Landmark prosecutions involving Bitcoin Fog and Tornado Cash demonstrate when cryptocurrency privacy infrastructure can become unlawful money transmission or criminal laundering, while sharply divided verdicts reveal that software development, autonomous code, operational control, criminal knowledge, and intentional assistance remain legally distinct questions.
WASHINGTON — Cryptocurrency mixers promise financial privacy by separating identifiable blockchain deposits from later withdrawals, but federal prosecutions involving Bitcoin Fog and Tornado Cash demonstrate that obscuring transaction histories can produce serious criminal exposure when operators knowingly process illegal proceeds or maintain unlicensed financial services.
The two cases are frequently described together, although their outcomes remain fundamentally different because Bitcoin Fog operator Roman Sterlingov was convicted of money laundering offenses, whereas a Manhattan jury convicted Tornado Cash co-founder Roman Storm only of conspiring to operate an unlicensed money-transmitting business.
Jurors considering Storm’s prosecution could not reach unanimous verdicts concerning conspiracy to commit money laundering and conspiracy to violate United States sanctions, leaving those significant accusations unresolved while prosecutors sought another trial and Storm pursued acquittal from his remaining conviction.
That distinction matters because cryptocurrency privacy is not automatically money laundering, software capable of concealment is not inherently criminal, and prosecutors must ordinarily establish the required knowledge, agreement, conduct, control, or intent surrounding the defendant rather than relying exclusively upon the technology’s existence.
Cryptocurrency Mixers Break Visible Transaction Connections
Public blockchains permanently record transfers between cryptocurrency addresses, allowing investigators, exchanges, victims, compliance teams, journalists, and ordinary users to observe how digital assets move even when the legal identities controlling particular wallets remain initially unknown.
A mixer attempts to weaken that transparency by combining deposits from numerous participants, separating incoming cryptocurrency from later withdrawals, standardizing transaction amounts, delaying transfers, introducing intermediary addresses, or using cryptographic proofs that conceal which depositor received a particular payment.
Customers can possess legitimate reasons for using these systems, including protecting salaries, commercial payments, charitable donations, personal savings, political activity, investment holdings, or account balances from competitors, criminals, hostile governments, abusive partners, and indiscriminate public surveillance.
However, the same separation that protects lawful users can help ransomware operators, darknet vendors, hackers, fraud organizations, sanctions evaders, corrupt officials, and thieves convert publicly traceable proceeds into assets whose immediate criminal origins become considerably more difficult to identify.
Privacy Technology Does Not Automatically Become Laundering
Money laundering generally involves financial transactions intended to conceal or disguise the nature, location, source, ownership, or control of proceeds derived from specified unlawful activity, although exact federal charges and evidentiary requirements depend upon the particular statute prosecutors select.
Merely writing privacy software does not necessarily establish such an offense because investigators may still need to prove criminal knowledge, intentional participation, an agreement with others, involvement with unlawful proceeds, operational responsibility, or another factual connection satisfying every statutory element.
The legal analysis becomes more complicated when software operates through autonomous smart contracts that developers cannot modify or stop, because traditional financial regulations frequently assume that an identifiable intermediary accepts funds, exercises control, maintains customer relationships, and possesses practical authority over transactions.
Bitcoin Fog and Tornado Cash therefore became important legal tests not simply because both obscured blockchain histories, but because their technical structures, operational models, developer involvement, revenue arrangements, customer relationships, compliance controls, and alleged criminal knowledge differed substantially.
Bitcoin Fog Operated for Approximately a Decade
Bitcoin Fog began operating during 2011 and became one of the longest-running Bitcoin mixing services associated with darknet commerce, processing more than 1.2 million bitcoins before authorities arrested Russian-Swedish citizen Roman Sterlingov during April 2021.
Those bitcoins were valued at approximately $400 million when the transactions occurred, although their later market value became dramatically higher, illustrating why historical cryptocurrency cases should distinguish contemporaneous transaction values from modern valuations that can produce misleadingly enormous totals.
