much what it has done so far. But since these financial interactions are clearly displayed on the blockchain, everyone can see the infraction occurring. Eventually, OFAC will have to confront the problem and make some tough decisions, a few of which may end up damaging companies like Coinbase and the Ethereum network.

The whole affair is also awkward for the crypto industry. After a 2022 in which much of the ecosystem went bankrupt or succumbed to fraud, crypto currently finds itself in the damaging crosshairs of the culture war and the pervasive threat of being banned. It is desperate for social license, yet here is crypto's leading company choosing to operate in contravention of one of the key pillars of U.S. national defence.

Meanwhile, Coinbase's main U.S. competitor, Kraken, has taken a very different approach to dealing with Tornado Cash. As the table above shows, Kraken has processed zero Tornado Cash transactions over the last two weeks compared to Coinbase's 686. These diverging approaches to handling sanctioned transactions only highlight the awkward nature of crypto's "compliance" with sanctions law.

Before I dive deeper, we need to fill in the basics. For folks who are confused about crypto, what follows is a quick explanation why Coinbase is interacting with Tornado Cash, whereas Kraken isn't.

What is validation?

To begin with, Coinbase and Kraken operate in many different businesses. Their most well known business line is to provide a trading venue where people can deposit funds in order to buy and sell crypto tokens.

I suspect that both companies are being very careful to ensure that their trading venues avoid any dealings with Tornado Cash. If someone were to try to deposit Tornado-linked funds to Coinbase's exchange, for instance, I'm sure Coinbase would quickly freeze those transactions, which is precisely what OFAC obliges it to do. Crypto trading venues have gotten in trouble before for dealing with sanctioned entities: last year Kraken was fined by OFAC for processing 826 transactions on behalf of Iranian individuals.

But the issue here isn't these companies' trading platforms. Coinbase's interactions with Tornado Cash are occurring in an adjacent line of business. Let's take a look at how Coinbase and Kraken's validation services business operate.

Say that Sunil lives in India and wants to make a transaction on the Ethereum network, perhaps a deposit of some ether to Tornado Cash. He begins by inputting the instructions into his Metamask wallet. This order gets broadcast to the Ethereum network for validation, along with a small fee, or tip. A validator is responsible for taking big batches of uncompleted transactions, one of which is Sunil's Tornado Cash deposit , and proposing them in the form of "blocks" to the Ethereum network for confirmation. As a reward, the validator collect the tips left by transactors.

The biggest validators are the ones that own large amounts of ether, the Ethereum network's native token. Since Kraken and Coinbase have millions of customers who hold ether on their platforms, they have become two of the most important providers of Ethereum validation services. Coinbase accounts for 14% of global validation while Kraken stands at 3%, according to the Ethereum Staking dashboard. So even though Sunil is not actually depositing any crypto to Coinbase's trading venue, he may end up interfacing with Coinbase via its block proposal and validation business.  

Validators can choose what transactions to include in their blocks. This explains the difference between the two exchanges. Whereas Kraken chooses to exclude transactions like Sunil's Tornado Cash deposit, Coinbase includes all transactions linked to Tornado Cash in the blocks that it proposes, in the process earning transaction fees linked to Tornado Cash.

To sum up, Coinbase operates its trading venue in a way that complies with OFAC regulations, but it doesn't run its validation service in the same manner, whereas Kraken does. Next, we need to fill in another important part of the story. What does OFAC do?

OFAC around and find out

For folks who don't know how U.S. sanctions work, a big part of OFAC's job is to blacklist foreign individuals and organizations who are deemed to undermine U.S. national security or foreign policy objectives. These blacklisted entities are known as SDNs, or specially designated nationals. U.S. citizens and companies cannot deal with SDNs without getting a license.

OFAC also administers comprehensive sanctions. These prevent U.S. individuals or businesses from interacting with entire nations, like Iran.

