Ultimate magazine theme for WordPress.

The Hype Fades, But Oversight Remains Part II – Issues Related to Mixer Sanctions | Ingram Yuzek Gainen Carroll & Bertolotti, LLP

Following our previous blog post on the changes to EU anti-money laundering laws and their implications, the US authority responsible for administering sanctions programs, the Office of Foreign Assets Control (“OFAC”), recently closed the cryptocurrency and NFT Community Surprised Naming a Cryptocurrency Mixer “Tornado Cash” as a Sanctioned Target.

On August 8, OFAC identified Tornado Cash (aka “Tornado Cash Classic” and “Tornado Cash Nova”) on its Specially Designated Nationals and Blocked Persons List (“SDN List”) as a sanctioned entity, noting that certain Smart contract addresses associated with the Tornado Cash protocol are also included on the SDN list as part of the Tornado Cash “entity”. OFAC pointed out that Tornado Cash was used to cover up illegal financial activities conducted in violation of OFAC’s sanctions programs (such as the $455 million stolen by the North Korean-sponsored Lazarus Group, and the designation comes as part of the ” Actions against blenders launder virtual currency for criminals and those who help them.” While OFAC has previously designated another cryptocurrency blender, Blender.io, as a sanctioned entity, this time’s determination, it turns out, has prompted resistance and uncertainty that will be clarified.

What is Tornado Cash?

Tornado Cash is a decentralized protocol that offers cryptocurrency mixing services through self-executing smart contracts based on zero-knowledge proof functionality. Simply put, the protocol allows a cryptocurrency holder to preserve their transaction data and disrupt on-chain activity by obscuring the flow of deposited/withdrawn cryptocurrencies in their liquidity pools. If someone wants to secretly transfer 1 ETH from their publicly identified wallet to a secret non-publicly identified wallet, they can simply deposit that 1 ETH into the log, get a deposit slip as a private key for their later withdrawal, and request that 1 ETH (subject to the Protocol Fees) is sent to the specified wallet address. An independent third party tracking this transaction would not be able to determine when and to which address this 1 ETH is withdrawn, as the Tornado Cash protocol layers all ETH received (thus disrupting the traceability of the 1 ETH in question) and Send varying amounts of ETH to one or more wallet addresses when a withdrawal request is made. It is reported that with such merging services, “over $7 billion in cryptocurrency has flowed through Tornado Cash since its inception, with approximately 20% of those funds tied to illicit activities.”

What are sanctions?

Sanctions are a set of restrictions imposed on certain states, organizations or individuals to achieve specific goals or to change the behavior of the sanctioned goals. The most common limitations of a sanctions program are prohibitions on transactions or dealings with a sanctioned target, which means that no US entity or person (and, in certain circumstances, no US entity or person) may participate in a transaction with the sanctioned target in any form, unless OFAC grants a license permitting such a transaction. In general, sanctions can be divided into the following two types according to their scope:

  • Primary Sanction The primary sanction applies to US citizens, US incorporated companies and transactions coming into or from the US (e.g. USD denominated transactions). If a product’s source is from the United States, that product could also be subject to the primary sanction. In general, the key to determining whether the primary sanction is applicable is whether a transaction has a “US nexus” that could link it to the US. Once the nexus is determined to exist, the parties involved must comply with the primary sanction.

  • Secondary Sanction On the other hand, the secondary sanction provides the basis on which the US government punishes foreign individuals or entities violating US sanctions without any connection to the US. Unlike the primary sanction, the restrictions imposed by the secondary sanction are typically imposed in connection with a sanctions program (e.g., the Iran and North Korea sanctions programs) and/or as an extraterritorial effect that foreign companies/individuals deem necessary to U.S. Comply with sanctions in your own interest. The common consequence of violating secondary sanctions is denial of access to US financial systems, which can be accomplished through SDN listing.