Prosecutors maintained that substantial portions of Bitcoin Fog’s activity originated from darknet marketplaces and criminal operations involving narcotics trafficking, computer fraud, identity theft, and child sexual abuse material, rather than merely ordinary users seeking confidentiality for lawful financial activity.
Bitcoin Fog charged fees for concealing the origin and destination of customers’ cryptocurrency, creating an ongoing commercial service whose profitability depended upon processing transactions designed to become harder for investigators, counterparties, exchanges, and other observers to reconstruct.
Blockchain Forensics Identified Sterlingov
Investigators did not discover a conventional registration document plainly naming Sterlingov as Bitcoin Fog’s operator, requiring them instead to reconstruct historical blockchain transactions, cryptocurrency purchases, exchange records, internet activity, payment relationships, and other evidence connecting him with the service.
Prosecutors argued that Sterlingov funded early Bitcoin Fog expenses through a complicated sequence beginning with bitcoins purchased through an account registered under his identity, followed by several transactions and exchanges that ultimately paid for infrastructure associated with the mixer.
Blockchain analysis relied upon clustering, transaction timing, address relationships, exchange attribution, payment patterns, historical records, and behavioral evidence, demonstrating how investigators can combine probabilistic technical conclusions with conventional documentation rather than treating forensic software as an independent witness.
Sterlingov disputed the government’s attribution and challenged aspects of the blockchain methodology, making the prosecution a closely watched examination of whether jurors would accept complex digital tracing performed across transactions that had occurred more than a decade earlier.
The Bitcoin Fog Jury Returned Sweeping Convictions
Following a month-long federal trial during March 2024, jurors convicted Sterlingov of conspiracy to commit money laundering, money laundering, operating an unlicensed money-transmitting business, and violating the District of Columbia’s money-transmission licensing requirements.
The laundering conviction established that operating a cryptocurrency mixer can create liability beyond technical licensing violations when prosecutors prove that the defendant knowingly participated in transactions designed to conceal criminal proceeds or property represented as originating from illegal activity.
Federal investigators also conducted controlled transactions involving cryptocurrency presented as proceeds from narcotics activity, supplying direct evidence concerning how the service responded when customers communicated an expressly criminal purpose for the funds they wanted obscured.
The verdict rejected the proposition that pseudonymous customers, layered transactions, intermediary exchanges, and a long passage of time necessarily prevent prosecutors from identifying an operator or proving that a mixing business knowingly facilitated illegal financial concealment.
Sterlingov Received More Than Twelve Years
During November 2024, United States District Judge Randolph Moss sentenced Sterlingov to twelve years and six months in federal prison, reflecting the scale, duration, criminal associations, financial operation, and laundering functions attributed to Bitcoin Fog.
The court also imposed forfeiture involving cryptocurrency and monetary assets connected with the operation, demonstrating that mixer prosecutions can threaten not only personal liberty but also digital holdings accumulated from transaction fees and service-related financial activity.
The Justice Department’s account of the Bitcoin Fog sentencing described a service that provided criminals with technological concealment while processing cryptocurrency associated with darknet markets, illegal narcotics, identity theft, computer crime, and exploitation offenses.
Sterlingov’s punishment does not establish a universal sentence for mixer operators because future outcomes depend upon transaction values, criminal knowledge, operational authority, customer communications, predicate offenses, personal history, acceptance of responsibility, obstruction, forfeiture, and applicable sentencing calculations.
Bitcoin Fog Resembled a Managed Financial Service
Bitcoin Fog’s centralized characteristics became important because customers transferred cryptocurrency into infrastructure associated with an identifiable service, paid fees, and relied upon the operator’s continuing activity to receive bitcoins disconnected as effectively as possible from their original deposits.
A centrally managed service can implement registration, transaction monitoring, suspicious-activity procedures, sanctions screening, recordkeeping, law-enforcement responses, and customer restrictions, making deliberate refusal to adopt controls more significant than similar omissions within code that nobody can alter.
