Publishing privacy software is not money transmission

The most important fact in Roman Storm’s case is also the easiest one for malicious prosecutors to obscure: Storm never received users’ funds and never executed their transactions.

The Tornado Cash website provided a client-side application built from HTML and JavaScript. When someone opened it, the software ran in that person’s browser. The user generated the necessary information locally, connected their own wallet and authorized their own transaction. Storm’s web server delivered code for software; it did not act as a financial intermediary by running that software.

The same interface code was published open-source. Anyone could download it, build it and run it locally. Tornado Cash even published a minified version designed to be hosted independently. Opening Storm’s website was therefore functionally similar to downloading the program and opening it yourself. In either case, the software ran on the user’s device.

The underlying protocol was even further removed from anything that could be misconstrued as Storm’s control. The developers deployed smart contracts to Ethereum and made the main pools immutable. After that, nobody — not Storm, the other developers or the government — could alter them, remove them or decide who could use them.

The Fifth Circuit later confirmed this technical reality in the litigation over the Treasury sanctions. It found that the immutable contracts operated automatically, without human intervention, and could no longer be controlled by their creators. Users could also interact with them directly, without Storm’s website, and could withdraw without using a relayer.

Storm did more than type the code and disappear. He helped develop and promote Tornado Cash, maintained the interface, paid for some ancillary infrastructure and profited indirectly from the project’s TORN tokens. Prosecutors also showed that he knew criminals were using the protocol.

Those facts establish that he remained involved in the project. They do not establish that he transmitted anyone’s money.

That distinction is the entire case.

The government combined ordinary protocol-team activity — publishing an interface, promoting a project, maintaining related infrastructure and benefiting from its adoption — and called the result operation of a money-transmitting business. But none of those activities gave Storm custody of user funds or the ability to approve, reject or reverse a transaction. Under the government’s definition, every protocol team in the blockchain space is a money transmitter, which obviously stretches the definition of “money transmitter” far beyond its original meaning.

FinCEN’s own guidance had drawn what appeared to be a clear boundary. A person who accepts cryptocurrency and retransmits it as an anonymizing service is a money transmitter. A person who supplies anonymizing software is not. FinCEN explained that software suppliers provide tools that may be used for money transmission, but are engaged in trade rather than money transmission themselves. It also said that creating a decentralized application does not make its developer a money transmitter unless the developer actually uses it to accept and transmit value. (FinCEN guidance)

If Storm had set out to deliberately structure Tornado Cash to remain on the software side of that boundary, he would have done essentially what he did: never take custody of funds, never execute transactions for users and remove his own ability to control the protocol.

He went further than merely avoiding custody. The Tornado Cash developers created a compliance tool allowing users to voluntarily prove that a particular withdrawal came from their own earlier deposit. The tool did not prevent criminals from using the immutable protocol, but it allowed legitimate users to disclose the source of their funds when dealing with an exchange, auditor or law-enforcement agency.

Despite all this, Storm’s home was searched and he was indicted on three conspiracy charges carrying a combined statutory maximum of 45 years. A jury later deadlocked on the money-laundering and sanctions charges but convicted him of conspiring to operate an unlicensed money-transmitting business. He now faces up to five years on that conviction and a possible retrial on the two deadlocked charges, carrying another 40 years of potential exposure.

The Samourai Wallet case is not technically identical, and it should not be presented as if it were. Samourai operated an active Whirlpool coordinator, collected fees and produced much stronger evidence of deliberately courting criminal users. Keonne Rodriguez and William Lonergan Hill eventually pleaded guilty to conspiring to operate a money-transmitting business knowing that it transmitted criminal proceeds. They are now serving five- and four-year prison sentences.

But Samourai was still non-custodial. Its users retained their private keys and controlled their bitcoin. According to a defense filing quoting the prosecution’s own pre-indictment memo, FinCEN officials told prosecutors that this lack of custody strongly suggested Samourai was not a money-services business. The guilty pleas prevented that question from receiving a final ruling after a trial.

The statements and marketing attributed to the Samourai developers were legitimate evidence of intent. They were not evidence of custody. The government still had to turn software that coordinated user-controlled transactions into a business that legally “transmitted” the funds.

That is what makes these cases dangerous beyond Tornado Cash and Samourai.

MetaMask also publishes software that users run to create and authorize cryptocurrency transactions. Its developers maintain interfaces, promote the product and benefit from its adoption. Criminals inevitably use it. If these ordinary facts are enough to convert the author of user-controlled software into the operator of every transaction performed with it, the same theory can be extended far beyond privacy wallets.

Perhaps prosecutors would promise not to use it that way. But a developer’s freedom should not depend on prosecutorial discretion. There must be a legal distinction between creating the tool and executing the transaction.

The Justice Department itself now largely recognizes this. It says new money-transmission charges should not be approved where software is genuinely decentralized, merely automates peer-to-peer transactions and leaves third parties without custody or control of user assets. It has also said that developers of neutral tools, without criminal intent, should not be held responsible for someone else’s misuse. (DOJ policy statement)

That is almost exactly the boundary Storm had reason to believe already existed.

Privacy software will be used by criminals because criminals need privacy. It will also be used by ordinary people because public blockchains expose their transaction histories to anyone capable of connecting an address to their identity. The existence of criminal users does not turn the software itself into a criminal enterprise.

The government should prosecute the people who steal money, evade sanctions or knowingly assist particular criminals. But it should not impose a duty on software authors to stop transactions they neither execute nor control.

That is not money transmission. It is publishing code.

America cannot maintain a serious commitment to coding and internet freedom while treating the author of autonomous software as the operator of everything strangers later do with it.

submitted by /u/aminok [link] [comments]r/CryptoCurrencyRead More

You might also be interested in reading Merck wins FDA approval for subcutaneous Keytruda: Endpoints.