With each of the individuals or entities that it designates, OFAC discloses an array of useful information including the SDN's name, their aliases, address, nationality, passport, tax ID, place of birth, and/or date of birth. U.S. individuals and firms are supposed to take a risk-based approach to cross-checking this information against each of the counterparties they transact with so as to ensure that they aren't dealing with an SDN. They must also be aware of U.S. comprehensive sanctions so they don't accidentally interact with an entire class of sanctioned individuals, say all Iranians. Failure to comply can result in a monetary penalty or jail time.

Whereas Coinbase appears to have chosen to ignore OFAC's requirements when it comes to validation, Kraken hasn't, and has incorporated the SDN list into the internal logic of the validation services that it provides. But Kraken has only done so in a limited way, as I'll show below.

Five years ago OFAC began to include an SDN's known cryptocurrency addresses in its array of SDN data. To date, OFAC has published around 600 crypto addresses, including around 150 Ethereum addresses, of which a large chunk are related to Tornado Cash. Kraken is using this list of 150 addresses as the basis for excluding certain transaction from the blocks that it is proposing to the Ethereum network.

Data source: OFAC and Github

Among members of the crypto community, this sort of editing out of OFAC-listed addresses is sometimes described as creating "OFAC-compliant blocks." Hard core crypto ideologues believe that it compromises Ethereum's core values of openness and resistance to censorship.

While Kraken's approach may appear to be the compliant approach to proposing blocks, it's not. It's half-compliance, or compliance theatre. 

OFAC-compliant blocks as compliance theatre 

Right now, Kraken's block validation process merely weeds out transactions involving the 150 or so Ethereum wallets that OFAC has explicitly mentioned, which includes Tornado Cash addresses. But many of the SDNs linked to these 150 wallets have probably long since adapted by getting new wallets. Kraken isn't taking any steps to determine what these new wallets are, and is therefore almost certainly processing these SDN's transactions in its blocks. This would put it in violation of OFAC policy.

Of the 12,000 or so SDNs on OFAC's SDN list, most are not explicitly linked by OFAC to a specific Ethereum wallet. But that doesn't mean that these entities don't have such wallets. To be compliant, Kraken needs to scan the entire list of 12,000 SDNs and verify that none of them are being included in Kraken blocks. Again, it doesn't appear to be doing that.

Complying with OFAC isn't just about crosschecking the SDN list. Remember, OFAC has also levied comprehensive sanctions on nations such as Iran, which prohibit any U.S. entity from dealing with Iranians-in-general. Because Kraken limits its block editing to the 150 or so Ethereum addresses mentioned by OFAC, it is almost certainly letting Iranian transactions into the blocks that it is proposing. Which is ironic, since the very infraction that Kraken was punished for last year was allowing Iranians to use its trading platform. Apparently Kraken has one Iran policy for its trading venue, and another policy for its block proposal service.

Coinbase's decision to ignore OFAC altogether now makes more sense. Perhaps it's better to not comply at all and thereby retain the ability to claim the non-applicability of sanctions law to validation, than to comply insufficiently but in the process tacitly admit that OFAC has jurisdiction over validation. As part of this strategy, Coinbase may try to fall back on arguments that validation isn't a financial service, but qualifies as the "transmission of informational materials," which is exempt from sanctions law.

Having started down the path to compliance, the only way for Kraken's validation business to be even close to fully compliant with sanctions law is to adopt the very same exhaustive process that its own crypto trading venue abides by. That means painstakingly collecting and verifying the IDs of all potential transactors, cross-checking them against OFAC's requirements, and henceforth only proposing blocks that are made up of transactions sourced from its internal list of approved addresses.  

By adopting this complete approach to verifying transactions, Kraken would now be closer to compliance. As for OFAC, it would be relieved of its awkward situation.

There is no easy policy decision for OFAC

However, this approach has its drawbacks. A requirement that IDs be verified for the purposes of block inclusion would be expensive for Kraken to implement. I suspect that the company would react by ceasing to offer validation services. Even if Kraken and Coinbase were to roll out an OFAC-compliant know-your-customer (KYC) process for assembling blocks, most Ethereum transactions would probably flow to no-hassle offshore validators, which don't check ID because they are under no obligation to comply with OFAC.

