Cointime

Download App
iOS & Android

Mixers and Tumblers: Regulatory Overview and Use in Illicit Activities

Validated Media

The use of mixers and tumblers in various illicit activities such as money laundering and hacks is rapidly increasing. Attackers run illicit proceeds through mixers and tumblers to obscure the trail of ownership by pooling others’ holdings, scrambling it, and redistributing the funds on the other end. On January 18, 2022, $34 million in crypto was stolen from Singapore-based crypto exchange, Crypto.com. Reportedly, the stolen Ethereum (ETH) was laundered through Tornado Cash — an ETH mixer protocol  — and Bitcoin was laundered through an unknown Bitcoin mixer.

However, with the rise in the use of mixers and tumblers for illicit activities, the regulatory scrutiny around them is also increasing. The FATF in its Second 12 Month Review Report, under the section, Trends in the use of Virtual Assets (VA) for ML/TF purposes, noted that the use of mixers/tumblers by bad actors for obfuscating the source of funds has significantly gone up.

Use of cryptocurrency tumblers in conducting illicit activities

Hacks: Crypto mixers and tumblers are services that help attackers confuse the trail of crypto transactions by associating unrelated funds together using various methods. Attackers often use unregulated decentralized mixers and tumblers on the darknet to surpass regulatory requirements such as the Know Your Customer (KYC) requirement

In 2021, a large number of hackers used mixers and tumblers to evade detection. In the Liquid Global Hack, hackers sent roughly 6,000 stolen Ethereum (ETH) amounting to $20 million to Tornadocash.com, allowing them to hide their transactions by mixing their coins in with the others. Similarly, in the BitMart Hack hackers stole $150 million worth of tokens from ETH and Binance Smart Chain (BSC) hot wallets. The hackers swapped the stolen tokens by using the 1inch — decentralized exchange aggregator — and then used Tornado Cash to deposit the funds, allowing them to keep their identities hidden.

Darkweb: Criminals may use mixers and tumblers and the dark web to clean dirty crypto. Mixers and tumblers clean dirty crypto by bouncing it between various addresses, before recombining the full amount through a crypto wallet hosted on the dark web.

To conduct illicit activities using mixers and tumblers, attackers usually use one crypto wallet hosted on Clearnet (public internet) and two or more crypto wallets running solely on the dark web. For example, an attacker will send crypto from a wallet hosted on Clearnet to mixers and tumblers. After tumbling the clean crypto is transferred to the attackers’ TOR wallets. TOR wallets are anonymous wallets designed to keep their user’s identities hidden. TOR works by changing the location of the users’ internet address and encrypts the internet address by rerouting the users’ network via multiple remote servers. These encrypted transactions are repeated multiple times across dark web crypto addresses, adding a layer of obfuscation with each transaction.

Money laundering: The process of running dirty crypto through mixers and tumblers is very similar to the three stages of money laundering. The three stages of the money laundering process are placement, layering, and integration.

In the placement, stage criminals deposit dirty crypto into the tumbler. In a decentralized mixer, users receive crypto from other users during this stage. They are at the risk of receiving dirty crypto, which has been used for illicit activities, and can now connect them to these activities.

The second stage is called layering. In this phase, criminals use various types of services such as mixers and tumblers to create a complex transaction trail, removing the direct association with funds’ origin. Mixers split transactions into multiple smaller transactions and combine them again. Money launderers use mixes multiple times at various steps, making the source of funds unidentifiable.

The third stage is known as Integration. Once the process of mixing is complete, clean crypto is transferred to pre-determine wallets —either back to the sender or the new owner. Now, that the source of these funds is untraceable, the final phase is to legitimize the funds. There are many ways of doing this, sometimes money launderers may create new businesses providing services, which accept crypto payments. Then convert the crypto received into fiat currency through off-shore banking services.

Regulatory overview

FATF: The FATF in its Second 12 Month Review Report, under the sections — Trends in the use of Virtual Assets (VA) for ML/TF purposes — noted that the use of mixers/tumblers by bad actors for obfuscating the source of funds has significantly gone up. The FATF also observed that several mixer/tumbler services have been taken offline following enforcement action for operating as unregistered VASPs.

Further, in its Virtual Assets Red Flag Indicator Guidance, the FATF has stated that the transactions making use of mixing and tumbling services should be flagged, as they suggest an intent to obscure the flow of illicit funds between known wallet addresses and darknet marketplaces.

The U.S.: Under the Bank Secrecy Act (BSA), a money transmitter is required to develop and maintain a functional anti-money laundering (AML) compliance program and adhere to the applicable reporting and recording-keeping requirements. FinCEN further clarified its guidance in 2019 with FIN-2019-G001, stating the crypto anonymizing services — mixers and tumblers—are also considered money transmitters under the BSA.

