{"id":14155,"date":"2026-09-02T14:36:00","date_gmt":"2026-09-02T14:36:00","guid":{"rendered":"https:\/\/blogs.culturamas.es\/eldelorean\/2026\/09\/02\/tornado-cash-cryptocurrency-mixing-service-to0209c\/"},"modified":"2026-09-02T14:36:00","modified_gmt":"2026-09-02T14:36:00","slug":"tornado-cash-cryptocurrency-mixing-service-to0209c","status":"publish","type":"post","link":"https:\/\/blogs.culturamas.es\/eldelorean\/2026\/09\/02\/tornado-cash-cryptocurrency-mixing-service-to0209c\/","title":{"rendered":"Tornado Cash Cryptocurrency Mixing Service"},"content":{"rendered":"<h1>Tornado Cash Cryptocurrency Mixing Service Explained<\/h1>\n<p>Tornado Cash cryptocurrency mixing service operates as a decentralized protocol on Ethereum that breaks the on-chain link between deposit and withdrawal addresses through zero-knowledge proofs. The platform processes transactions through smart contracts that pool deposits of identical amounts (0.1, 1, 10, or 100 ETH) and issues cryptographic notes as withdrawal credentials. Users must wait for sufficient anonymity set formation before withdrawing to a different address, with recommended delays of 24-72 hours for optimal privacy protection.<\/p>\n<p>The protocol&#8217;s core innovation lies in its implementation of zk-SNARKs (Zero-Knowledge Succinct Non-Interactive Arguments of Knowledge), which prove ownership of deposited funds without revealing which specific deposit corresponds to a withdrawal. Each deposit generates a unique commitment hash stored in a Merkle tree structure within the smart contract. When withdrawing, users submit a zero-knowledge proof demonstrating they possess a valid note without exposing which leaf in the tree represents their deposit.<\/p>\n<p>Statistical analysis reveals that anonymity sets grow proportionally to the number of deposits in each pool denomination. A pool containing 100 deposits provides approximately 6.64 bits of entropy, while 1,000 deposits yield 9.97 bits. The 1 ETH pool historically maintains the highest liquidity with average daily volumes between 500-2,000 ETH, making it the most effective denomination for privacy preservation. Withdrawal timing patterns show that 73% of users withdraw within 7 days of deposit, potentially reducing their anonymity set by correlating temporal patterns.<\/p>\n<h2>How Tornado Cash Uses Zero-Knowledge Proofs to Break Transaction Links<\/h2>\n<p>Zero-knowledge proofs enable users to prove they deposited funds into the protocol&#8217;s pool without revealing which specific deposit belongs to them. The system generates a cryptographic commitment when you deposit, stores it in a Merkle tree on-chain, and later allows withdrawal using a nullifier that prevents double-spending while maintaining complete anonymity between deposit and withdrawal addresses.<\/p>\n<p>The protocol implements zk-SNARKs (Zero-Knowledge Succinct Non-Interactive Arguments of Knowledge) through the Groth16 proving system. When depositing ETH or ERC-20 tokens, the smart contract generates a commitment hash from two random values: a nullifier and a secret. This commitment gets added to the Merkle tree, creating a cryptographic receipt without storing any connection to your wallet address.<\/p>\n<p>Breaking the on-chain link happens through a clever separation of knowledge. Your browser generates the proof locally using the secret and nullifier, demonstrating you own a valid deposit without revealing which one. The proof size remains constant at approximately 200 bytes regardless of the anonymity set size, making verification gas-efficient at around 300,000 gas units.<\/p>\n<p>The Merkle tree structure allows the protocol to maintain an ever-growing anonymity set. Each tree can store up to 2^20 (over one million) deposits, with older trees becoming immutable after filling. Withdrawal proofs reference a specific Merkle root, proving membership in the deposit set without pointing to any particular leaf. This design means your anonymity grows stronger as more users join the pool.<\/p>\n<p>Circuit constraints enforce the mathematical relationships between public and private inputs. The withdrawal circuit verifies that the nullifier hash matches the commitment, the Merkle path is valid, and the recipient address corresponds to the proof. These constraints compile into roughly 28,000 R1CS constraints, requiring about 2 seconds to generate a proof on modern hardware.