Cover photo

Tornado Cash: What Is It and How Does It Work?

Tornado Cash explained: how the leading crypto mixer works, why it’s used, and why U.S. Treasury sanctions were ultimately lifted.

Tornado Cash is a decentralized privacy protocol built on Ethereum that enables users to improve the privacy of their on-chain transactions. By breaking the direct link between sender and recipient addresses, Tornado Cash introduces an additional layer of financial privacy in public blockchain environments.

Originally launched in 2019, Tornado Cash has become one of the most widely recognized privacy tools in the Ethereum ecosystem. Its design, governance model, and regulatory history have made it a reference point in discussions around privacy, decentralization, and open-source infrastructure.

This article explains how Tornado Cash works, why privacy tools exist on public blockchains, and how the protocol is structured.


What Is Tornado Cash?

post image

Tornado Cash is a non-custodial crypto mixer that operates through immutable smart contracts. These contracts allow users to deposit and later withdraw crypto assets in a way that makes it difficult to link the two transactions on-chain.

The protocol works using fixed-denomination pools. Each pool accepts:

  • A single asset

  • A specific amount (for example, exactly 1 ETH or 10 ETH)

All deposits of the same size are combined into a shared pool, creating an anonymity set. Because all users interact with identical amounts, withdrawals cannot be easily associated with specific deposits.

Tornado Cash supports multiple assets and networks, with Ethereum accounting for the majority of activity.

Supported networks and assets include:

  • Ethereum: ETH, DAI, cDAI, USDC, USDT, WBTC

  • Arbitrum & Optimism: ETH

  • BNB Chain: BNB

  • Avalanche: AVAX

  • Polygon: MATIC

  • Gnosis Chain: xDAI

The core pool contracts are immutable. Once deployed, their logic cannot be changed, even by the original developers. Certain auxiliary components are governed through on-chain governance.

Official updates and protocol-related announcements are shared via the project’s X (Twitter) account:
👉 https://x.com/tornadocash_app


How Tornado Cash Works

post image

Using Tornado Cash involves two main steps: deposit and withdrawal.

Deposit

A user deposits a fixed amount of crypto into a Tornado Cash pool using the official or community-maintained frontend interface, such as
👉 https://tornadocash.bot

In return, the user receives a cryptographic note — a secret that represents ownership of the deposited funds.

Anonymity Set Growth

As more users deposit into the same pool, the anonymity set grows. A larger pool makes it increasingly difficult to associate withdrawals with earlier deposits.

Withdrawal

At any later time, the user can withdraw funds by presenting a zero-knowledge proof derived from the note. Withdrawals can be sent to any address, not necessarily the one that made the original deposit.

The protocol relies on zk-SNARKs (zero-knowledge proofs), allowing the smart contract to verify that a valid deposit exists without revealing which specific deposit is being withdrawn.

All transactions remain visible on-chain, but the cryptographic design prevents direct transaction linkage.


Why Privacy Tools Matter on Public Blockchains

Public blockchains are transparent by default. Every transaction, balance, and interaction is permanently visible. While transparency is a core strength of blockchain systems, it can also expose sensitive financial relationships.

Privacy tools like Tornado Cash are commonly used for:

  • Reducing address-level traceability

  • Funding new wallets without revealing historical balances

  • Preserving transactional privacy in open financial systems

  • Managing operational security for teams and developers

In this sense, Tornado Cash functions as privacy infrastructure rather than an application with predefined use cases.


In August 2022, Tornado Cash smart contracts were added to the U.S. Treasury’s OFAC sanctions list. This action sparked global debate around whether decentralized, open-source smart contracts could be sanctioned in the same way as centralized entities.

In November 2024, a U.S. federal court ruled that sanctioning autonomous smart contracts exceeded OFAC’s statutory authority. Following this decision, the sanctions were officially lifted in March 2025.

The ruling clarified an important legal distinction between software code and identifiable operators, and it has since been referenced in broader discussions around decentralized infrastructure and regulatory boundaries.


Governance and the TORN Token

post image

Tornado Cash is governed by a decentralized autonomous organization (DAO). Governance decisions are made using the TORN token.

Key facts about TORN:

  • Total supply: 10,000,000

  • Governance-based voting and proposals

  • Participation requires locking TORN tokens

Governance proposals can include:

  • Adding or adjusting pools

  • Modifying governance-controlled parameters

  • Managing treasury-related decisions

The governance system operates independently of the immutable core contracts, maintaining a clear separation between protocol logic and administrative coordination.


On-Chain Presence

post image

Tornado Cash has operated continuously on-chain since its launch. Activity levels have varied over time in response to broader market conditions and regulatory developments, but the protocol itself has remained accessible through its smart contracts.

Community discussion, governance references, and updates continue to be shared publicly through its official communication channels, including
👉 https://x.com/tornadocash_app


Conclusion

Tornado Cash is one of the most influential privacy protocols in the crypto ecosystem. Its use of zero-knowledge cryptography, immutable smart contracts, and decentralized governance has shaped how privacy is implemented on public blockchains.

As regulatory frameworks evolve and privacy discussions mature, Tornado Cash remains a central example of how open-source infrastructure can operate independently of centralized control — and why privacy remains a foundational topic in blockchain design.