Prosecutors could consequently describe Bitcoin Fog as an operating business rather than merely a published software experiment, connecting Sterlingov with financial activity that allegedly remained profitable because illegal users valued the service’s ability to frustrate blockchain tracing.
The case warned custodial or administratively controlled privacy providers that using cryptocurrency instead of conventional money does not automatically remove licensing, anti-money-laundering, sanctions, reporting, or criminal obligations that may apply when a business accepts and transmits value.
Tornado Cash Presented a Different Technical Model
Tornado Cash launched during 2019 as an Ethereum-based privacy protocol allowing users to deposit standardized cryptocurrency amounts into smart contracts and withdraw equivalent value toward different addresses by presenting cryptographic proofs without publicly identifying the corresponding deposit.
Its core smart contracts eventually became immutable, meaning their deployed code could continue receiving and processing transactions without founders possessing a traditional administrator capable of changing the underlying program, rejecting particular customers, reversing transfers, or shutting down the principal pools.
That architecture created a difficult legal question because an autonomous protocol can facilitate value movement without exercising human discretion over individual transactions, while related developers may continue managing websites, interfaces, governance systems, relayers, promotional activity, or commercial components surrounding the immutable code.
Supporters portrayed Tornado Cash as general-purpose privacy infrastructure, whereas prosecutors argued that its founders operated and profited from an integrated service while knowing that hackers, fraudsters, and sanctioned North Korean cybercriminals used it to conceal enormous amounts of stolen cryptocurrency.
The Lazarus Group Intensified Government Scrutiny
North Korea’s Lazarus Group used Tornado Cash after major cryptocurrency thefts, including the Ronin Network attack associated with hundreds of millions of dollars, creating national-security concerns extending far beyond ordinary questions involving customer privacy and financial licensing.
American authorities have repeatedly accused North Korean cyber units of stealing cryptocurrency to generate revenue for the country’s weapons programs, making services that conceal those proceeds a priority for sanctions enforcement, blockchain tracing, exchange intervention, and international asset recovery.
Prosecutors alleged that Tornado Cash’s founders knew the protocol was processing criminal proceeds, received complaints from hacking victims, discussed technical responses, and continued maintaining profitable components despite understanding that illicit customers relied upon the platform’s privacy features.
The defense countered that Storm could not control immutable smart contracts, did not agree with individual criminals, created software possessing extensive lawful uses, and should not become responsible for autonomous transactions initiated without his participation, permission, custody, or practical intervention.
Treasury Sanctions Encountered an Appellate Reversal
The Treasury Department’s Office of Foreign Assets Control Sanctioned Tornado Cash during 2022, identifying smart-contract addresses and alleging that the service had processed billions of dollars in cryptocurrency, including substantial assets connected with Lazarus and other cybercriminal organizations.
Six Tornado Cash users challenged those restrictions, arguing that immutable smart contracts were autonomous software rather than property belonging to a sanctionable person or entity, creating an unprecedented dispute concerning how decades-old emergency economic legislation applies toward decentralized blockchain infrastructure.
During November 2024, the United States Court of Appeals for the Fifth Circuit concluded that immutable Tornado Cash smart contracts did not constitute sanctionable property under the relevant statute because they could not be owned, controlled, modified, excluded, or removed by any identifiable party.
A Reuters report concerning the appellate ruling and its consequences explained that the court considered Treasury’s concerns legitimate but determined that expanding sanctions authority toward autonomous software required congressional action rather than administrative interpretation.
Treasury Removed Tornado Cash from Its Sanctions List
During March 2025, Treasury removed Tornado Cash from the sanctions list after reviewing the developing legal and policy environment, while emphasizing that North Korea’s malicious cyber operations and use of digital assets remained substantial threats toward American national security.