<\/p>\n<p>The nullifier mechanism prevents double-spending while preserving privacy. Each nullifier can only be used once &#8211; the smart contract maintains a mapping of spent nullifiers and rejects any transaction attempting to reuse one. Since nullifiers are deterministically derived from the secret but computationally unlinkable to the commitment, observers cannot connect withdrawals to deposits.<\/p>\n<p>Trusted setup ceremonies established the protocol&#8217;s proving and verification keys. The Powers of Tau ceremony involved over 1,000 participants, with the final circuit-specific setup completed in 2019. Security depends on at least one honest participant destroying their toxic waste &#8211; the random values used during setup. The verification key hash 0x1b2c2b3b remains embedded in the smart contract code.<\/p>\n<p>Relayers add an extra privacy layer by submitting withdrawal transactions on behalf of users. Without relayers, withdrawing to a fresh address would require ETH for gas, creating a traceable funding transaction. The protocol includes a fee mechanism allowing relayers to receive compensation directly from the withdrawn amount, maintaining the privacy guarantee while incentivizing a competitive relayer market where fees typically range from 0.1% to 0.5% of the withdrawal amount.<\/p>\n<h2>Step-by-Step Process of Depositing and Withdrawing Funds Through Tornado Cash<\/h2>\n<p>Connect your wallet to the protocol&#8217;s interface using MetaMask or WalletConnect, ensuring you have sufficient ETH for gas fees before initiating any transaction. The deposit process requires selecting your desired denomination (0.1, 1, 10, or 100 ETH), generating a deposit note, and sending funds to the smart contract address.<\/p>\n<p>Each deposit generates a unique cryptographic note containing two components: a secret and a nullifier hash. This note serves as your only proof of ownership and must be stored securely offline, preferably written on paper or saved in multiple encrypted locations. The protocol does not store this information, and losing the note means permanent loss of access to your deposited funds. The smart contract processes your deposit by adding it to a Merkle tree data structure, where it becomes indistinguishable from other deposits of the same denomination.<\/p>\n<p>Wait for sufficient anonymity set accumulation before withdrawing, typically 24-72 hours minimum. The longer you wait, the larger the pool of potential depositors becomes, strengthening privacy guarantees.<\/p>\n<p>Withdrawal requires pasting your deposit note into the interface, selecting a recipient address different from your deposit address, and optionally using a relayer to pay gas fees. Relayers charge approximately 0.3-1% of the withdrawal amount but eliminate the need for ETH in your receiving wallet, preventing any on-chain connection between addresses. The protocol verifies your zero-knowledge proof, confirming you possess a valid deposit without revealing which specific deposit belongs to you.<\/p>\n<p>The verification process employs zk-SNARKs technology, allowing the smart contract to validate your claim mathematically without accessing the underlying data. This cryptographic proof demonstrates knowledge of a secret corresponding to one unspent commitment in the Merkle tree.<\/p>\n<p>Monitor transaction confirmations carefully, as network congestion can delay processing times from minutes to several hours. Standard transactions require 12 confirmations on Ethereum mainnet, though some users wait for 30+ confirmations for large amounts.<\/p>\n<p>Advanced users can enhance privacy by splitting withdrawals across multiple addresses, using different relayers for each transaction, and varying withdrawal timing patterns. The protocol supports partial withdrawals through change outputs, enabling you to withdraw portions while maintaining anonymity for the remainder. Consider using fresh addresses generated specifically for receiving mixed funds, and avoid combining these outputs with doxxed addresses in future transactions.<\/p>\n<h2>Supported Blockchains and Token Types Available for Mixing<\/h2>\n<p>Privacy protocols currently operate on Ethereum mainnet, Binance Smart Chain, Polygon, Optimism, Arbitrum, Gnosis Chain, and Avalanche C-Chain. Each network supports different token standards and denomination pools, with Ethereum offering the most extensive selection including ETH pools of 0.1, 1, 10, and 100 ETH denominations.