The Department of Justice (DOJ) first charged Larry Harmon, the primary operator of bitcoin mixers Helix and Ninja, in 2019, with three crimes — conspiracy to commit money laundering, operating an unlicensed money transmitting business, and conducting money transmission without a license. In October 2020, FinCEN assessed a civil monetary penalty of $60 million against Harmon for not registering Helix as a money service business. Finally, in August 2021, Harmon pleaded guilty to helping darknet market criminals launder around $300 million.

In April 2021, U.S. authorities arrested Roman Sterlingov — Russian-Swedish founder of bitcoin tumbling service Bitcoin Fog — for helping people launder $335 million. 

In its first government-wide list of priorities for AML/CFT, the FinCEN made virtual currency considerations one of its top priorities. Further, the FinCEN had also issued a warning, noting that in cases of hacks, criminals may leverage tools such as mixers and tumblers in order to break the connection between the sender address and the receiver address.

On October 6, 2021, the U.S. Department of Justice announced the National Cryptocurrency Enforcement Team (NCET), an enforcement team dedicated to investigating and prosecuting criminal misuses of cryptocurrency — in particular mixers and tumblers.

 On August 8, 2022, the U.S. Department of Treasury’s Office of Foreign Assets Control (OFAC) sanctioned cryptocurrency mixer Tornado Cash, which has been used to launder more than $7 billion worth of crypto since 2019. 

Tornado Cash is the most popular coin-mixing service on the Ethereum blockchain. The service offers a set of smart contracts that enable the user to obfuscate their funds by cutting the link between their original address and the address they eventually receive the funds in.

This is not the first time a crypto mixer has been sanctioned by the U.S. Treasury. In May 2022, the OFAC added the crypto mixing service Blender. io to its Specially Designated Nationals list. The OFAC revealed that the crypto currency mixer was used to process more than $20.5 million in the Ronin Network Attack, which the U.S. Treasury had linked to the North Korea- backed Lazarus Group. This move is the latest in the Biden Administration's efforts to disrupt the illicit flow of funds from cyberattacks, especially crypto-centric North Korean cyberattacks. The OFAC has added Tornado Cash and 44 associated Ethereum and USD Coin (USDC) wallet addresses to its SDN list.According to the OFAC, Lazarus Group used Tornado Cash to launder circa $450 million. In fact, Tornado Cash has been at the center of multiple recent hacks including the Ronin bridge attack, Harmony bridge exploit, Nomad heist, Beanstalk flash loan attack, and more.“Despite public assurances otherwise, Tornado Cash has repeatedly failed to impose effective controls designed to stop it from laundering funds for malicious cyber actors on a regular basis and without basic measures to address its risks. Treasury will continue to aggressively pursue actions against mixers that launder virtual currency for criminals and those who assist them.” warned Under Secretary of the Treasury for Terrorism and Financial Intelligence Brian E. NelsonTornado Cash is the most popular coin-mixing service on the Ethereum blockchain. The service offers a set of smart contracts that enable the user to obfuscate their funds by cutting the link between their original address and the address they eventually receive the funds in. As a result of today’s sanctions all property and interests in the property of Tornado Cash that is in the U.S. or in the possession or control of the U.S. persons are blocked and must be reported to OFAC. Moreover, U.S. persons or entities cannot interact with Tornado Cash.

Comments

All Comments

Recommended for you

  • Hedge Fund Net Exposure to US Tech Giants Reaches Record High of 22%

    On October 10, according to data from Goldman Sachs and The Kobeissi Letter, investor sentiment towards large tech stocks has reached an all-time high. Hedge fund net exposure to the 'Big Seven' tech giants in the US has risen to 22%, marking a historic peak; this figure has surged by 7 percentage points since July, representing the largest three-month increase in 2023, and surpassing the previous high of 21% set in June 2024 (compared to only 8% during the bear market low in 2022). During the same period, hedge fund net exposure to semiconductor stocks in the US has increased to 12%, slightly below the peak of 14% in June 2026, while this metric was only 2% at the beginning of 2025.

  • Anthropic Reveals Internal Issues: Out-of-Control AI Attempted to Access Multiple Government Websites, Reported to the White House

    Anthropic stated on Friday that its AI agents acted autonomously, attempting to access various federal, state, and local government websites. The company did not disclose which government agencies were involved but confirmed that it has reported these incidents to the White House. In a blog post, Anthropic mentioned that one of its AI models under testing had taken several unauthorized actions, including exploiting a vulnerability on a university website to download data and submitting a form to a government agency that it had been explicitly instructed not to submit. The company noted that it discovered these incidents after beginning a review of the AI's actions in July. Earlier on Friday, the Philadelphia Police Department stated that Anthropic had notified them that its technology had submitted a false homicide tip to the police website.