The delisting did not declare every Tornado Cash transaction lawful, absolve individual sanctioned actors, reverse pending criminal allegations, or prevent prosecutors from pursuing defendants whose personal conduct independently satisfied money-laundering, sanctions, conspiracy, or unlicensed-transmission statutes.
Sanctions litigation and criminal prosecution involve different legal questions because one proceeding examined whether Treasury could blacklist autonomous smart contracts as property, whereas Storm’s prosecution examined whether he personally joined conspiracies and operated an unlawful money-transmission enterprise.
Consequently, commentators who describe the appellate ruling as complete legalization of every mixer misunderstand its limited significance, just as those describing the ruling as irrelevant overlook its important recognition that immutable software does not fit comfortably within traditional property-based sanctions authority.
Roman Storm Faced Three Federal Conspiracy Charges
Federal prosecutors charged Storm with conspiracy to commit money laundering, conspiracy to violate the International Emergency Economic Powers Act, and conspiracy to operate an unlicensed money-transmitting business, exposing him initially to decades of potential imprisonment if convicted across every count.
The government argued that Storm and his colleagues developed Tornado Cash, promoted its anonymity, maintained important infrastructure, collected substantial financial benefits, and knowingly enabled criminal organizations to conceal cryptocurrency derived from hacks, fraud schemes, and sanctions violations.
Storm’s attorneys emphasized that software publication and protocol development cannot become criminal merely because unaffiliated users later commit offenses, particularly when developers lack custody over deposited assets and cannot prevent autonomous contracts from processing requested withdrawals.
The resulting trial became a broader referendum upon developer liability, financial privacy, decentralized infrastructure, and whether conventional money-transmission laws can apply when users interact directly with blockchain code rather than depositing funds with a traditional intermediary.
The Tornado Cash Verdict Was Decisively Mixed
After a four-week trial during 2025, Manhattan jurors convicted Storm of conspiring to operate an unlicensed money-transmitting business, concluding that his participation within Tornado Cash’s broader operation satisfied the requirements of that particular federal offense.
However, the same jury failed to reach unanimous verdicts concerning conspiracy to commit money laundering and conspiracy to violate sanctions, producing a partial mistrial rather than convictions upon the two allegations carrying the most severe potential punishments.
This outcome means it would be inaccurate to claim that Storm was convicted of laundering money through Tornado Cash, although prosecutors remained entitled to seek another trial upon unresolved counts unless judicial rulings or prosecutorial decisions ended those allegations.
As of July 22, 2026, Storm continued challenging his money-transmission conviction while the unresolved laundering and sanctions counts remained subjects of continuing litigation, preventing responsible reporting from presenting accusations, requested retrials, or deadlocked deliberations as final convictions.
Money Transmission Became the Successful Theory
The government’s successful count alleged that Storm conspired to operate a business transferring funds without complying with federal registration requirements, a theory that did not require jurors to agree unanimously that he joined a specific laundering conspiracy involving criminal proceeds.
That distinction shows why a privacy provider can face criminal exposure even when prosecutors cannot prove money laundering, since licensing and registration statutes govern how financial services operate rather than requiring proof that every transmitted asset originated from crime.
The controversial question involved whether Tornado Cash transmitted funds despite lacking traditional custody, because users deposited cryptocurrency into smart contracts and later withdrew assets through cryptographic instructions instead of handing money directly toward Storm or his colleagues.
Storm’s conviction therefore created concern among open-source developers who feared that maintaining interfaces, promoting autonomous protocols, operating relayers, or receiving governance-related benefits could expose programmers to financial-service obligations traditionally applied toward custodial intermediaries.
Deadlock Did Not Establish Innocence or Guilt
A deadlocked jury means jurors could not agree unanimously upon a verdict after deliberation, leaving the relevant charge unresolved without establishing either that prosecutors proved guilt or that the defendant received a final acquittal.
Prosecutors can sometimes retry unresolved counts because the constitutional protection against double jeopardy generally does not prohibit another trial following a mistrial caused by genuine jury deadlock, although procedural circumstances and later judicial decisions can affect that authority.