<\/p>\n<p>Ethereum mainnet remains the primary network for privacy operations, supporting native ETH pools alongside ERC-20 tokens like DAI, cDAI, USDC, USDT, and WBTC. Pool sizes vary by asset type: stablecoin pools operate with fixed denominations of 100, 1,000, 10,000, and 100,000 units. The 10,000 USDC pool typically maintains the highest anonymity set with over 50,000 deposits historically recorded. Smart contract addresses differ for each denomination and token type, requiring users to interact with the specific contract matching their desired amount.<\/p>\n<p>Binance Smart Chain implementation focuses on BNB pools with 0.1, 1, 10, and 100 BNB denominations. The protocol uses identical zero-knowledge proof mechanisms but operates through BSC-specific smart contracts deployed at different addresses from their Ethereum counterparts. Transaction fees on BSC average $0.50-$2.00 compared to Ethereum&#8217;s $20-$100 during high congestion periods, making smaller denomination pools more economically viable.<\/p>\n<p>Layer 2 solutions like Polygon, Optimism, and Arbitrum support MATIC, ETH, and various stablecoins with reduced gas costs enabling smaller minimum deposits. Polygon&#8217;s 100 MATIC pool and Arbitrum&#8217;s 0.1 ETH pool see significant usage due to transaction costs below $0.10. These networks process withdrawals faster than mainnet, typically confirming within 2-5 minutes versus Ethereum&#8217;s 15-minute average. Cross-chain functionality does not exist &#8211; deposits and withdrawals must occur on the same blockchain network.<\/p>\n<p>Avalanche and Gnosis Chain implementations remain more limited, supporting only native tokens AVAX and xDAI respectively in select denominations. The anonymity sets on these networks stay smaller, with typical pool sizes ranging from 100-500 deposits compared to thousands on Ethereum mainnet. Users should verify current pool depths through block explorers before depositing, as low-activity pools reduce privacy guarantees substantially. Each blockchain requires separate note management since cryptographic commitments cannot transfer between networks.<\/p>\n<h2>Anonymity Set Sizes and Their Impact on Privacy Levels<\/h2>\n<p>Choose pools with at least 100 participants for basic privacy protection, while pools exceeding 1,000 users provide significantly stronger anonymization guarantees. The anonymity set represents the total number of deposits within a specific pool denomination that could potentially be linked to any given withdrawal, making individual transaction tracking exponentially more difficult as the set grows larger.<\/p>\n<p>The mathematical relationship between set size and privacy follows a logarithmic curve where doubling the participant count doesn&#8217;t double privacy but increases it by a smaller factor. A pool with 10 users offers minimal protection since observers can narrow down potential sources to just 10 addresses. When that same pool grows to 10,000 users, the probability of correctly identifying a specific transaction drops to 0.01%, assuming uniform distribution and no additional metadata leaks.<\/p>\n<p>Different denomination pools accumulate anonymity sets at varying rates based on user preferences and market conditions. The 0.1 ETH pools typically achieve larger sets faster due to their accessibility to smaller users, often reaching thousands of deposits within weeks of deployment. Meanwhile, 100 ETH pools grow more slowly but attract institutional users who value the higher absolute privacy gained from mixing with similarly sized transactions. <a href=\"https:\/\/etherscan.io\/\">Etherscan data shows<\/a> that medium-denomination pools around 1-10 ETH strike an optimal balance between set growth rate and meaningful transaction sizes.<\/p>\n<p>Time correlation attacks become less effective as anonymity sets expand beyond certain thresholds. With fewer than 50 participants, timing analysis can reduce the effective anonymity set by 60-80% when deposits and withdrawals occur within predictable windows. Sets larger than 500 participants resist timing correlation much more effectively, especially when combined with randomized withdrawal delays.