So in the end, the very transactions that OFAC wants to discourage would end up happening anyway.

Compounding matters, by pushing validation away from U.S. soil, the U.S. national security apparatus would have destroyed a nascent "U.S. Ethereum nexus," one they might have otherwise levered as a tool for projecting U.S. power extraterritorially. If you're curious what this entails, consider how the New York correspondent banking nexus is currently harnessed by the state to exert U.S. policy overseas. A San Francisco-based Ethereum nexus would be the crypto-version of that. But not if it gets chased away.

To prevent validation from being performed everywhere but the U.S., the government could twin a requirement that domestic block validators implement KYC with a second requirement that all U.S. individuals and companies submit all Ethereum transactions to sanctions-compliant validators. This would pull U.S. Ethereum transactions back onto U.S. soil and into the laps of Coinbase and Kraken.

But this is a complicated chess game to play, and you can see why OFAC has been hesitating.  

On the other hand, OFAC can't prevaricate forever. Sure, crypto is still small. But OFAC is an agency with a democratic mandate to administer law, and law is clearly being broken. It cannot "not govern." To boot, sanctions are a matter of national security, which adds to the urgency of the issue.

One option would be for OFAC to offer an explicit sanctions law exception to U.S. blockchain validators in the form of a special license. But that invokes questions of technological neutrality and equal treatment before the law. Why should Coinbase and Kraken be allowed to maintain financial networks that admit sanctioned actors whereas other network operators, like Visa or American Express, do not enjoy this same exemption?

This isn't just about fairness. By providing a blockchain carve-out, OFAC may unintentionally spur the financial industry to switch over to blockchain-based validation, because that has become the least-regulated and therefore cheapest technological solution for deploying various financial services. At that point, OFAC will find itself with far less to govern, because a big chunk of finance now lies in the zone that OFAC has carved-out.

I don't envy the mandarins at OFAC. They've got a tough decision to make. In the meantime, Coinbase continues to process Tornado Cash transactions every hour.

Monday, November 20, 2023

Is it legal to mix cash in a jar?

Chris Blec asks the following question:

Source: Twitter

Chris's premise is that it is "not illegal" for him to get together with a bunch of strangers to mix cash. But that's not quite right. It can be legal. It can also be illegal. To determine which it is, we need to understand the motivations of Chris and the other ten strangers. Why are they getting together to mix in the first place? Alas, Chris doesn't mention this in his tweet.

There are certainly all sorts of perfectly legal albeit quirky reasons to mix cash. We could imagine that Chris and ten other strangers are waiting for the bus, and to decide who goes first, they all put a $20 note into a jar, remembering their respective serial number. After the notes have been mixed, one note is taken out and whoever it belongs to wins. The notes are then given back. Nothing wrong with that.

On the other hand, if Chris and the other 10 strangers are mixing their cash because they want to conceal the source, then they need to be careful. They've taken one step down the path to engaging in money laundering.

The U.S. has several money laundering statutes. Below is part of one of the most contravened ones: 

Source: LII

As you can see, one of the key triggers for a money laundering conviction is making transactions that are designed to "conceal or disguise."

Even if Chris and the other strangers' motivations for mixing is to conceal the origins of their cash, that's not necessarily illegal. Before they reach the point at which they can be accused of having crossed the line over to money laundering, at least one of the strangers needs to contribute banknotes to the jar that are the "proceeds of specified unlawful activity." For argument's sake, let's say that one of the strangers contributes cash that they've earned from contract killing. Chris and the other 10 strangers are now a step closer to a potential money laundering indictment. 

Only one last criteria is lacking. Chris and the other strangers must participate in a "knowing" way. They must be aware that the property involved is criminally-derived. The most obvious example would be if one of the 10 strangers were to loudly announce just prior to putting their notes in the jar that the notes come from contract killing, and everyone hears this yet still participates. 

