Cointime

Download App
iOS & Android

Crypto-privacy advocates land a legal haymaker

Cointime Official

From projectglitch xyz

Greetings, glitchy friends! We are gearing up for lots more publishing again soon, but in the meantime we had a couple of new items we wanted to send your way. Watch out for at least one more issue before an end-of-year break, then we’ll be back in your inbox on the regular starting in January. Now onto the good stuff…

Photo by Joel Muniz on Unsplash

A win for crypto in the Tornado Cash fight. Over the last two years, a prize fight has been playing out between the US government and crypto-privacy advocates. The two sides have gone back and forth over the definition—and therefore legal status—of Tornado Cash. Last month, those in crypto’s corner landed a huge blow, and it all boils down to the interpretation of a couple of key words in the law.

The match began in 2022, when the US Treasury’s Office of Foreign Assets Control (OFAC) announced that it had designated the group of blockchain-based software programs known as Tornado Cash as national security threats. The Tornado Cash programs, which are known as smart contracts, anonymize crypto transactions by pooling user funds and using advanced cryptography to hide users' identities when they withdraw.

OFAC alleged that the Lazarus Group, a sanctioned North Korean state-sponsored hacking group, had used Tornado Cash to launder more than $455 million worth of stolen digital money. The sanctions, the first ever against smart contracts, made it illegal for Americans to transact using the software.

In response, Tornado Cash users who say they use the software for legitimate purposes—like donating money to support the Ukrainian war effort without revealing the transaction to Russian hackers—sued the Treasury Department. In two separate cases in federal district court, these users argued that OFAC has no authority to sanction the Tornado Cash software.

The court initially sided with the Treasury in both cases. The judges said Tornado Cash is an entity that North Korea has an interest in, and that the software is “property” that can legally be blocked under the relevant law, which is known as the International Emergency Economic Powers Act (IEEPA). The word property is critical here, because IEEPA very clearly gives the executive branch power to block “any property in which any foreign country or a national thereof has any interest” in the name of national security.

Both groups appealed and now we have another decision. Just before Thanksgiving, the Fifth Circuit Court of Appeals agreed with the appellants in one of the cases that the district court had given too much “deference” to OFAC’s definition of property.

So now we have two pivotal words to examine. We’ll get to “property,” but “deference” is doing a lot of work here too. As the Fifth Circuit judges noted in their decision, the case fell under a new legal tenet established in June in the Supreme Court’s decision in a case called Loper Bright v Raimondo. That decision overturned a 1984 decision (Chevron v. Natural Resources Defense Council) that established a legal doctrine known as the Chevron deference. The doctrine called on the courts to defer to a government agency’s interpretation of a law when the wording of the law is ambiguous—as long as the interpretation was reasonable. This is important because agencies draft rules and regulations to implement the laws that Congress passes.

Overturning the Chevron deference shifted the balance of power away from federal agencies. The onus is now on the courts to “decide whether the law means what the agency says,” Chief Justice John Roberts wrote in his opinion. In the Tornado Cash case, what’s relevant here is that the wording of IEEPA did not define the term “property.” OFAC felt that the definition encompassed Tornado Cash’s software. On the contrary, “property” must be ownable, the appeals court judges wrote. Ownership includes “the right to exclude everyone else from interfering with it.”

The court concluded: “The immutable smart contracts at issue in this appeal are not property because they are not capable of being owned.”

Time to analyze yet another word. An “immutable” smart contract “cannot be altered or removed from the blockchain,” the court explained. “They remain available for anyone to use”—including the Lazarus Group hackers. Since immutable software can’t be owned and thus is not “property,” OFAC “exceeded its statutory authority,” the judges said.

It’s an enormous win for crypto and privacy advocates. But as the court noted, it’s just interpreting the law. And the law can be changed. “Perhaps Congress will update IEEPA, enacted during the Carter Administration, to target modern technologies like crypto-mixing software.” —Mike Orcutt

Today’s SNARKs are “riddled with bugs.” That’s according to Justin Thaler, a research partner at a16z and a leading researcher in the field of applied zero-knowledge (ZK) cryptography. That’s as bad as it sounds, he writes in a recent blog post. “The slightest bug in a SNARK can lead to catastrophic security failures.”

For the uninitiated, succinct non-interactive arguments of knowledge (SNARKs) are systems that allow a user to prove, for example, that they are over 18 or have a certain amount of money in their bank account without revealing their actual age or bank account balance. Zcash, which uses SNARKs to keep blockchain transaction data secret, was the first implementation in 2016. Since then, the research field has exploded.

Early SNARK designs were limited to proving small things, like that a user holds a secret key that controls the crypto wallet behind a given blockchain transaction. More recent designs can prove the user ran a computer program on that secret information—that makes it possible to compute a transaction offchain and then send proof to the blockchain that the computation was done correctly. This has been a big step forward, allowing decentralized computing platforms like Ethereum to handle more transactions per second.