<\/p>\n<p>The quality of an anonymity set depends not just on raw numbers but on the diversity of participants and their transaction patterns. A pool with 1,000 users from similar geographic regions or time zones provides weaker privacy than a pool with 500 globally distributed users operating across all hours.<\/p>\n<p>Pool fragmentation across different protocols and denominations dilutes the overall anonymity available in the ecosystem. When users spread across five different 1 ETH pools with 200 participants each instead of concentrating in a single pool with 1,000 participants, every user receives less privacy despite the same total number of participants in the system.<\/p>\n<p>Withdrawal timing strategies can maximize the benefit of large anonymity sets. Waiting until the set doubles after your deposit before withdrawing increases your effective privacy by approximately 30%. Users who withdraw immediately after depositing waste the privacy potential of growing sets and may link their transactions through timing patterns.<\/p>\n<p>Network effects create a positive feedback loop where larger anonymity sets attract more users, further increasing privacy for all participants. Pools that reach critical mass around 5,000 deposits often see accelerated growth as users recognize the superior privacy guarantees, while smaller pools may struggle to attract deposits despite offering identical technical features.<\/p>\n<h2>Gas Fees and Transaction Costs When Using Tornado Cash Pools<\/h2>\n<p>Expect to pay between 0.01 and 0.05 ETH for each deposit and withdrawal operation when utilizing privacy pools on Ethereum mainnet. These network fees fluctuate based on blockchain congestion, with peak times potentially pushing costs above 0.1 ETH per transaction. Smart contract interactions for anonymization protocols require substantially more computational resources than standard transfers, resulting in gas consumption of approximately 1-1.5 million units for deposits and 300,000-400,000 units for withdrawals.<\/p>\n<p>The cost structure involves multiple components beyond basic network fees. Each deposit triggers several smart contract functions: note generation, Merkle tree updates, zero-knowledge proof verification, and pool balance adjustments. Withdrawal operations consume less gas since they primarily verify proofs and transfer funds, though using a relayer adds an additional 2-3% fee on top of base network costs.<\/p>\n<p>Pool size selection directly impacts transaction economics. The 0.1 ETH pool typically costs $30-50 per complete cycle during moderate network activity, while 100 ETH pools spread similar fixed costs across larger amounts, reducing percentage-based expenses to 0.03-0.05% of the deposited value.<\/p>\n<p>Layer 2 deployments on Arbitrum, Optimism, and Polygon offer significant cost reductions, with total fees ranging from $2-10 per operation. These rollup solutions maintain identical privacy guarantees while processing transactions at 5-10% of mainnet costs. Gnosis Chain provides an ultra-low-cost alternative with fees under $0.50, though with reduced anonymity sets due to lower overall usage.<\/p>\n<p>Timing strategies can reduce expenses by 40-60%. Weekend periods and late-night UTC hours consistently show lower network congestion, with gas prices dropping to 15-25 gwei compared to weekday peaks of 50-100 gwei.<\/p>\n<p>Relayer selection affects final costs through their fee structures. Most charge 0.3-0.5% for amounts under 10 ETH, decreasing to 0.1-0.2% for larger withdrawals. Some relayers offer flat-rate options for frequent users or bulk operations.<\/p>\n<p>Multi-step anonymization patterns multiply expenses. Each additional hop through different pool sizes or cross-chain bridges adds another complete fee cycle. A three-step obfuscation process might total $150-300 on mainnet or $15-30 on Layer 2 networks.<\/p>\n<p>Calculate total anonymization costs by combining deposit gas (1.2M units \u00d7 current gas price), withdrawal gas (350k units \u00d7 gas price), plus relayer fees if applicable. For a 10 ETH transaction at 30 gwei gas price: deposit costs 0.036 ETH ($65), withdrawal costs 0.0105 ETH ($19), and relayer fees add 0.03 ETH ($54), totaling approximately $138 for complete privacy enhancement.<\/p>\n<h2>Q&amp;A:<\/h2>\n<h4>What exactly is Tornado Cash and how does it work to mix cryptocurrency?