
Roman Storm, co-founder of the Tornado Cash privacy protocol, criticized the legal theory behind the U.S. case against him, arguing that by the same logic, mainstream technology companies such as Google and OpenAI could be held liable if sanctioned actors misuse their tools. His comments, posted on X, come amid an ongoing legal battle that could shape how courts treat developer responsibility for open-source software used in illicit activity.
Storm Challenges Prosecutors’ Theory of Liability
Storm argued that the government’s approach to Tornado Cash is overly broad and inconsistent. He contended that if developers can be held responsible for autonomous software later used by sanctioned entities, then other platforms whose products are used by North Korean operatives could face similar exposure. He cited Google and OpenAI as examples to illustrate what he called a flawed standard for liability.
U.S. officials have long asserted that cyber theft and sanctions evasion help finance North Korea’s weapons programs. Storm’s remarks position the Tornado Cash case within a larger debate over whether toolmakers should be accountable for how bad actors use widely available technologies.
Background: Tornado Cash, Sanctions, and the DOJ Case
Tornado Cash is an Ethereum-based privacy tool that uses smart contracts to obscure transaction trails, enhancing on-chain anonymity. In August 2022, the U.S. Treasury’s Office of Foreign Assets Control (OFAC) sanctioned Tornado Cash, alleging it was used to launder funds tied to cyberattacks, including thefts attributed to North Korea’s Lazarus Group.
In 2023, the U.S. Department of Justice charged Storm and others with conspiracy offenses related to money laundering, sanctions violations, and operating an unlicensed money-transmitting business. Prosecutors allege the protocol facilitated the laundering of illicit proceeds, including funds connected to state-sponsored hacking. Defense arguments have emphasized Tornado Cash’s open-source, non-custodial design and the limits of developer control once smart contracts are deployed.
Broader Debate on Developer Responsibility
The case has become a focal point for the crypto industry and open-source advocates concerned about the precedent it could set for software authors whose code is later misused. It also intersects with ongoing policy questions about financial privacy, sanctions enforcement, and the extent to which decentralized protocols can or should incorporate controls against illicit finance.
What to Watch
- How courts weigh the distinction between creating autonomous software and operating a money service.
- Whether liability theories extend to other technology providers when sanctioned entities use general-purpose tools.
- Potential policy or regulatory responses that balance privacy, innovation, and sanctions compliance in decentralized finance.