At this point, the three triggers have been met. Chris and the other strangers have acted in 1) a knowing way 2) to conceal 3) the actual proceeds of unlawful activity.

The state of "knowing" needn't be established in such an explicit fashion as the criminal announcing it loudly. For instance, even if the criminal says nothing, but Chris and the other participants suspect the possibility that dirty money is entering the jar, but they don't do due diligence, then they could be found guilty of money laundering. To demonstrate that they aren't knowing participants, Chris and the other strangers may have to take proactive measures, say like checking ID.

So Chris is right to say that mixing cash in a jar can be legal, but he incorrectly omits to say that it can also be illegal.

Having fleshed out Chris's premise, what about his conclusion? Can the jar-of-cash thought experiment teach us about the legality of crypto mixing methods such as custodial mixers, Tornado Cash, or CoinJoin? I'll let the readers work that one out on their own.

Tuesday, September 26, 2023

Thoughts on Privacy Pools and the law


Here's my quick first-pass take on Privacy Pools, the heir apparent to privacy tool Tornado Cash. My comments are on the legal side, and less so the technical side, although the two aren't mutually exclusive. 

I've already written a bunch of times about Tornado Cash on this blog. Financial privacy is an important topic. 

The quick story is that after attracting a few billion in criminal funds, the Tornado Cash "stack" was sanctioned by the Office of Foreign Assets Control (or OFAC, the U.S.'s sanctioning authority). Privacy Pools is the Ethereum community's attempt to offer up an olive branch to OFAC. "We know you didn't like the last attempt, but we're going to make some changes. What do you think?"

I'm fascinated with the Privacy Pools idea, which will allow users to pick and choose who they associate with, thus excluding potentially bad actors. With fewer bad actors, OFAC may be less hasty to sanction the tool. 

While in theory that sounds great, here's my worry. Privacy Pools still relies on an old Tornado Cash feature: relayers. (For this observation, I'm indebted to Jon Reiter, who wrote a useful article on Privacy Pools for Blockhead.) It also relies on a new type of third-party: association set providers or ASPs.

Relayers and association set providers are a problem, as I'll show below. And the reason has nothing to do with OFAC or sanctions law, but a set of Federal statutes against racketeering found in Chapter 95 of the U.S. criminal code.

Let's assume that Privacy Pools gets deployed and begins to successfully screen out bad actors. That'll make it an even more tempting target for dirty money seeking redemption, bad actors devoting ever more resources to sneak into the mix. Inevitably, some of them will get through and when they do, the authorities will have to find an actor in the Privacy Pools stack to blame. I suspect they'll target relayers and ASPs.

Let's start with relayers. It's likely that the authorities can show that relayers are engaged in an activity defined under a key section of U.S. racketeering law, § 1960, as "money transmission." To avoid breaking this law, relayers will need to register with the Financial Crimes Enforcement Network, or FinCEN, the U.S. government's money laundering watchdog. Registration will obligate relayers to set up an iron-clad customer identification program, which involves collecting and verifying user ID cards, as well as filing Suspicious Activity Reports (SARs) with FinCEN, thus undoing much of Privacy Pools' stated benefits.

Let's back up a sec. Who are relayers?

Doing stuff on the Ethereum blockchain requires paying a small processing fee, and these fees are visible to everyone. When a privacy seeker withdraws from Privacy Pools or Tornado Cash, this fee payment effectively reveals who the user is. To solve this problem, both systems rely on a group of third-party individuals or entities relayers to pay this fee on behalf of users, thus restoring privacy, an effort they are remunerated for. But this sounds to me like "transferring funds on behalf of the public," which is Chapter 95's definition of money transmission, which leads me to suspect that relayers can be drawn into said law's licensing and registration requirements.*

Now, I'm just a maritime lawyer, so if I suspect that relayers are money transmitters, who really cares, right? But it's not just me who is making this claim. In its recent indictment of individuals involved in the Tornado Cash stack, the Department of Justice named relayers as engaging in money transmission.