<\/h4>\n<p>Tornado Cash is a decentralized protocol built on Ethereum that allows users to break the on-chain link between source and destination addresses. It works by using smart contracts that accept deposits of specific amounts (like 0.1, 1, 10, or 100 ETH). When you deposit funds, you receive a cryptographic note. Later, you can use this note to withdraw the same amount to a different address. The mixing happens because multiple users deposit and withdraw from the same pool, making it difficult to trace which withdrawal corresponds to which deposit. The protocol uses zero-knowledge proofs to verify that users have the right to withdraw without revealing which deposit is theirs.<\/p>\n<h4>Is using Tornado Cash legal, and what happened with the US sanctions?<\/h4>\n<p>The legal status of Tornado Cash varies by jurisdiction. In August 2022, the US Treasury&#8217;s Office of Foreign Assets Control (OFAC) sanctioned Tornado Cash, making it illegal for US persons to interact with the protocol&#8217;s smart contracts. This unprecedented move marked the first time the US government sanctioned a piece of autonomous code rather than individuals or organizations. Several other countries have followed with their own restrictions. The sanctions sparked significant debate about whether it&#8217;s possible or appropriate to ban interaction with immutable smart contracts that exist on a public blockchain.<\/p>\n<h4>Can Tornado Cash actually be shut down if it&#8217;s decentralized?<\/h4>\n<p>The protocol itself cannot be completely shut down because it consists of smart contracts deployed on Ethereum. These contracts are immutable and will continue to function as long as the Ethereum network exists. However, authorities have taken actions against the surrounding infrastructure &#8211; the website was taken down, the GitHub repository was removed, and one of the developers was arrested in the Netherlands. While the core smart contracts remain operational, accessing them has become more difficult for average users, and using them may carry legal risks depending on your location.<\/p>\n<h4>What are the fees for using Tornado Cash and how long does the mixing process take?<\/h4>\n<p>Tornado Cash itself doesn&#8217;t charge protocol fees, but users need to pay Ethereum gas fees for deposits and withdrawals. These gas costs vary based on network congestion but typically range from $20 to $200 per transaction. Additionally, users often need to pay for a relayer service (around 0.5-1% of the transaction amount) if they want to withdraw to a fresh address without first funding it with ETH for gas. The mixing process involves two steps: depositing (immediate) and withdrawing (which you should wait to do). For better privacy, it&#8217;s recommended to wait at least 24 hours between deposit and withdrawal, though waiting several days or weeks provides stronger anonymity.<\/p>\n<h4>How can law enforcement trace transactions through Tornado Cash if it&#8217;s designed for privacy?<\/h4>\n<p>While Tornado Cash provides strong privacy, it&#8217;s not perfect. Law enforcement and blockchain analysis firms use several techniques to potentially trace transactions. These include analyzing deposit and withdrawal patterns (amounts and timing), examining the Ethereum addresses used before deposits and after withdrawals, and correlating off-chain data like IP addresses if users don&#8217;t take proper precautions. If someone deposits 7.4 ETH and then withdraws exactly 7.4 ETH shortly after, the connection might be obvious despite the mixing. Blockchain analysis companies like Chainalysis have developed sophisticated tools to identify statistical patterns and probability-based links between deposits and withdrawals.<\/p>\n<h4>How does Tornado Cash actually mix cryptocurrency transactions, and can the process be traced?<\/h4>\n<p>Tornado Cash operates through smart contracts on the Ethereum blockchain that break the on-chain link between deposit and withdrawal addresses. When you deposit funds, the protocol generates a cryptographic commitment (a hash) that gets stored in a Merkle tree. You receive a secret note containing random numbers that prove ownership. During withdrawal, you provide a zero-knowledge proof demonstrating you have a valid deposit without revealing which specific deposit is yours. The mixing occurs because multiple users deposit the same denomination amounts (0.1, 1, 10, or 100 ETH), creating an anonymity pool. While deposits and withdrawals are visible on the blockchain, connecting them becomes nearly impossible without the secret note. The larger the anonymity set and the longer you wait between deposit and withdrawal, the stronger the privacy protection.