Defendants may challenge the legal sufficiency of evidence, seek judgments of acquittal, oppose retrial, contest jury instructions, appeal resulting convictions, and argue that the government’s statutory interpretation improperly transforms neutral technology development into participation within customers’ crimes.
Reporting should therefore distinguish Sterlingov’s completed laundering convictions from Storm’s unresolved laundering allegation, because combining them under one simplified conclusion would erase the most important legal difference between the landmark mixer cases.
Knowledge Remains Central to Laundering Liability
A tool’s availability to criminals does not alone prove its developer joined a laundering conspiracy, because general-purpose technologies ranging from encrypted communications to automobiles, cloud services, cash, and privacy software can support both legitimate and illegal behavior.
Prosecutors strengthen their position when evidence shows that operators knowingly accepted criminal proceeds, responded to explicit laundering requests, maintained customer relationships, advertised concealment toward offenders, altered systems to preserve illegal business, or shared profits from identifiable unlawful transactions.
Defendants possess stronger arguments when code operates autonomously, developers lack custody, services have substantial lawful uses, operators cannot identify users, and no evidence demonstrates an agreement with criminals or intentional participation within their illegal financial objectives.
The boundary remains fact-dependent rather than technological, requiring courts and juries to examine what the accused controlled, understood, promised, maintained, profited from, concealed, ignored, or intentionally contributed toward the movement of particular criminal proceeds.
Blockchain Mixing Does Not Erase Transaction Evidence
Mixers can weaken straightforward tracing, but they do not delete deposits, withdrawals, timing information, standardized amounts, exchange records, wallet histories, internet activity, service payments, seized devices, communications, or operational evidence preserved outside the blockchain.
Investigators can combine probabilistic transaction analysis with subpoenas, customer records, cooperating witnesses, controlled transactions, domain information, server evidence, search histories, bank accounts, travel records, and cryptocurrency exchange identification to construct a broader evidentiary narrative.
Modern forensic tools can identify mixer interactions, trace pre-deposit activity, evaluate post-withdrawal spending, compare transaction timing, follow address clusters, and recognize when assets later reach centralized platforms capable of connecting cryptocurrency with verified customers.
Accordingly, users should never interpret successful mixing as proof that cryptocurrency became untraceable, because new analytical methods or attribution evidence can reveal relationships years after an apparently anonymous transfer entered the permanent blockchain record.
Lawful Users Still Possess Legitimate Privacy Interests
Public blockchains can expose salaries, donations, purchases, business revenues, investment balances, supplier relationships, household spending, and personal security information to anyone who connects one known address with an identifiable individual or organization.
Victims holding substantial cryptocurrency face extortion, kidnapping, home invasion, impersonation, targeted phishing, and physical violence, making transactional privacy a genuine security requirement rather than a concern limited exclusively to criminals hiding unlawful proceeds.
Businesses may also need confidentiality surrounding payroll, treasury reserves, supplier pricing, acquisitions, charitable activity, and commercial relationships, particularly when transparent wallet balances provide competitors with information unavailable through ordinary private banking systems.
The mixer prosecutions therefore should not be interpreted as judicial declarations that privacy itself is suspicious, because their central questions concerned operation, control, licensing, knowledge, unlawful proceeds, sanctions, intentional assistance, and relationships between defendants and criminal activity.
Compliance Depends Upon Practical Control
A service capable of identifying customers, rejecting deposits, freezing withdrawals, changing transaction rules, maintaining custody, responding to complaints, and controlling operational infrastructure will ordinarily face different compliance expectations from immutable software lacking administrators or exclusion mechanisms.
Developers and service providers should document which components they control, how revenue is earned, whether customer assets enter custody, who maintains interfaces, how relayers operate, which parties can change code, and what procedures address criminal use.