For a16z, Thaler has been working on the most advanced kind of SNARK, also called a zero-knowledge virtual machine (zkVM). In April, his team released the first version of their zkVM, called Jolt, and they’ve since made incremental progress on improving its performance. But Thaler remains seriously concerned about Jolt’s security. “Until we have confidence that our toolchains are completely bug-free, projects using SNARKs cannot really be secured by the SNARK itself,“ he writes. Finding bugs in SNARKs requires PhD-level expertise, so it’s unlikely many people will be able to find them. But that doesn’t mean they’re not there. “At best, they are secured by obscurity,” he says in the post.

To account for potential security holes, SNARKs are just one of many security layers in today’s systems, which can include “semi-centralized” layers like whitelists, trusted hardware, and security councils with the authority to step in and reverse transactions. “The very worst case scenario is that we think our SNARK toolchains are bug-free,” Thaler argues. Then teams might stop relying on those other layers.

The long-term goal, according to Thaler, should be to develop formal verification methods, the way the traditional software industry uses established mathematical methods to prove the “correctness” of a software system relative to a separate mathematical description (called a “specification”) of how it is supposed to behave. “But formal methods are not some magic wand that can be waved at any piece of software and magically make all the bugs go away,” Thaler writes. “Major technical challenges will have to be overcome to get any kind of guarantee that zkVM toolchains are end-to-end correct and secure.”

Thaler notes that the Ethereum Foundation is investing in a project to develop zkVM formal verification methods. But the goal remains years away, he says. “In fact, I consider it a distinct possibility that in five years’ time, we still don’t have strong confidence that any performative zkVM toolchain is actually bug-free.” —Mike Orcutt

(Interested in learning more about the science of SNARKs? Check out my fireside chat with Justin Thaler at the DC Privacy Summit, Project Glitch’s first in-person event, which explored the novel legal and policy questions raised by Tornado Cash and crypto-privacy generally.)

HEADLINE WATCHER

How crypto insiders turned “debanking” into a political storm. The New York Times examines crypto companies' difficulties maintaining bank accounts in the US—a phenomenon most crypto folks now call “Chokepoint 2.0.”

US officials urge Americans to use encrypted apps amid unprecedented cyberattack. During a recent “news call,” these officials wouldn’t say how long it might take to be sure major telecom providers including AT&T, Verizon, and Lumen Technologies are free of alleged Chinese hackers in the wake of the “Salt Typhoon” cyberattack. “Encryption is your friend, whether it’s on text messaging or if you have the capacity to use encrypted voice communication,” Jeff Green, executive assistant for cybersecurity at the Cybersecurity and Infrastructure Agency (CISA), said, according to NBC News.

Why ‘open’ AI systems are actually closed, and why this matters. “At present, powerful actors are seeking to shape policy using claims that ‘open’ AI is either beneficial to innovation and democracy, on the one hand, or detrimental to safety, on the other,” write three co-authors, including Signal’s Meredith Whittaker, in the science journal Nature. The authors argue that the “rhetoric around ‘open’ AI is frequently wielded in ways that exacerbate rather than reduce concentration of power in the AI sector.”

Ukraine asks if Telegram, its favorite app, is a sleeper agent. The messaging app has become a “lifeline for millions of Ukrainians,” but in recent months officials “have become more alarmed by the country’s dependence” on it as “worries that the app was used as a vector of disinformation and a spying tool for Russia have mushroomed,” reports the New York Times.

The number of (zero knowledge) related (smart) contracts used grew from 47 in 2020 to 680 in 2024. Though still a nascent field, the use of zero-knowledge cryptography in blockchain applications is ballooning, according to Electric Capital’s annual Crypto Developer Report.

Comments

All Comments

Recommended for you

  • SEC and CFTC Update Crypto FAQs: Token Buybacks and Network Upgrades Not Necessarily Securities, CFTC Allows On-Chain Record Keeping

    On September 26, the U.S. Securities and Exchange Commission's Division of Corporation Finance released an updated FAQ on September 25, clarifying that token buybacks, network upgrades, and marketing statements do not automatically make crypto assets securities. SEC staff noted that announcing a buyback plan for an operational crypto network does not, by itself, make the associated tokens investment contracts; however, if the network is not operational and the issuer promotes the buyback as a source of returns for holders, it may be a different case. The FAQ also clarified that services provided once a crypto system is operational, aimed at securing, maintaining, improving, or enhancing the system or its functions, or promoting network effects, do not constitute managerial efforts under the Howey test. Marketing existing uses of the network typically does not create profit expectations, and statements about future functionalities do not either, provided there is no promotion of profit potential. This update reiterates that conclusions will still heavily depend on specific cases and are based on the SEC's interpretative release regarding the applicability of securities laws to crypto assets issued in March this year. On the same day, the Commodity Futures Trading Commission updated its crypto FAQ, allowing futures firms and clearinghouses to invest customer funds in tokenized versions of previously permitted assets, provided they meet investment and custody requirements. CFTC staff also indicated that regulated companies may use blockchain for record keeping but must still be able to provide records if the blockchain or its block explorer is non-operational. These updates come as the CLARITY Act failed to advance in the Senate, with regulators continuing to push forward with the crypto regulatory framework based on existing laws.