<\/p>\n<h4>What happened with the U.S. sanctions against Tornado Cash, and can I still use it?<\/h4>\n<p>In August 2022, the U.S. Treasury&#8217;s Office of Foreign Assets Control (OFAC) sanctioned Tornado Cash, adding its smart contract addresses to the Specially Designated Nationals list. This unprecedented move marked the first time the U.S. government sanctioned autonomous code rather than individuals or organizations. The sanctions prohibit U.S. persons and entities from interacting with the protocol. Several major platforms like GitHub removed Tornado Cash repositories, and dYdX, Aave, and other DeFi protocols blocked addresses that interacted with the mixer. The smart contracts themselves continue functioning on the blockchain since they&#8217;re immutable, but accessing them through conventional interfaces has become difficult. Legal challenges to these sanctions are ongoing, with critics arguing that sanctioning open-source code sets a dangerous precedent for software development and financial privacy rights.<\/p>\n<h4>Is using Tornado Cash illegal, and what are the legitimate use cases?<\/h4>\n<p>Using Tornado Cash isn&#8217;t automatically illegal, though jurisdiction matters significantly. The protocol has numerous legitimate applications: protecting commercial transaction privacy, safeguarding personal wealth information from hackers, making anonymous donations to causes in authoritarian regimes, and preventing front-running attacks in DeFi trading. Many users simply want financial privacy similar to traditional cash transactions. However, regulatory scrutiny has intensified because criminals have exploited the service for money laundering. The Lazarus Group allegedly laundered over $455 million through Tornado Cash. This dual-use nature creates a complex legal situation. In jurisdictions without specific prohibitions, using the protocol for lawful purposes remains legal, but users must comply with local regulations, tax obligations, and avoid facilitating illegal activities. The arrest of developer Alexey Pertsev in the Netherlands demonstrates that involvement with privacy tools carries real legal risks, even for legitimate participants.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Tornado Cash Cryptocurrency Mixing Service Explained Tornado Cash cryptocurrency mixing service operates as a decentralized protocol on Ethereum that breaks the on-chain link between deposit and withdrawal addresses through zero-knowledge proofs. The platform processes transactions through smart contracts that pool deposits of identical amounts (0.1, 1, 10, or 100 ETH) and issues cryptographic notes as<\/p>\n<p><a href=\"https:\/\/blogs.culturamas.es\/eldelorean\/2026\/09\/02\/tornado-cash-cryptocurrency-mixing-service-to0209c\/\">Leer m\u00e1s\u2026<\/a><\/p>\n","protected":false},"author":60,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","enabled":false},"version":2}},"categories":[26],"tags":[],"class_list":["post-14155","post","type-post","status-publish","format-standard","hentry","category-tornado-cache-v3"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_shortlink":"https:\/\/wp.me\/p4mrwe-3Gj","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/blogs.culturamas.es\/eldelorean\/wp-json\/wp\/v2\/posts\/14155","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.culturamas.es\/eldelorean\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.culturamas.es\/eldelorean\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.culturamas.es\/eldelorean\/wp-json\/wp\/v2\/users\/60"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.culturamas.es\/eldelorean\/wp-json\/wp\/v2\/comments?post=14155"}],"version-history":[{"count":0,"href":"https:\/\/blogs.culturamas.es\/eldelorean\/wp-json\/wp\/v2\/posts\/14155\/revisions"}],"wp:attachment":[{"href":"https:\/\/blogs.culturamas.es\/eldelorean\/wp-json\/wp\/v2\/media?parent=14155"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.culturamas.es\/eldelorean\/wp-json\/wp\/v2\/categories?post=14155"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.culturamas.es\/eldelorean\/wp-json\/wp\/v2\/tags?post=14155"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}