  • No Flights Departing or Arriving at Riyadh's King Khalid Airport Following Explosion Sounds

    On October 10, according to CCTV International News, witnesses reported that explosion sounds were heard at Terminal 3 of King Khalid International Airport in Riyadh, the capital of Saudi Arabia, this afternoon, leading to the evacuation of personnel from the airport. Flight tracking website 'FlightRadar24' indicates that there are currently no flights departing or arriving at the airport, and some flights heading to Riyadh have been diverted or returned. King Khalid International Airport has issued a traveler advisory, recommending that passengers contact their airlines to confirm flight status before heading to the airport.

  • BTC Surpasses $83,000

    Market data shows that BTC has surpassed $83,000, currently priced at $83,020.19, with a 24-hour decline of 0.2%. The market is experiencing significant fluctuations, so please ensure proper risk management.

  • ETH Surpasses $2500

    Market data shows that ETH has surpassed $2500, currently priced at $2500.03, with a 24-hour increase of 0.33%. The market is experiencing significant fluctuations, so please ensure proper risk management.

  • Houthi Forces Claim Saudi Airstrikes on Sana'a Airport in Yemen

    On October 10, according to information released by the Houthi forces in Yemen, on the afternoon of the same day local time, the Saudi-led coalition conducted airstrikes on Sana'a International Airport, which is under the control of the Houthi forces, dropping four bombs. Additionally, the Saudi coalition also targeted a communication facility in Hajjah Province, controlled by the Houthi forces, dropping three bombs. There has been no response from the Saudi side regarding these incidents. (Jinshi)

  • French Finance Committee Approves Amendments on Stablecoin Exchange Tax and Crypto Exit Tax

    On October 10, Decrypt reported that the Finance Committee of the French National Assembly approved two amendments related to cryptocurrency taxation this week: starting January 1, 2027, exchanges of stablecoins regulated under MiCA will be considered taxable sales; and an exit tax will be imposed on taxpayers who have been French tax residents for at least six of the past ten years and have moved abroad with crypto assets totaling over 800,000 euros. On October 9, the committee voted 31 to 3 to reject the budget revenue portion, and the full National Assembly will review based on the government's original text. The amendments will not be automatically included; supporters must reintroduce them during the debate starting on October 13, with a formal vote scheduled for October 20. The related measures have not yet become law. The stablecoin amendment was proposed by Nicolas Sansu, a member of the left-wing GDR party group, along with 16 co-signers, and does not set a new tax rate but aims to include the revenue under France's existing 31.4% flat tax system. The committee also passed an amendment allowing crypto asset losses to be carried forward for ten years to offset future gains.

  • Luxshare Precision: Company and Luxshare Technology Involved in 337 Investigation, Currently in Initial Filing Stage

    On October 10, Luxshare Precision announced that the company and its holding subsidiary, Dongguan Luxshare Technology Co., Ltd., have been listed as respondents in a 337 investigation by the U.S. International Trade Commission (ITC), involving U.S. Patent US 10,903,700. The ITC officially launched the investigation on October 9, 2026, with investigation number 337-TA-1526. The case is currently in the initial filing stage, and no substantial determination has been made regarding the relevant infringement claims. The products involved are in the customer verification stage and have not yet entered mass production.

  • South Korea's Financial Commission: Shareholding Restrictions for Exchange Major Shareholders Not Targeting Specific Companies

    On October 10, Lee Ik-yeon, chairman of the Financial Services Commission of South Korea, stated that the provisions regarding shareholding restrictions for major shareholders of virtual asset exchanges in the ongoing 'Basic Law on Digital Assets' are not aimed at specific individuals or companies. Instead, they are designed to ensure that exchanges, once institutionalized, bear a higher level of public responsibility. Currently, South Korean virtual asset exchanges operate under a system that requires updates every three years, but this will transition to a licensing system after the implementation of the 'Basic Law on Digital Assets.' Lee emphasized that exchanges have infrastructure attributes and must possess public accountability and responsibility commensurate with their status.

  • SVRN Acquires Infrastructure Platform FastNEAR

    On October 10, it was officially announced that NEAR Treasury Company SVRN has acquired the NEAR infrastructure platform FastNEAR. FastNEAR will join SVRN as a wholly-owned subsidiary, with its co-founders Evgeny (Eugene) Kuzyakov and Mike Purvis also joining the SVRN team. The announcement stated that FastNEAR is a high-performance RPC infrastructure provider behind NEAR applications and supports most of the data layer for NEAR, including server clusters for handling network read and write operations, archival infrastructure for storing complete transaction histories, and NEARDATA, a data source for developers to process these historical records.