  • BTC Surpasses $84,000

    Market data shows that BTC has surpassed $84,000, currently priced at $84,004, with a 24-hour decline of 0.25%. The market is experiencing significant volatility, so please ensure proper risk management.

  • BTC Falls Below $84,000

    Market data shows that BTC has fallen below $84,000, currently priced at $83,988.06, with a 24-hour increase of 0.52%. The market is experiencing significant volatility, so please ensure proper risk management.

  • ETH Falls Below $2700

    Market data shows that ETH has fallen below $2700, currently priced at $2699.7, with a 24-hour increase of 1.95%. The market is experiencing significant volatility, so please ensure proper risk management.

  • BTC Surpasses $85,000

    Market data shows that BTC has surpassed $85,000, currently priced at $85,000.02, with a 24-hour increase of 1.72%. The market is highly volatile, so please ensure proper risk management.

  • ETH Surpasses $2700

    Market data shows that ETH has surpassed $2700, currently priced at $2700.14, with a 24-hour increase of 1.23%. The market is experiencing significant fluctuations, so please ensure proper risk management.

  • Yushu Technology's Wang Xingxing: Key to Breakthrough in Embodied Intelligence Lies in Solving Millimeter-Level Error Issues

    On September 25, the 5th Global Digital Trade Expo was held in Hangzhou, where Wang Xingxing, founder of Yushu Technology, delivered a keynote speech titled "From Machinery to Intelligence - The Evolutionary Theory of Embodied Future." Wang stated that the embodied intelligence industry may soon experience a critical breakthrough similar to that of ChatGPT. He believes that when robots can complete approximately 80% of tasks through voice interaction and embodied intelligence capabilities in about 80% of unfamiliar environments, the industry will enter a critical phase of large-scale application. He pointed out that the ability for robots to understand and execute specific tasks based on voice commands has already made breakthroughs last year, but the industry still faces a core technological bottleneck, namely the precise matching issue between artificial intelligence models and the real physical world. Wang noted that currently, robots still have a few millimeters of error during actual operations, which limits their stability and reliability in complex environments. "In the future, whoever can solve this problem will fundamentally resolve the issues with robots."

  • Swissquote Analyst Warns AI Narrative is a Core Pillar of US Stocks, Potential Break Could Trigger Significant Correction

    On September 25, Ipek Ozkardeskaya, a senior analyst at Swissquote Bank, stated that broad market indices and retirement funds are now deeply tied to the AI wave, with technology stocks accounting for about 40% of the S&P 500 index. She pointed out that the market capitalization weight of just three chip manufacturers makes up over 25% of the MSCI Emerging Markets Index. Ozkardeskaya indicated that AI has become the 'core pillar' of the market, and this pillar 'must not show any cracks.' She believes that, in the short term, the US stock market will continue to be supported by seasonal factors, and the current market uptrend may extend until the end of the year. However, she also warned that the worst-case scenario would be a shake in the investment logic surrounding AI, which could undermine market confidence in the AI narrative, potentially triggering a significant market correction.

  • U.S. Stock Index Futures Turn Positive; Chip Stocks Rally in After-Hours Trading

    On September 25, U.S. stock index futures rose into positive territory, with Nasdaq futures up 0.36%. In after-hours trading, storage and semiconductor stocks saw widespread gains, with AMD, Intel, and SanDisk all rising by 2%.

  • NEAR Partners with Ondo to Launch 20 Tokenized US Stocks and ETFs

    On September 25, according to Cryptonews, NEAR Protocol and Ondo Finance have launched trading for tokenized US stocks and ETFs on near.com, with an initial offering of 20 assets including Nvidia, Tesla, Apple, Microsoft, Amazon, as well as SPY and QQQ. Eligible users can deposit using over 30 supported stablecoins or other crypto assets, with NEAR Intents serving as the cross-chain distribution layer, allowing similar assets to be routed to connected wallets and DeFi protocols in the future. Purchases are settled in USDon, which is backed 1:1 by US dollars in brokerage accounts, and completed via atomic swaps. This product is not available to US persons; the overall Ondo platform has launched over 100 assets, with NEAR initially offering only one-fifth of that.