Descriptions such as decentralized, autonomous, open-source, or noncustodial should correspond with actual technical and operational conditions because prosecutors, regulators, courts, and juries will examine practical authority rather than relying entirely upon promotional terminology chosen by developers.
A supposedly autonomous protocol may still depend upon centrally controlled websites, developer-operated relayers, governance keys, fee collectors, communication channels, front-end infrastructure, or upgrade mechanisms that create legal responsibilities surrounding otherwise immutable blockchain functions.
International Users Face Overlapping Legal Systems
Cryptocurrency mixing transactions can involve developers, servers, users, exchanges, validators, victims, wallet addresses, and criminal proceeds distributed across numerous jurisdictions, allowing several countries to assert regulatory, criminal, tax, sanctions, or asset-forfeiture authority simultaneously.
Conduct permitted or unregulated within one country may remain prohibited elsewhere when a service accepts customers internationally, processes assets connected with American victims, interacts with sanctioned persons, or uses financial infrastructure subject to United States jurisdiction.
Responsible international asset protection and relocation planning should preserve truthful beneficial ownership, lawful taxation, reliable source-of-funds evidence, sanctions compliance, and complete cryptocurrency records rather than treating mixers as substitutes for defensible cross-border financial structures.
Clients transferring digital assets between countries should document wallet ownership, acquisition history, tax treatment, counterparties, transaction purposes, exchange accounts, and institutional disclosures so that legitimate privacy does not create unexplained gaps during banking or regulatory review.
Privacy Must Preserve Institutional Verifiability
Lawful privacy limits unnecessary public exposure while allowing tax authorities, banks, courts, trustees, auditors, immigration agencies, and other authorized institutions to verify ownership, control, taxation, transaction purpose, and the legitimate origin of substantial assets.
Responsible privacy and international risk-management services should reduce exposure to criminals and commercial data collectors while maintaining coherent records capable of surviving enhanced due diligence, source-of-wealth examination, litigation, succession, and regulatory scrutiny.
Using a mixer to protect a publicly visible wallet from stalkers differs fundamentally from using the same technology to conceal ransomware payments, stolen cryptocurrency, fraudulent proceeds, sanctioned assets, tax evasion, corruption, or transactions performed for criminal customers.
Individuals requiring blockchain privacy should obtain qualified legal advice before using concealment infrastructure, particularly when transactions involve large values, foreign jurisdictions, sanctioned regions, disputed assets, criminal counterparties, regulatory investigations, or professional responsibilities within regulated industries.
The Mixer Rulings Establish a Nuanced Warning
Bitcoin Fog established that a managed cryptocurrency mixing service can support money-laundering convictions, lengthy imprisonment, and substantial forfeiture when prosecutors connect its operator with illegal proceeds, criminal customers, unlicensed transmission, and deliberate transaction concealment.
Tornado Cash established a narrower and more contested result because Storm was convicted of conspiring to operate an unlicensed money-transmitting business, while jurors deadlocked upon the separate laundering and sanctions allegations that generated the prosecution’s most consequential claims.
The Fifth Circuit’s sanctions ruling added another distinction by concluding that immutable smart contracts were not sanctionable property, without deciding that individual developers, operators, relayers, users, hackers, or criminal organizations could never face liability for their personal conduct.
Together, the cases reject two simplistic conclusions: cryptocurrency privacy is neither automatically criminal nor automatically protected, because legal responsibility turns upon architecture, control, custody, knowledge, licensing, criminal intent, operational participation, and the purpose surrounding particular transactions.
For privacy developers, the enduring challenge involves creating technology that protects legitimate users without maintaining profitable systems knowingly tailored toward criminal proceeds, while documenting technical limitations and responding responsibly wherever meaningful operational control remains available.
For cryptocurrency holders, the enduring warning remains equally direct: a mixer may complicate the public trail, but it cannot transform unlawful proceeds into legitimate wealth, eliminate licensing duties, erase historical evidence, or guarantee that investigators will never identify the people behind concealed transactions.