Issues related to naming the SDN list

The first issue arising from OFAC’s designation is the legitimacy of listing smart contracts as sanctioned entities on the SDN list. As the research center Coin Center pointed out, the entire Tornado Cash protocol actually consists of multiple Ethereum smart contract addresses working independently and automatically, meaning that no entity/individual would have the authority to control these smart contracts. While OFAC has the authority under Executive Order 13694 to designate any person or “organization” as a sanctioned subject, the term “organization” is defined as “a partnership, association, trust, joint venture, corporation, group, sub-group or other organization”, which, given the nature and workings of a smart contract, probably cannot be considered autonomous codes. Accordingly, the inclusion of these autonomous smart contract addresses inevitably raises the question of the legality of naming and whether it would be appropriate to separate autonomous smart contracts from entities/individually controlled entities when determining the scope of subjects to be placed SDN- List.

Another issue after OFAC’s naming is the “dust attack” initiated by an unidentified person (or entity). As noted above, individuals and entities are prohibited from doing business with parties on the SDN List and may face serious consequences (e.g., fines and denial of access to the US financial system) for violating this prohibition. However, while complying with sanctions is fairly easy in conventional financial services environments, since one party could actively screen and filter other transaction parties, in the cryptocurrency environment “active screening and filtering” may not be sufficient, as cryptocurrencies can be sent to publicly identified addresses with no action taken on sides of the recipient. The Dust Attack in question is initiated on the basis of such a difference, when an individual (or a company) demands that a minimal amount of ETH be withdrawn from Tornado Cash and transferred to celebrities (e.g. Coinbase CEO and Youtuber Logan Paul), Thus, these celebrities’ wallet addresses are being tainted by cryptocurrency service providers (like exchanges and NFT platforms) and flagged as high-risk addresses. While the holders of these tainted wallet addresses could certainly argue and prove (arduously) that they never accessed Tornado Cash and requested a withdrawal, they would still be left with the question of how they treat this “tainted ETH” received from Tornado Cash and should dispose of . In traditional financial services environments, funds determined to have originated from a sanctioned target are commonly segregated by financial institutions in one or more independent interest-bearing accounts so that they are not mixed up with other funds or assets that are not subject to sanctions and could remain frozen, monitored and reported (as required by relevant OFAC requirements). In the cryptocurrency environment, however, it remains unclear how the “tainted ETH” could be dealt with. Obviously individuals would not have an interest bearing account to segregate the tainted ETH and it may be impossible to ask an established cryptocurrency exchange to take over such tainted ETH given various considerations. In the event that an average Joe gets stuck with tainted ETH, he/she would be subject to ongoing compliance obligations that can eventually become unbearable and would be at risk of inadvertently breaching applicable requirements. All of these concerns would take time, effort and regulatory input to resolve.

Finally, further consideration may need to be given to risk assessments conducted in connection with the naming of Tornado Cash. As mentioned in our previous post, risk assessment is the core underlying an AML/CFT program and how an individual or entity is assessed in accordance with their activities would require a substantial review of the AML/CFT methodology, – Program policies and procedures require. Suppose an innocent person receives ETHs from another person, but those ETHs were previously routed and layered through Tornado Cash. How far back should this routing and layering go for this innocent person to be considered “truly innocent”? In the context of dust attack trolling, should the recipient of the tainted ETH be considered a high-risk customer by default until proven otherwise? Would the rating be different for a person subject to only a secondary sanction? Until relevant practices are established and/or regulatory guidance is provided, the most plausible response to all of these considerations may be a legal one – it depends. Essentially, the AML/CFT program would require a case-by-case assessment based on the actual needs and unique operations of the program administrator.

The world is changing and the laws are catching up. It is important to keep in mind how all these developments would play out. Stay tuned to Ingram’s NFT Newsroom for more on the latest developments in NFTs.

Learn Crypto Trading, Yield Farms, Income strategies and more at CrytoAnswers
https://nov.link/cryptoanswers

Comments are closed.

%d bloggers like this: