The U.S. Treasury Department published a 32-page report to Congress in March 2026 formally acknowledging that cryptocurrency mixers serve legitimate financial privacy purposes on public blockchains. The same week, prosecutors in the Southern District of New York filed a letter requesting an Octob...
"It is not reasonable to expect users to have an advanced understanding of what information they are or aren't broadcasting." — Zachary Williamson, Co-founder & CEO, Aztec Network
The U.S. Treasury Department published a 32-page report to Congress in March 2026 formally acknowledging that cryptocurrency mixers serve legitimate financial privacy purposes on public blockchains. The same week, prosecutors in the Southern District of New York filed a letter requesting an October 2026 retrial for Tornado Cash co-founder Roman Storm on two counts where a jury deadlocked in August 2025: conspiracy to commit money laundering and conspiracy to violate sanctions. Combined maximum exposure on those two counts: 40 years.
The two actions represent a structural contradiction at the center of U.S. crypto privacy policy. One arm of the federal government tells Congress that lawful users may rely on mixers to shield personal wealth, business payments, and charitable donations from public view. Another arm of the same government seeks decades of prison time for the developer of the most widely used mixer protocol ever deployed. The tension reflects unresolved questions about where software development ends and money transmission begins — questions that neither the GENIUS Act, the April 2025 DOJ memo, nor the SEC/CFTC joint guidance has answered.
The Treasury's March 2026 report, delivered to Congress under the GENIUS Act's reporting requirements, represents the first time the department has formally acknowledged that mixing services have uses beyond illicit finance. The language is precise: lawful users "may leverage mixers" to protect personal wealth, business payments, charitable donations, and consumer spending habits from full public view on transparent blockchains.
The report stopped short of endorsing any specific protocol. Instead, it laid out a framework distinguishing custodial from non-custodial mixing infrastructure. For custodial platforms — those where an operator takes temporary possession of user funds — Treasury recommended registration with the Financial Crimes Enforcement Network (FinCEN) under existing money transmission rules. For non-custodial protocols — smart contracts operating autonomously without an intermediary — the report notably did not recommend new restrictions.
Treasury's four core legislative recommendations:
The report was prepared under Treasury Secretary Scott Bessent's direction and reflects input from FinCEN, OFAC, and the Office of Terrorist Financing and Financial Crimes.
On March 9, 2026, SDNY prosecutors filed a letter with Judge Katherine Polk Failla proposing to retry Roman Storm on two unresolved counts. The filing proposed start dates of October 5 or 12, 2026, with an estimated trial length of three weeks.
The case history: Storm was indicted in August 2023 alongside Tornado Cash co-founder Roman Semenov. His four-week trial in the Southern District of New York concluded in August 2025. The jury convicted Storm on one count — operating an unlicensed money transmitting business, carrying a maximum sentence of five years. The jury deadlocked on two remaining counts: conspiracy to commit money laundering (20-year maximum) and conspiracy to violate U.S. sanctions laws (20-year maximum).
Storm's defense team has filed a Rule 29 motion seeking acquittal on the convicted count, with oral arguments scheduled for April 9, 2026. Storm stated publicly that the prosecution amounts to seeking "decades in prison for writing open-source code. For transactions I never touched."
The case centers on Tornado Cash, a non-custodial smart contract protocol on Ethereum that processed approximately $7 billion in transactions since its 2019 launch. Prosecutors alleged approximately $455 million of that volume was linked to the Lazarus Group, a North Korea-affiliated hacking operation. Defense attorneys argued Storm neither controlled the protocol's smart contracts nor profited from specific laundering transactions.
A legal defense fund has raised approximately $5 million, with support from the Ethereum Foundation and the DeFi Education Fund, among over 65 crypto organizations that have urged executive intervention.
The SDNY retrial request arrived less than 12 months after Deputy Attorney General Todd Blanche issued a memorandum on April 7, 2025, directing federal prosecutors to end "regulation by prosecution" of digital asset platforms. That memo specifically instructed the Criminal Division's Fraud Section to cease cryptocurrency enforcement and disbanded the National Cryptocurrency Enforcement Team (NCET).
The Blanche memo carved out exceptions for cases involving "sanctions, hacking, terrorism, organized crime, and sanctioned states." SDNY prosecutors have framed Storm's case under these exceptions — the Lazarus Group connection ties Tornado Cash to North Korean state-sponsored hacking, a category the memo explicitly preserved.
Treasury's own actions compound the ambiguity. In March 2025, OFAC removed Tornado Cash from its sanctions list following a Fifth Circuit ruling questioning the Treasury's authority to sanction autonomous smart contracts. Twelve months later, the same department published a report acknowledging mixer privacy has legitimate uses. Yet prosecutors seek to retry Storm under the very sanctions conspiracy charge that OFAC's own delisting arguably undermined.
The result: three federal policy instruments — the Blanche memo, the Treasury report, and the OFAC delisting — all point toward accommodation of privacy technology. The SDNY prosecution points in the opposite direction.
The Treasury report contained specific illicit finance figures that frame the scale of the problem alongside the privacy argument:
| Metric | Value | Period | |--------|-------|--------| | Crypto stolen by North Korean groups | $2.8 billion | Jan 2024 – Sep 2025 | | Bybit exchange hack losses | $1.5 billion | Single event, 2025 | | Stablecoins moved through ~50 bridges | $37.4 billion | Since May 2020 | | Mixer deposits flowing into bridges | $1.6 billion | Since May 2020 | | Funds through single DPRK-linked bridge | $900 million | Since May 2020 | | Tornado Cash alleged total volume | $7 billion | Since 2019 | | Tornado Cash Lazarus Group-linked volume | $455 million | Since 2019 |
The data shows that illicit flows through mixers, while significant in absolute terms, represent a fraction of total mixer volume. The $455 million attributed to Lazarus Group constitutes approximately 6.5% of Tornado Cash's $7 billion total throughput. Treasury flagged that crypto-to-bridge flows from mixers totaled $1.6 billion since May 2020, with $900 million tied to a single bridge favored by North Korean actors.
Tornado Cash's current total value locked stands at approximately $506 million, according to DefiLlama, down from a peak near $1.5 billion in late 2025. The protocol generates annualized fees of approximately $8.6 million.
Treasury's endorsement of "privacy-preserving digital identity" aligns with a generation of protocols that have emerged specifically to solve the mixer-compliance tension. The approach: prove compliance without revealing transaction data.
Privacy Pools, co-developed by 0xBow, use shared deposit pools where users generate zero-knowledge proofs demonstrating their funds originated from "clean" sources — deposits not linked to known sanctioned or hacked wallets. A USDC pool is already operational. Nathaniel Fried, 0xBow's co-founder, has described the model as "pragmatic privacy" — anonymity bounded by provable sanction compliance.
Railgun operates directly on-chain through smart contracts, using what it calls "Proofs of Innocence." Users cryptographically prove their funds did not originate from known illicit sources without disclosing their actual transaction history. Eric Hill, Railgun's counsel and formerly head of legal at Lido, has advised that non-custodial, open-source protocols that avoid central control, administrator-held upgrades, and transaction profits are best positioned to avoid prosecution.
Aztec Network, approaching mainnet, plans to offer privacy-by-default on an Ethereum Layer 2, with built-in anonymous sanctions checks via selective disclosure. The architecture uses two layers of zero-knowledge proofs: one encrypts transactions for privacy, a second compresses them before Ethereum submission.
These tools represent a shift in the privacy technology landscape from total anonymity (the Tornado Cash model) toward what the industry now calls "pragmatic privacy" — compliance-compatible shielding that satisfies both user demand and regulatory requirements.
Despite the Treasury report, the April 2025 DOJ memo, the SEC/CFTC joint guidance of March 2026, and the signed GENIUS Act, no statute directly addresses the core legal questions raised by the Storm case:
Is deploying a non-custodial smart contract "operating" a money transmitting business? The convicted count against Storm rests on this theory. The Blanche memo does not answer it. The Treasury report draws a custodial/non-custodial distinction but has no legislative force.
Can a developer be criminally liable for users' transactions through autonomous code? The Samourai Wallet case offers one data point: developers Keonne Rodriguez and William Lonergan Hill were sentenced to four to five years in November 2025 for unlicensed money transmission, despite the non-custodial design of their software. The precedent has not been overturned.
Where does OFAC delisting end and DOJ prosecution begin? Treasury removed Tornado Cash from the sanctions list. DOJ seeks to retry Storm for conspiracy to violate the very sanctions that no longer exist for the protocol. The legal theory appears to rest on conduct during the period when sanctions were active.
The Congressional Research Service published a comprehensive primer on DeFi policy in March 2026, examining how Bank Secrecy Act and AML requirements apply to noncustodial protocols. The primer identified the tension but offered no resolution. The SEC's December 2025 roundtable on financial surveillance and privacy, where Chairman Paul Atkins spoke about zero-knowledge proofs and selective disclosure, similarly produced discussion but no rulemaking.
The U.S. government is simultaneously telling Congress that crypto mixer privacy is legitimate and telling a federal court that a mixer developer belongs in prison for 40 years. The contradiction is not rhetorical — it is structural. Different agencies, operating under different mandates and different career incentives, have reached opposite conclusions about the same category of technology.
The Treasury report provides a framework for resolution: distinguish custodial from non-custodial, require registration for the former, develop compliance-compatible privacy tools for the latter, and give institutions authority to hold suspicious assets. None of this framework is law. The GENIUS Act, the Blanche memo, and the SEC/CFTC joint guidance each address adjacent questions without touching the central one: when does writing code become operating a financial service?
Until Congress legislates a clear answer, the Storm retrial will proceed under legal theories developed before the current administration's policy shift. The outcome will establish precedent that either aligns with or contradicts the direction three federal agencies are now moving. The April 9 oral arguments on Storm's Rule 29 motion will be the next indicator of which direction the judiciary chooses.