Let's move on to ASPs. With Privacy Pools, users can build unique association sets that allow them to dissociate from potential bad actors. In a recent paper, the Privacy Pools designers suggest that in practice, professional intermediaries – association set providers will emerge to set up and curate these sets. Users will in turn subscribe to whatever ASP-provided sets meet their needs.

It's inevitable that ASPs will make mistakes and let bad actors into their sets, resulting in illicit money being laundered through Privacy Pools. In response, the authorities may try to follow the same script they used for relayers and accuse a faulty ASP of being an unlicensed money transmitter. But that may not stick; unlike a relayer, an ASP doesn't actually transfer any money. The Department of Justice has more up its sleeve than that, though. They can charge faulty ASPs with breaking other laws in Chapter 95, specifically the money laundering statutes §1956 and 1957.

To avoid a potential money laundering indictment, the intermediaries that curate association sets will have to make a good faith effort to exclude bad actors. Simple blacklists derived from chain tracing tools provided by companies like Chainalysis probably won't cut it. ASPs will have to undertake the same level of customer due diligence as banks and other financial institution. That means painstakingly collecting ID, doing background checks, and more. As before, that may unravel some of the purported anonymity of the Privacy Pools system.

The fact that relayers and ASPs may face FinCEN registration requirements and/or other anti-money laundering obligations isn't necessarily a death knell for projects like Privacy Pools, but it may pose some challenges.

1) Relayers and ASPs may try to sidestep U.S. law by operating outside the U.S. and, if possible, set up their operations to exclude Americans. That means cutting off a big chunk of the world from using the tool. With fewer users, the ability of Privacy Pools to obfuscate the tracks of all its non-U.S. users will be limited.

2) Some relayers and ASPs may choose to accept American customers in a compliant way. They'll verify their users, submit reports to FinCEN, and more. But at that point an American will probably be roughly indifferent between getting privacy from Privacy Pools or Coinbase, a centralized exchange that already complies with the requirements. Any U.S. user who becomes a customer of Coinbase can deposit ether and withdraw it to a new address, thus removing the outside world's ability to track the transaction, albeit at the expense of disclosing their personal information to Coinbase. Privacy Pools would afford this same level of privacy. It would offer U.S. users privacy from the broader community, but not from the employees of a relayer or ASP.**

If Privacy Pools is only providing Coinbase-levels of privacy to Americans, what's the point?

3) Lastly, perhaps the developers can figure out now  before Privacy Pools is even deployed  how to do away with relayers while still preserving privacy, thus entirely bypassing Federal racketeering law's definition of money transmission. Or maybe they can figure out how to design the relaying system such that it falls out of the definition. 

Whether that's even possible is a technical issue that goes waaay beyond my abilities.


* Why can't other elements of the Privacy Pools stack, including the core smart contracts and the people who develop them, be pulled into being defined as money transmitters? My assumption in this post is that if the smart contracts are: 1) non-upgradeable, that is, they are set in stone from the moment they are published, 2) the developer no longer has any association with the "stack" after publishing the contracts; 3) the system is not governed by a DAO; 4) there is no stream of profits thrown off by the system; and 4) there is no token (as was the case with Tornado Cash's TORN), then it is probably less likely that the smart contracts and/or their designers would fall under the definition of a money transmitter. But I could be wrong.

** Mind you, Coinbase and a fully-compliant Privacy Pools wouldn't be perfect substitutes. Whereas Coinbase takes ownership of one's ether, thus subjecting privacy seekers to the risk of Coinbase going bankrupt, Privacy Pools is just a smart contract, and not subject to that same risk. For a sub-group of privacy seekers who worry about Coinbase going bust, FinCEN-compliant relayers and ASPs may be strictly superior to Coinbase.